When a production uses AI, it isn’t always clear which legal aspects are relevant. We’ve put together a short list of the aspects worth thinking through before deploying AI in your production.
01Data control
What it’s about. Making sure the material you put into a tool (footage, characters, designs, information, personal data, anything confidential or under NDA) is used only for purposes you are and remain in control of. And not for purposes of third parties, such as training and improving someone else’s model.
Why it matters. Many tools, especially consumer-grade tools, allow themselves to access and make use of data uploaded into their models for their own purposes. Terms and conditions may include a warranty covering free and unrestricted usage by the provider of the tool. This might be acceptable as long as the input is exclusively owned by yourself and you can (and want to) actually agree to such usage. But when confidential (or copyrighted) material of your client goes in under such terms, you no longer control where it ends up. That’s a real exposure and not just a theoretical question.
How it’s handled. Check the Terms and Conditions of the provider thoroughly before employing the tool. If unclear, get a lawyer on board and/or get confirmation from the provider. If you choose to use the tool anyway, be careful and selective with the input.
02Data privacy
What it’s about. In addition to remaining in control of data, making sure the “personal data” you put into a tool (e.g. visual appearance of real persons, information on real persons) is handled in a legally permissive way.
Why it matters. Personal data is subject to extensive protection across the world, e.g. via GDPR in the European Union. Infringements can lead to fines and procedures, invoked by data subjects and authorities alike. Not adhering creates real exposure.
How it’s handled. There are broadly two routes, and they’re often combined:
- Work locally, on own infrastructure. The work runs on hardware you or your vendor controls, so the material never leaves the building. Local and open-weight models are capable, but they can’t do every task to the same level as the larger cloud models, so this route won’t cover every shot on its own.
- Work in the cloud, but under a Data Processing Agreement. Where a cloud model is employed, the practical safeguard is to use it backed by a Data Processing Agreement (Auftragsverarbeitungsvertrag / DPA). This needs to adhere to the requirements of Art. 28 GDPR, but should also address secrecy in general (if such is not part of the Terms and Conditions already). Many providers offer such a modus operandi, but maybe only on business or enterprise tiers. However, not every DPA adheres to GDPR, so have this checked before relying on it. Document closing the DPA properly and do not rely on a default toggle that can change, without the ability to prove both the DPA and its contents.
03Copyright and input
What it’s about. Using copyrighted material in AI tools matters — for every input into an AI tool constitutes a relevant usage under copyright and, as such, requires permission of the owner.
Why it matters. You want to use copyrighted material of your client in AI tools? OK, your client may well agree to such usage, for purposes of getting the project done — but this should be discussed with the client upfront. Data control is especially vital in this regard: you do not want to allow a provider to train their tool with copyrighted material of your client.
How it’s handled. Transparency is key: get your client on board and let them know what you do. And what you don’t do, i.e. the measures you take to protect the material of your client.
04Copyright and output: human authorship
What it’s about. Whether the finished work is protected by copyright. Under German law that depends on human creative authorship reaching the threshold of originality (Schöpfungshöhe).
Why it matters. Output that is purely machine-generated may not clear that threshold on its own, and the legal picture for AI-involved work is still developing. So the practical aim isn’t to assume protection is automatic. It’s to strengthen the human creative contribution and be able to show it, which makes both the protection and the rights chain easier to stand behind.
How it’s handled. Usually through a combination of steps that each add to the human-authorship record:
- Building on your own source images where possible, so the rights in the underlying material already sit with the production.
- Reference work assembled by the director and art direction, so the creative direction is human-led from the start.
- A documented chain of creative decisions through the project, so there’s a record of who decided what.
- Embedded provenance data such as C2PA Content Credentials, so each image carries information about where it came from. (C2PA is a provenance and metadata standard: it documents origin, but isn’t in itself a legal guarantee of anything.)
Taken together these can help support the authorship case and make the rights chain easier to demonstrate if it’s ever questioned.
05Where the final image comes from
What it’s about. Rights clearance. The source of the actual delivered pixels, the image that goes into the master.
Why it matters. The final work delivered may infringe on somebody else’s property, maybe because such property was included in the training data (again: data control is vital!). It helps to have a clear view on the process as a whole, but the relevant clearance questions apply to the final image. The further upstream a step sits, the less relevance it carries, as the final image is where the standard tightens.
How it’s handled. For the final image, two approaches reduce exposure:
- A model fine-tuned on the production’s own material, so what comes out is anchored in what the production put in.
- Models trained only on licensed material that come with indemnification from the provider. (Worth noting: these indemnities come with conditions and limits, so it pays to read what is actually covered rather than assume it’s blanket cover.)
Earlier, exploratory steps (generating motion, exploring ideas, testing compositions) can use a wider range of tools. The discipline applies most strictly at the point where content enters the final deliverable.
The five aspects so far concern where the content comes from. The next four are about what that means once the production is actually running.
06Broadcaster acceptance
What it’s about. Whether the workflow meets what a given customer (e.g. broadcaster or streamer) will actually accept.
Why it matters. Requirements differ between customers (e.g., a public broadcaster and a streaming platform may not draw the line in the same place), and they’re moving targets. What clears one may not clear another, and an assumption made at the start can surface as a problem at delivery.
How it’s handled. Keep track of what each broadcaster currently accepts, keep workflow options open rather than committing to one path too early, and agree the approach with the broadcaster before the project begins instead of after the work is done.
07Consent and likeness rights
What it’s about. Using a real person’s image, face, voice, age, or appearance: digital doubles, voice work, de-aging, appearance changes.
Why it matters. This touches personality and image rights (§22 KUG), as well as privacy: the visual appearance of a human being is always considered personal data. It might even be considered biometric data as a special category under Art. 9 GDPR. For talent working under collective agreements (ver.di / BFFS), there are specific requirements on top of that.
How it’s handled. Shape your processes and have your legal basis straight — before getting to work. There are different ways of getting a valid legal basis for making use of likeness. One way to go is written consent, and compensation arranged. The key is timing: this belongs in a conversation with the talent ahead of production, not in a clause added to the delivery agreement afterwards.
08Disclosure and transparency
What it’s about. Telling the broadcaster, and in some cases the audience, that AI was used. The broadcaster needs to adhere to transparency obligations, so providing this information is not nice-to-have, nor up for discussion. It is an essential duty of the producer.
Why it matters. Be aware of transparency obligations set up by law (esp. the EU AI Act, Art. 50) as well as industry codes such as the KI-Kodex.
It’s worth being precise about where they bite hardest! Marking AI use matters most where material could be considered by the audience as “real”, e.g. documentary or factual content. Here, labelling aims to protect against misinformation: something which never happened shouldn’t be presented and/or understood as if it did. For work which is obviously fictional, transparency obligations hit less hard: under Art. 50 the disclosure for evidently artistic or fictional content need only be made in a way that doesn’t hamper the enjoyment of the work. Either way, disclosure must be proactive rather than something offered only when asked.
How it’s handled. Disclose AI use to the client and the broadcaster up front, as part of setting the project up, so it’s a known and agreed part of the production rather than a discovery later. Discuss whether you should include AI marking right in the production. Be consistent and precise with time-codes and able to provide information on when and where which AI tool was used.
09Tool flexibility
What it’s about. Not being locked into a single tool or model for the whole production.
Why it matters. No single tool is the best, or the lowest-risk, choice for every shot. Being tied to one means either compromising on quality or stepping outside the parts of the workflow you’ve made sound.
How it’s handled. Choose the right capability per shot, and make each choice sound through the workflow, so that whatever tools are used along the way, the final delivered image still comes from a better-documented or lower-risk source (see aspect 05).
30 minutes. We’ll figure out if it makes sense for your project. Free, no commitment.
10How the pieces fit together
A simple way to hold all of this in one shape:
Your material in → AI does the heavy lifting → a final re-render through a documented source, where possible (a model fine-tuned on your material, or a model with indemnification) → your material out.
In practice, what a production needs to supply is modest:
- Source images or footage to build a fine-tuned model from.
- The consents of the talent involved.
- An informed confirmation that AI is being used.
The rest is workflow.
None of these aspects sit outside the reach of a normal production. What they have in common is timing: each one is straightforward to handle when it’s decided before the project starts, and awkward to handle once the work is already underway. The producer who has thought them through in advance is simply the one who can answer the questions when they come.
This is why, in practice, it comes down to a conversation. TDM works through the intended workflow with every client, and makes sure it fits both their own expectations and those of their commissioners, including on the legal side, before the work goes into production.
AI and new media for film and TV professionals. One piece every two weeks. No noise.

