Most discussion of AI and intellectual property is about copyright: what goes into training and whether outputs copy it. Trademarks are a different body of law with a different question. A trademark is a sign, such as a word, logo or shape, that tells buyers who a product comes from. Trademark law asks whether a use of that sign is likely to confuse people about the source, or, for well-known marks, whether it trades on or damages the mark's reputation. AI systems touch that question in four concrete places, and each one has an engineering control.

This article explains the law at the level an engineer needs, summarises what courts and registries have actually decided so far, and builds the controls: logo and watermark checks on generated images, an attribution check on generated text, a name-clearance screen, and rules for agents that write ads or send messages. It is not legal advice; trademark rights are national or regional, and anything you ship should be cleared by counsel in the markets you sell into.

Trademark law in five ideas

Five ideas cover most of what an engineering team needs.

  • Source identification. A mark protects the link between a sign and a trader. Using the word Apple for fruit is fine; using it for phones is not, because buyers would assume a connection.
  • Likelihood of confusion. The core test compares the marks (how they look, sound and what they mean) and the goods or services. Similar names in unrelated markets often coexist.
  • Classes. Registrations list goods and services, usually grouped by the Nice Classification. Software products are commonly filed in class 9 (downloadable software) and class 42 (software as a service and IT services). A conflict search starts with the classes you will use.
  • Reputation and dilution. Famous marks get wider protection. In the US this is dilution by blurring or tarnishment; in the UK and EU it covers marks with a reputation. Linking a famous brand to low-quality or false content can be actionable even without confusion.
  • Descriptive use. You may usually name another company's product to refer to it, for example to say your tool imports files from a named spreadsheet product, as long as you do not imply endorsement. Purely descriptive terms cannot be registered at all.

Where AI products touch trademarks

Four places an AI product meets someone else's trademarktraining and retrievallogos, watermarks, brand textmodel and agentgenerates, acts, names itself1. marks in outputslogos, watermarks in images2. false attributiontext credited to a brand3. product namingmodel, app, agent names4. agents in commerceads, emails, impersonationcontrolsdetect, attribute, clear, reviewfeedscounseljurisdiction, classes, risk callshortlistEngineering produces evidence and shortlists; a lawyer in the right jurisdiction makes the call.Trademarks are territorial and class-based, so the same name can be free in one market and taken in another.
Figure: the four trademark surfaces of an AI product and where engineering controls feed a legal decision.

The figure maps the four surfaces. Marks in outputs arise when a generator has seen a logo or watermark so often that it reproduces it. False attribution arises when a text model credits invented content to a real publisher or company. Product naming is the oldest problem, made sharper by the rush to put AI-flavoured names on everything. Agents in commerce are new: an agent that drafts ads, emails or listings can use a competitor's mark, or can present itself in a way that looks like another brand.

What decisions and filings show so far

Three public decisions and filings anchor the picture. Each is summarised narrowly; check the current status before relying on any of them.

  • Getty Images v Stability AI (High Court of England and Wales, 4 November 2025). At first instance, Getty's secondary copyright claim failed because the court held the model weights were not an infringing copy. Getty succeeded on trade mark infringement under sections 10(1) and 10(2) of the Trade Marks Act 1994, but only for specific, limited examples of Getty and iStock watermarks generated by early versions of Stable Diffusion; the judge described the findings as extremely limited in scope. The engineering lesson is direct: watermark reproduction in outputs is a trademark exposure, separate from the training question.
  • The USPTO's refusal of OpenAI's GPT application (final refusal, February 2024). The examiner held that GPT merely describes a feature of the goods, generative pre-trained transformer software. Technical terms of art are hard to own, which cuts both ways: you can usually use them descriptively, and you will struggle to register them.
  • Dow Jones and NYP Holdings v Perplexity (S.D.N.Y., filed 2024). Alongside copyright claims, the complaint alleged trademark harms under the Lanham Act, including that the answer engine attributed invented text to the publishers under their names. Whatever the outcome, it shows how publishers frame hallucinated attribution: as a false designation of origin and a tarnishment of their marks.

Control 1: marks in generated images

For image and video generators, the control is a post-generation check plus training-data hygiene. Detect visible watermarks and registered logos in outputs with a detector trained on your own labelled set; open-source logo detection datasets exist but rarely cover the marks you care about, so plan on labelling. Route detections by policy rather than blocking blindly, because many legitimate prompts mention brands.

def review_image(img, prompt, policy):
    hits = logo_detector(img)             # [(mark_id, score, bbox)], your own model
    wm = watermark_detector(img)          # stock-photo overlays, text banners
    if wm.score > policy.watermark_block:
        return "regenerate", {"reason": "watermark", "detail": wm.label}
    for mark_id, score, _ in hits:
        if score < policy.logo_threshold:
            continue
        if mark_id in policy.customer_owned_marks(prompt.tenant):
            continue                       # the customer's own brand: allowed
        if policy.context(prompt) == "editorial":
            return "allow_with_label", {"mark": mark_id}
        return "regenerate", {"reason": "third_party_logo", "mark": mark_id}
    return "allow", {}

Upstream, filter or caption training images that carry stock watermarks; a model that rarely sees them rarely draws them. Log every regenerate decision with the detector score, so that the false-positive rate is measurable and the threshold can be tuned with evidence rather than by complaint.

Control 2: attribution in generated text

In retrieval-augmented systems, hallucinated attribution is detectable because you know which sources were retrieved. If an answer says a publisher reported something, and no retrieved document came from that publisher, the attribution is unsupported. A pattern match catches the common phrasings; a small classifier or an LLM judge catches the rest.

import re

ATTRIB = re.compile(r"\b(?i:according to|reported by|as reported in|says)\s+(?:the\s+)?"
                    r"([A-Z][\w&.\- ]{1,40}?)(?=[,.;:]|\s+(?:that|on|in)\b)")

def unsupported_attributions(answer, protected, retrieved_sources):
    cited = {s.lower() for s in retrieved_sources}
    flagged = []
    for m in ATTRIB.finditer(answer):
        name = m.group(1).strip()
        if name.lower() in protected and name.lower() not in cited:
            flagged.append(name)
    return flagged

unsupported_attributions(
    "According to Reuters, rates rose. As reported in the Wall Street Journal, the deal closed.",
    {"reuters", "wall street journal"}, ["Reuters"])
# ['Wall Street Journal']

On a flag, either rewrite the sentence without the attribution or drop the claim, and record the event. This is the same machinery as a citation verification pipeline; the trademark angle simply raises the priority of attributions that name real brands.

Control 3: screening product and model names

Naming a model, app or agent is where most teams first hit a trademark problem. A useful screen normalises the candidate (strip accents, map look-alike characters such as 0 for o, drop spaces), then compares it against registered marks in your target classes by spelling similarity, sound and containment. Register data can come from the official offices' search tools and bulk data downloads, or from a commercial clearance provider.

import re, unicodedata
from difflib import SequenceMatcher

CONFUSABLE = str.maketrans({"0": "o", "1": "l", "3": "e", "4": "a", "5": "s", "$": "s", "@": "a"})

def normalize(mark):
    s = unicodedata.normalize("NFKD", mark).encode("ascii", "ignore").decode().lower()
    return re.sub(r"[^a-z]", "", s.translate(CONFUSABLE))

def soundex(word):                         # standard 4-character American Soundex
    codes = {**dict.fromkeys("bfpv", "1"), **dict.fromkeys("cgjkqsxz", "2"),
             **dict.fromkeys("dt", "3"), "l": "4", **dict.fromkeys("mn", "5"), "r": "6"}
    if not word:
        return ""
    out, last = word[0].upper(), codes.get(word[0], "")
    for ch in word[1:]:
        code = codes.get(ch, "")
        if code and code != last:
            out += code
        if ch not in "hw":
            last = code
    return (out + "000")[:4]

def screen(candidate, register, classes, threshold=0.8):
    """A shortlist for counsel, not a clearance decision."""
    n = normalize(candidate)
    hits = []
    for e in register:
        if not set(e["classes"]) & set(classes):
            continue
        m = normalize(e["mark"])
        visual = SequenceMatcher(None, n, m).ratio()
        sounds = soundex(n) == soundex(m)
        contains = len(m) >= 4 and (m in n or n in m)
        if visual >= threshold or sounds or contains:
            hits.append((round(visual, 2), sounds, contains, e["mark"]))
    return sorted(hits, reverse=True)

screen("Lumena AI", [{"mark": "Lumina", "classes": [9, 42]}], classes=[42])
# [(0.71, True, False, 'Lumina')]  -- sounds alike: send to counsel

Soundex is crude and English-centric; use it as a recall booster, not a judge. A clean screen is not clearance, because unregistered rights, other languages and meaning also count. What the screen does is stop obviously doomed names early, before design work and domains are bought.

Control 4: agents in commerce

Agents that write marketing copy, product listings or outbound email use other people's marks routinely, mostly legitimately. The risky patterns are specific: comparative claims that are false, a competitor's name used so that the message appears to come from or be endorsed by them, and lookalike sender identities. Put three rules in the agent's output policy: competitor marks only in plain text, never as logos or styled wordmarks; any comparative claim must cite an approved source; and sender names, domains and avatars must come from an allowlist the agent cannot edit.

The same thinking applies to how your own agents are named in tool and agent registries. A tool or skill called after a well-known company, published by someone else, is both a trademark problem and an impersonation vector, so registry reviews should check publisher identity against the brand in the name.

Worked example: launching a writing assistant

This example is illustrative: the names, the toy register and the rates are invented to show the workflow, not drawn from real filings. A team launches a writing assistant called Lumena AI, sold as a hosted service. The name screen returns Lumina, listed in classes 9 and 42 in the team's test register, as sounding alike with a 0.71 spelling ratio. Counsel judges the conflict real in the US and suggests a different name; the team picks one that screens clean and files in class 42. During beta, the attribution check flags 0.4 percent of answers for crediting a named newspaper that was not among the retrieved sources; the team rewrites those sentences automatically and adds the phrasing to the regression suite. The image feature's logo detector fires on 1.2 percent of generations, mostly for users' own brands, so the team adds a tenant-owned-marks allowlist and the regenerate rate drops to 0.3 percent with no new complaints. None of these controls is clever. Their value is that each leaves a log that shows a reasonable process, which is what you want to hand counsel when a letter arrives.

Failure modes

  • Treating copyright clearance as trademark clearance. Licensed training data does not license the marks that appear in it.
  • Blocking every brand mention. Descriptive use is normal and users need it; over-blocking pushes them to tools with no controls at all.
  • Screening one class or one country. A name that is free for class 9 in one market can be taken for class 42 or in the next market you enter.
  • Attribution checks without retrieval logs. If you do not record which sources were retrieved, you cannot tell supported from invented attribution later.
  • No evidence trail. Decisions made in chat and never logged cannot be shown to a court or an insurer.

Trade-offs

Every control trades recall against user friction. Strict logo thresholds regenerate legitimate images; loose ones let watermarks through. Strict attribution checks strip useful citations; loose ones let invented quotes stand. The defensible position is a measured threshold with logged outcomes and a human escalation path, revisited when the false-positive data says so.

There is also a build-versus-buy choice. Commercial clearance services and brand-protection vendors maintain register data, watch new filings and cover many jurisdictions; an in-house screen is cheaper and faster to iterate but sees only the data you load into it. A common split is to screen in-house during brainstorming, when hundreds of names are cheap to reject, and pay for a full search only on the two or three finalists. The same split works for logo detection: a general detector catches watermarks and frequent logos, while a vendor or a custom-trained model covers the specific marks your customers or legal team worry about.

Finally, location matters. Running a check after generation adds latency to every request, while running it asynchronously means some outputs reach users before review. For images, synchronous checks are usually affordable because generation is already slow; for streamed text, check the completed answer and correct it before it is stored or shared. For the neighbouring questions, see AI and copyright, AI model licenses and insurance for AI systems.

What to do next

  1. List where your product touches marks: image outputs, text attribution, product and agent names, agent-written commerce.
  2. Run a name screen across your target classes and markets before naming anything, and send the shortlist to counsel.
  3. Add a watermark and logo detector to image outputs, with a tenant-owned-marks allowlist.
  4. Log retrieved sources per answer and flag attributions to protected brands that the sources do not support.
  5. Write agent output rules for competitor marks, comparative claims and sender identity.
  6. Keep every decision in a log that counsel can read, and review thresholds quarterly.
Key takeaway: Trademarks protect the link between a sign and a source, so AI risk sits in outputs, attributions, names and agent behaviour rather than in training alone. Detect logos and watermarks in images, check attributions against retrieved sources, screen names before launch, constrain agents, and log every decision for counsel.