The figure we produced with AI for that proposal deck — can we put it in front of the client as it stands?
It is the sort of query that crops up regularly between the legal and compliance team at a B2B firm and the floor managers who actually build the sales decks and white papers.
Until a few years ago, checking copyright largely meant confirming licences for external material and making sure quotations were attributed. These days the remit is rather broader: what may we feed into a generative AI tool, how does the AI service we use handle that input, and may we use the output in external materials or advertising?
In March 2024 Japan’s Agency for Cultural Affairs published its “Approach to AI and Copyright”, setting out its thinking on the relationship between AI and copyright along with supporting materials. In July 2024 it followed up with a “Checklist and Guidance on AI and Copyright”, organising the practices it considers advisable for each party involved with generative AI.
In this article we divide the copyright risk of generative AI into three buckets — input, training, and use of output — and set out guidance for drafting internal rules so that legal, the production floor, and the IT function can all work from the same yardstick.
The aim is not to bring AI use to a halt. It is to draw a clear line between the situations that warrant a check and those that can safely be left alone, so the floor is not forever hesitating and legal is not forever chasing things after the fact.
That said, writing a rulebook on its own will not do. Only when it is paired with training, review, and regular updates does a rule actually function in practice.
Generative AI copyright risk is easier to handle in three parts
When you sit down to think about the copyright risk of generative AI, trying to settle everything on a straight “lawful or unlawful” basis tends to grind the discussion to a halt. In practice, the sensible first move is to separate out the situations in which risk actually arises.
The points a company needs to check fall, broadly, into three.
- The matter of input — what you put into the AI. For instance, whether you may feed another company’s paid report, materials entrusted to you by a client, copy written by an external writer, or the body text of web articles straight into a generative AI.
- The matter of training — how the AI service you use treats your data. You need to confirm, in the terms of service or contract, whether your input is used to train the model and how the provider stores and processes it.
- The matter of using the output — how you use the text, images, code, or materials the AI generates. The level of checking required differs depending on whether it is an internal memo, a client-facing document, or an advert or landing page.
In short, an internal rule that says only “may we use generative AI?” is not enough. For each of input, training, and output use, you need to decide what is permitted, what is restricted, and who does the checking.
Input risk: deciding what may be fed into the AI
The first thing to settle is the line between information that may be fed into a generative AI and information that may not.
On the floor, the hesitation tends to surface not as a question about copyright but as “am I allowed to put this document into the AI?” Consider the following cases.
- Pasting in a whole web article and asking for a summary
- Loading in a paid report and asking it to produce a market analysis
- Using materials received from a client to draft a proposal
- Having it rewrite copy delivered by an outside production house
- Copying a competitor’s service page and asking for a comparison table
In these cases the input may well contain third-party copyrighted works or material subject to contractual restrictions. Not every instance amounts to an infringement straight away, but neither can any of them be called “information you are free to enter”.
In the internal rules, sort by type of information
An input rule that merely says, in the abstract, “mind the copyright” will not work. To let the floor actually make a call, you need to break it down by type of information.
| Category | Rough guide to whether input is permitted | Examples | How the internal rule should treat it |
|---|---|---|---|
| Public information | Permitted, with conditions | Government materials, public IR disclosures, official websites | Keep the URL or document name and limit input to what is needed |
| Materials you produced yourself | Permitted, with conditions | Your own sales decks, internal manuals | Confirm the confidentiality classification and the permitted scope of use |
| Materials supplied by clients | As a rule, check first | RFPs, requests for proposal, contract-related materials | Confirm whether an NDA, contract terms, or client consent are required |
| Third-party copyrighted works | As a rule, check first | Paid articles, paid reports, books, image assets | Confirm the licence, the permitted extent of quotation, and the contract terms |
| Personal data and sensitive information | As a rule, not permitted | Names, addresses, health information, My Number, and the like | Mask it, or prohibit input altogether |
A table of this kind can go straight into the body of your internal rules. The important thing is to pitch it at a level of detail that not only the legal team but also the people producing materials or running marketing can read and act on.
Keep quotation and AI input as separate questions
Once copyright comes up, you sometimes hear on the floor that “surely it’s fine if it’s a quotation”. But quoting in an article or report is not the same thing as feeding material into a generative AI to be processed.
Whether something stands as a quotation turns on conditions such as the relationship between the quoted passage and your own text, attribution, and being confined to what is necessary. Input to an AI, by contrast, also brings in the terms of the AI service, how data is processed, whether it is used for training, and any contractual duty of confidentiality.
For that reason it is worth stating plainly in the internal rules that “even where material may be quoted, that does not mean it may always be fed into a generative AI”.
Training risk: how to choose which AI service to use
The next thing to sort out is how the data you enter is treated on the AI service’s side.
Generative AI services come in many forms — consumer products, enterprise products, those used via an API, those run wholly within your own environment, and more. From the standpoint of copyright and confidential information, you have to confirm the data-handling terms for each service.
In the United States, the National Institute of Standards and Technology has published the AI Risk Management Framework, a voluntary framework intended to help organisations manage the risks of AI systems across their lifecycle. Frameworks of this kind are a sensible reference point when deciding how a given service handles input data.
The point here is not to hand the floor the brush-off of “read the terms of service yourselves and decide”. The company needs to settle which AI tools may be used and spell out how far they may be used in the course of work.
What the internal rules should require you to confirm
Before an AI service is used internally, it is worth confirming at least the following.
- Whether input data is used to train the AI model
- Whether input and output data are stored
- If stored, what the retention period and deletion conditions are
- Where the data is stored and how it is managed
- Whether there is an enterprise contract or administrator functionality
- Whether permissions can be managed per user
- Whether usage logs and operation history can be reviewed
- Whether it is suitable for handling client or confidential information
- Who reviews changes to the terms of service when they occur
These touch not only on copyright but on information security, data protection, and contract management. It is therefore realistic to have legal, IT, and the business units confirm them jointly.
Show not only what is forbidden but where use is allowed
To steer clear of risk, some companies ban free generative AI tools outright. But run on prohibition alone and the floor is left unsure “which tool, then, may I use?” and “is even a light bit of proofreading off limits?”
The upshot is that use either stops, or carries on beyond the company’s sight.
So the internal rules should set out not only what is prohibited but, as below, where use is allowed.
- General ideation drawn from public information is permitted
- Tidying up the wording of text containing no personal or client information is permitted
- Input of confidential internal materials is confined to approved tools
- Use of client-supplied materials calls for confirming the contract terms and consulting a manager or legal
- Anything bound for external publication is always reviewed by a person
By setting a yardstick for each working scenario in this way, you can manage the risk without bringing AI use to a halt.
Output-use risk: don’t use the generated material as it stands
The third matter is how you use the output the AI generates.
Generative AI output is put to all sorts of uses — internal drafts, summaries of minutes, first cuts of emails, outline structures for proposals, advertising copy, image assets, code, and so on.
The thing to watch here is that something being AI-generated does not reduce the copyright risk to nil. There remains the possibility that it contains expression resembling an existing work, or that it infringes a third party’s rights.
In particular, for externally published materials, advertising, websites, white papers, and sales decks, you need to make clear where responsibility for checking the output lies.
Vary the level of review by where the output is used
In the internal rules, it works well to set different levels of review depending on where the AI output is used.
| Where it is used | Examples | Rough guide to the review level |
|---|---|---|
| Personal drafts | Notes, marshalling of points, draft emails | Checked by the author |
| Internal sharing | Minutes, internal briefing materials, draft FAQs | Checked by the person responsible or their manager |
| Submitted to clients | Proposals, reports, materials for negotiations | Reviewed by a manager or the relevant department |
| Published externally | Landing pages, advertising, articles, white papers | Checked by the production lead, communications, legal, and so on |
| Contract and legal matters | Contracts, terms of service, rights notices | Legal review mandatory |
Routing every piece of AI output through legal tends to bring things to a standstill. You need a design that concentrates review resource on the higher-risk situations.
Output to watch especially closely
The copyright risk tends to run higher for output of the following kinds.
- Images produced to the specified style of a particular author, manga artist, designer, or brand
- Text that leans heavily on an existing article or a competitor’s site
- Summaries of books or paid reports
- Advertising copy or landing-page copy for commercial use
- Proposals or reports to be submitted to clients
- Source code or design data
- Output close to a character, logo, illustration, or photograph
For these, rather than concluding after the fact that “the AI made it, so it’s fine”, you need to check resemblance to existing works, licensing, attribution, and whether commercial use is permitted.
The minimum that should go into your internal rules
From here, we set out the items for translating generative AI copyright risk into internal rules.
The purpose of the rules
Start by stating the purpose of the internal rules plainly.
The purpose is not to over-restrict AI use. It is to press ahead with greater efficiency and creativity while preventing copyright infringement, breach of contract, leakage of confidential information, and the external release of misinformation.
A sample clause might read as follows.
These rules set out the basic criteria for judging matters of copyright, contract, confidential information, and output checking, so that generative AI can be used safely and appropriately in our work. They do not prohibit the use of generative AI across the board; their purpose is to make clear which situations are permitted and which require a check.
The AI tools covered
Next, define which tools are covered.
“Generative AI” spans a wide range — chat-based AI, image-generation AI, proofreading AI, minutes AI, code-generation AI, and more. The internal rules need to spell out specifically what is covered.
For instance, you might organise it as follows.
- Generative AI services the company has contracted for or approved
- External generative AI services used via a browser or app
- AI services that generate images, video, or audio
- AI minutes, AI summarisation, AI translation, and AI proofreading tools
- Code-generation AI used in development work
It also helps to state that “using an unapproved tool for work requires prior application”, which makes it harder for the roster of tools in use to grow on the floor’s say-so alone.
Information that must not be entered
Write the list of prohibited input as specifically as you can.
For example, the following information should, as a rule, be prohibited from input or made subject to prior confirmation.
- Personal data
- Sensitive information
- Confidential information received from clients
- Contracts, NDAs, terms of service, litigation-related materials
- Undisclosed financial information
- Undisclosed personnel information
- Third-party copyrighted works such as paid articles, paid reports, and books
- Deliverables from external contractors
- Other companies’ sales decks, manuals, and design documents
Here you need to weigh not only copyright but also contractual duties of confidentiality and data protection.
Handling third-party works
As a copyright rule, set out how third-party works are to be handled.
At a minimum, you need provisions of the following kind.
- Do not enter a third party’s work in full, or in substantial part, as it stands
- Do not enter paid content, or material whose permitted use is restricted by contract, without prior confirmation
- When using a web article or public material, keep the source URL or document name
- Even when using material for quotation or summary, confine it to the minimum necessary
- Do not give instructions to imitate a particular author, brand, or character
- When using material in externally published work, check resemblance to existing works
This item matters especially to the production floor. Because the floor is prone to hesitation here, adding concrete examples makes it easier to operate.
Responsibility for checking output
For generative AI output, make clear who is responsible for checking it.
It is worth putting the following sentence into the internal rules.
Where the output of a generative AI is used in our work, ultimate responsibility for checking it rests with the user and with the person responsible for the work in question. The fact that something was AI-generated is no excuse for misinformation, copyright infringement, breach of contract, or violation of rights.
Our Kanata’s everyday best-practice guide likewise sets out, as a matter of principle, that AI output should be reviewed by a person before it goes out, and that documents, figures, and quotations leaving the company should be fact-checked by a person.
The approval flow for external use
Where AI output is to go outside the company, settle an approval flow in advance.
For example, rules of the following kind.
- Where AI output is used in client-facing materials, the person responsible checks the content and a manager approves it
- Where it is used in advertising, landing pages, white papers, or articles, the production lead checks it
- Where there are concerns about copyright, trade marks, quotation, likeness, or characters, legal is consulted
- Where an AI-generated image is used commercially, the service’s terms and any resemblance are checked
- Text bearing on contracts, terms of service, or legal explanations requires legal review as a matter of course
An approval flow made too fiddly simply will not be used. The realistic approach is to design it clearly and confine it to higher-risk external use.
Reporting procedure when something goes wrong
Set out, too, the procedure for reporting cases where a work or confidential information has been entered by mistake.
The items to include in the internal rules are as follows.
- Which AI tool it was entered into
- When it was entered
- What was entered
- Whether the output was saved, shared, or published
- Who is to be informed
- How the chat history and output are to be handled
- Whether the rules or training are to be reviewed to prevent a recurrence
What matters is fostering an atmosphere in which it is easy to report. Once a culture of hiding input slips takes hold, risks are spotted too late.
Who does what when drafting the rules, department by department
A generative AI copyright rule drawn up by the legal department alone tends not to take root on the floor. To make a rule that is actually used in practice, you need to divide up the roles among the departments involved.
Legal and compliance
Legal and compliance design the criteria for judgement and the handling of exceptions.
Their main roles are as follows.
- Drawing up the rules for using third-party works
- Marshalling the thinking on quotation, reproduction, summary, and adaptation
- Setting the criteria for feeding client or contract materials into the AI
- Deciding the review criteria for externally published work
- Acting as the point of contact for higher-risk cases
That said, routing every AI use through legal will bring work to a halt. Ideally legal is involved not as “the department that checks everything” but as “the department that sets the criteria for judgement”.
IT and information security
The IT department gets the available AI tools and the data-management conditions in order.
Their main roles are as follows.
- Selecting approved AI tools
- Managing accounts and permissions
- Confirming the conditions for storing input data and using it for training
- Managing logs and keeping track of usage
- Deciding how prohibited and unapproved tools are to be handled
Copyright risk may look like a matter for legal alone, but confirming how input data is handled and used for training cannot be done without the IT department’s cooperation.
Marketing and sales
Marketing and sales are the departments that most often use AI output at the point of contact with the client.
Their main points to confirm are as follows.
- Whether AI output may be used in advertising copy or landing-page copy
- How external material is to be handled in white papers and articles
- Whether AI-generated images or text may go into client-facing proposals
- Whether, in producing competitive comparisons, the wording of other companies’ sites has been lifted
- How AI use is to be treated in contracts with external production houses
In this department, casting the copyright rules as a “production checklist” helps them take root.
Management and business owners
Management and business owners are the ones who set the risk appetite for AI use.
The floor wants to use it, legal wants to proceed with care, and IT wants it kept within a manageable scope. Striking the balance among these requires management to set the direction.
For example, judgements of the following kind.
- Which work to extend AI use into first
- Which work to restrict AI use in for the time being
- How much review cost is acceptable
- How to reconcile efficiency gains from AI with risk management
- At what level reporting is required when an incident occurs
Internal rules are detailed working guidance for the floor and, at the same time, a statement of management’s judgement.
A working draft of internal rules you can actually use
Here we offer some draft wording you can use as the backbone of your internal rules. When putting it to actual use, do adjust it to your own contract terms, information-security policy, and line of work.
Purpose
These rules set out the basic matters concerning input information, permitted tools, checking of generated material, external use, and incident response, so that generative AI may be used safely and appropriately in our work.
Work for which use is permitted
Generative AI may be used for the following work.
- Drafting text
- Summarising minutes and notes
- Ideation
- Marshalling the angles for a piece of research
- Drafting the structure of internal documents
- Drafting emails
- Producing a first cut of a document’s structure
- Drafting FAQs and manuals
That said, final judgements, legal judgements, contractual judgements, formal replies to clients, and the final check of externally published work are to be made by a person.
Information prohibited from input
The following information must not be entered into a generative AI, save in an environment the company has approved or where prior approval has been given.
- Personal data
- Sensitive information
- Clients’ confidential information
- Contracts, NDAs, terms of service, litigation-related materials
- Undisclosed financial information
- Undisclosed personnel information
- Third-party copyrighted works such as paid articles, paid reports, and books
- Deliverables from external contractors
- Other companies’ sales decks, manuals, and design documents
Use of third-party works
Where a third party’s text, images, video, audio, code, or materials are to be entered into a generative AI, confirm the licence, the contract terms, the need for any quotation, and the extent of input.
In particular, it is safest to adopt a rule that paid content, and material whose permitted use is fixed by contract, are not entered into a generative AI without prior confirmation.
Use of output
When using the output of a generative AI, the user confirms the following.
- That there are no errors of fact
- That figures, dates, and proper nouns are correct
- That it does not resemble a third party’s work
- That there are no passages requiring quotation or attribution
- That there is no wording liable to mislead clients or business partners
- That there is no undue assertion, exaggeration, or comparative claim
- That any approval needed for external use has been obtained
Approval for external use
Where the output of a generative AI is to be used with clients, business partners, or in publicly available media, it is checked by the person responsible for the work. Where there are concerns bearing on copyright, trade marks, likeness, contract, or legal explanation, legal or the responsible department is consulted.
Incident response
Where prohibited information has been entered into a generative AI by mistake, or where the output of a generative AI raises the possibility of infringing a third party’s rights or releasing misinformation, report promptly to your manager and the responsible department.
To make it stick on the floor, turn it into a checklist
Internal rules do not take root simply by being posted as a PDF or on the intranet. They need to be converted into a form usable in day-to-day work.
A checklist is particularly effective.
A checklist for before you enter anything into the AI
- Does it contain personal data?
- Does it contain a client’s confidential information?
- Is this material we are contractually permitted to enter into an external service?
- Have we copied a third party’s work in full or in substantial part?
- Have we pasted in the contents of a paid article, paid report, or book?
- Have we confined it to the extent that genuinely needs to be entered?
- Have we masked the information that can be masked?
- Are we using an approved AI tool?
A checklist for before AI output goes outside the company
- Have we checked proper nouns, figures, and dates against the source?
- Does it resemble an existing work too closely?
- Are there passages requiring a source or attribution?
- Have we confirmed the conditions for commercial use of any images or figures?
- Is the tone fit to put in front of a client?
- Have we toned down any exaggeration or over-assertion?
- Has it been reviewed by a manager or the relevant department?
- Is this content that requires legal review?
Kanata’s everyday best-practice guide likewise sets out, as checklist items, masking confidential and personal information before sending a prompt, and cross-checking proper nouns, figures, and dates against the source before AI output goes outside the company.
Things worth sorting out if you use Kanata
The environment for using generative AI offers several options — general-purpose AI services, enterprise AI services, internal knowledge-search tools, minutes and summarisation tools, and so on. Whichever you choose, the rules on copyright, confidential information, and output checking are needed all the same.
On that footing, if you use Kanata it helps to design its project and library features around the way your internal rules operate.
Kanata is described as a work-support platform with AI chat, AI summarisation, e-learning, and the like. Its operating manual also shows that users, data, and apps can be organised on a per-project basis.
Separate the information handled by project
In Kanata, information is organised around the notions of spaces, projects, apps, and libraries. The operating manual explains that a project can be created as a group corresponding to a unit of work, with members and permissions managed per project.
From a copyright and confidential-information standpoint too, separating the information handled per project makes it easier to manage.
For example, a split of the following kind.
- A company-wide AI-use project
- A project for legal and compliance checks
- A project for drafts of marketing production work
- A project to support the drafting of client proposals
- A project for internal training and guideline study
By separating projects, it becomes easier to keep track of who can access which information.
Register safe instructions in the prompt library
Kanata’s operating manual explains that a project library contains an AI library, a prompt library, and a training-data library, and that frequently used instructions can be registered in the prompt library.
To make copyright rules stick, rather than having users write out the caveats from scratch every time, it is effective to template the safe prompts.
For example, you might register an instruction of the following kind.
Tidy up the following text so that it reads well, without changing its meaning.
However, do not add expression that draws on a third party’s work, quotations of unknown origin, or figures that cannot be verified.
Mark anything uncertain as “needs checking”.
For externally published work, a prompt of the following kind is also worth considering.
Check this text against the criteria for review before external publication.
In a table, flag any passages that raise concerns about copyright, quotation, attribution, proper nouns, figures, undue assertion, or possible infringement of a third party’s rights.
Label any passage requiring a legal judgement as “legal review”.
Set criteria for what goes into the training-data library
Kanata’s project library is described as having a training-data library, in which internal materials you want the AI to refer to can be registered.
It is therefore important to decide in advance what may be registered in the training-data library.
The points to confirm before registering are as follows.
- Is it material we hold the rights to?
- Does it contain a work belonging to an external contractor?
- Does it contain client or third-party materials?
- Are secondary use and internal sharing permitted under the contract?
- Does it contain outdated material or incorrect information?
- Does it contain personal data or confidential information?
- Has an administrator and an update frequency been settled for after registration?
Using Kanata does not make the copyright judgement go away of its own accord.
The operation you need once the rules are drawn up
An internal rule for generative AI is not finished once it is written. Because the technology, the service terms, the law, the case law, and the way it is used in practice all shift, you need to review it regularly.
Build an FAQ
Marshal the questions likely to come up from the floor into an FAQ.
For example, questions of the following kind.
- May I have it summarise a web article?
- May I put a client’s request for proposal into the AI?
- May I use an image made with generative AI in an advert?
- Does text produced by an AI have copyright?
- May I build a comparison table with reference to another company’s service page?
- May I have the AI rewrite copy by an external writer?
- May I use a free image-generation AI for work?
An FAQ not only lightens the load of queries on legal but also speeds up the floor’s decision-making.
Run training
A rulebook alone leaves the floor unable to make concrete judgements.
In training, it is effective to handle cases close to actual work, rather than merely explaining clauses and the legal regime.
For example, exercises of the following kind.
- May this material be entered into the AI?
- May this AI-generated image be used in an advert?
- Does this white-paper draft need attribution?
- Does this proposal require legal review?
- Is this prompt raising the copyright risk?
Kanata is described as having an e-learning feature, centred on video content, for internal training, onboarding, and self-study. Where you use such a feature, it works well to turn the copyright rules and checklists into learning content and pair it with an operation of regular review.
Review it regularly
Because the environment for AI use changes quickly, review the internal rules regularly too.
It helps to settle the timing of reviews along the following lines.
- Once a quarter
- When a new AI tool is introduced
- When the terms of service change
- When AI use in externally published work increases
- When an incident or near-miss occurs
- When there is a major update to the law or to official guidance
Authoritative bodies generally treat AI guidance as a living set of materials, updated as needed; the OECD, for instance, maintains its AI Principles as an evolving reference. A company’s own rules, likewise, should be designed on the assumption of updates, rather than fixed once written.
In closing: manage copyright risk by dividing it up, not by shutting it down
The copyright risk of generative AI cannot be managed by vague unease alone. At the same time, ban everything and you make it hard for the floor to improve its work or use AI creatively.
What matters is marshalling the risk into the following three parts.
- Input: what may be fed into the AI
- Training: how the AI service you use treats your data
- Use of output: where and how the generated material is used
On that footing, set down in writing, as internal rules, the prohibited input, the handling of third-party works, the permitted tools, output review, approval for external use, and incident reporting.
A generative AI copyright rule is not a document for legal alone. It takes root in practice when management sets the direction, IT gets the environment in order, the floor uses it in line with a checklist, and legal keeps the criteria for judgement up to date.
Rather than shutting AI use down, separate the situations where use is allowed from those that warrant a check. That design is the first step in drafting internal rules for the generative-AI era.
Q&A: common questions on generative AI copyright risk and internal rules
Can text produced by a generative AI be used in external materials as it stands?It is safer to avoid using it as it stands. When using it in external materials, adopt an operation in which you check the facts, figures, proper nouns, quotations, resemblance to existing works, and any exaggeration, and then, as needed, have it reviewed by a manager, communications, or legal.
May I paste a web article into the AI and have it summarised?Even with a publicly available web article, it does not follow that you may paste it in full. Confine it to what is needed, keep the source URL, and check that it does not breach the AI service’s terms or your internal rules. Paid articles and members-only articles call for especially careful confirmation.
May I put materials received from a client into the AI to produce a proposal?As a rule, you need to confirm the contract terms, any NDA, and whether the client has consented. Client materials may contain copyrighted works, trade secrets, and personal data. Even when using an approved AI environment, you should mask the data and confirm the permitted scope before input.
Can an image made with a generative AI be used in advertising?Beyond the AI service’s conditions for commercial use, you need to check that it does not resemble an existing character, brand, author’s style, photograph, or logo. For external work such as advertising and landing pages, it is safer to set up a checking flow involving the production lead, legal, and communications.
Is it enough for the legal department to draw up the internal rules on its own?Drawing them up in legal alone risks rules the floor finds hard to use. Legal builds the criteria for judgement, IT designs the tooling and permission management, and the floor departments translate it into the actual workflow. Management needs to signal how far to take AI use and which risks it will not accept.