Try “Veo”, “voiceover”, “thumbnail” or “Descript” · Esc to close

🏢 Teams & agencies · Guide 1 of 2

Rights, Watermarks and AI Disclosure: A Team Policy

11 min read · Last reviewed 25 Sep 2026

Your team probably uses a dozen AI tools, on a mix of free trials, personal subscriptions and one or two company plans. Each tool has its own rules on commercial use, watermarks, likeness and labelling. Most of the risk sits in the gaps between those rules. A designer exports a free-plan clip for a client ad. A freelancer clones a voice nobody signed off on. An editor re-saves an image and strips the provenance data a platform was going to read.

This guide is a policy template you can adapt, then a one-page checklist to pin in your team channel. It is not legal advice. For the tool-by-tool details, keep /rights and /disclosure open next to it. We update both as vendors change their terms.

Rule 1: the plan tier decides what you may publish

Commercial rights are rarely a property of the tool. They come with the plan. Across the listings in this directory, the same pattern keeps appearing: the free tier is for trying things out, and publishing for a client starts on a paid tier. Sometimes it starts on the second paid tier. At the time of writing:

ToolFree planWhere commercial use startsThe catch
ElevenLabsPersonal use onlyStarter (lowest paid tier)Music for film, TV and studio games needs an Enterprise licence
Kling AIWatermarked, no commercial rightsEvery paid tierNothing made on the free plan becomes commercial later
PikaNo watermark, no commercial licenceCreator, not StarterA paid plan is not always a commercial plan
SunoPersonal, non-commercialPro and PremierSubscribing later does not convert free songs. Downloads are capped
MidjourneyNo free planAll paid plansCompanies over $1M gross revenue must be on Pro or Mega. Images are public unless you use Stealth Mode
Microsoft Copilot (consumer)Personal useNot in consumer plansUse the business Copilot plans for work

Two lessons for the policy follow from this table.

No watermark does not mean you have the rights. Pika's free plan exports clean files and still grants no commercial licence. The reverse also happens: Kling AI removes the watermark and adds commercial use in the same step. Treat the watermark as a sign of which plan was used, never as permission.

Rights are tied to when you made the asset, not when you publish it. On Suno, songs made on the free plan stay non-commercial even after you upgrade. So the policy has to ask "what plan was active when this was generated?" That question is hard to answer months later unless someone wrote it down.

Rule 2: every asset carries a rights record

The fix is dull but it works. Every AI asset that could reach a client or a public channel gets five fields in your asset library, project tracker or file naming scheme:

  1. Tool and model (for example "Firefly Image" or "partner model inside Firefly", because the rules differ).
  2. Account and plan at the time of generation (company Pro seat, not "Sam's trial").
  3. Date generated.
  4. Inputs that carry third-party rights: uploaded stock, client photos, a person's face or voice, reference tracks.
  5. Disclosure needed? Yes, no, or which platforms.

Ban personal accounts for client work. This one rule removes most plan-tier problems, because finance can see exactly which plans the team pays for. It also keeps company prompts and outputs out of consumer terms. Some of those terms, like consumer Copilot's, limit use to personal purposes.

Watch for tools that switch models under you. Multi-model apps such as Adobe Firefly treat their own models differently from partner models. Adobe says Firefly-model outputs are designed to be commercially safe, while for partner-model outputs you judge suitability yourself. Your record needs the model, not just the app. The model map shows which apps route to which models.

AI tools make it very easy to use someone's face or voice. That is exactly where teams get into trouble.

  • Avatars. HeyGen's moderation policy requires the explicit consent of anyone you make an avatar of. Synthesia says it enforces consent requirements for avatars. Your policy should add one thing the tools can't check: consent must be written, name the uses (ads, organic, internal training), the markets and the time period, and say how it can be withdrawn.
  • Voice clones. ElevenLabs asks you to confirm consent for cloning. A Professional Voice Clone must be your own voice, checked with a read-aloud voice captcha. When a client wants a spokesperson's voice, the spokesperson clones it on an account the client controls, and your team gets access. Never clone a voice from YouTube clips.
  • Stock and templates. Editors mix licensed assets into AI projects, and licences don't always carry across. CapCut checks commercial use asset by asset, and one non-commercial element limits the whole export to non-commercial use. CapCut's terms also give it a broad licence to content you upload, which matters if you upload unreleased client material.
  • Fake people giving testimonials. In the US, the FTC's rule on consumer reviews and testimonials bans reviews and testimonials from people who don't exist, including AI-generated ones. An AI avatar reading a script is an ad. An AI avatar presented as a real customer describing their experience is a fake testimonial. Your video ad scripts must never cross that line.

Rule 4: know who carries the risk if a claim arrives

IP indemnity means the vendor promises to defend you, and usually to pay, if someone sues claiming the output infringes their rights. Few plans include it, and those that do attach conditions:

  • Adobe Firefly: IP indemnification applies only to eligible enterprise customers and select Firefly outputs. Partner models are not covered.
  • Krea and Stable Audio: indemnification for enterprise customers under their agreements.
  • Microsoft: the Copilot Copyright Commitment covers paid commercial Copilot services. You must use the built-in content filters and not try to generate infringing material.
  • Creatify: IP assignment on Enterprise.
  • Midjourney: no IP indemnity on any plan.

Vendors rarely say this plainly: indemnity on a $20 seat is almost unheard of. If your agency promises clients that AI assets are "cleared", you are carrying that risk yourself. Decide in the policy which work needs an indemnified tool, for example national paid campaigns and packaging. Then decide which work can use anything with a commercial licence, like organic social and internal drafts.

Rule 5: put AI in the client contract, both ways

Add a short AI clause to your master services agreement or statement of work:

  • Permission and scope. The client agrees that AI tools may be used, or lists where they may not be used (for example no synthetic people, or no AI in regulated product claims).
  • Tool list. Name the approved tools, or the rule for approving them. Some clients will want to see the list.
  • Ownership language that matches reality. Many vendors assign output rights to you. That is a promise from the vendor, not a guarantee that the output is protectable or non-infringing. Don't warrant more to the client than your vendors warrant to you.
  • Client inputs. The client confirms it owns, or has licensed, the photos, logos, voices and likenesses it supplies.
  • Disclosure duties. Say who applies platform labels, and that the client may not remove them.
  • Data. Say whether client material may be uploaded to tools that train on inputs. Check each vendor's data settings before you agree.

Rule 6: label where each platform asks, the way it asks

Platforms mostly care about realistic content: a real person saying something they didn't say, altered real events, or lifelike scenes that never happened. They care much less about script help, colour grading or obvious fantasy. The practical summary, based on our /disclosure research:

WhereWhat must be labelledHow
YouTubeRealistic altered or synthetic content a viewer could mistake for realYouTube Studio > Details > "AI use" when uploading
TikTokAI or heavily edited realistic people or scenes, including voice mimicryThe AIGC label when posting, or a clear caption, sticker or watermark
Instagram, Facebook, ThreadsPhotorealistic video or realistic audio that was created or alteredMeta's AI disclosure and label tool when posting
LinkedInSynthetic media showing a person doing or saying what they didn'tNo toggle: disclose in the post or on the media. C2PA credentials show an icon
Google SearchNo visible label requiredKeep IPTC "TrainedAlgorithmicMedia" in AI images; label AI product data in Merchant Center
Google and Meta election or issue adsRealistic synthetic people or eventsThe synthetic content checkbox in the ad settings
Apple PodcastsAI voices, AI hosts, replicas of real peopleProminent disclosure in the audio and in episode and show metadata
Amazon KDP / ACXAI-generated text, images or translations (KDP); ACX bans unauthorised AI narrationThe KDP publishing questions; use KDP virtual voice for AI audiobooks

Spotify has no general AI-labelling duty, but it removes unauthorised voice clones, and AI credits go through your distributor. Several platforms, YouTube and Meta among them, add labels themselves when they detect AI content or C2PA data. So an unlabelled post can get labelled anyway, and repeat failures to disclose can lead to penalties. If you publish in China, the labelling measures in force since 1 September 2025 require you to declare AI content when you post, and forbid removing labels.

The team rule: the person who schedules the post applies the label, and the rights record says whether one is needed.

Rule 7: the EU AI Act changes the default from August 2026

Article 50's transparency duties apply from 2 August 2026. For marketing teams, the part that matters is for deployers, meaning anyone using AI professionally:

  • Deepfakes (realistic image, audio or video that could pass as real) must be disclosed clearly, at the latest at first exposure. Creative, satirical or fictional work gets a lighter duty: disclose in a way that doesn't spoil the work.
  • AI-generated text published to inform the public on matters of public interest must be disclosed. The exception is text that went through human review or editorial control, where a person or company holds editorial responsibility. Your editorial sign-off is part of your compliance, so record it.
  • Providers of generative tools must mark outputs in a machine-readable way. There is a grace period to 2 December 2026 for systems already on the market.

Fines for breaching these duties can reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher (Article 99). If any campaign reaches EU audiences, make platform labels plus a visible caption or on-screen note the default for realistic synthetic media. Don't decide it post by post.

Rule 8: keep Content Credentials intact

Content Credentials (the C2PA standard) are signed metadata that record how a file was made. Several generators attach them. Adobe says all Firefly outputs include Content Credentials. OpenAI's image model adds C2PA plus Google DeepMind's SynthID watermark, and Google pairs SynthID with C2PA for Nano Banana. TikTok, Meta, YouTube and LinkedIn read C2PA to label or show provenance, and Pinterest reads IPTC metadata.

That works in your favour only if the data survives your pipeline. Re-exports, screenshots, compression and some editing steps can drop it. The policy:

  • Export from the original file, not a screenshot or a screen recording.
  • Test each step once. Run a sample file through your editor, scheduler and CMS, then check whether the credentials are still there with the Content Credentials inspect tool.
  • Never strip metadata to avoid a label. Platforms such as YouTube and TikTok can apply labels themselves, and China's rules forbid removing labels outright.

The one-page checklist

Pin this where the team works:

  • [ ] Client work only on company accounts, on plans with a commercial licence.
  • [ ] Rights record on every asset: tool, model, plan, date, third-party inputs, disclosure.
  • [ ] Nothing made on a free plan goes to a client, watermark or not.
  • [ ] Written consent on file for every face, voice and avatar, naming uses, markets and time period.
  • [ ] No AI "customers" giving testimonials.
  • [ ] Indemnified tools for campaigns the policy marks high-risk. Everything else gets a commercial licence at minimum.
  • [ ] AI clause signed in each client contract: permission, tools, inputs, labels, data.
  • [ ] The person who schedules the post applies the platform's AI label.
  • [ ] EU audiences: realistic synthetic media is labelled by default. Editorial sign-off is recorded for public-interest text.
  • [ ] Content Credentials are checked after export and never removed.
  • [ ] One owner reviews /rights and /disclosure every quarter and updates this list.

Takeaways:

  • Rights come from the plan and the date the asset was made, not from the tool's name or the missing watermark.
  • Consent and indemnity are where vendors' promises end, so your contracts have to cover the rest.
  • Labelling is mostly about realistic people and events. From August 2026, the EU makes disclosure the safe default.
  • Provenance metadata protects you only if your export pipeline keeps it.

More for teams at /guides/business.

Read the official docs for…

Mentioned in this guide

The rest of this level

  1. Rights, Watermarks and AI Disclosure: A Team Policy
  2. Keeping One Brand Voice Across Every AI Tool

All four levels →