AI
How to incorporate AI without risking your intellectual property
A pricing model that took three months to argue into shape can be improved by an assistant over lunch. So can the onboarding sequence, the margin assumptions and the deck. The speed is real, and it is why the fifth and sixth paste happen without anyone asking what is in them.
What is in them, often enough, is the part of the business that has value precisely because nobody outside it has seen it. That has a legal shape, and it is the only kind of intellectual property a company can lose by accident.
Patents and trademarks survive neglect, because they are registered and on file whatever kind of quarter you had. A trade secret has no file. It lasts exactly as long as its three conditions hold, and the third of those is not about the information at all.
What actually makes something a trade secret
Trade secret protection has no registration, no filing fee and no expiry date. It also has no automatic existence. The USPTO sets out three conditions: the information has actual or potential independent economic value because it is not generally known, that value comes from others being unable to discover it by proper means, and the owner takes reasonable efforts to maintain its secrecy. All three are required, and the office is explicit that if one of them stops being true, the trade secret stops existing.
The third condition is the one AI touches directly. Reasonable efforts is not a feeling about how careful your team is. In a dispute it becomes a list of things you did: who signed what, which systems held the material, what your policy said, and whether anyone followed it. Pasting your customer acquisition model into a service that retains conversations and reserves training rights is a fact that goes on that list, on the wrong side of it. So is the decision to move the same work to a ChatGPT alternative that retains nothing, which goes on the same list on the other side, with a date on it.
Can you copyright what the model gives back?
The other half of the problem runs in the opposite direction. Material you feed in can lose protection. Material that comes out may never have had any. A landing page written end to end by a model sits on uncertain ground if a competitor copies it word for word, and the same goes for generated illustration, generated code and generated product names.
Image Credit: Addicted2Success
What governs this is the human authorship requirement, which the US Copyright Office has been working through in public since 2023 and now addresses directly on its AI initiative pages. The practical reading is that protection attaches to what a person contributed rather than to what the tool produced on request. For marketing copy that is survivable. It matters a great deal more when the generated thing is the core of what you sell, and which side of that line an asset falls on is worth settling before the asset exists.
Set the boundary at the tool
Writing the AI policy is the easy part. The hard part is being able to say, months later, whether anyone followed it. A rule that lives in a Notion page and depends on ten people remembering it under deadline pressure is a rule you cannot evidence, and evidence is the whole game under condition three.
A tool whose retention behavior you can point to is different. When conversations are encrypted so the provider holds no key, or the terms contractually exclude training and you kept the signed version, you have something to hand a lawyer. When the code is open and independently reviewable, you have something better than a claim. That is the basis to choose on, and the policy comes afterwards, written to describe what the tool already does, so the two documents still agree on the week everyone is shipping.
What happens when the secrets are someone else’s
Your own secrets are the easier half. Client work usually arrives with confidentiality terms that prohibit disclosure to third parties, and an assistant that stores the text and reserves the right to train on it is a third party by any reading. That is not a hypothetical exposure. Enterprise buyers now ask about it directly in security questionnaires, and the question is not whether you have a policy. It is what your tools do.
Which means the answer has to be true in three places at once: in the vendor’s terms, in what your sales team has been telling customers, and in what your team actually did last Tuesday. Those three drift apart quietly and nobody notices until diligence. A tool that retains nothing collapses them into a single answer, because there is nothing left to reconcile. Keep the record of it, and the speed stays available to you without your pricing model ending up in a corpus you do not own.