RatedWithAI

RatedWithAI

Accessibility scanner

AI Copyright & LiabilityAugust 13, 2026

The Deliverable Shipped From a Personal Account. Your IP Assignment Assumed a Company Laptop.

Employment agreements were written for work an employee produces with company tools. A rising share of real output is now drafted in a consumer AI account the company has no contract with, no logs from, and no ability to search when a client asks where their data went.

The Ownership Gap

Standard invention-assignment language transfers what the employee creates. It cannot transfer rights that were never created in the first place. Where the human contribution is a short prompt and an accept-as-is, there may be very little protectable authorship to assign to anyone.

The Custody Gap

Consumer accounts belong to the individual. When that person leaves, the prompt history, uploaded source files and generated drafts leave with them — along with whatever customer information was pasted in. You cannot preserve, produce or delete what you have no access to.

Three Separate Questions People Collapse Into One

"Who owns AI output" is really three questions with different answers, and conflating them is why so many AI policies fail to protect anything.

  • Does copyright exist at all? U.S. registration practice requires human authorship. Material generated by a model in response to a prompt is not itself protected; a human's creative selection, arrangement, editing and integration of that material can be. The registration application must disclaim the machine-generated portions.
  • If it exists, who holds it? That is the employment and assignment question, and it is usually well covered by existing agreements — as long as the work is within the scope of employment. Work done off-hours in a personal account on a side idea is exactly the fact pattern those clauses fight about.
  • What did the provider's terms say? Major providers assign output rights to the user, but "the user" is the account holder. If the account belongs to your employee personally, the contractual chain runs to them, not to your company, and you are relying on the employment agreement to bridge a gap the vendor never knew about.

Confidentiality Is the Bigger Exposure

Ownership disputes are rare. Confidentiality failures are routine, and they arrive through client contracts rather than copyright law. Most master services agreements and data processing agreements require you to restrict who processes customer information, to flow obligations down to subprocessors, and to notify the customer of new ones. A personal AI account is an undisclosed processor sitting in the middle of the workflow.

Trade secret protection compounds the problem. Protection turns on whether you took reasonable measures to keep the information secret. A company that publishes a policy, trains on it, provides a sanctioned tool with enterprise terms, and logs usage has a clean story. A company whose engineers pasted architecture documents into consumer chat interfaces for two years has a harder one — not because the disclosure automatically destroys the secret, but because the reasonable-measures element becomes contested where it should have been obvious.

What Actually Changes the Outcome

The fix is unglamorous and mostly procedural. It is also the difference between an incident you can describe and one you can only guess at.

  1. Provide a sanctioned tool first. Policy without a usable alternative produces shadow usage. Enterprise or team agreements typically add confidentiality terms, disable training on your data by default, and give you administrative access to history.
  2. Write the scope rule in terms of data, not tools. "No customer data, credentials, unreleased financials, source code or personnel records in any non-approved AI service" survives the next product launch; a list of banned apps does not.
  3. Extend the assignment clause explicitly. Say that work product includes prompts, prompt libraries, fine-tuning data and AI-assisted output created in the course of employment, in any tool, on any account. It costs one sentence and removes the argument.
  4. Require disclosure at the deliverable level. For client work, know whether AI was used before the client asks. Many enterprise and government contracts now require notice, and a few prohibit it outright for specific deliverables.
  5. Handle offboarding as a data event. Departing employees should attest that company information has been removed from personal AI accounts, the same way you handle personal cloud storage.
  6. Keep human-contribution records for anything you will register. If a work matters enough to register or to enforce, keep evidence of the human authorship — drafts, edits, direction — because the disclaimer requirement means you will be asked to draw the line yourself.

Find the Gaps Before a Client Audit Does

AI disclosure, privacy and accessibility obligations all show up on the same public pages. RatedWithAI checks what your site actually says against what those obligations require.

Run a Free Scan →

Frequently Asked Questions

An employee built a useful internal tool in their personal Claude account on a weekend. Who owns it?

It depends on scope of employment, whether company resources or confidential information were used, and your state's rules on invention assignment — several states limit assignment of inventions developed entirely on personal time without company resources. The AI account does not change the analysis, but it does make the facts harder to reconstruct, which is why disclosure-and-transfer at the moment of adoption is better than a dispute later.

Do we lose copyright in a document just because AI helped write it?

No. You lose protection in the portions that are purely machine-generated. A document with substantial human drafting, editing, structuring and judgment remains protectable, and registration practice expects you to disclaim the AI-generated material rather than abandon the filing.

Our vendor's terms say the customer owns the output. Isn't that enough?

It settles the vendor's claims, not third-party claims and not your internal chain of title. Output that reproduces someone else's protected expression is still a risk regardless of who the vendor says owns it, and an output-ownership clause in a personal account runs to the employee.

Should we tell clients we used AI on their deliverable?

Check the contract before deciding as a matter of taste. A growing number of MSAs, government contracts and RFPs include AI use, disclosure or subprocessor terms. Silence is only safe if nothing you signed asked.

Is a written policy enough on its own?

It is the floor. What holds up is the combination: a policy, a sanctioned tool people prefer, training records showing staff were told, and some logging or attestation showing you checked. A policy nobody was trained on mostly proves you knew about the risk.

This article is general information, not legal advice. Ownership and confidentiality outcomes depend on your agreements, your state's law and the specific facts — consult qualified counsel before relying on any of it.