UK copyright arises automatically, but proving what was created, in what form, and on what date sits entirely with the creator — and the government's decision of 18 March 2026 not to legislate leaves that burden untouched. The question facing every UK creator is no longer whether their work is protected. The question is whether they could prove that protection in court.
The Copyright, Designs and Patents Act 1988 is among the most generous copyright statutes in the world: protection attaches at the moment of creation, with no registration, no deposit, no fee, and a term running seventy years beyond the author's death. The generosity conceals a structural gap. A right that arises with no formality also arises with no record — and once enforcement begins, the record is the whole case.
This post examines what the government's Report on Copyright and Artificial Intelligence decided and what it declined to decide, what automatic protection demands of a creator once a dispute begins, the two tests arriving over the next eighteen months, and what an independent record of creation requires.
The Report's significance lies in what it confirms will not happen. Published on 18 March 2026, as required by sections 135 and 136 of the Data (Use and Access) Act 2025, the Report closes a process that began with the December 2024 consultation and drew more than 11,500 responses — 88 per cent of which favoured requiring a licence to train AI on copyright works — the Report announces no new legislation, no new regulator, and no new rights. The government's previously preferred mechanism, a text and data mining exception with a rights-holder opt-out, has been abandoned after overwhelming opposition from the creative industries. The courts will apply the law as it stands. The accompanying written ministerial statement, delivered by the Science Secretary on the day of publication, framed the ambition as making the UK an "AI maker, not an AI taker" — growth language, not protection language, and a signal of where the government expects the balance to settle.
What remains is a programme of further work: best practice on transparency and the labelling of AI-generated content, exploration of a possible personality right against digital replicas, a market-led approach to licensing kept under review, and continued work on enforcement barriers. The Report also proposes one genuine change of substance: removing the protection that section 9(3) of the 1988 Act currently extends to wholly computer-generated works, under which the author is deemed to be the person who made the arrangements for the work's creation. Works made with AI assistance would remain protected; works made by AI alone would not. The change sharpens rather than softens the human-authorship question — and with it, the evidential question of demonstrating how much of a given work a human made.
For working creators, the operative guidance sits in the practical steps the government and its commentators recommend: prepare licensing terms, monitor for scraping, watermark files, embed metadata, and enforce proactively. Read those steps closely and a single assumption runs beneath every one. Watermarking a file proves the file was marked; a watermark says nothing about when the underlying work was created. Metadata can be edited by anyone holding the file. Monitoring services locate suspected uses; they cannot establish that the creator's work pre-dated the use. Each recommended step presupposes an answer to a prior question — when did this work exist, in this form, in this creator's hands — and the Report leaves the task of answering to the creator alone.
Enforcement under the 1988 Act begins with evidence the Act never generates. Suppose a UK illustrator finds their images inside the training data of a commercial AI model. The Act protects them from the moment each image was drawn. To enforce, they must show on the balance of probabilities that they authored the works, that the works pre-existed the ingestion, and that the works in the dataset are the works they created. The statute supplies the right and one limited aid — section 104 presumes authorship in favour of whoever is credited on published copies, until an opponent proves otherwise — but that presumption reaches only published, credited work. Consider how little of a modern creative output qualifies. A photographer's archive is overwhelmingly unpublished; a designer's client work ships without a credit; a developer's repository never carries a name on a title page; pseudonymous and collaborative work muddies the credit even where one exists. The unpublished archive, the client draft, the versioned working file: for these, the Act offers no evidential machinery at all.
What the illustrator holds instead is a folder of self-generated records. A file date on a device they control. An email showing the work existed at some moment, in some form. A social media upload, if the work was ever posted. An invoice showing a sale, not a creation. None of these is independent; every one can be questioned, and in contested proceedings every one will face challenge. The balance of probabilities rewards whichever side holds the only record made outside its own control — and in most authorship disputes, neither side holds one.
The evidential gap — what UK creators hold versus what a dispute demands
What creators typically hold | Why a dispute discounts it |
File creation date on their own device | Controlled by the creator; editable; not independent |
Email or message showing the work | Shows existence at one moment, not creation date or exact form |
Social media post | Shows publication date only, not creation date or the full original form |
Client invoice | Shows a transaction, not authorship or the date the work was made |
The gap is not uniquely British, but Britain feels it without a cushion. An American creator who registers with the US Copyright Office acquires, as a by-product, a public record fixing the work and its date — the gateway to statutory damages under the US regime. US evidence law has also moved to accommodate exactly this kind of record: Federal Rules of Evidence 902(13) and 902(14) allow certified records generated by an electronic process, and certified data copied from electronic systems, to authenticate themselves without a live witness, provided the process is shown to produce an accurate result. The European Union shares the UK's no-registry model, and both jurisdictions instead recognise the qualified electronic timestamp — an instrument that EU law, through eIDAS Article 41, presumes accurate as to its date and the integrity of the data it seals, and that the UK's retained framework accepts as strong electronic evidence. In systems where no registry will ever exist, that instrument is the closest thing to the record the statute never made.
The pause defers legislation; it does not defer the proof question, which two live processes are about to ask. The first is Getty Images v Stability AI, the UK's leading AI copyright case. The High Court's judgment of 4 November 2025 ([2025] EWHC 2863 (Ch)) dismissed Getty's secondary infringement claim, after Getty had discontinued its primary training claim for jurisdictional reasons. On 16 December 2025, Mrs Justice Joanna Smith granted Getty permission to appeal ([2025] EWHC 3343 (Ch)) on the question at the centre of the case: whether an AI model can constitute an 'infringing copy' under sections 22 and 23 of the 1988 Act — a question no UK court had previously considered. Court of Appeal listings currently run seven to fifteen months from the decision under appeal, placing the hearing in late 2026 or into 2027. The case already carries two warnings for smaller rightsholders. Getty's primary training claim was discontinued because the training acts could not be tied to the UK — a reminder that establishing where and when acts occurred is half the battle. And the costs outcome was brutal: Stability emerged the clear overall victor, leaving Getty, a company with deep resources, facing a substantial interim costs liability. Pause on the one claim Getty did win. The trade mark finding, limited to historic versions of Stable Diffusion, succeeded because Getty's watermarks appeared in the model's generated output — infringement the court could see, anchored to marks Getty could prove were its own. The single successful claim in the UK's biggest AI copyright case was the one where the evidence required no explanation. However the appeal resolves, the litigation that follows it will turn on evidence of which works were ingested by which systems before which dates — questions answered by records, not assertions.
The second is the Creative Content Exchange, the government's pilot marketplace for licensing digitised creative and cultural assets to AI developers. Hosted at the Natural History Museum with funding from UK Research and Innovation, the pilot began in December 2025 and runs to December 2026, with an operational platform targeted for summer 2026. Its early participants are institutions — the National Archives, Historic England, the Royal Armouries — organisations whose collections carry provenance records built over decades. If the marketplace scales to individual creators, as the government intends, every seller will face the question institutions answer by infrastructure: demonstrating ownership of the works they offer. A licensing market pays those who can prove title. It has nothing to say to those who merely hold one.
Not every timestamp carries evidential weight; what separates evidence from decoration is who issued the record, whether anyone else can verify it, and whether it survives its issuer. The traditional self-help methods fail the first requirement outright. Posting a manuscript to yourself proves possession of a sealed envelope; emailing files to your own inbox produces a record on infrastructure you control; screenshotting a folder shows a date your own machine displayed. Free timestamping utilities fail more quietly — a bare hash on a blockchain shows some data existed, but unless an accredited provider stands behind the timestamp, a certificate makes the record independently checkable, and the chain from hash to file to depositor holds together, a court has little to weigh beyond the depositor's own explanation.
Cryptographic prior proof at the qualified standard works in four layers:
Return to the illustrator. With such a record established for each image at the time of creation, the dispute changes shape. Authorship and dating no longer rest on files from the illustrator's own devices; they rest on a certificate issued by an accredited third party, verifiable by anyone, alterable by no one. The opposing side can still argue about what the ingestion of the work means in law. What they can no longer usefully argue about is when the work existed and what, byte for byte, the work contained.
The government has chosen litigation and licensing over legislation, and both of those mechanisms run on proof. The Report tells creators, in terms, that their rights are enforceable and that enforcing them is their own responsibility — while the machinery for discharging that responsibility is the one thing neither the Act nor the Report provides. The Getty appeal will refine what the law means; the licensing market will price what creators own; and in both arenas the creators who matter will be the ones who can put an independent record in front of a court or a counterparty.
There is one part of the burden of proof a creator can discharge years in advance, and only one: the record of what existed and when. The law will not change in the next eighteen months. The evidence still can.
Report on Copyright and Artificial Intelligence — UK Government, March 2026 (full text)
CPR 32.19: What UK Courts Require to Prove a Document Is Authentic
NDA Breaches and the Evidence Problem: Proving What Was Disclosed Under an NDA
James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com