AI in the workplace: who owns AI-generated content?

The letters AI beside a glowing circuit-board brain, illustrating ownership of AI-generated content at work

Copyright on AI-generated content only exists under Dutch law if a human made creative choices that are recognisable in the result. Text, images or code that ChatGPT produces from a short instruction and that is used unedited is in principle not a protected work, so nobody owns it and competitors are free to reuse it. Where an employee does add creative input, the copyright is in principle vested in the employer under article 7 of the Dutch Copyright Act (Auteurswet); with a freelancer or an intern it stays with that person unless it is transferred by a written deed.

That is the short answer, and it is also the reason why the terms of use of an AI provider settle less than they appear to. A provider can only grant what it holds; it cannot create a copyright that Dutch law does not recognise, and it cannot override the mandatory rules on employee works, moral rights or the transfer of rights. This article sets out how Dutch and EU law allocate the rights in AI-assisted work, where the infringement and confidentiality risks sit, which obligations the AI Act and the GDPR impose on employers in 2026, and which clauses and policies actually secure the position.

Does AI output qualify for copyright at all?

Dutch copyright protects works of literature, science or art that have their own original character and bear the personal stamp of the maker. The Court of Justice of the European Union applies the same threshold in EU terms: a work is protected if it is the author own intellectual creation, which requires free and creative choices. In the case law on that test, choices dictated by technical function or by rules leaving no creative room fall outside protection. An output generated by a model on the basis of a short prompt is the result of the system, not of human creative choices, and it therefore falls short.

The practical consequence is uncomfortable for businesses: the material sits outside copyright, which means it can be copied freely by anyone, including a competitor who finds it on your website. Unlike some jurisdictions outside the European Union, Dutch law has no separate category for computer-generated works and no fallback protection for the person who operated the machine. There is no registration route either, because copyright in the Netherlands arises automatically or not at all.

What changes the analysis is genuine human authorship. Selecting from several generated variants, reworking structure and formulation, combining fragments into a whole with its own composition, and making editorial choices that are visible in the final text can produce a protected work, either in the edited whole or in the human contribution to it. The more the human input is limited to accepting a first draft, the weaker the position. For anything that matters commercially, that argues for a documented editing step and for keeping a record of who did what, because in a dispute the burden of showing creative human input rests on the party claiming the right.

Two neighbouring rights can fill part of the gap. A substantial investment in obtaining, verifying or presenting a collection of data can attract database rights under the Databases Act (Databankenwet), independently of any copyright in the individual items. And material that is not protected at all can still be shielded commercially as a trade secret, provided it is kept confidential, which is exactly why the confidentiality regime discussed below matters more for AI output than it does for ordinary text.

Who holds the rights: employer, employee or freelancer

Where a protected work does arise, Dutch law allocates it by relationship rather than by who typed the prompt. Article 7 of the Copyright Act provides that if work carried out in the service of another consists in producing certain works, the employer is regarded as the author of those works, unless the parties agreed otherwise. The condition is that producing such material falls within the duties the employee performs; a marketing officer who writes campaign copy with an AI tool is squarely within it, while a warehouse employee who writes a novel in the evening is not. Article 8 covers works published by a legal entity as its own without naming a natural person as author, and there is a separate rule for works made after the design and under the direction and supervision of another person.

Outside employment the default reverses. A freelancer, an intern who is not employed, an agency or a consultant retains the copyright in what they make, and the client only acquires a licence to the extent that the assignment implies one. Transfer requires a deed: article 2 of the Copyright Act demands a written instrument intended for that purpose, and an exchange of e-mails or an invoice reference is not enough. Signing that deed before or at the start of the assignment, rather than after delivery, avoids the awkward position in which the supplier holds the rights to material you have already published. The same applies to exclusive licences, which likewise require a deed.

Moral rights stay with the human author even where the economic rights sit elsewhere. Under article 25 of the Copyright Act the author can oppose publication without attribution, alterations to the name, and changes to the work; the right to oppose distortion or mutilation that could damage the author honour or reputation cannot be waived at all, while the other moral rights can be waived by agreement. In practice this rarely bites for routine business copy, but it matters for design, photography, architecture and creative campaign work where an AI tool was used as part of a human creative process. Our intellectual property lawyers deal with these allocations and with the related publication and portrait rights questions that arise when generated images resemble real people.

Patents follow their own logic and should not be assumed to travel with copyright. An inventor under the European and Dutch patent systems is a natural person; a model cannot be named as inventor. Where an employee makes an invention in the course of duties that entail inventive work, the entitlement to the patent belongs to the employer under the Patents Act 1995 (Rijksoctrooiwet), and the employee may be entitled to fair compensation where their salary does not reflect the invention. The greater danger with AI drafting is disclosure rather than ownership: circulating a draft claim set or a technical description outside a confidential circle before filing can destroy novelty, and novelty once lost cannot be restored.

What platform terms do and do not settle

The terms of use of the major AI providers typically state that, as between provider and user, the rights in the output belong to the user, and that the user is responsible for the prompts submitted and for the way the output is used. Those terms usually also contain an indemnity in favour of the provider, a right to suspend the account for breach of the usage policy, and specific rules for business and enterprise plans on whether input may be used to train models. Terms change without warning, so the version to rely on is the one in force at the moment of use, not the one summarised in a blog post.

Three limits are worth internalising. First, a provider can only transfer what it has: if the output attracts no copyright under Dutch law, the clause hands over an empty box. Second, no clause makes the output free of third-party rights; if the generated material reproduces protected expression, the rightholder addresses the party that published it, and the contractual indemnity runs in favour of the provider rather than in favour of you. Third, mandatory Dutch and EU rules prevail over the terms regardless of the choice of law: the employee copyright rule, the deed requirement for transfers, the non-waivable part of moral rights, and the whole of data protection law.

The operational conclusion is simple. Have staff work in corporate accounts under company control rather than in private ones, so that the account holder is the company and the audit trail exists; agree in the licence and service terms with the provider where data are stored and whether input is used for training; and align what your employment contracts, contractor agreements and internal policy say about ownership with what the platform terms actually provide.

When AI output infringes someone else rights

The risk that goes with unclear ownership is infringement, and it lands on the publisher. If generated text, an image or a block of code reproduces protected expression from a third party in recognisable form, publishing it is a reproduction and a communication to the public for which permission is needed. Dutch law has no general fair use defence; the exceptions are limited and specific, and they are interpreted narrowly. The quotation right in article 15a of the Copyright Act allows quotation in a context such as an announcement, review or scientific treatise, provided the work was lawfully made public, the quotation is proportionate, the source and the author name are stated, and the moral rights are respected. That does not cover a generated passage that silently absorbs someone else phrasing.

The text and data mining exceptions introduced in the Copyright Act to implement the EU directive on copyright in the digital single market concern the analysis of lawfully accessible material, with a broad exception for research organisations and a general exception for other uses that rightholders may reserve in an appropriate machine-readable manner. Those exceptions govern the training of models rather than your use of the output, but they explain why the debate about what a model has ingested is a live one, and why the AI Act now requires providers of general-purpose models to have a copyright policy and to publish a sufficiently detailed summary of the content used for training.

Software deserves separate attention. Generated code can reproduce fragments from open-source repositories, and open-source licences carry conditions: attribution, preservation of licence notices and, for copyleft licences, an obligation to make the source of derived work available under the same terms. That obligation can be incompatible with a proprietary product. Practical controls are code-similarity and licence scanning in the build pipeline, a rule that generated code is reviewed by a named developer before it is committed, and retention of prompt and version history so that independent creation can be demonstrated if a claim is made. Where a dispute does arise, the response is the same as for any other IP conflict, and our guide on intellectual property disputes in the Netherlands sets out the routes available.

Reputational exposure runs alongside the legal exposure, and it is not repaired by winning. Generated material also carries factual risk: invented figures, fabricated citations and non-existent case references in a client report are not a copyright problem but they are a professional one, and a review step by someone who can judge the substance is the only control that catches them.

Prompts, trade secrets and confidentiality

What goes into the model matters as much as what comes out. Under the Trade Secrets Act (Wet bescherming bedrijfsgeheimen), which implements the EU trade secrets directive, information is protected as a trade secret only if it is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. Pasting a draft contract, a client list, source code or an unpublished invention into a consumer AI account is difficult to reconcile with reasonable steps, and once protection is lost it does not come back. The remedies under the Act, including injunctions and damages, depend on having taken those steps beforehand.

The same applies to information you hold under a duty of confidentiality towards a client or a counterparty. A non-disclosure agreement usually restricts disclosure to third parties, and submitting the information to an external AI service can be exactly that, particularly where the provider may use input for training. Enterprise arrangements that exclude training use and keep data within the European Economic Area reduce the problem but do not remove the need to check the contract you signed with your own client.

Prompts themselves can be valuable. A refined prompt library, a system message tuned over months or a retrieval configuration is know-how that competitors would like to have. Treat it accordingly: store it with access control, mark it as confidential, cover it in confidentiality and IP clauses in employment and contractor agreements, and remember that departing employees take with them what they can remember, which is why a well-drawn confidentiality clause is worth more than a slogan about innovation. Where the material relates to employees rather than clients, the rules on employer rights and obligations apply in parallel.

What the AI Act and the GDPR require of employers in 2026

Two European instruments apply directly to workplace AI use and neither is optional. The AI Act has been phasing in since 2024. The prohibitions on unacceptable practices have applied since 2 February 2025, and among them is the prohibition on inferring emotions of workers in the workplace outside medical and safety purposes, which rules out a category of monitoring tools that vendors still market. The obligation to promote AI literacy among staff who work with these systems also applies: employers must take measures so that the people using the tools understand what they do and where they fail. Obligations for providers of general-purpose AI models have applied since 2 August 2025, and the transparency rules in article 50 became applicable on 2 August 2026, with the specific marking obligation for providers of systems generating synthetic content postponed to 2 December 2026.

Article 50 is the provision that touches everyday publishing. It requires that AI-generated or manipulated content be marked in machine-readable form by the provider, that people be informed when they interact with an AI system, and that a deployer publishing AI-generated text to inform the public on matters of public interest disclose that the text was artificially generated, unless a human has reviewed it and someone bears editorial responsibility for it. For a company blog or a newsroom that is a workable rule: keep a human editor in the loop and be able to show it. The obligations for high-risk systems were postponed by the digital omnibus package, to 2 December 2027 for the systems listed in Annex III, which include recruitment and employee-management uses, and to 2 August 2028 for the Annex I products; the postponement concerns the timing, not the content, of those duties.

The GDPR applies to every prompt containing personal data, and it does so from the moment the data are submitted. The employer is the controller for that processing and needs a lawful basis, a purpose limitation, a retention period and a processor agreement with the provider; transfers outside the European Economic Area need an appropriate transfer mechanism. Special categories of data, such as health data in an HR context, require an exception under article 9 GDPR that is rarely available for a convenience use. Where AI is used for decisions about people, article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and a data protection impact assessment will usually be required for systematic monitoring or evaluation of staff.

There is also a Dutch layer that is easy to forget. A scheme for monitoring or checking the presence, conduct or performance of staff requires the consent of the works council under article 27 of the Works Councils Act (Wet op de ondernemingsraden). An AI usage policy that logs prompts, measures output or evaluates performance falls within that description, and a policy introduced without works council consent can be challenged. Involving the works council early is faster than repairing the policy afterwards, and it fits the broader framework of Dutch employment law obligations towards staff.

Where things go wrong in practice

Four patterns account for most of the disputes that reach a lawyer. The first is the published marketing text or design that turns out to be unprotected: a competitor copies the campaign, and the company discovers that there is no right to enforce because no human creative choice can be shown. The remedy is preventive rather than curative, and it consists of documented editing and, where the material carries real value, a trade mark or design registration for the elements that can be registered.

The second is the freelance deliverable without a deed of assignment. The client has paid, published and built on the material, and only when the relationship ends does it emerge that the copyright never moved. The supplier is then in a strong bargaining position, and the client is exposed on exactly the assets it thought it had bought. Due diligence in a financing round or an acquisition tests precisely this chain of title, which is why the gap tends to surface at the worst possible moment.

The third is generated software that carries an open-source licence with it. The obligation attaching to copyleft components can be incompatible with a proprietary distribution model, and the fix, once the code is embedded, is either rewriting or negotiating. Licence scanning at commit time costs a fraction of that.

The fourth involves people rather than assets. An employee who used a private account, took the prompt library to a new employer or published a client document through an external service raises questions of confidentiality, of the non-competition or relationship clause and of the employment relationship itself. Those situations are usually resolved by agreement rather than by litigation, and a settlement agreement that also covers the return and deletion of material is the instrument for it. The condition for negotiating from a position of strength is, again, documentation: which account, which tool, which files, and what the contract and the policy said at the time.

Contracts and policies that actually secure the position

Copyright on AI-generated content is settled in three documents, and each covers a different relationship. The employment contract should state that rights in works, software, designs, data and other material created in the performance of duties belong to the employer, whether created with or without AI tools, and should record consent to the modification of such material to the extent that moral rights allow. It should also oblige the employee to use only approved tools and corporate accounts and to observe the confidentiality rules on prompts. Employers who want that obligation to have teeth can attach it to the disciplinary framework, and a penalty clause in the employment contract is possible, provided the statutory requirements for such a clause are met.

Contracts with freelancers, agencies and interns need an assignment in a signed deed covering existing and future rights in the deliverables, plus a warranty that the material does not infringe third-party rights and an indemnity for claims that it does. Ask expressly whether AI tools were used, require disclosure of open-source components in code, and countersign before the first payment; a transfer agreed after delivery leaves an interval in which the supplier held the rights, and an intern working without a written arrangement is the most common gap of all.

The third document is the internal AI policy. It should name the approved tools and prohibit private accounts for company work, state what may never be entered into a prompt, require a named human reviewer before publication or commit, set a retention rule for prompts and drafts that matches the retention rules elsewhere in the organisation rather than an arbitrary period, and assign responsibility for keeping the tool list current. Keep it short enough to be read, and align it with the confidentiality, privacy and security policies already in force. Where the policy touches monitoring, involve the works council. And where staff-facing consequences are attached to it, check the wider obligations employers have under Dutch law before enforcing it.

International teams: which law and which court

Ownership questions do not always fall under Dutch law. Copyright is territorial, and the protection of a work in a given country is judged by the law of that country, while the contractual relationship between the parties is governed by the law they chose or, absent a choice, by the law that follows from the European conflict rules. Employment relationships have their own protective rules that cannot be set aside by a choice of law, so an assignment clause that would be valid under one system may still run into mandatory rules in the country where the employee habitually works.

Some jurisdictions outside the European Union take a different view of machine-generated material, and a team spread over several countries can end up with the same output protected in one place and free in another. That is a reason to be explicit rather than to hope for the best: agree the governing law and forum in your contracts with contractors and vendors, apply the strictest standard in your policy so that it works everywhere, and record who created what and where. For groups of companies, an intra-group licence or assignment structure keeps the rights where the business needs them. The shareholders agreement and related corporate documents should reflect that structure when the IP is a material asset of the company.

What to do next

Start with an inventory: which teams use which tools, on which accounts, for which output, and what has already been published. Then close the contractual gaps in this order: employment contracts and the AI clause, the deed of assignment for every contractor and intern who has delivered material, and the vendor terms for the tools you keep. Add a review step before publication, a similarity and licence scan for code, and a record of prompts and drafts for anything commercially significant. Finally, check whether your use falls into a category that the AI Act treats separately, in particular in recruitment and staff management, and whether the works council must be involved.

Copyright on AI-generated content is, in the end, secured by process, not by a clause alone: human creative input is what creates a right, documentation is what proves it, and confidentiality is what protects the material for which no right exists. For copyright questions on published material, our articles on copyright on photos and on when content is public deal with two of the situations that come up most often.

Law & More advises employers, agencies and technology companies on the ownership of AI-assisted work, on AI policies and works council involvement, and on contracts with employees, freelancers and vendors. We also act where a claim of infringement is made or received. Please contact Law & More if you would like your position reviewed, and see our overview of employment law in the Netherlands for the wider workplace framework.

Frequently asked questions

Who owns the copyright in content generated by ChatGPT under Dutch law?

Under OpenAI’s terms, the user generally owns the output, but under Dutch and EU copyright law, protection only arises if a work is the author’s own intellectual creation, requiring genuine human creative choices. Purely machine-generated text accepted as-is with minimal human input may fall outside copyright altogether and sit in the public domain, unless meaningful human editing, selection or arrangement adds the necessary creative spark.

What does OpenAI’s terms of service say about ownership of ChatGPT output?

OpenAI’s terms state that, subject to compliance with its policies, the user owns all rights, title and interest in the output generated. However, users must indemnify OpenAI against claims arising from prompts and output, and violating the usage policy can void the licence and retroactively strip the ownership grant.

Can Dutch law override the ownership terms set out by an AI platform like OpenAI?

Yes, in several ways. Dutch courts first assess whether a work meets the originality threshold before any copyright can exist at all. Moral rights under Article 25 of the Dutch Copyright Act are inalienable, so an employee-author can still object to alterations of highly creative AI-assisted work even after assigning economic rights. Consumer protection rules can also invalidate unfair indemnity clauses for freelancers, and GDPR obligations override conflicting licence terms if personal data is entered into prompts.

Can an employer claim ownership of AI-generated content created by an employee?

It depends on the employment contract and internal policies, which can outrank the platform’s boilerplate terms. Employers should check whether employment contracts and workplace policies clearly address ownership of AI-assisted work, since this internal agreement can determine who ultimately holds the rights, separate from what the AI provider’s terms state.

Does using freelancers or gig workers to generate AI content change the ownership picture?

Yes. Unlike employees, freelancers, interns and gig workers are not automatically covered by the same work-related ownership assumptions, so contracts with these workers need explicit clauses addressing who owns AI-generated output, to avoid disputes over rights to content created using tools like ChatGPT.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Protect yourself from cybercrime in the Netherlands! Explore Dutch laws, understand your rights, and learn

Dutch law prohibits traders from using unfair commercial practices towards consumers, and it does so

GDPR and AI in the Netherlands come together at one point: as soon as an

Dutch criminal law distinguishes three offences against reputation. Insult is an expression that serves only

Almost every international company operating in the Netherlands buys computing capacity from someone else. The

High-risk AI systems are the focal point of the European AI Regulation (Regulation (EU) 2024/1689),

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.