Artificial intelligence has not created a separate body of law so much as it has put pressure on the laws we already have. The questions are the familiar ones: who owns this work, is any of it protectable, what did we license, what did we fail to keep confidential. Each gets harder once the work is produced with tools trained on material the business does not own, and configured in ways nobody inside the business has read.
The cheapest exposure to create is the confidentiality one. Where a tool's terms permit the provider to retain inputs or train on them, material entered into it may no longer be secret in any sense the law recognizes. Trade-secret protection depends on having taken reasonable measures to keep the information secret, so what matters is not whether an individual employee meant well. It is which tools the business approved, what it told its people they could enter, and whether anything was in place to make that instruction stick.
Vendor terms govern most of that, and those terms reward close reading. They set whether inputs are retained and for how long, whether the provider trains on your data, what confidentiality obligations actually attach, what the provider will and will not indemnify, and what becomes of your material when the agreement ends. Retention and training are frequently configurable rather than fixed, which means a business can hold a protection it never switched on, or assume one it does not have.
Those terms then have to reach whoever is doing the work. If a contractor, an agency or a sublicensee operates the tool, a no-training or confidentiality term that binds only the company you signed with protects considerably less than it appears to. Flow-down provisions are the fix. They require you to pass the same obligations on to everyone further down the chain, so the promise made to you also binds the people actually handling the material.
What can be claimed in the output is a different question from who owns it, and it is the one people get wrong. In its January 2025 report on copyright and artificial intelligence, the Copyright Office set out its position that copyright does not extend to purely AI-generated material, or to material where there was insufficient human control over the expressive elements, and that on current technology prompts alone do not supply the control that authorship requires. What a human contributes can still be protected: expression perceptible in the output, the creative selection, coordination or arrangement of material, and creative modification of what the tool produced. Whether a particular contribution is enough is assessed case by case, and the Office has said it will revisit its conclusions as the technology and the law develop.
The practical response is not to avoid these tools. It is to be deliberate about how they are used, to know which parts of the output the business can actually claim, and to keep a record of how the work was conceived, produced and settled into its final form. Such a record is straightforward to keep while the work is under way and difficult to reconstruct once it is finished.
Governance is what turns those decisions into something a business can rely on. A usable AI policy is short and specific: which tools are approved, what categories of information may never be entered into them, when the use of a tool must be disclosed to a client or counterparty and who is responsible for making that disclosure, and who inside the business decides the questions the policy does not squarely answer. It is also the document an acquirer, an insurer or an opposing party is likely to ask for, which is a reason to be able to produce one before anybody asks.
Many organizations are, and the exposure builds quietly. Where a particular business stands depends on which tools it uses and on what terms.