AI creates two separate risks for architects. On copyright, work generated mostly by AI may not be protected, the tool's terms decide what you own, and image generators can produce something close to another designer's work. On client data, drawings, briefs and site photos uploaded to the wrong plan can be stored, used for training or even published.
The two risks need different fixes, which is why practices that treat "AI risk" as one thing tend to fix neither. Copyright risk is managed by how much genuine design control your team keeps and by choosing tools whose training and terms you can live with. Data risk is managed by which plan you're on, what staff are allowed to upload, and what your appointment says. A practice can be careful about one and careless about the other: a principal who never uploads client drawings may still be pasting "in the style of" a famous living architect into an image prompt every week.
Who owns an AI-assisted design, in plain terms
Three questions get mixed up here, and they have different answers.
Does the tool let you use the output? That's a contract question, answered by the tool's terms. Midjourney's terms, for example, say users own what they create, but a company with more than $1 million a year in gross revenue must be on the Pro or Mega plan to own its outputs. A practice above that threshold on a cheaper plan is outside its own tool's terms.
Is the output protected by copyright at all? That's a legal question, and in many jurisdictions copyright protects human authorship. An image produced from a one-line prompt, with no further human design input, may have little or no protection, which means a competitor or client could reuse it and you'd have limited grounds to object. Some jurisdictions have special rules for computer-generated works, and the law is still moving, so treat this as a question for an IP solicitor if a design's value depends on it.
Does the output infringe someone else's rights? That depends on what the output looks like and, arguably, how the model was trained. In June 2025 Disney and Universal sued Midjourney, alleging it was trained on their works and generates copies of their characters. Buildings aren't cartoon characters, but the same logic applies to an AI image that closely reproduces a specific, recognisable building, drawing or photograph.
For practices this matters because of how appointments usually work. Most architect appointments keep copyright in the design with the architect and give the client a licence to use it for the project. That arrangement is what stops a client taking your scheme to a cheaper practice for the next phase. If the distinctive parts of a scheme came mostly from an image generator, your position in that argument is weaker. The practical rule: let AI generate options, but make sure the design that goes forward is visibly shaped by your team's decisions, sketches and drawings, and keep the evidence (dated sketches, model iterations, design notes).
That evidence is easiest to keep as a short design log on each project, one line whenever AI output feeds a decision. Two illustrative entries for a small infill house:
| Date | AI used for | What it produced | What we decided | Evidence |
|---|---|---|---|---|
| 12 Mar | Six facade options from the massing model | Mixed materials; option 4 had vertical timber fins | Kept none as drawn. Took the fin idea, set spacing to the 1.2m structural grid, reduced to the upper storey only | Sketch SK-07; model v3 |
| 19 Mar | Mood images for the entrance | Deep recessed porch in brick | Rejected: loses the ground-floor study. Recess reduced to 600mm, door moved to the side | Sketch SK-09; client meeting note 20 Mar |
Two minutes per entry. If a client later reuses the scheme, the log shows the design choices were your team's, and the AI images were one input among several.
How an image generator slips someone else's work into a concept board
Style as such usually isn't protected by copyright, but close copies of specific works can be, and image generators don't warn you when they've drifted from "influenced by" to "near copy". The risk rises with how specific the prompt is. Compare two prompts a junior designer might write for the same concept board:
Riskier:
"Rear extension in the style of [named living architect], like their
house at [named project], same cantilevered roof and timber fins,
photorealistic."
Safer:
"Single-storey rear extension to a brick terraced house, charred timber
cladding, deep flat roof overhang facing the garden, full-width sliding
glazing, overcast light, early concept sketch style."
The first asks the model to reproduce a particular building. If the result looks like it, you have a concept image you can't safely show a client, submit or publish. The second describes materials, form and mood, which is what a concept board is for.
Tool choice changes the risk too. Adobe says its Firefly models are trained on content it has permission to use, such as Adobe Stock and public-domain material, and it offers contractual IP indemnification for select outputs to enterprise customers. That doesn't make every output safe, and the indemnity doesn't extend to every plan, but it's a different risk position from a model trained on scraped images. One catch: the Firefly app also offers partner models from other companies, and Adobe's statements about licensed training data cover its own Firefly models, not those. A concept board built in Firefly Boards can mix images from both, so check which model made each image before one goes into marketing. If a practice uses AI images in marketing or client presentations regularly, the training source of the tool is worth checking. The tutorial on whether you can legally use AI-generated images in marketing covers the wider picture.
What happens to a client's drawings once you upload them
Architects handle unusually sensitive material without always thinking of it that way: floor plans of private homes (which show where valuables and bedrooms are), security layouts for schools or offices, unannounced commercial projects, planning strategies a developer hasn't disclosed, and site photos with neighbours, children and number plates in them. Where that material goes depends on the plan and the tool.
- Public galleries. On Midjourney's cheaper plans, generated images are visible in its public gallery. Only Pro and Mega plans offer Stealth Mode to keep them private. An unannounced scheme rendered on a basic plan is, in effect, published.
- Training on your uploads. Consumer chat assistants let users switch off model training in privacy settings, but it's on by default on some; business plans such as ChatGPT Business, Claude Team and Gemini in Workspace don't train on business content by default. Staff using personal accounts for work bypass whatever the practice chose.
- Retention and sub-processors. Even with training off, uploads may be kept for a period and handled by other companies the vendor uses. The guide to checking an AI tool's privacy terms shows what to look for.
- AI inside your design software. Rendering plug-ins and AI features in CAD or BIM packages may send model data to the vendor's servers. Check each feature's terms, not just the main licence.
Much of the exposure is in the words typed, not the files attached. Here's a request to draft part of a design and access statement, before and after a one-minute edit:
Before:
"Draft the context section for [client company]'s new flagship at
[street address], opening next spring. They're keeping the launch
quiet until the lease on their current store ends. Scheme is three
storeys, glazed ground floor, retained upper facade."
After:
"Draft the context section for a retail scheme on a corner plot in
a mixed high street. Three storeys, fully glazed ground floor, upper
facade retained. Neighbours: a two-storey bank and a terrace of
shops with flats above."
The draft that comes back is just as usable, because the model needed the building, not the client. The names, address and launch plans go back in when the text is pasted into the practice's own document.
A risk map for the AI jobs practices actually do
| AI job | Copyright risk | Client data risk | Control that works |
|---|---|---|---|
| Concept images from text prompts | Medium to high: weak protection, possible near copies | Low if no client material is uploaded | Describe form and materials, never named works; keep sketches showing your design input |
| Rendering your own 3D model | Low: geometry and design are yours | Medium: the model is uploaded | Private or business plan; check the render tool's retention terms |
| Design and access or planning statement drafts | Low | Medium: brief and site details go in | Business plan; remove client names and addresses from the prompt |
| Specification and schedule drafting | Low | Low to medium | Check every product and standard referenced; AI invents product codes |
| Client meeting notes | Low | High: personal and commercial detail | Tell attendees, use an approved tool, delete recordings on a schedule |
| Marketing images of completed work | Medium if AI adds or alters features | Medium: identifiable homes | Client permission; don't let AI "improve" what was built |
The rendering row is the one practices most often get backwards. Rendering your own model feels risky because it's your real project, but the copyright position is strong (the design is yours) and the data risk is fixable with the right plan. Text-to-image concepts feel harmless because nothing confidential goes in, but they carry the weaker ownership position. The comparison of AI rendering tools for small practices notes which tools offer private modes.
The marketing row fails in a way that's easy to picture. A practice photographs a finished house extension, but scaffolding is still up next door, so someone asks an image assistant to "remove the scaffolding and tidy the background". It does, and it also removes the neighbour's own dormer and replaces their dated windows with neat new ones. The image goes on the practice's social feed. The neighbour sees their house "improved" in someone else's advert and complains; the client, who has to live next to them, is embarrassed. The fix is procedural: AI edits to photos of real buildings are limited to what was asked (sky, scaffolding, a skip), someone compares the edited image with the original before posting, and third-party property is left exactly as it is or cropped out.
Walking one project through both risks
Take a five-person practice: a principal, two architects, a technologist and a part-time assistant, working on two jobs at once. One is a rear extension for a family. The other is a shop fit-out for a retail client who has signed an NDA with the practice because the store opening is unannounced.
The extension. The architect wants 20 concept images for the first client meeting. She uses an image generator on a business plan with private generation, writes prompts that describe materials and form (no named architects or buildings), and picks three directions. From there, the design moves into sketches and the practice's own 3D model; the AI images appear in the meeting deck labelled "early mood images, not the design". The client's measured survey and photos of the garden, which show two neighbours' back windows and a child's bedroom, never go into any AI tool. Time cost of the precautions: about 15 minutes to write better prompts and add the label.
The fit-out. The NDA says confidential information must not be disclosed to third parties without consent. An AI service is a third party. Before using any AI tool on this project, the principal emails the client: "We use [tool] on a business plan that doesn't train on our content and keeps renders private. We'd like to use it for internal renders and specification drafting only. Please confirm you're happy with that." The client agrees for renders but not for uploading its brand guidelines. That answer goes on the project file. Without that email, one upload by the technologist would have been a breach, however harmless it felt.
What changed across both projects: two plan settings, one email, one label, and a rule about survey photos. None of it slowed the work in any way the clients would notice.
An edge case the fit-out raises: the practice's obligations travel with the drawings. When the structural engineer and a freelance visualiser receive the shop's drawings, the NDA still binds the practice, but those consultants make their own tool choices. A visualiser who drops the model into a browser render tool on a public-gallery plan has published the unannounced store, and the client will hold the architect responsible. One sentence in the issue email or sub-consultant brief handles it: "This project is confidential under an NDA; please don't upload drawings, models or images of it to AI tools unless you've confirmed with us that the tool keeps them private and doesn't train on them."
Four assumptions that don't hold up
"We pay for it, so we own it and nobody can copy it." Paying settles what the tool's terms allow. It doesn't make a mostly AI-generated image protectable. Both questions need answering.
"Nothing confidential goes into image prompts." Staff describe projects in prompts all the time: "four-storey mixed-use block on a corner site next to the railway station, client wants 42 flats". On a public-gallery plan, that description and the image become visible.
"A business plan means no risk." It removes default training and usually tightens retention. It doesn't stop a staff member using a personal account, uploading an unredacted survey, or publishing an AI image with a neighbour's house altered in it.
"Old project drawings are ours to reuse." Your copyright in the design doesn't cancel the confidentiality you owe past clients. Uploading an archive of house plans to build a "practice style" generator puts old clients' layouts into a tool they never agreed to. If you want to reuse past work, the tutorial on reusing past client work without leaking client data shows how to strip what identifies them.
Clauses to add to your appointment and your staff rules
Two short pieces of wording close most of the gap. First, a line for your appointment or terms of engagement (have your own adviser or professional body's template reviewed before relying on it):
AI tools. We may use artificial intelligence tools to help prepare
concept images, renders, drafts and notes. We use business versions
that do not train on client material, and a qualified member of our
team directs and reviews all design work. We will not upload your
drawings, surveys or confidential information to AI tools without
your agreement where you have told us the project is confidential.
AI-generated illustrations are labelled as illustrative and do not
form part of the design unless stated.
Second, five rules for the studio wall:
1. Approved AI tools only, on practice accounts. No personal accounts
for project work.
2. Never name a living architect, a specific building or a
photographer in an image prompt.
3. Never upload surveys, site photos with people or neighbours'
property, security layouts, or NDA material without the project
lead's written OK.
4. Label every AI image in client, planning or marketing material.
5. Keep your sketches and model iterations: they show the design is ours.
Rules on a wall drift unless someone checks them. Every quarter, spend 20 minutes asking each person which AI tools they used for project work last month, then compare the answers with the approved list and look at the account settings. An illustrative first check in the five-person practice turned up three things: the technologist had drafted a specification section in a personal chat account because the practice login was on another machine; the image tool's private-generation setting had been switched off after a plan change; and the part-time assistant was making marketing graphics in a design app nobody had reviewed. None had caused harm yet. The fixes took an afternoon: a shared login on the second machine, the setting back on and noted in the renewal checklist, and a look at the design app's terms before it was added to the list.
If you're weighing where AI fits in the practice more broadly, where AI saves a small architecture practice time covers the uses with the best return, and most of them sit in the low-risk rows of the map above.
Questions architects ask about AI, ownership and confidentiality
Can a client refuse to let us use AI on their project?
Yes, if your appointment says so or if they ask and you agree. Some clients, especially on commercial or security-sensitive projects, add a clause restricting AI tools or requiring approval. It's easier to raise it yourself at appointment stage, explain which tools you use and for what, and record the agreement, than to discover a restriction in a contract amendment halfway through a project.
Should we label AI-generated images in a planning submission?
Label them clearly as illustrative and never present an AI image as an accurate view of the proposal. Planning decisions rely on drawings and visuals representing what will be built. An AI image that improves the massing, softens a neighbour's outlook or invents landscaping can mislead, and it becomes a public document once submitted. Accurate verified views still need your own model and a proper method.
Is it safer to run an image model on our own computers?
It removes the risk of uploads being stored or published by an online service, which helps with confidential projects. It does not remove the copyright questions about how the model was trained or whether its output resembles someone else's work. You also take on the job of keeping the software and machines secure, which a small practice may find harder than choosing a business plan with good terms.
Further reads
- AI for Freelance Designers: Faster Concepts Without Rights Issues — How designers keep AI concept work clear of rights problems.
- AI Renders vs Outsourced Visualisation: What Practices Save — What a practice actually saves by moving renders in-house.
- How Architects Use AI for Fee Proposals, Briefs and Paperwork — Lower-risk AI jobs: fee proposals, briefs and paperwork.
- Should You Design Your Logo With AI? Copyright and Quality Risks — Copyright and quality risks when AI designs your own brand marks.
- How to Stop AI Tools Training on Your Business Data — How to switch off model training in the tools your team uses.
- How Much Does AI Cost a Small Architecture Practice per Month? — What the safer business-plan versions of these tools cost.
- AI Room Visualisation From Client Photos: A Designer's Workflow — Turn a client's room photo into an honest concept visual: shooting rules, a lock-list prompt, drift checks and the caption every image needs.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Midjourney Terms of Service and plan documentation (ownership threshold and Stealth Mode); Adobe Firefly business pages and enterprise legal FAQs (training data and IP indemnification); public reporting of the June 2025 Disney and Universal lawsuit against Midjourney; vendor privacy terms for business AI plans.