Generative AI Copyright Risks Explained: Input, Training & Output — A Guide to Internal Rules

Column
Generative AI Copyright Risks Explained: Input, Training & Output — A Guide to Internal Rules

Introduction

A guide that sorts the copyright risk of generative AI into three challenges — input, training, and output use — and sets out the steps for legal and compliance teams and the production floor to translate it into internal rules.

Tatsuya Ito

Tatsuya Ito

Artificial Intelligence Consultant

company-icon

Third Scope Ltd.

Born in 1985 and originally from Mie Prefecture, Japan. In 2012, he joined an AR startup in Hong Kong as an engineer. Since then, he has been involved in new business development and AI service launches at several AI startups. In 2018, he founded the current ThirdScope Inc. by taking over an AI service and its development team. He now supports companies in adopting and utilizing AI, with a focus on AI-driven business development, operational transformation, and product development. He has also been involved in AI research as a Project Researcher at the University of Tokyo. Today, he continues to work at the forefront of AI project development, providing practical consulting from both technical and business perspectives.

The figure we produced with AI for that proposal deck — can we put it in front of the client as it stands?

It is the sort of query that crops up regularly between the legal and compliance team at a B2B firm and the floor managers who actually build the sales decks and white papers.

Until a few years ago, checking copyright largely meant confirming licences for external material and making sure quotations were attributed. These days the remit is rather broader: what may we feed into a generative AI tool, how does the AI service we use handle that input, and may we use the output in external materials or advertising?

In March 2024 Japan’s Agency for Cultural Affairs published its “Approach to AI and Copyright”, setting out its thinking on the relationship between AI and copyright along with supporting materials. In July 2024 it followed up with a “Checklist and Guidance on AI and Copyright”, organising the practices it considers advisable for each party involved with generative AI.

In this article we divide the copyright risk of generative AI into three buckets — input, training, and use of output — and set out guidance for drafting internal rules so that legal, the production floor, and the IT function can all work from the same yardstick.

The aim is not to bring AI use to a halt. It is to draw a clear line between the situations that warrant a check and those that can safely be left alone, so the floor is not forever hesitating and legal is not forever chasing things after the fact.

That said, writing a rulebook on its own will not do. Only when it is paired with training, review, and regular updates does a rule actually function in practice.

Generative AI copyright risk is easier to handle in three parts

Generative AI copyright risk is easier to handle in three parts

When you sit down to think about the copyright risk of generative AI, trying to settle everything on a straight “lawful or unlawful” basis tends to grind the discussion to a halt. In practice, the sensible first move is to separate out the situations in which risk actually arises.

The points a company needs to check fall, broadly, into three.

  1. The matter of input — what you put into the AI. For instance, whether you may feed another company’s paid report, materials entrusted to you by a client, copy written by an external writer, or the body text of web articles straight into a generative AI.
  2. The matter of training — how the AI service you use treats your data. You need to confirm, in the terms of service or contract, whether your input is used to train the model and how the provider stores and processes it.
  3. The matter of using the output — how you use the text, images, code, or materials the AI generates. The level of checking required differs depending on whether it is an internal memo, a client-facing document, or an advert or landing page.

In short, an internal rule that says only “may we use generative AI?” is not enough. For each of input, training, and output use, you need to decide what is permitted, what is restricted, and who does the checking.

Input risk: deciding what may be fed into the AI

Input risk: deciding what may be fed into the AI

The first thing to settle is the line between information that may be fed into a generative AI and information that may not.

On the floor, the hesitation tends to surface not as a question about copyright but as “am I allowed to put this document into the AI?” Consider the following cases.

  • Pasting in a whole web article and asking for a summary
  • Loading in a paid report and asking it to produce a market analysis
  • Using materials received from a client to draft a proposal
  • Having it rewrite copy delivered by an outside production house
  • Copying a competitor’s service page and asking for a comparison table

In these cases the input may well contain third-party copyrighted works or material subject to contractual restrictions. Not every instance amounts to an infringement straight away, but neither can any of them be called “information you are free to enter”.

In the internal rules, sort by type of information

An input rule that merely says, in the abstract, “mind the copyright” will not work. To let the floor actually make a call, you need to break it down by type of information.

Categories of information fed into generative AI and a rough guide to whether input is permitted
Category Rough guide to whether input is permitted Examples How the internal rule should treat it
Public information Permitted, with conditions Government materials, public IR disclosures, official websites Keep the URL or document name and limit input to what is needed
Materials you produced yourself Permitted, with conditions Your own sales decks, internal manuals Confirm the confidentiality classification and the permitted scope of use
Materials supplied by clients As a rule, check first RFPs, requests for proposal, contract-related materials Confirm whether an NDA, contract terms, or client consent are required
Third-party copyrighted works As a rule, check first Paid articles, paid reports, books, image assets Confirm the licence, the permitted extent of quotation, and the contract terms
Personal data and sensitive information As a rule, not permitted Names, addresses, health information, My Number, and the like Mask it, or prohibit input altogether

A table of this kind can go straight into the body of your internal rules. The important thing is to pitch it at a level of detail that not only the legal team but also the people producing materials or running marketing can read and act on.

Keep quotation and AI input as separate questions

Once copyright comes up, you sometimes hear on the floor that “surely it’s fine if it’s a quotation”. But quoting in an article or report is not the same thing as feeding material into a generative AI to be processed.

Whether something stands as a quotation turns on conditions such as the relationship between the quoted passage and your own text, attribution, and being confined to what is necessary. Input to an AI, by contrast, also brings in the terms of the AI service, how data is processed, whether it is used for training, and any contractual duty of confidentiality.

For that reason it is worth stating plainly in the internal rules that “even where material may be quoted, that does not mean it may always be fed into a generative AI”.

Training risk: how to choose which AI service to use

Training risk: how to choose which AI service to use

The next thing to sort out is how the data you enter is treated on the AI service’s side.

Generative AI services come in many forms — consumer products, enterprise products, those used via an API, those run wholly within your own environment, and more. From the standpoint of copyright and confidential information, you have to confirm the data-handling terms for each service.

In the United States, the National Institute of Standards and Technology has published the AI Risk Management Framework, a voluntary framework intended to help organisations manage the risks of AI systems across their lifecycle. Frameworks of this kind are a sensible reference point when deciding how a given service handles input data.

The point here is not to hand the floor the brush-off of “read the terms of service yourselves and decide”. The company needs to settle which AI tools may be used and spell out how far they may be used in the course of work.

What the internal rules should require you to confirm

Before an AI service is used internally, it is worth confirming at least the following.

  • Whether input data is used to train the AI model
  • Whether input and output data are stored
  • If stored, what the retention period and deletion conditions are
  • Where the data is stored and how it is managed
  • Whether there is an enterprise contract or administrator functionality
  • Whether permissions can be managed per user
  • Whether usage logs and operation history can be reviewed
  • Whether it is suitable for handling client or confidential information
  • Who reviews changes to the terms of service when they occur

These touch not only on copyright but on information security, data protection, and contract management. It is therefore realistic to have legal, IT, and the business units confirm them jointly.

Show not only what is forbidden but where use is allowed

To steer clear of risk, some companies ban free generative AI tools outright. But run on prohibition alone and the floor is left unsure “which tool, then, may I use?” and “is even a light bit of proofreading off limits?”

The upshot is that use either stops, or carries on beyond the company’s sight.

So the internal rules should set out not only what is prohibited but, as below, where use is allowed.

  • General ideation drawn from public information is permitted
  • Tidying up the wording of text containing no personal or client information is permitted
  • Input of confidential internal materials is confined to approved tools
  • Use of client-supplied materials calls for confirming the contract terms and consulting a manager or legal
  • Anything bound for external publication is always reviewed by a person

By setting a yardstick for each working scenario in this way, you can manage the risk without bringing AI use to a halt.

Output-use risk: don’t use the generated material as it stands

Output-use risk: don't use the generated material as it stands

The third matter is how you use the output the AI generates.

Generative AI output is put to all sorts of uses — internal drafts, summaries of minutes, first cuts of emails, outline structures for proposals, advertising copy, image assets, code, and so on.

The thing to watch here is that something being AI-generated does not reduce the copyright risk to nil. There remains the possibility that it contains expression resembling an existing work, or that it infringes a third party’s rights.

In particular, for externally published materials, advertising, websites, white papers, and sales decks, you need to make clear where responsibility for checking the output lies.

Vary the level of review by where the output is used

In the internal rules, it works well to set different levels of review depending on where the AI output is used.

A rough guide to review levels by where AI output is used
Where it is used Examples Rough guide to the review level
Personal drafts Notes, marshalling of points, draft emails Checked by the author
Internal sharing Minutes, internal briefing materials, draft FAQs Checked by the person responsible or their manager
Submitted to clients Proposals, reports, materials for negotiations Reviewed by a manager or the relevant department
Published externally Landing pages, advertising, articles, white papers Checked by the production lead, communications, legal, and so on
Contract and legal matters Contracts, terms of service, rights notices Legal review mandatory

Routing every piece of AI output through legal tends to bring things to a standstill. You need a design that concentrates review resource on the higher-risk situations.

Output to watch especially closely

The copyright risk tends to run higher for output of the following kinds.

  • Images produced to the specified style of a particular author, manga artist, designer, or brand
  • Text that leans heavily on an existing article or a competitor’s site
  • Summaries of books or paid reports
  • Advertising copy or landing-page copy for commercial use
  • Proposals or reports to be submitted to clients
  • Source code or design data
  • Output close to a character, logo, illustration, or photograph

For these, rather than concluding after the fact that “the AI made it, so it’s fine”, you need to check resemblance to existing works, licensing, attribution, and whether commercial use is permitted.

The minimum that should go into your internal rules

The minimum that should go into your internal rules

From here, we set out the items for translating generative AI copyright risk into internal rules.

The purpose of the rules

Start by stating the purpose of the internal rules plainly.

The purpose is not to over-restrict AI use. It is to press ahead with greater efficiency and creativity while preventing copyright infringement, breach of contract, leakage of confidential information, and the external release of misinformation.

A sample clause might read as follows.

These rules set out the basic criteria for judging matters of copyright, contract, confidential information, and output checking, so that generative AI can be used safely and appropriately in our work. They do not prohibit the use of generative AI across the board; their purpose is to make clear which situations are permitted and which require a check.

The AI tools covered

Next, define which tools are covered.

“Generative AI” spans a wide range — chat-based AI, image-generation AI, proofreading AI, minutes AI, code-generation AI, and more. The internal rules need to spell out specifically what is covered.

For instance, you might organise it as follows.

  • Generative AI services the company has contracted for or approved
  • External generative AI services used via a browser or app
  • AI services that generate images, video, or audio
  • AI minutes, AI summarisation, AI translation, and AI proofreading tools
  • Code-generation AI used in development work

It also helps to state that “using an unapproved tool for work requires prior application”, which makes it harder for the roster of tools in use to grow on the floor’s say-so alone.

Information that must not be entered

Write the list of prohibited input as specifically as you can.

For example, the following information should, as a rule, be prohibited from input or made subject to prior confirmation.

  • Personal data
  • Sensitive information
  • Confidential information received from clients
  • Contracts, NDAs, terms of service, litigation-related materials
  • Undisclosed financial information
  • Undisclosed personnel information
  • Third-party copyrighted works such as paid articles, paid reports, and books
  • Deliverables from external contractors
  • Other companies’ sales decks, manuals, and design documents

Here you need to weigh not only copyright but also contractual duties of confidentiality and data protection.

Handling third-party works

As a copyright rule, set out how third-party works are to be handled.

At a minimum, you need provisions of the following kind.

  • Do not enter a third party’s work in full, or in substantial part, as it stands
  • Do not enter paid content, or material whose permitted use is restricted by contract, without prior confirmation
  • When using a web article or public material, keep the source URL or document name
  • Even when using material for quotation or summary, confine it to the minimum necessary
  • Do not give instructions to imitate a particular author, brand, or character
  • When using material in externally published work, check resemblance to existing works

This item matters especially to the production floor. Because the floor is prone to hesitation here, adding concrete examples makes it easier to operate.

Responsibility for checking output

For generative AI output, make clear who is responsible for checking it.

It is worth putting the following sentence into the internal rules.

Where the output of a generative AI is used in our work, ultimate responsibility for checking it rests with the user and with the person responsible for the work in question. The fact that something was AI-generated is no excuse for misinformation, copyright infringement, breach of contract, or violation of rights.

Our Kanata’s everyday best-practice guide likewise sets out, as a matter of principle, that AI output should be reviewed by a person before it goes out, and that documents, figures, and quotations leaving the company should be fact-checked by a person.

The approval flow for external use

Where AI output is to go outside the company, settle an approval flow in advance.

For example, rules of the following kind.

  • Where AI output is used in client-facing materials, the person responsible checks the content and a manager approves it
  • Where it is used in advertising, landing pages, white papers, or articles, the production lead checks it
  • Where there are concerns about copyright, trade marks, quotation, likeness, or characters, legal is consulted
  • Where an AI-generated image is used commercially, the service’s terms and any resemblance are checked
  • Text bearing on contracts, terms of service, or legal explanations requires legal review as a matter of course

An approval flow made too fiddly simply will not be used. The realistic approach is to design it clearly and confine it to higher-risk external use.

Reporting procedure when something goes wrong

Set out, too, the procedure for reporting cases where a work or confidential information has been entered by mistake.

The items to include in the internal rules are as follows.

  • Which AI tool it was entered into
  • When it was entered
  • What was entered
  • Whether the output was saved, shared, or published
  • Who is to be informed
  • How the chat history and output are to be handled
  • Whether the rules or training are to be reviewed to prevent a recurrence

What matters is fostering an atmosphere in which it is easy to report. Once a culture of hiding input slips takes hold, risks are spotted too late.

Who does what when drafting the rules, department by department

Who does what when drafting the rules, department by department

A generative AI copyright rule drawn up by the legal department alone tends not to take root on the floor. To make a rule that is actually used in practice, you need to divide up the roles among the departments involved.

Legal and compliance

Legal and compliance design the criteria for judgement and the handling of exceptions.

Their main roles are as follows.

  • Drawing up the rules for using third-party works
  • Marshalling the thinking on quotation, reproduction, summary, and adaptation
  • Setting the criteria for feeding client or contract materials into the AI
  • Deciding the review criteria for externally published work
  • Acting as the point of contact for higher-risk cases

That said, routing every AI use through legal will bring work to a halt. Ideally legal is involved not as “the department that checks everything” but as “the department that sets the criteria for judgement”.

IT and information security

The IT department gets the available AI tools and the data-management conditions in order.

Their main roles are as follows.

  • Selecting approved AI tools
  • Managing accounts and permissions
  • Confirming the conditions for storing input data and using it for training
  • Managing logs and keeping track of usage
  • Deciding how prohibited and unapproved tools are to be handled

Copyright risk may look like a matter for legal alone, but confirming how input data is handled and used for training cannot be done without the IT department’s cooperation.

Marketing and sales

Marketing and sales are the departments that most often use AI output at the point of contact with the client.

Their main points to confirm are as follows.

  • Whether AI output may be used in advertising copy or landing-page copy
  • How external material is to be handled in white papers and articles
  • Whether AI-generated images or text may go into client-facing proposals
  • Whether, in producing competitive comparisons, the wording of other companies’ sites has been lifted
  • How AI use is to be treated in contracts with external production houses

In this department, casting the copyright rules as a “production checklist” helps them take root.

Management and business owners

Management and business owners are the ones who set the risk appetite for AI use.

The floor wants to use it, legal wants to proceed with care, and IT wants it kept within a manageable scope. Striking the balance among these requires management to set the direction.

For example, judgements of the following kind.

  • Which work to extend AI use into first
  • Which work to restrict AI use in for the time being
  • How much review cost is acceptable
  • How to reconcile efficiency gains from AI with risk management
  • At what level reporting is required when an incident occurs

Internal rules are detailed working guidance for the floor and, at the same time, a statement of management’s judgement.

A working draft of internal rules you can actually use

A working draft of internal rules you can actually use

Here we offer some draft wording you can use as the backbone of your internal rules. When putting it to actual use, do adjust it to your own contract terms, information-security policy, and line of work.

Purpose

These rules set out the basic matters concerning input information, permitted tools, checking of generated material, external use, and incident response, so that generative AI may be used safely and appropriately in our work.

Work for which use is permitted

Generative AI may be used for the following work.

  • Drafting text
  • Summarising minutes and notes
  • Ideation
  • Marshalling the angles for a piece of research
  • Drafting the structure of internal documents
  • Drafting emails
  • Producing a first cut of a document’s structure
  • Drafting FAQs and manuals

That said, final judgements, legal judgements, contractual judgements, formal replies to clients, and the final check of externally published work are to be made by a person.

Information prohibited from input

The following information must not be entered into a generative AI, save in an environment the company has approved or where prior approval has been given.

  • Personal data
  • Sensitive information
  • Clients’ confidential information
  • Contracts, NDAs, terms of service, litigation-related materials
  • Undisclosed financial information
  • Undisclosed personnel information
  • Third-party copyrighted works such as paid articles, paid reports, and books
  • Deliverables from external contractors
  • Other companies’ sales decks, manuals, and design documents

Use of third-party works

Where a third party’s text, images, video, audio, code, or materials are to be entered into a generative AI, confirm the licence, the contract terms, the need for any quotation, and the extent of input.

In particular, it is safest to adopt a rule that paid content, and material whose permitted use is fixed by contract, are not entered into a generative AI without prior confirmation.

Use of output

When using the output of a generative AI, the user confirms the following.

  • That there are no errors of fact
  • That figures, dates, and proper nouns are correct
  • That it does not resemble a third party’s work
  • That there are no passages requiring quotation or attribution
  • That there is no wording liable to mislead clients or business partners
  • That there is no undue assertion, exaggeration, or comparative claim
  • That any approval needed for external use has been obtained

Approval for external use

Where the output of a generative AI is to be used with clients, business partners, or in publicly available media, it is checked by the person responsible for the work. Where there are concerns bearing on copyright, trade marks, likeness, contract, or legal explanation, legal or the responsible department is consulted.

Incident response

Where prohibited information has been entered into a generative AI by mistake, or where the output of a generative AI raises the possibility of infringing a third party’s rights or releasing misinformation, report promptly to your manager and the responsible department.

To make it stick on the floor, turn it into a checklist

To make it stick on the floor, turn it into a checklist

Internal rules do not take root simply by being posted as a PDF or on the intranet. They need to be converted into a form usable in day-to-day work.

A checklist is particularly effective.

A checklist for before you enter anything into the AI

  • Does it contain personal data?
  • Does it contain a client’s confidential information?
  • Is this material we are contractually permitted to enter into an external service?
  • Have we copied a third party’s work in full or in substantial part?
  • Have we pasted in the contents of a paid article, paid report, or book?
  • Have we confined it to the extent that genuinely needs to be entered?
  • Have we masked the information that can be masked?
  • Are we using an approved AI tool?

A checklist for before AI output goes outside the company

  • Have we checked proper nouns, figures, and dates against the source?
  • Does it resemble an existing work too closely?
  • Are there passages requiring a source or attribution?
  • Have we confirmed the conditions for commercial use of any images or figures?
  • Is the tone fit to put in front of a client?
  • Have we toned down any exaggeration or over-assertion?
  • Has it been reviewed by a manager or the relevant department?
  • Is this content that requires legal review?

Kanata’s everyday best-practice guide likewise sets out, as checklist items, masking confidential and personal information before sending a prompt, and cross-checking proper nouns, figures, and dates against the source before AI output goes outside the company.

Things worth sorting out if you use Kanata

Things worth sorting out if you use Kanata

The environment for using generative AI offers several options — general-purpose AI services, enterprise AI services, internal knowledge-search tools, minutes and summarisation tools, and so on. Whichever you choose, the rules on copyright, confidential information, and output checking are needed all the same.

On that footing, if you use Kanata it helps to design its project and library features around the way your internal rules operate.

Kanata is described as a work-support platform with AI chat, AI summarisation, e-learning, and the like. Its operating manual also shows that users, data, and apps can be organised on a per-project basis.

Separate the information handled by project

In Kanata, information is organised around the notions of spaces, projects, apps, and libraries. The operating manual explains that a project can be created as a group corresponding to a unit of work, with members and permissions managed per project.

From a copyright and confidential-information standpoint too, separating the information handled per project makes it easier to manage.

For example, a split of the following kind.

  • A company-wide AI-use project
  • A project for legal and compliance checks
  • A project for drafts of marketing production work
  • A project to support the drafting of client proposals
  • A project for internal training and guideline study

By separating projects, it becomes easier to keep track of who can access which information.

Register safe instructions in the prompt library

Kanata’s operating manual explains that a project library contains an AI library, a prompt library, and a training-data library, and that frequently used instructions can be registered in the prompt library.

To make copyright rules stick, rather than having users write out the caveats from scratch every time, it is effective to template the safe prompts.

For example, you might register an instruction of the following kind.

Tidy up the following text so that it reads well, without changing its meaning.
However, do not add expression that draws on a third party’s work, quotations of unknown origin, or figures that cannot be verified.
Mark anything uncertain as “needs checking”.

For externally published work, a prompt of the following kind is also worth considering.

Check this text against the criteria for review before external publication.
In a table, flag any passages that raise concerns about copyright, quotation, attribution, proper nouns, figures, undue assertion, or possible infringement of a third party’s rights.
Label any passage requiring a legal judgement as “legal review”.

Set criteria for what goes into the training-data library

Kanata’s project library is described as having a training-data library, in which internal materials you want the AI to refer to can be registered.

It is therefore important to decide in advance what may be registered in the training-data library.

The points to confirm before registering are as follows.

  • Is it material we hold the rights to?
  • Does it contain a work belonging to an external contractor?
  • Does it contain client or third-party materials?
  • Are secondary use and internal sharing permitted under the contract?
  • Does it contain outdated material or incorrect information?
  • Does it contain personal data or confidential information?
  • Has an administrator and an update frequency been settled for after registration?

Using Kanata does not make the copyright judgement go away of its own accord.

The operation you need once the rules are drawn up

The operation you need once the rules are drawn up

An internal rule for generative AI is not finished once it is written. Because the technology, the service terms, the law, the case law, and the way it is used in practice all shift, you need to review it regularly.

Build an FAQ

Marshal the questions likely to come up from the floor into an FAQ.

For example, questions of the following kind.

  • May I have it summarise a web article?
  • May I put a client’s request for proposal into the AI?
  • May I use an image made with generative AI in an advert?
  • Does text produced by an AI have copyright?
  • May I build a comparison table with reference to another company’s service page?
  • May I have the AI rewrite copy by an external writer?
  • May I use a free image-generation AI for work?

An FAQ not only lightens the load of queries on legal but also speeds up the floor’s decision-making.

Run training

A rulebook alone leaves the floor unable to make concrete judgements.

In training, it is effective to handle cases close to actual work, rather than merely explaining clauses and the legal regime.

For example, exercises of the following kind.

  • May this material be entered into the AI?
  • May this AI-generated image be used in an advert?
  • Does this white-paper draft need attribution?
  • Does this proposal require legal review?
  • Is this prompt raising the copyright risk?

Kanata is described as having an e-learning feature, centred on video content, for internal training, onboarding, and self-study. Where you use such a feature, it works well to turn the copyright rules and checklists into learning content and pair it with an operation of regular review.

Review it regularly

Because the environment for AI use changes quickly, review the internal rules regularly too.

It helps to settle the timing of reviews along the following lines.

  • Once a quarter
  • When a new AI tool is introduced
  • When the terms of service change
  • When AI use in externally published work increases
  • When an incident or near-miss occurs
  • When there is a major update to the law or to official guidance

Authoritative bodies generally treat AI guidance as a living set of materials, updated as needed; the OECD, for instance, maintains its AI Principles as an evolving reference. A company’s own rules, likewise, should be designed on the assumption of updates, rather than fixed once written.

In closing: manage copyright risk by dividing it up, not by shutting it down

In closing: manage copyright risk by dividing it up, not by shutting it down

The copyright risk of generative AI cannot be managed by vague unease alone. At the same time, ban everything and you make it hard for the floor to improve its work or use AI creatively.

What matters is marshalling the risk into the following three parts.

  • Input: what may be fed into the AI
  • Training: how the AI service you use treats your data
  • Use of output: where and how the generated material is used

On that footing, set down in writing, as internal rules, the prohibited input, the handling of third-party works, the permitted tools, output review, approval for external use, and incident reporting.

A generative AI copyright rule is not a document for legal alone. It takes root in practice when management sets the direction, IT gets the environment in order, the floor uses it in line with a checklist, and legal keeps the criteria for judgement up to date.

Rather than shutting AI use down, separate the situations where use is allowed from those that warrant a check. That design is the first step in drafting internal rules for the generative-AI era.

Q&A: common questions on generative AI copyright risk and internal rules

Can text produced by a generative AI be used in external materials as it stands?

It is safer to avoid using it as it stands. When using it in external materials, adopt an operation in which you check the facts, figures, proper nouns, quotations, resemblance to existing works, and any exaggeration, and then, as needed, have it reviewed by a manager, communications, or legal.

May I paste a web article into the AI and have it summarised?

Even with a publicly available web article, it does not follow that you may paste it in full. Confine it to what is needed, keep the source URL, and check that it does not breach the AI service’s terms or your internal rules. Paid articles and members-only articles call for especially careful confirmation.

May I put materials received from a client into the AI to produce a proposal?

As a rule, you need to confirm the contract terms, any NDA, and whether the client has consented. Client materials may contain copyrighted works, trade secrets, and personal data. Even when using an approved AI environment, you should mask the data and confirm the permitted scope before input.

Can an image made with a generative AI be used in advertising?

Beyond the AI service’s conditions for commercial use, you need to check that it does not resemble an existing character, brand, author’s style, photograph, or logo. For external work such as advertising and landing pages, it is safer to set up a checking flow involving the production lead, legal, and communications.

Is it enough for the legal department to draw up the internal rules on its own?

Drawing them up in legal alone risks rules the floor finds hard to use. Legal builds the criteria for judgement, IT designs the tooling and permission management, and the floor departments translate it into the actual workflow. Management needs to signal how far to take AI use and which risks it will not accept.

Generative AI Copyright Risks Explained: Input, Training & Output — A Guide to Internal Rules
Share this article