For most of the last three years, documenting AI use was a courtesy. In 2026 it is a contractual and legal requirement in several of the places creative work actually gets delivered. The requirements come from different directions, but they converge on the same demand: not a yes-or-no answer about AI, but the record behind the answer. This guide walks through who requires what, then gives you the per-shot checklist that satisfies all of them at once.
Who already requires documentation
Streaming platforms. Netflix tells its production partners directly: “we expect all production partners to share any intended use of GenAI with their Netflix contact.” The guidance sets out five guiding principles for low-risk use, one of which is that “Generated material is temporary and not part of the final deliverables.” The moment your generated material crosses that line, the requirement escalates: “if the output includes final deliverables, talent likeness, personal data, or third-party IP, written approval will be required before you proceed.” To request that approval credibly, you need to state what was generated, with which tool, and what ended up in the cut. That is documentation, whether or not the word appears in your contract.
Agency associations. The German agency association GWA tells agencies in its KI-Whitepaper that when they use AI tools, their co-responsibility covers the labelling obligation and the documentation of use. The whitepaper also walks through the EU AI Act’s transparency duties that apply from August 2026 and the liability questions that follow when AI-generated content causes a dispute. The practical consequence for an agency is that a client can ask, at any point after delivery, how a given asset was made, and the agency is expected to have an answer on file rather than a reconstruction from memory.
Rights offices. The US Copyright Office’s registration guidance states that “applicants have a duty to disclose the inclusion of AI-generated content in a work submitted for registration and to provide a brief explanation of the human author’s contributions to the work.” AI-generated content that is more than de minimis should be explicitly excluded from the claim, which means you must be able to say precisely which parts of the work are AI-generated and which parts a human authored. The guidance also warns that applicants who fail to correct the record “risk losing the benefits of the registration.” If your client ever registers the work you delivered, your documentation is what makes their application accurate.
The EU AI Act. Article 50 of Regulation (EU) 2024/1689 creates transparency obligations for AI-generated and AI-manipulated content and applies from 2 August 2026. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake “shall disclose that the content has been artificially generated or manipulated.” Non-compliance with Article 50 sits in the penalty tier of up to EUR 15 000 000 or, for an undertaking, up to 3 % of total worldwide annual turnover, whichever is higher. We cover the article in detail, including the carve-out for evidently artistic work, in the companion guide EU AI Act Article 50 for creative teams.
What these requirements have in common
None of them can be answered from the finished file. A delivered MP4 or PNG does not carry its own history: it does not say which regions were generated, which prompt produced them, what a human repainted afterwards, or whose reference images shaped the style. Every requirement above is really a question about the making of the work, and the making of the work only exists as a record if someone kept one. Teams that try to assemble that record at delivery time discover the same failures every time: prompts were never saved, the tool has since updated and renamed its models, the freelancer who ran the generation has rolled off the project, and nobody remembers which of forty-one iterations became the final.
The per-shot checklist
The following checklist covers what every requirement above asks for, applied per shot or per delivered asset. It reads long, but in a working setup most of it is captured automatically at generation time; the manual part is a few sentences per asset.
- Which parts are AI. Classify the asset: fully AI-generated, AI-assisted, or human-made. If it is mixed, describe the boundary in one sentence, for example that the background plate was generated while the character was hand-drawn and composited. This single field answers the Copyright Office’s disclosure duty and the first question every client review asks.
- Tool, model, and version. Record the product name, the specific model identifier, the version in use, and the date of generation. Model names change and behaviour drifts between versions, so “made with Midjourney” is not an answer two years later; “made with model X, version Y, on this date” is.
- The prompt and inputs. Keep the full prompt text, any negative prompt, and every input that shaped the output: image prompts, control inputs, strength settings, and the seed where the tool exposes one. These are the reproducibility fields. Without them, nobody can explain why the output looks the way it does.
- What the human changed. List the edits made after generation: paint-over, retouch, compositing, grading, cutting, upscaling, and who performed each. This is exactly the “explanation of the human author’s contributions” the Copyright Office asks for, and it is also what separates AI-assisted work from AI-generated work in most client policies.
- Whose references are in it. For every reference or style source used, record where it came from, who supplied it, and what permission covers it. Netflix’s escalation categories include copyrighted references and talent likeness for a reason: references are where third-party rights enter the work.
- Who signed off, and when. Record the internal approver, the client approval, and the dates. Where a platform requires written approval, attach it to the asset it covers rather than leaving it in an inbox. An approval that cannot be matched to a specific version of a specific asset protects nobody.
- Version lineage. Note which iteration became the final and how it relates to earlier versions. When a question arrives months later, the first thing anyone needs to establish is which file is actually the delivered one.
Capture during the work, not after
The economics of this checklist depend entirely on when you fill it in. At creation time, every field is either already on screen or one sentence of typing. At delivery time, several fields are unrecoverable at any price. The practical rule is that a generation without its record attached should be treated as unfinished work, the same way an unsaved file is unfinished work. Filled in at creation time, the checklist costs seconds per asset. Reconstructed at delivery time, it costs days and still ships with gaps.
This is also the honest reason documentation tools exist as a category. A shared drive can store a spreadsheet of prompts, but it cannot bind the prompt to the asset, keep the link alive through renames and iterations, or show a client a single page per shot. If you build the habit manually first, you will know exactly what you need from tooling later.
What a delivery package looks like
When the work ships, the documentation ships with it. A complete package contains four things.
- A per-asset record covering the checklist above, one page per delivered asset.
- A project-level summary naming every AI tool and model used anywhere in the production, so the client can answer their own disclosure duties without opening every asset record.
- A disclosure statement in whatever form the client’s policy or the applicable law requires, consistent with the per-asset records behind it.
- The sign-off trail: who approved which version, with dates, and any written approvals a platform required.
Be precise about what your documentation proves
A documentation record is evidence of three things: that specific information was captured, that it has not been altered since, and when it existed. Kept properly, that is strong evidence, and it is what every requirement in this guide actually asks for. It is worth being equally clear about what no record can prove: that a particular reference image causally produced a particular output. No current system can read that relationship out of the pixels, and a vendor who claims otherwise is overclaiming.
State the limits alongside the record. A delivery note that says “these references were used in this generation session, and this record has been intact since that date” is credible precisely because it does not claim more than it can support. A record with stated limits is the kind of documentation a client, a platform, or a rights office can actually rely on.