The reflex is understandable. A page needs a picture, a search returns thousands, one of them is perfect, and it is on the server before the paragraph is finished. The trouble is that a web page is not a mood board: it is a publication, in the legal sense, and the image on it is reproduced and communicated to the public whether or not anyone charged for the privilege. The obligations attach at upload. For the full shape of what a licence actually covers, territory, duration, exclusivity, releases and provenance, the UK reference we reach for is The Rights Desk and its pages on picture licensing for websites.
What should a site owner check before uploading a found image?
Four questions, in order. Who made it, and who holds the rights now; the photographer and the current rightsholder are often different entities. What licence attaches to the copy in front of you, and whether that licence covers editorial web use, commercial use or neither. Whether the image needs releases beyond copyright: a recognisable person, a private interior, a trademarked product each carry their own permission layer. And whether the file is what it claims to be, which is the provenance question covered below. An image that survives all four checks is safe to publish; an image that fails one is a liability with a nice crop.

The grey zones are where sites actually get bitten. Google Images is an index, not a licence. A photographer’s portfolio site is a shop window, not a gift. Social platforms grant the platform a licence, not you. And in the UK the copyright exceptions catalogued on the government’s guidance page are narrower than the folklore suggests: quotation, criticism and review have conditions, and “it was already online” is not among them.
Does a web licence differ from a print licence?
Yes, and in ways that matter at renewal time. A print run is bounded: ten thousand copies, distributed, done. A web page is unbounded in time and territory by default, which is why web licences are written around duration and placement rather than print run. A licence bought for a campaign microsite does not automatically cover the blog post that reuses the same picture; an editorial licence does not stretch to the advertising banner beside it. The boundary between editorial and commercial use is the clause most often misread, and it is the one that decides whether a marketing page may carry the image at all.
Rights-managed and royalty-free are pricing structures, not permission levels: royalty-free still means licensed, with stated limits. The habit that keeps a site clean is boring and cheap: record the source, the licence and the date next to each image, the way the refresh guide records what changed on a page and when. The day a claim arrives, the file answers it.
Which provenance signals show an image is what it claims?
Start with the metadata that survives: IPTC fields carry creator, credit and rights lines when the supply chain bothered to fill them. Newer files may carry signed credentials that record where the image came from and whether it was altered or generated, which matters more each month as generated pictures enter the libraries. A claimed image with no metadata, no credit line and no findable source is not automatically fake, but it is unverifiable, and unverifiable is a reason to keep looking rather than a reason to publish. Orphan works, images whose rightsholder genuinely cannot be found, have their own licensing route rather than a shrug.
The working rule this desk uses: an image earns its place on the page the way a fact does, by being traceable. The publishable image is the one whose chain you could show a stranger without embarrassment.