3. the name of the artist who created the photographed work of art.
However, the issues surrounding image ownership in connection with the use of tools based on artificial intelligence remain entirely unresolved.
The practical effectiveness of this protection system is limited in two respects. On the one hand, companies rarely publish images with the photographer’s name and, in the absence of such information related rights are not enforceable against third parties, unless the rights holder can prove the reproducer acted in bad faith. On the other hand, even images that originally contain all the information in their metadata are frequently reposted and uploaded to other websites and platforms which remove them: if the information is not permanently affixed to the photograph, the file circulates without it and the related rights are not enforceable against third parties.
Withdrawal of Ai
Mining permitted within the limits of the law
Reproductions and extractions from works or other materials contained on the internet or in databases to which one has lawful access, for the purposes of text and data extraction using artificial intelligence models and systems, including generative AI, are permitted in accordance with the provisions of the Copyright Act.
Text and data extraction refers to any automated technique designed to analyse large quantities of text, audio, images, data or metadata in digital format with the aim of generating information, including patterns, trends and correlations.
Extraction is permitted where the use of the works and other materials has not been expressly reserved by the holders of copyright and related rights, or by the owners of databases.
For the lawful exercise of mining, it is therefore necessary for the third party to have lawful access to the content via licences or subscriptions, and for the rights holder not to have exercised their right of reservation. Furthermore, the legislation does not specifically regulate the procedures by which copyright holders should express their refusal to allow the use of images (the so-called opt-out).
The property
Software does not always grant exclusive rights
In addition to copyright issues, it is important to bear in mind that the models used to create AI-generated images do not always grant commercial licences or exclusive rights of use. This means that a company might create images without being able to use them for promotional purposes, or that others (even competitors) may use identical or similar images even before the promotional campaign has begun.
Most systems that allow users to generate images using AI have default settings which, if not changed, grant the provider the right to use the uploaded images for training purposes: settings that users often do not change or that the system does not allow them to change. Thus, for example, a company might upload photos of a new prototype, and the service provider might use those very same images to build or expand its own datasets; consequently, the model might generate images for other users that reproduce, in whole or in part, components covered by trade secrets.
Further checks are therefore essential, not least because there are various software licence agreements, the terms of which are, moreover, constantly being amended. If the company uses external suppliers, the relevant contracts must include specific clauses and conditions, including a prohibition on the use of systems that lack the appropriate safeguards.
Protections
Disclosure and labelling requirements
The advent of AI necessitates a complete redefinition of all the technical conditions and, above all, the legal conditions governing the production, use and protection of images. Processes, internal policies, controls and safeguards must be rigorous and extended to include external suppliers (photographers, post-production specialists, communications agencies) with whom the company works, thereby mapping out and monitoring the entire production chain leading to the final image.
This is not merely a matter of best practice. From 2 February 2025, Regulation (EU) 2024/1689 requires developers and professional users to ensure that their staff and collaborators have adequate expertise in AI. From 2 August 2026, system providers will be required to label synthetic outputs in a machine-readable format, and users will, in certain cases, be required to state clearly and visibly, at the time of first public display, whether or not content has been generated using AI. These deadlines are not affected by the current version of the EU’s Digital Omnibus extension measure.
Please note that the obligation to disclosure lies with whoever publishes the content and not (or not only) with whoever produced it: the professional using the AI tool must inform the client, but it is the company disseminating the material that must ensure the public is notified where necessary.
Companies will therefore need to put in place processes, internal control systems and prevention models (Legislative Decree 231/2001), all the more so given the forthcoming introduction of new categories of offences.
Insurance cover should also be checked carefully, as some policies on the market may exclude the risk of AI. Furthermore, the compensation offered by providers only covers certain plans, includes exclusions and does not constitute full cover.