AI indemnification in ads: who stands behind the asset
Who owns an AI generated image, and who defends it if a claim lands? What providers publish today, and why Nubu's generation runs on Google models.
The question rarely comes from the creative team. It arrives from legal, or from the client, usually after the work is already good: can we run this AI generated image in a paid campaign, and who owns it?
It is the right question in the wrong shape: really three questions wearing one coat, answered by provider contracts, copyright law, and the conditions buried in each provider's terms. Teams also ask us a pointed version: why does Nubu's built-in image and video generation run on Google's models rather than OpenAI's, or ByteDance's Seedance? The short answer is that for the asset that ships in an ad, who stands behind it matters as much as how it looks, and at the time of writing Google publishes the strongest indemnification suite covering the exact model families we run. The long answer is this article.
One thing said plainly before we start: this is not legal advice, and provider terms change. Every claim below comes from the providers' own published documents or the US Copyright Office, linked so you can read the current versions, and anything high stakes belongs in front of your lawyers.
Who owns it? Three questions hiding inside one
When someone asks "can I use AI images in ads", untangle it into three questions before answering.
Is the output infringing? A question of fact about a specific asset: does this image or video reproduce someone else's protected work, likeness, or brand? No contract can answer that in advance. What contracts can do is decide who deals with the consequences if the answer turns out to be yes. That is indemnity territory.
Is the output ownable? Two layers here, routinely conflated. The contractual layer: provider terms, which today mostly assign output rights to the customer or disclaim any claim over them. The legal layer: is the output copyrightable at all? Under the US Copyright Office's published position, discussed below, purely AI generated material is not, whatever the terms say. A provider can give you everything it has in the output; it cannot give the output a copyright it does not qualify for.
Who stands behind it commercially? If a rightsholder sends a letter about an ad you ran, who defends it and who pays? This is indemnification, and it separates the providers most sharply today.
What indemnification means here, precisely
Indemnification is a contractual promise: the provider agrees to defend you against specified third party claims and to cover specified costs if those claims succeed. It is not a warranty that the output is clean. It is a commitment about who carries the fight if the output is challenged.
For generative AI there are two distinct exposures, and Google's framing of them has become the industry's vocabulary. Announcing its approach in an October 2023 post, Google Cloud described a two-pronged commitment. The training data indemnity: if someone alleges that the provider's use of training data to build the model infringed their rights, that claim concerns the provider's own conduct, and the provider stands behind it. The generated output indemnity: if someone alleges that the thing you generated and published infringes their rights, the provider steps in for that too, subject to conditions.
The conditions are where the real coverage lives: every published output indemnity we have read excludes intentional misuse, and most exclude modified outputs, disabled safety systems, and certain claim types entirely. The headline tells you a provider's posture; the carve-outs tell you what you hold.
What the providers publish, at the time of writing
Google: two prongs, a published service list, named model families
Google's commitments live in the Google Cloud Service Specific Terms, in the generative AI section. The output prong extends Google's indemnification obligations to allegations that an "unmodified Generated Output" from a Generative AI Indemnified Service infringes a third party's intellectual property rights; the training data prong extends them to allegations that Google's use of training data to create any of its pre-trained models infringes a third party's rights.
Which services count is not left vague: Google maintains a versioned page listing the Generative AI Indemnified Services. As published now (last modified July 20, 2026), the list includes the platform API formerly known as the Vertex AI API "used with generally available versions" of named foundation model families: Codey, Gemini, Imagen, PaLM and Veo. For a team generating ad images and video, that is the important sentence: the image and video model families are named on the provider's own indemnified list, not inferred from a press release.
The published conditions are equally concrete:
- Coverage applies where the service "is not provided to Customer free of charge". Paid use, in other words.
- It applies to generally available model versions; Google's terms exclude pre-GA offerings from indemnity coverage.
- It applies to unmodified output.
- It does not apply where the customer "knew or should have known" the output was likely infringing, disregards, disables, modifies or circumvents "source citations, filters, instructions, or other tools" Google provides for responsible use, or keeps using output after a rightsholder's infringement notice.
- It does not apply to trademark related claims arising from use of the output "in trade or commerce". Hold that thought; it matters enormously for advertising.
- The customer is solely responsible for its "use, non-use, or modification" of safety filters.
On ownership, the same document is clear: "Generated Output is Customer Data", and Google "does not assert any ownership rights in any new intellectual property created in the Generated Output".
One precision that affects real accounts: these indemnities are Google Cloud commitments attached to the listed services. Google's separate Gemini API additional terms for its developer API surface state that Google "won't claim ownership" over generated content but, as published at the time of writing, contain no comparable indemnification language. Which document governs you depends on the surface and tier your account and key belong to, so confirm that before treating any indemnity as yours.
OpenAI: Copyright Shield for business customers
OpenAI announced its commitment as Copyright Shield at its November 2023 developer conference: it would step in to defend customers and pay the costs incurred in copyright claims over output, for generally available features of ChatGPT Enterprise and its developer platform. The contractual substance sits in two documents today.
OpenAI's Business Terms have OpenAI agreeing to "indemnify, defend, and hold Customer harmless" against third party claims "alleging that the Services infringe any third-party IP Right", and state that the service specific indemnity below is included in the agreement and "is not subject to any liability cap".
OpenAI's Service Terms then add the output layer. For API customers, OpenAI's indemnification obligations "include any third party claim that Customer's use or distribution of Output infringes a third party's intellectual property right", and the same output indemnity is extended to ChatGPT Enterprise customers. The published exclusions run close to Google's: no coverage where the customer knew or should have known the output was infringing, where relevant "citation, filtering or safety features" were disabled, ignored or unused, where the output was "modified, transformed, or used in combination with" non-OpenAI products, where the customer lacked rights to the input or fine-tuning files, where the claim is a trademark claim over use of output "in trade or commerce", or where the output came from a third party offering. Consumer tiers sit outside this: the indemnity attaches to business surfaces, not free or personal ChatGPT accounts.
It is a serious, well drafted commitment. What decided our media default is narrower than "who indemnifies": it is which provider pairs an output indemnity with an explicit training data prong and a versioned list naming the specific image and video model families Nubu runs on. At the time of writing, that is Google.
Seedance: nothing comparable that we could find
ByteDance's Seedance video models are commercially available through its BytePlus platform, whose published video generation model service terms show a last update of May 22, 2026. Those terms address ownership: generated output is "Your Data", and "the intellectual property rights of Your Data belong to you or other applicable rights holder(s)". They prohibit generating content that infringes third party rights, and prohibit removing watermarks or metadata indicating AI generation.
What we could not find, in those terms or elsewhere in ByteDance's published commercial documents, is any published indemnification comparable to Google's or OpenAI's commitments running from the provider to the customer for output related IP claims. The published indemnity we did find runs the other way: the customer agrees to indemnify BytePlus, and the terms disclaim BytePlus's liability for generated output. We state that carefully as the result of our search of the published documents, not as a claim about anything unpublished, and terms can change at any time. A team weighing Seedance for paid advertising should read those terms and draw its own conclusion about who stands behind a challenged asset.
Side by side
| What is published | Google (Cloud terms) | OpenAI (business terms) | ByteDance (Seedance via BytePlus) |
|---|---|---|---|
| Training data indemnity | Yes, a named prong for claims about Google's training of its models | General indemnity for claims that the Services infringe; no named training data prong | None found in the published terms |
| Generated output indemnity | Yes, for unmodified output from listed paid services | Yes, for API and ChatGPT Enterprise customers | None found; customer indemnifies the provider |
| Media model families named in the covered scope | Yes: GA versions of Gemini, Imagen and Veo families via the platform API | Output indemnity not tied to a published model list | Not applicable |
| Output ownership position | Output is customer data; Google asserts no ownership | OpenAI claims no IP rights in customer content | Output IP belongs to the customer or other rights holders |
| Trademark claims from use in commerce | Excluded from the output indemnity | Excluded from the output indemnity | Not applicable |
| The caveat that governs this table | All rows describe published terms at the time of writing (August 2026); read the current documents before relying on them. |
Why this matters more in advertising than almost anywhere
A generated image in a brainstorm document is a draft: if it resembles something protected, you delete it and the story ends. An ad is different in kind, not degree.
Ads run at paid scale, in public, under a brand's name, with money pushed behind distribution. An infringing asset is not a file you quietly remove; it is a campaign that ran, with receipts, on platforms that keep archives. The exposure attaches at distribution, precisely the moment creative automation multiplies: one concept becomes dozens of formats, markets and variants, each a published copy.
There is also a contractual chain above it. Agencies routinely indemnify clients for IP infringement in delivered work; it is a standard master service agreement clause. Put a generated asset into a client campaign and the agency stands behind it downstream whether or not anyone upstream stands behind it. Provider indemnity is what keeps that chain from ending at the agency's own balance sheet, which is why procurement teams now ask about generative AI indemnity by name.
And advertising sits squarely on the one carve-out both major indemnities share: trademark claims arising from use of output in trade or commerce, excluded by Google's and OpenAI's published terms alike. Commercial use is what an ad is. If a generated frame echoes someone's mark or trade dress, that risk stays with you under both suites. Indemnification narrows the field to copyright style claims about the content itself; it does not replace the brand clearance you already apply to stock imagery and shot footage.
Why Nubu's built-in generation runs on Google's models today
Nubu's built-in media generation runs on Google's models: image generation on the Gemini image model family, and video generation on the Veo 3.1 family. Teams ask why, usually with a specific alternative in mind. For the media surface, the asset that actually ships in an ad, the deciding bar was the indemnification suite as published. At the time of writing, Google pairs an output indemnity with an explicit training data indemnity and a public list naming the exact model families involved. For advertising, where who owns the asset and who stands behind it is existential rather than academic, we weighted that above benchmark scores.
Three design decisions make the position more than a preference.
Your key, your protections. Generation in Nubu runs on your organisation's own Google API key: Nubu sells no AI credits, the provider bills your organisation directly, and the terms relationship runs between your organisation and Google, never through us as a reseller. Whatever protections Google's terms attach to your account and tier belong to your organisation directly, not to us on your behalf. To be precise: Nubu itself provides no indemnity, and the provider's current terms for your account govern what you hold. That is the point of bring your own keys: a protection you hold directly, under terms you can read, beats one routed through an intermediary's contract. Our connecting Gemini guide covers the setup; the section above explains why the surface and tier your key sits on is worth confirming.
Provenance by default. Every generated asset lands in your asset library as an organisation asset, tagged with "AI", "AI Generated", the model that produced it and the provider. That tag set is not decoration. If a claim ever arrives, the first questions are the ones the tags answer: which model, which provider, which account, and is this the unmodified original? The same record is what an EU AI Act inventory of AI generated ad content needs. An indemnity you cannot evidence your way into is a right you technically hold and practically cannot use.
A default, not a dependency. Nubu is not wedded to one AI lab: text tasks already run across OpenAI, Anthropic and Google, and the platform is built to bring new image and video models on board quickly when the market moves. If OpenAI extends its published media terms to meet the same bar, or ByteDance publishes an output indemnity for Seedance, the default we ship can change with the market, and we would genuinely welcome that. The current answer is a snapshot of published terms, held loosely on purpose.
The same applies wherever generation happens in the product: whether an asset is created through an AI node in a flow or through Nubu's assistant, it runs on your organisation's own key under the same provider terms, and the assistant confirms before the first generation rather than spending on your key unprompted. Everything it produces lands as a tagged organisation asset in the same provenance trail, because AI proposes and humans approve is how the whole system is built.
The conditions you actually have to meet
An indemnity is a conditional instrument; Google's published conditions translate into practical rules for an advertising workflow:
- Use a paid, covered surface. Google's output indemnity applies where the service is not provided free of charge, and to the services on its published list. Free tiers are for exploration, not covered campaign assets.
- Use generally available model versions. Google's terms exclude pre-GA offerings from indemnity coverage. Preview models are for evaluation, not the hero asset of a paid campaign.
- Leave the safety systems on. Coverage falls away where the customer disregards, disables, modifies or circumvents the citations, filters, instructions or other responsible use tools the provider makes available. If a workflow ever seems easier with a filter off, that convenience is being paid for with your indemnity.
- Do not aim at someone's work. Both suites exclude output the customer knew or should have known was infringing. Prompting towards a recognisable artist, character or campaign is exactly the conduct the exclusions are written for.
- Keep the unmodified original. Google's indemnity speaks to unmodified generated output, and OpenAI excludes output that is modified or transformed. Ad workflows edit almost everything, so preserve the original file alongside your edits; it is the reference for what the provider generated and stands behind.
- Stop on notice. Under Google's published terms, continued use after a rightsholder's infringement notice ends coverage for that output. Have a route for pausing an asset across live campaigns quickly.
- Clear trademarks yourself. The trade or commerce carve-out in both suites means brand collisions remain your job, exactly as with stock and shot footage.
A short practical checklist
- Identify which account, surface and tier your generation runs on, and read that tier's current terms, not a summary (including this one).
- Route campaign generation through the organisation account that holds the protections, never through personal or free tier keys.
- Keep provenance for every generated asset: provider, model, date, owning account, and the unmodified original file.
- Treat preview models as evaluation tools and generate shippable assets on generally available versions.
- Run generated assets through the same trademark and brand clearance you apply to any other footage.
- Fold the provider's conditions into internal guidelines so nobody disables a safety feature to save a revision round.
- Involve legal early for high stakes usage: talent likenesses, regulated categories, and anything a competitor would enjoy challenging.
Honest limits
A piece arguing indemnification matters owes you the boundaries of the argument.
Indemnity is not ownership. A provider assigning you the output, and a provider defending you against claims about it, are separate instruments, and neither makes the output copyrightable. The US Copyright Office's position, set out in Part 2 of its Copyright and Artificial Intelligence report released in January 2025, is that copyright requires human authorship: protection extends to outputs "only where a human author has determined sufficient expressive elements", and not to "the mere provision of prompts". The Office does recognise protectable human contributions, including a human authored work perceptible in the output, creative selection and arrangement, and creative modifications, assessed case by case. The practical reading is sober: a purely generated asset may be yours by contract and defended by indemnity, while your ability to stop others reusing something similar remains constrained. Composed, human directed work carries more protectable authorship than raw generations.
Coverage is narrower than confidence. The trademark carve-out, the modification conditions and the paid tier boundaries make an indemnity a strong floor, not a substitute for clearance judgement.
Terms change. Google's indemnified services page carries its own revision history, and every document linked here has been updated since it first appeared. This article describes the published landscape at the time of writing, August 2026, and we said at the start what it is not. Read the current documents; that is why every claim above links to one.
Generation that arrives with its paperwork
The asset that ships in an ad should come with three things: a provider that stands behind it, an account relationship that makes those protections yours, and a provenance record proving what was generated, by what, and for whom. That is what Nubu's built-in generation does, on your own key, with every output tagged and filed. If you are weighing generative assets for paid campaigns, create a workspace and connect your own Google key, or see pricing for how BYO keys fit each plan. The models will keep changing; the paperwork discipline is what you keep.