Tag: AI Governance

  • Disney v. Midjourney and the Broader Copyright Question for AI Users

    Disney v. Midjourney and the Broader Copyright Question for AI Users

    Disney v. Midjourney makes the AI copyright fight more concrete.

    The case is about training data, but it is also about outputs that allegedly look too much like famous protected characters and franchise imagery.

    What the case is actually about

    Disney, Universal, and affiliated rights holders sued Midjourney in federal court in Los Angeles on June 11, 2025.

    The case is:

    • Case: Disney Enterprises Inc. v. Midjourney Inc.
    • Court: C.D. Cal.
    • Docket: 2:25-cv-05275
    • Status: pending

    The studios' position is straightforward. They say Midjourney was built using copyrighted works and that the service can generate outputs that are too close to protected characters and expressive elements. The complaint reportedly includes example prompts and output images involving well-known properties, which is part of why the case landed so clearly in public discussion.

    Two examples from the complaint show why the output issue is getting so much attention:

    Cropped complaint comparison image showing an alleged Midjourney Homer Simpson output beside Disney reference images.
    Cropped complaint comparison image showing an alleged Midjourney Homer Simpson output beside Disney reference images. Source: Complaint, Disney Enterprises Inc. v. Midjourney Inc., No. 2:25-cv-05275 (C.D. Cal.), page 32.
    Cropped complaint comparison image showing an alleged Midjourney Minions output beside Universal reference images.
    Cropped complaint comparison image showing an alleged Midjourney Minions output beside Universal reference images. Source: Complaint, Disney Enterprises Inc. v. Midjourney Inc., No. 2:25-cv-05275 (C.D. Cal.), page 51.

    Midjourney’s likely response is also familiar. Training is not the same as republishing a work. Not every prompted image is substantially similar enough to infringe. And not every reference to a known character, franchise, or visual style cleanly collapses into liability for the platform.

    That is why this case matters. Both sides are arguing about where the legal line sits when a model produces commercially useful images that unmistakably evoke existing protected expression.

    Can businesses use Midjourney images commercially?

    Midjourney’s published guidance says customers generally own the images and videos they create and may use them commercially, subject to its terms and plan requirements. For businesses with more than $1 million in annual gross revenue, Midjourney says a Pro or Mega Plan is required for commercial use.

    That contractual permission is only one part of the analysis. It does not guarantee that a particular output is noninfringing, that the user owns every element in the output, or that the output qualifies for copyright protection. Midjourney’s terms provide the service and assets on an “as is” basis, disclaim a warranty of noninfringement, and place responsibility for using or redistributing assets on the customer.

    For business use, the practical controls should include:

    • confirming that the account and subscription plan permit the intended commercial use;
    • screening prompts and outputs for recognizable characters, logos, protected expression, and other third-party rights;
    • retaining records of prompts, source materials, edits, and human review;
    • requiring additional clearance before using AI-generated images in prominent campaigns, products, or customer deliverables; and
    • reviewing vendor terms regularly because platform rules and protections can change.

    Commercial-use permission from the platform answers whether Midjourney permits the use. It does not answer whether a rights holder may challenge it.

    Related Clearon AI analysis: OpenAI copyright MDL and data governance and AI-generated code and copyleft risk.

    The bigger issue

    For companies, the issue is not just whether Midjourney wins or loses.

    It is whether the business has decided what level of copyright and brand-adjacent risk it is actually willing to accept when employees use generative AI in public-facing work.

    Many legal teams are comfortable saying obvious character replication is out of bounds. The harder question is the gray zone. Is the company willing to rely on a fair use argument if a marketing image is styled to evoke Disney, South Park, or another highly recognizable visual world? Is it comfortable arguing that a prompt drew on a style, not a protected work? Is it willing to defend that position after publication, in a customer campaign, or in court?

    That is the governance issue this case sharpens. Companies need a view on where they are comfortable being aggressive, where they want to be conservative, and which arguments they are actually prepared to stand behind if challenged.

    They also need to account for contract risk, not just copyright doctrine. Most, if not all, major AI image providers put the user on the hook for at least some infringement risk tied to prompts, inputs, or outputs. Even when a vendor offers limited indemnity, it is often narrow and conditional. So a company deciding to operate in the gray zone may also be deciding that it, not the service provider, will carry much of the downstream claim risk.

    The Clearon AI takeaway

    Disney v. Midjourney turns AI copyright risk into a risk-allocation question for users, not just model developers.

    The practical lesson is less “never touch this” and more “decide, in advance, which copyright arguments your company is truly willing to own.”

    Sources

  • The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK's recent data-law changes matter for AI governance because they suggest a real break from the EU approach to automated decision-making.

    If you want the official legislation, the UK law is here: Data (Use and Access) Act 2025.

    Under section 80 of the Data (Use and Access) Act, the UK has replaced the old Article 22 framework with a more permissive structure: automated decision-making with safeguards, rather than a prohibition-first starting point.

    This is a real shift

    Under the classic Article 22 model, the analysis usually began with a restriction. The UK's newer approach is more operational and less categorical. The question becomes less "is this forbidden unless an exception applies?" and more "what safeguards, transparency, and review rights are required when this happens?"

    That may sound subtle, but it matters. It gives companies more room to deploy automated systems, while also increasing pressure to justify how those systems are used.

    What multinational teams should watch

    A lot of organizations still hope they can run one clean global policy for AI-enabled decision-making. The UK’s move makes that harder. If the EU and UK keep drifting apart here, legal teams may need separate assessments for profiling, scoring, and model-driven recommendations that affect individuals.

    That does not just affect flashy AI products. It can reach ordinary systems used in employment, insurance, financial services, fraud detection, customer eligibility, and prioritization workflows.

    The takeaway

    The UK is not abandoning regulation. It is choosing a different posture. A permission-with-safeguards model still requires governance, and in some ways it requires better governance because companies have more room to act.

    Cross-border AI compliance is starting to look less like one policy problem and more like jurisdiction management. That is the part legal teams should plan around now.

  • Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois is becoming one of the clearest examples of where employment AI regulation is heading: notice, documentation, and practical scrutiny of how tools influence decisions.

    If you want the official bill history, Illinois’s law is here: HB 3773. The Illinois Department of Human Rights also has a direct summary page here: Artificial Intelligence in Employment.

    Recent draft rules from the Illinois Department of Human Rights would implement the state's newer restrictions on AI discrimination in employment. The bigger point is the compliance model taking shape around them.

    The trigger looks broad

    The reported standard is not limited to futuristic hiring bots. The rules would apply when AI is used “to influence or facilitate” covered employment decisions, including recruiting, hiring, promotion, discipline, discharge, training selection, and terms or conditions of employment.

    That deserves attention because the notice trigger may be broader than many employers expect. If AI is involved in screening resumes, targeting job ads, evaluating candidates, analyzing interviews, or helping shape employment outcomes, notice may be required even if the employer did not intend discrimination.

    Employment AI is becoming an operations issue

    The trend line is clear: employment AI law is moving away from “prove the tool caused unlawful bias first” and toward “tell people when the tool is in the process, document what it is doing, and be ready to defend the workflow.”

    That is why legal teams need a real inventory of where AI shows up in the employment stack, not just in one recruiting product. AI can appear in sourcing, ranking, interview analytics, assessments, chatbots, promotion systems, and workforce-monitoring features.

    The takeaway

    The answer is not to ban every automated feature. It is to map the tools, define which ones influence covered decisions, and decide where notice, contract review, testing, and documentation are required.

    Illinois is sending a simple message: if AI helps shape employment outcomes, silence is not a compliance strategy.

  • California Is Using Procurement Power to Shape AI Governance

    California Is Using Procurement Power to Shape AI Governance

    California's latest AI move did not come through a broad consumer AI statute. It came through procurement.

    If you want the official source, California’s executive order is here: Executive Order N-5-26.

    In March 2026, Governor Gavin Newsom issued Executive Order N-5-26, directing the state to build a new procurement framework for AI. That may sound narrower than a headline AI law, but it could matter just as much for companies that sell AI tools or services into large buyers.

    Procurement is where AI governance gets real

    The order points toward a system in which AI vendors may need to make structured representations about how their systems are built, governed, and monitored. That includes familiar pressure points like data handling, bias controls, civil-liberties protections, and related safeguards.

    Procurement is where abstract AI principles often become contract obligations. It is easy to talk about responsible AI in marketing language. It is much harder to answer a buyer's concrete questions about training data, oversight, controls, auditability, and remediation.

    What legal teams should take from it

    Procurement is one of the fastest ways to force operational discipline. Buyers can demand certifications, representations, warranties, and disclosure commitments long before legislatures settle every policy fight.

    That means legal departments are no longer just debating AI governance in theory. They are negotiating it in contracts.

    The takeaway

    For vendors, the lesson is simple: if governance documentation does not exist in a usable form, build it now. For buyers, California offers a practical model for imposing more discipline on higher-risk AI tools without waiting for a perfect statute.

    California is not just regulating AI through lawmaking. It is shaping the market through purchasing power. That is often how governance becomes real.

  • Connecticut’s SB 5 Shows How Far a State Can Push on AI Governance

    Connecticut’s SB 5 Shows How Far a State Can Push on AI Governance

    Connecticut has moved from “state to watch” to a state companies may actually need to operationalize against.

    If you want the official bill text, Connecticut’s latest substitute text is here: SB 5.

    On May 1, 2026, the legislature passed SB 5, a broad AI bill that would place Connecticut among the more aggressive state players in AI governance. The point is not just that another state acted. It is that Connecticut appears to be building a framework that spans multiple AI risk areas at once.

    What makes this state move worth watching

    A lot of state AI proposals focus on one slice of the problem, usually hiring tools, consumer protection, or deepfakes. Connecticut's approach is broader. It treats AI governance as a cross-functional legal problem rather than a niche product issue.

    That matters because it better reflects how organizations actually use AI. AI now touches hiring, customer communications, vendor tools, automated decisions, synthetic media, and internal workflows.

    The patchwork problem is getting harder

    SB 5 is also another reminder that federal law is not about to simplify the map. States are continuing to legislate, and they are doing it with different definitions, priorities, and enforcement models.

    That creates two practical tasks for legal teams. First, they need a real inventory of where AI shows up in the business. Second, they need a governance structure that can absorb state variation without rewriting the whole policy stack every time a legislature moves.

    The takeaway

    Connecticut’s bill may not become the national template by itself. But it does point toward the future: AI governance that looks more like privacy or employment compliance, meaning state-specific, operationally demanding, and hard to solve with one policy memo.

    Connecticut is not the whole story. But it is increasingly part of the real one.

  • Colorado Rewrites Its AI Law Before It Fully Takes Hold

    Colorado Rewrites Its AI Law Before It Fully Takes Hold

    Colorado's AI law is moving again before many companies have even finished mapping the original version.

    If you want the official text, the Colorado bill is here: SB26-189.

    In May 2026, lawmakers passed SB 26-189, a major rewrite of the state's earlier AI framework. The main shift is from regulating broadly defined “high-risk AI systems” to regulating automated decision-making technology, or ADMT, when it materially influences consequential decisions.

    What stands out is how directly the law targets decision environments legal teams already care about: employment, housing, lending, insurance, health care, education, and essential government services. The practical question is less about what a tool is called and more about how it is used when it affects a person in a meaningful way.

    The new focus is operational accountability

    The revised bill is set to take effect on January 1, 2027. That buys time, but it also makes the compliance direction clearer.

    Developers would need to give deployers technical documentation on intended uses, training data categories, limitations, and human-review instructions. Deployers would need to provide consumer notices and, after an adverse outcome, a plain-language explanation of the role the system played. Consumers would also have rights to seek correction of inaccurate data and meaningful human review.

    What legal teams should focus on

    This is especially important for employment and other high-impact workflows. Recruiting tools, ranking systems, interview-analysis products, and recommendation engines can all end up inside the regulatory frame if they materially influence decisions.

    That means the compliance question becomes more concrete: what is the system doing, who is relying on it, what notice is required, and what happens when someone challenges the outcome?

    The bigger lesson

    Colorado’s rewrite is a useful reminder that state AI compliance is still moving in real time. Static AI policies are going to age badly. Legal and compliance teams need a more flexible operating model that can absorb changing definitions, disclosure duties, and review rights across states.

    The takeaway is not that Colorado is backing away from AI regulation. It is that Colorado is trying to make its law more targeted and more workable. For companies using AI in consequential decisions, the safer question is not “do we use AI?” but “can we explain and defend how this system influenced the decision?”

  • The EU AI Act Priorities Just Shifted Again

    The EU AI Act Priorities Just Shifted Again

    The EU AI Act story in 2026 is no longer about one looming deadline.

    It is about figuring out what moved, what did not, and where legal teams should spend compliance time first.

    “The AI Act was delayed” is too sloppy to be useful.

    Recent reporting indicates that the European Parliament and Council reached agreement on amendments that would postpone some major obligations, especially around high-risk AI uses and watermarking timing, while the European Commission also published draft guidance on transparency obligations that still begin this year.

    So the practical question is not whether the AI Act matters less. It is where the immediate compliance pressure now sits.

    It is what still appears to hit in 2026 and what can likely be sequenced later.

    The short version

    Here is the cleanest practical read based on current reporting:

    What did not move

    • core transparency obligations still appear set for August 2, 2026
    • disclosure expectations for AI systems that interact with people
    • related user-facing design and notice questions
    • the need to review where AI-generated or AI-manipulated content appears in products and workflows

    What moved later

    • AI-generated content transparency and some watermarking-related timing reportedly moves to December 2, 2026
    • Annex III high-risk AI systems reportedly move to December 2, 2027
    • Annex I product and product-safety high-risk AI systems reportedly move to August 2, 2028

    That does not mean companies can relax.

    It means they should stop treating every AI Act obligation as if it lands on the same day.

    What stayed on the 2026 calendar

    The biggest mistake legal teams can make here is hearing “delay” and translating it into “not urgent.”

    That would be a bad read.

    Even with the reported changes, core transparency obligations still appear positioned to matter starting August 2, 2026.

    For many organizations, that means focusing now on systems that interact directly with users and making sure disclosures are not buried in terms or documentation nobody reads.

    In plain English, companies should be asking:

    • Where are users directly interacting with AI systems?
    • Is the disclosure clear in the interface itself?
    • Are we treating different user groups appropriately?
    • Do any product flows involve AI-generated or AI-manipulated content that raises separate transparency issues?
    • Are product, legal, compliance, and design teams aligned on what the user actually sees?

    That is practical work. Not compliance cosplay.

    What legal teams should do now

    This is the moment for reprioritization, not celebration.

    A practical checklist:

    • map AI systems that directly interact with users
    • identify where AI-generated or AI-manipulated content appears
    • review interface-level disclosures instead of relying on buried policies
    • separate immediate 2026 transparency work from later high-risk build-out
    • revisit vendor diligence questions and contract language in light of the updated timing
    • give business teams a clearer timeline so “delay” does not become an excuse for doing nothing

    For in-house teams, this is also a communications problem.

    If the business hears only that the EU delayed the AI Act, the organization may under-resource work that still appears likely to happen this year.

    That misunderstanding can create more risk than the original deadline pressure.

    The bigger lesson

    The EU AI Act is becoming a sequencing challenge.

    That means the winning move for legal teams is not just knowing the rules. It is knowing the order in which the rules matter.

    That is what good AI governance looks like in practice.

    Not panic.
    Not delay theater.
    Just disciplined prioritization.

    The AI Act still matters in 2026.

    The real question now is which part of it is knocking first.

    One caution, though: because this area is moving through amendments, guidance, and implementation detail at the same time, legal teams should confirm the latest official timetable before treating any one summary as the final word.

  • Anthropic Pushes Further Into the Legal Workflow Layer

    Anthropic Pushes Further Into the Legal Workflow Layer

    Anthropic's latest legal AI release looks like more than a product update.

    On May 12, the company rolled out a broader legal package for Claude that reportedly includes 12 legal practice-area plug-ins, more than 20 integrations with legal and adjacent platforms, and tighter workflow support across Microsoft 365. Public reporting suggests the package is aimed at law firms, in-house teams, and other legal users. It also suggests Anthropic wants Claude closer to the legal workflow layer.

    The competitive question is shifting.

    It is becoming less about which model writes the best draft in isolation and more about which company can sit inside the legal workflow itself.

    Anthropic's latest move looks like an effort to push Claude further in that direction.

    From general legal help to practice-specific workflows

    Anthropic had already entered the legal workflow conversation earlier this year with a general legal plug-in for Claude Cowork. This new release appears to go further by organizing legal work around more specific workflows and user types.

    Public reporting describes plug-ins aimed at commercial, corporate, privacy, regulatory, litigation, employment, product, and AI-governance work, along with tools for law students, clinics, and legal builders. The point is not simply that Claude can answer legal questions. The point is that Anthropic is trying to package legal work into more structured, agentic flows that can move across applications and systems.

    That is significant because lawyers do not work in a single interface. They work across Word, Outlook, document management systems, diligence platforms, e-discovery tools, contract systems, research resources, and internal knowledge sources. A system that carries context across those environments becomes much more useful than a model that only produces polished text in a chat window.

    This deserves law-firm attention

    For law firms and legal departments, the strategic implication is pretty straightforward: foundation-model companies are moving closer to the lawyer.

    That puts pressure on legal AI vendors whose main value is wrapping a frontier model with prompts, UI, and light workflow features. It does not mean those vendors disappear. It does mean they will need to show real differentiation — authoritative sources, traceable outputs, stronger governance, better matter-specific workflows, deeper institutional knowledge integration, or more defensible professional use.

    For in-house legal departments, the implications may be even more immediate. A system that can help with first-pass contract review, playbook-based redlines, privacy and regulatory issue spotting, and better organization of matter context could allow internal teams to handle more work before involving outside counsel. That does not mean outside firms become less important. It means the handoff may change. Instead of sending out broad, early-stage requests, in-house teams may increasingly use AI-assisted workflows to narrow the issues, improve initial drafts, and escalate more selectively. If that happens, the impact will not just be productivity. It will be a shift in how legal spend is allocated and where legal work gets done.

    That is especially clear in the Thomson Reuters response. Thomson Reuters announced a Claude integration for CoCounsel Legal and emphasized “fiduciary-grade” legal AI, authoritative content, traceability, and trusted professional standards. That framing is telling. It suggests the market is sorting into two overlapping but distinct layers:

    • general-purpose AI for speed, drafting, and exploratory work
    • professional-grade legal systems for authoritative, high-stakes work

    Those are not the same thing, and lawyers should not pretend they are.

    A useful tool is not the same thing as a defensible workflow

    That is the biggest caution here.

    Better plug-ins and more integrations do not automatically solve legal governance. Earlier reporting on Claude Cowork noted that Anthropic’s own support materials warned against using Cowork for regulated workloads because certain activity was not captured in compliance APIs, audit logs, or data exports. Even as Anthropic’s legal tooling gets more capable, firms still need to ask the boring-but-critical questions:

    • Where does the data go?
    • What can be logged and audited?
    • What is retained?
    • What can be supervised?
    • Which tasks are appropriate for AI drafting assistance, and which require a more controlled system?

    Those questions matter more than the demo.

    What this likely means next

    Anthropic’s release does not prove that specialized legal tech is finished. It does suggest that the legal tech stack is being reshaped from below. Foundation-model companies no longer seem content to remain behind the scenes while others own the workflow layer.

    For lawyers, the right response is neither panic nor dismissal. It is disciplined evaluation.

    The firms that benefit most from this shift will not necessarily be the ones that buy the most AI tools. They will be the ones that build the best workflows around them — with clear review standards, source verification, confidentiality guardrails, and realistic decisions about where general-purpose AI is enough and where it is not.

    Anthropic’s latest legal release is important not because it settles the legal AI race.

    It is important because it makes the real competition harder to miss.

    Practical guide: Legal AI Workflows: A Governance Checklist for Legal Teams