Who Publishes is Accountable

The four preceding articles in this series explored the territory of artificial intelligence from the perspective of licensing, rights over outputs, the repositioning of the image market, and the value of professional work in this new context. There is one aspect that runs through all these themes but deserves its own treatment: the regulatory framework that is redefining obligations and responsibilities for companies using AI-generated content.

This is not a theoretical exercise. Between Italian Law 132/2025, the European AI Act (Regulation EU 2024/1689) and amendments to copyright legislation, the perimeter of what a company can and cannot do with AI content has changed substantially over the past year. And some operational deadlines are imminent.

Liability rests with the Publisher, not the Producer

The cardinal principle, often underestimated, is straightforward: the company that publishes content is responsible for that content, regardless of who materially produced it.

If an agency, a photographer or an external supplier delivers materials produced with the assistance of AI, and those materials are published by the commissioning company in a campaign, on a website, in a catalogue or on social media, legal liability falls on the company. Not on the supplier. Not on the AI platform. On the company that decided to make that content public.

This applies to the infringement of third-party rights, to the improper use of real people’s likenesses, to the dissemination of misleading content and, from 2025 onwards, to a series of specific obligations related to the artificial nature of the content itself.

The Marking Obligation: 2 August 2026

From 2 August 2026, the European AI Regulation imposes two distinct and complementary obligations.

The first concerns the providers of generation systems: synthetic content — images, video, audio, text — must be marked in a machine-readable format. Not a label visible to the user, but information embedded in the file itself declaring its artificial origin.

The second concerns whoever publishes: at the moment of first public exposure, the use of AI must be declared clearly and visually. The obligation is not generic — it applies specifically to contexts where the artificial nature of the content is relevant to the intended audience.

In operational terms, this means that every company commissioning or internally producing content with AI tools must establish a process that traces the nature of the content from production to publication. It is no longer sufficient to receive a file from a supplier and publish it: it is necessary to know how that file was produced and act accordingly.

Releases written before AI are no longer sufficient

Anyone who has worked in photographic production is familiar with model releases — the agreements signed by photographed subjects authorising the use of their image for specified purposes.

Releases drafted before the advent of generative AI present a specific problem today: they do not contemplate the possibility that the subject’s image might be used to generate variants, digital replicas or derivative content through artificial intelligence tools. A release signed in 2018 authorises the use of that specific photograph, under the conditions set out in the document. It does not authorise the creation of synthetic versions of that face, nor the use of the image as a reference to generate new content.

For companies holding photographic archives built over time — catalogues, campaigns, institutional materials — this is a concrete issue. Using those images as input for AI tools without having updated the releases creates exposure that the original clauses were never designed to cover.

The Criminal dimension exists

It is an aspect that many prefer to ignore in the belief that it concerns only extreme cases. It does not.

Article 612-quater of the Italian Criminal Code, introduced with recent amendments, punishes anyone who transfers, publishes or disseminates images, video or voices falsified or altered by AI systems, capable of inducing deception as to their genuineness and liable to cause unjust harm. The person punished is not whoever generated the content — it is whoever disseminates it without the consent of the person concerned.

To this will be added, through implementing decrees currently being finalised, new criminal offences related to the failure to adopt security measures on high-risk AI systems, with extension of corporate liability under the model of Legislative Decree 231/2001.

For a company using visual content in significant volumes — in fashion, food, cosmetics, real estate — the assessment of criminal risk is no longer an academic hypothesis.

A Misleading product is an Unfair commercial practice

There is an area of risk that specifically concerns sectors where the product image plays a decisive role in the purchasing decision.

An AI-generated image depicting a food product with visual characteristics different from reality, a cosmetic with visually amplified effects, a garment with an idealised fit, or a property with non-existent finishes may constitute an unfair commercial practice under consumer protection law. The consequences include proceedings by competition authorities and interventions by advertising self-regulatory bodies.

Traditional commercial photography has always operated with a degree of idealisation — studied lighting, post-production, styling. The difference is that AI can generate product representations bearing no relation to the physical reality of the object, and do so in a visually credible manner. The boundary between enhancement and deception becomes thinner, and the responsibility for maintaining it falls on the company that publishes.

Photography loses protection in transit between platforms

Italian copyright law provides that simple photographs — those lacking autonomous creative character, such as typical e-commerce product shots — are protected by related rights only if they carry certain information: the name of the photographer or commissioner, the date of production, and in the case of photographed artworks, the name of the artist.

In practice, this information is embedded in the file’s metadata. And metadata is systematically stripped in transit between websites, social media and distribution platforms. The result is that an image correctly attributed at origin circulates without any identification after its first redistribution, and the related rights become effectively unenforceable.

For companies investing in product photography, this is a concrete problem that predates AI and that AI amplifies: unprotected images can be extracted, used as training data and reproduced — wholly or in part — without the rights holder having effective means of opposition.

Insurance Policies may not Cover the risk

The final aspect concerns an assumption that many companies take for granted: insurance coverage.

Professional liability policies and product damage coverage were drafted, in most cases, before the use of AI-generated content became widespread practice. Some contractual wordings may exclude — explicitly or through interpretation — damages arising from the use of artificial intelligence tools in content production.

Similarly, the indemnification guarantees offered by AI providers have defined perimeters: they cover specific plans, include exclusions, and in no case constitute full coverage equivalent to a traditional insurance policy. Relying exclusively on the provider’s guarantee without verifying one’s own insurance coverage is a risk worth assessing before, not after.

The Italian and European regulatory framework on artificial intelligence is not yet complete — implementing decrees, case law and market practice will define many of the still-open contours in the coming months. But the operational deadlines are already set, responsibilities are already assigned, and the consequences for non-compliance are already established. For companies using visual content as part of their communication, the moment to review processes, contracts and coverage is not tomorrow.

Regulatory References

Here are the links to the official sources cited in the article, organized by theme:

    • Law No. 132/2025 — Artificial intelligence, text and data mining

https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/sg

    • Law No. 633/1941 — Copyright, simple photographs, mandatory indications

https://www.normattiva.it/atto/caricaDettaglioAtto?atto.dataPubblicazioneGazzetta=1941-07-16

    • Art. 612-quater of the Italian Criminal Code — Deepfakes, unlawful dissemination of AI-generated content

https://www.brocardi.it/codice-penale/libro-secondo/titolo-xii/capo-iii/sezione-iii/art612quater.html

    • EU Regulation 2024/1689 — AI Act, labelling obligations

https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=it

    • Legislative Decree No. 206/2005 — Italian Consumer Code, unfair commercial practices

https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2005-09-06;206

    • EU Regulation 2016/679 — GDPR, processing of biometric data

https://eur-lex.europa.eu/eli/reg/2016/679/oj?locale=it