Skip to main content
web60

Infrastructure

Somebody Owns the Copyright to Every Photo on Your Website. It Might Not Be You.

Graeme Conkie··14 min read
A grid of overlapping empty picture frame outlines on a warm grey background, with one large teal circle overlapping several of the frames

Every image on your site is somebody's property. If you cannot say whose, you are exposed, and not in a vague theoretical sense that you can put off until next year. A licensing enforcement agency can find that photo with a reverse-image crawler, match it against a photographer's catalogue, and send you an invoice for using it. I have watched that letter land on business owners who had no idea they had done anything wrong.

That is the part I find genuinely infuriating. Almost nobody who gets caught was trying to steal anything. The site got built, photos went on it, nobody asked where they came from, and three years later an email arrives with a reference number and a figure in it.

Irish Copyright Needs No Symbol, No Notice, and No Registry

Most owners get one thing wrong before they get anything else wrong. They look for a copyright symbol, do not find one, and conclude the image is free to take.

The Intellectual Property Office of Ireland is blunt about this. There is no system of registration for copyright protection in Ireland, because copyright arises automatically on the creation of an original work. No form, no fee, no notice, no symbol. The photographer owns it the instant the shutter closes.

And photographs are explicitly covered. The Copyright and Related Rights Act 2000 defines an artistic work to include photographs "irrespective of their artistic quality", which is my favourite phrase in the whole Act. A badly lit snap of a coffee cup on a windowsill is protected exactly as firmly as a magazine cover.

How long does that last? Under the Act, protection runs until 70 years after the death of the author. So the image you lifted in 2019 will still be protected long after you have handed the business to somebody else. There is no expiry date you can quietly wait out.

The Act Does Contain an Ignorance Defence. Read It Properly.

People assume "I did not know" is worthless in law. It is not, quite. Section 128 of the Act is short and worth reading in full, because it does not say what people hope it says.

Subsection (2) provides that where it is shown that at the time of the infringement the defendant "did not know and had no reason to believe that copyright subsisted in the work", the plaintiff is not entitled to damages. That sounds like a lifeline. It is not much of one.

Look at what the test actually turns on. The question is not whether you knew you needed a licence. It is whether you had reason to believe that copyright existed in the work at all. For a professionally shot photograph pulled off a search results page, that is a very difficult argument to run with a straight face. And subsection (3) lets the court award aggravated or exemplary damages on top of ordinary compensation where the circumstances warrant it.

I am not your solicitor and none of this is legal advice. If a letter lands on your desk, get one. The point is narrower than that: the defence people assume they have is not the defence the Act actually gives them.

The Letter Will Not Come From the Photographer

This is the bit that catches owner-operators off guard. The photographer does not spot your site and ring you up. A licensing enforcement firm does it at scale, crawling the web with image-matching software on behalf of agencies and rights holders, then localising a demand letter to your jurisdiction.

The sums vary enormously and you should treat any single figure with suspicion. CBS News in Boston reviewed a batch of these letters and found settlement demands running from roughly fourteen hundred dollars up past eight thousand, with the letters citing US statutory maxima that do not apply here at all. Irish and UK demands tend to land considerably lower, often in the high hundreds. Different jurisdiction, different remedies, same business model.

Consider the pattern rather than the numbers. A garden centre in Meath refreshes its homepage for the spring planting season. Somebody grabs a nice shot of tulips from an image search because the real photos were taken in November and everything looks dead. Three years on, a demand arrives for that one picture. The person who put it there was a part-time helper who has long since moved on, the agency that built the site has been wound up, and there is no receipt to produce because there was never anything to receive. That is a composite of a pattern we see rather than one named business, but the shape of it is depressingly consistent.

Worth checking before you assume you are covered: liability for copyright claims usually sits under a media or multimedia extension of a policy rather than in the core cyber section, so it is worth reading yours properly. The fine print in a cyber insurance policy is a better guide to your actual exposure than the summary page.

I will admit my own version of this. Years ago I signed off on a marketing page for one of our own properties using imagery a contractor had supplied, and I never asked him for the licence receipt. Nothing ever came of it. That was luck, not process, and we ask for the receipt now.

Flat illustration of a plain document sheet sitting over a cluster of overlapping teal and navy circles traced with fine ellipse lines
Enforcement runs on image-matching software at scale, not on a photographer noticing your homepage.

Four Ways Unlicensed Images End Up on an Honest Website

None of these involve anyone behaving badly. They involve nobody being responsible for the question.

Image search treated as a library. Someone needs a picture, types a description into a search engine, saves the best result. The search engine is an index of the web, not a rights clearance service. Nothing about the interface tells you that.

A handover with no records. Your last designer or agency chose the images. They may well have licensed them properly. But the licence was bought in their name, their account, and their inbox, and none of it came across in the handover. You are the publisher now, and you hold nothing you can produce.

Supplier and manufacturer product shots. Retailers reuse these constantly, and often they are genuinely permitted. Often is not always. Permission to sell a product is not automatically permission to publish the photography that came with it, and a written line in an email from your supplier costs you nothing to obtain.

"Free" stock sites with conditions in the small print. Some free licences require attribution in a specific form. Some exclude commercial use, which is exactly what your business website is. And some images on free platforms were uploaded by people who did not own them in the first place, which means the licence you relied on was never valid to begin with.

Credit for one thing, honestly: closed website builders that bundle their own stock library do remove this problem for you. The licence travels with the platform, so there is nothing to track and nothing to prove. If your business needs four images and you never intend to change them, that is a real advantage and I am not going to pretend otherwise. The catch is that it only covers their images, not the ones you upload yourself, and it lasts exactly as long as your subscription does.

AI-Generated Images Are Not the Loophole People Think

The obvious response to all of this is to generate your own images and be done with it. That solves the infringement question reasonably well. It creates a different one.

You probably do not own the result. The United States Copyright Office published the most detailed public analysis anyone has produced on this in Part 2 of its report on copyright and artificial intelligence, and its finding on prompting is direct: providing prompts is not authorship, because the person prompting does not determine the expression the system generates. Ireland and the wider EU apply the same underlying principle, requiring a work to be its author's own intellectual creation. Meaningful human creative input can change the analysis. Typing a description on its own generally does not.

So what does that mean at street level? If you generate a striking hero image and build brand recognition around it, you may have no exclusive right to stop a competitor two towns over using the identical output. You have avoided a bill. What you have not done is acquire an asset. Anyone treating an AI-built site as a set of things they own outright should read about the AI generated website that nobody could edit six weeks later, because the ownership question runs deeper than the images.

There is a regulatory layer arriving too, and it deserves precision rather than alarm. Article 50 of the EU AI Act applies from 2 August 2026, days after I am writing this.

Read the allocation of duties carefully, because most coverage of it does not. The machine-readable marking obligation in Article 50(2) falls on the providers of the AI systems, not on the business publishing the output. Deployers like you get a much narrower duty under Article 50(4), covering deep fakes and AI-generated text published to inform the public on matters of public interest. A generic illustration on your homepage is very unlikely to need a visible label. Check with your solicitor if your use is anything less ordinary than that.

What genuinely changes is detectability. Once providers embed those marks, generated content becomes far easier to identify at scale, which matters if you have been quietly passing AI imagery off as photographs of your own premises.

Split panel illustration with a solid navy rounded frame on a teal field beside an empty dashed outline frame on warm grey
A generated image avoids a licensing bill. It does not hand you anything exclusive.

What a Properly Run Media Library Actually Looks Like

Forget platforms for a moment. Any decent arrangement, on any host, meets four conditions.

Every image has a known origin. You can say where each one came from, even if the answer is "our own phone, taken in the shop". Second, every licensed image has a retrievable record: an invoice, a licence PDF, or a plain written email from the photographer, stored somewhere in the business rather than in one person's downloads folder. Third, that record survives staff changes, agency changes, and rebuilds, because the business owns it and not the person who happened to build the site. And fourth, you can actually get at the files. If you cannot export your own media library and look at it, you cannot audit it.

That last condition is where hosting genuinely matters, and it is why full WordPress beats a walled garden for this. Your uploads directory is a directory. It is yours, with dates on the files. Web60 runs real WordPress on Irish infrastructure with a built-in file manager and SFTP access, so pulling the whole media library down and going through it is an afternoon's work rather than a support ticket to a platform that may or may not answer. Keeping the licence records alongside your other business documentation is part of the same housekeeping as a proper WordPress security and backup routine, and it is worth doing at the same time.

The commercial angle is simple enough. A demand letter is precisely the kind of unbudgeted cost that damages a small business, and the whole point of hosting that costs sixty euro a year with everything included is that nothing arrives later with a figure on it that you were not expecting. Removing surprises is most of the job.

Now the honest limitation, because I would rather you heard it from me. No hosting platform, ours very much included, can tell you whether you hold a licence for a given photograph. We can show you every file on the server and the date it was uploaded. Nobody can produce a receipt that never existed. That audit is yours to run, and the tooling only makes it faster.

One more thing that surprises people. Taking the image down does not undo the past use. It stops the clock, which is worth doing immediately, but the period it was published still happened. Deleting it and hoping is not a strategy.

Conclusion

Nobody sets out to publish a photograph they have no right to publish. It happens because images are the one thing on a business website that everybody handles and nobody owns responsibility for, and because the internet presents itself as a library when it is really a shop with no visible prices.

Open your site this week and count the images on it. For each one, answer a single question: where did that come from, and can I show somebody the paperwork? Most owners cannot answer it for every image, and that is fine as a starting point. The gap between not knowing and knowing is a couple of hours and a folder, and it is very much cheaper to close it before somebody else closes it for you.

Frequently Asked Questions

Can I use images from Google Images on my business website?

No, not without checking the licence first. An image search is an index of pictures published across the web, not a library of images cleared for reuse. Some results will be freely licensed, many will not be, and the search interface does not reliably tell you which is which. Click through to the source, find the licence terms, and keep a copy.

Is crediting the photographer enough?

Generally no. Attribution satisfies some licences, notably certain Creative Commons variants, but only where the licence requires attribution as its condition. If no licence was granted at all, adding a credit line does not create one. It can actually make matters worse by evidencing that you knew the image was somebody else's work.

What should I do if I receive a copyright demand letter about an image on my website?

Do not ignore it, and do not pay it on the spot either. Take the image down straight away, then verify the claim: check whether the sender genuinely represents the rights holder, whether the image is the one they say it is, and whether you hold a licence you had forgotten about. Then get advice from a solicitor before you respond. These letters are written to be intimidating and the opening figure is rarely the final one.

Do I own an AI-generated image I made for my website?

Probably not, at least not on the strength of the prompt alone. The US Copyright Office has concluded that providing prompts is not authorship, and EU law requires a work to be its author's own intellectual creation. Substantial human creative modification can change that position. In practice, treat generated imagery as safe to use but not as something you can stop others from using.

Does deleting the image fix the problem?

It stops the ongoing use, which matters and should be done immediately. Deletion does not erase the period during which the image was published, and enforcement firms typically capture dated screenshots before they make contact. Remove it, then deal with the claim on its merits.

Are free stock photo sites safe to use for a business site?

Mostly, with care. Read the actual licence rather than the headline word "free", because some require attribution in a set form and some exclude commercial use. Download a copy of the licence terms as they stood on the day you took the image, along with the download page. If a claim ever arrives, that record is the difference between a five-minute reply and a negotiation.

Sources

Graeme Conkie
Graeme ConkieFounder & Managing Director, Web60

Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.

More by Graeme Conkie

Ready to get your business online?

Describe your business. AI builds your website in 60 seconds.

Build My Website Free →
Buy NowTry Free
Website Photo Copyright: Who Actually Owns Yours? | Web60