Artificial intelligence startups sit at the intersection of several different areas of law. A single generative AI feature release may raise questions of intellectual property, data protection and privacy, contract law, employment law, and reputational risk, sometimes all within the same product update. For founders used to moving quickly, this breadth can be frustrating. It can delay launches, or create a temptation to overlook legal protections and risks at the point a product is first built.
For legal advisers to the sector, the landscape is no less demanding. Media law expertise traditionally applied to publishing and broadcasting must now be reapplied to a fast changing environment. Keeping pace with the technology requires both rapidly-updating knowledge and a willingness to apply legal principles creatively to novel scenarios.
For AI startups operating under the law of England and Wales, we set out the issues they are likely to encounter, and points where specialist advice is likely to add the most value.
Content Use, Generation, and Sharing
Any AI startup that generates, publishes, or distributes content needs clear terms governing that activity. This includes establishing who owns the content produced, and, where the underlying source material was not generated by the company itself, how that material may be used and under what licence.
AI companies frequently use data relating to individuals as inputs, whether to build foundation models or to generate content directly. This data may be collected through chatbots or other tools that allow users to input information or communicate with the system. Where this data is processed, licensed, or otherwise used by the company, careful thought needs to be given to the terms of the policies, agreements, and contracts that govern its use. Those documents should be kept under review and updated as the underlying product changes, since a change to how a tool processes or uses data can quickly render existing documentation out of date. Where new users or third parties are brought onto the service, individual or bespoke agreements may be needed, particularly where different categories of data use or unique terms apply to different users.
AI companies also need to think carefully about how the information their systems handle might be changed, altered, or reinvented. A chatbot that produces a false statement about a real, identifiable person can give rise to a defamation claim. A platform that allows users to share AI altered images or video needs to think about its online safety duties, as well as the permissions attached to any original source material used to create that content. Those that do not address these risks at an early stage may leave themselves more exposed to liability.
Intellectual Property
One of the most pressing questions for any AI startup is which, if any, of the available intellectual property protections apply to its product. Can the product, or parts of it, be protected by copyright, a patent, or a registered design?
The answer tends to differ significantly depending on which part of the product is in question. Trained model weights sit in an unusual position: they are not naturally suited to registered IP protection, and their status under copyright is uncertain. As a result, weights are generally protected, if at all, through the law of confidence, subject to the test in Coco v A N Clark (Engineers) Ltd [1969] RPC 41, together with carefully drafted contractual confidentiality obligations. Where the relevant criteria are met, this protection is reinforced by the Trade Secrets (Enforcement, etc.) Regulations 2018, rather than by copyright or any registered right.
The position is different for the code that trains and runs the model. This is generally protected as a literary work under copyright, which arises automatically under the Copyright, Designs and Patents Act 1988 (the CDPA) without any need for registration. Curated training datasets may attract copyright separately as a database, or benefit from the sui generisdatabase right created by the Copyright and Rights in Databases Regulations 1997, which protects the investment made in obtaining, verifying, or presenting the data even where there is no originality in its selection or arrangement.
It is also worth being aware of section 9(3) of the CDPA, an unusual provision of English law dealing with “computer generated works”. This deems the author of a work with no human author to be the person who made the arrangements necessary for its creation. Whether model weights, or the outputs a model generates, could be brought within copyright protection through this route remains genuinely unresolved, and startups should not assume the point is settled either way.
Startups also need to think about any non-original source material their models rely on, and how the protections attaching to that material may restrict how it can be used, and constrain the outputs the model is able to generate. A narrow text and data mining exception exists under section 29A of the CDPA, but it is limited to non-commercial research and does not extend to training models for commercial purposes. The government has spent a considerable amount of time over the past two years considering whether reform is needed in this area, and the position has continued to develop.
On patents, protection under the Patents Act 1977 is generally unavailable for the trained weights themselves, since a specific set of trained parameters is not the kind of technical invention the Act is aimed at protecting. A novel architecture or training technique, however, could in principle meet the patentability threshold, provided it clears the usual hurdles of novelty, inventive step, and technical character and contribution. The legal test for assessing whether an AI related invention clears the threshold exclusion for computer programs has recently changed significantly, following a Supreme Court decision, Emotional Perception AI Ltd v Comptroller General of Patents, Designs and Trade Marks [2026] UKSC 3, handed down in February 2026. Startups considering patent protection for any part of their technology stack should take specialist advice on how that change affects their filing strategy, and the companion piece addresses this development in detail.
Reputational Risk
Generative AI tools have a well-documented tendency to produce statements that sound confident but are factually wrong, sometimes described as hallucinations. Where such a statement is false, and would tend to lower a real, identifiable person’s reputation in the eyes of right-thinking members of society, ordinary principles of defamation law may be engaged.
Under section 1(1) of the Defamation Act 2013, a statement is not defamatory unless its publication has caused, or is likely to cause, serious harm to the claimant’s reputation. This threshold was introduced to deter trivial claims, and a claimant must now establish it as part of the cause of action itself. Where the claimant is a body that trades for profit, section 1(2) requires serious financial loss, or the likelihood of it, rather than harm to reputation alone. While this raises the bar against trivial claims, it does not remove the underlying risk where an AI tool repeatedly or prominently generates damaging false statements about a named individual.
Startups deploying customer-facing AI tools should think carefully about how responsibility for AI generated content is allocated, both internally within the business and in contracts with customers. Terms of service, acceptable use policies, output disclaimers, and, where appropriate, technical guardrails around named individuals all have a part to play in a sensible approach to managing this risk. Various statutory defences may also be available to hosting providers and intermediaries in some circumstances, though none of these operate automatically, and their availability depends heavily on the specific facts, including the degree of editorial control exercised over the output in question. This is an area where seeking advice early can prove considerably more valuable than seeking it only once a dispute has already arisen.
The Online Safety Act and AI-Generated Content
The Online Safety Act 2023 places duties on providers of user-to-user services, search services, and services publishing pornographic content, requiring them to assess and mitigate the risk of illegal content and content harmful to children on their platforms. Ofcom, as the designated regulator, has made clear that AI generated content is regulated no differently to content created by a human user for the purposes of the Act.
This has real practical implications for AI startups. A standalone chatbot that interacts one-to-one with a single user, without allowing that user to share the chatbot’s output with others, and without searching the internet, will generally fall outside the Act’s illegal content and children’s safety duties under Part 3, save for the separate rules that apply where the chatbot generates pornographic content, which are covered under Part 5. This reflects Ofcom’s published position: content generated in “a one-to-one interaction between a user and a chatbot that does not involve searching the internet or sharing with other users… is not regulated under Part 3, but could be under Part 5 if it is pornographic.” Generative tools that search across the internet to compile their answers may separately fall within the Act’s definition of a search service.
Ofcom has significant enforcement powers at its disposal, including fines of up to eighteen million pounds or ten per cent of qualifying worldwide revenue, whichever is greater, and it has already taken enforcement action against providers of AI companion and chatbot services. Startups building AI products with any social, sharing, or search functionality should assess their regulatory status under the Act carefully at the design stage of their product, rather than attempting to retrofit compliance after launch.
Data Protection and Automated Decision Making
Most AI products involve processing personal data in some form, whether as training inputs, within user prompts, or in the outputs the system generates, and the UK GDPR and the Data Protection Act 2018 apply to this processing in the usual way. Startups should ensure they have identified an appropriate lawful basis for their processing, that their privacy notices genuinely reflect how personal data is used within their AI systems, and that appropriate technical and organisational measures are in place, particularly where special category data may find its way into training datasets or user inputs.
The law governing solely automated decision making has recently changed in a significant way, following reforms introduced by the Data (Use and Access) Act 2025. Startups offering AI tools that inform or make decisions about individuals, for example in recruitment, credit, or insurance contexts, should review these provisions carefully and build the required safeguards into their products at the design stage.
Contracts, Licensing, and Confidentiality
Many of the practical risks facing AI startups can be managed effectively through careful contract drafting. This includes licensing arrangements with content providers and data suppliers, terms of service and acceptable use policies for end users, warranties and indemnities in commercial agreements with enterprise customers, and confidentiality provisions protecting proprietary model architecture, training methods, and datasets. Given the pace of legal and regulatory change in this area, contracts should also build in a degree of flexibility to adapt to future developments, whether through defined review points, or provisions specifically addressing new regulatory obligations as they arise.
What’s Next?
The pace of change in this area means that legal risk for AI startups rarely sits still. A product that was low risk on launch may fall into a different regulatory category following a routine feature update, and the underlying law itself, particularly around copyright and AI, remains under active review by government.
Our team can work with AI startups from early stage development through to scale, advising on aspects including data and licensing, copyright and IP protection, online safety compliance, reputational risk, data protection, and the commercial contracts that underpin growth. We would be glad to discuss how these issues apply to your specific product and stage of development. Please get in touch to arrange an initial conversation.



