No AI-Specific IP Statute
The United States has not enacted AI-specific intellectual property legislation. There is no federal statute creating sui generis rights in AI systems or AI-generated material. AI and IP questions are resolved under generally applicable federal and state law governing copyright, trade marks, trade secrets and patents.
Guidance Rather Than Legislation
The most significant federal developments are administrative guidance and case law. The US Copyright Office has issued a multi-part report, Copyright and Artificial Intelligence, covering digital replicas (Part 1, July 2024), the copyrightability of AI outputs (Part 2, January 2025) and the use of copyrighted works to train AI models (Part 3, released in pre-publication form in May 2025). The US Patent and Trademark Office (USPTO) issued Revised Inventorship Guidance for AI-Assisted Inventions in November 2025, superseding its February 2024 guidance. These materials apply existing law to AI rather than creating a distinct regime.
Two Threshold Rules
Copyright requires human authorship (Thaler v Perlmutter) and patent law a natural-person inventor (Thaler v Vidal), so wholly AI-generated output is unprotectable and an AI system cannot be named as an inventor (see 6.1 Human Authorship and Copyright Protection, 6.2 Computer-Generated or AI-Generated Works and 6.5 Patent Inventorship and Entitlement).
The United States is party to numerous multilateral IP instruments, including the Berne Convention, the Paris Convention, the Agreement on Trade-Related Aspects of Intellectual Property Rights, the WIPO treaties and the Patent Cooperation Treaty. These determine which foreign works and rights-holders qualify for protection, but none creates an AI-specific regime, so their influence is indirect. Foreign rights-holders and foreign AI developers face no special AI rules, and national treatment applies.
Treaties are not self-executing in the United States and take effect through implementing legislation. For example, the Digital Millennium Copyright Act (DMCA) implemented the WIPO treaties.
Technology-Neutral Statutes
The core US federal IP statutes – the Copyright Act, the Patent Act and the Lanham Act – do not define “artificial intelligence”, “generative AI”, “foundation model”, “training data”, “model weights”, “prompts” or “outputs”. There is no US equivalent of the EU AI Act, so there is no statutory taxonomy, and agentic systems are not a distinct legal category for IP purposes (see 5.5 Agentic AI, Tool Use and Autonomous Acts). US copyright law also contains no concept of a computer-generated work with a deemed author (see 6.2 Computer-Generated or AI-Generated Works).
Definitions That Exist Elsewhere
Federal law defines “artificial intelligence” for program and co-ordination purposes in the National Artificial Intelligence Initiative Act of 2020, but that definition has had no operative effect on IP doctrine. Agency guidance supplies working definitions, but courts owe no deference to it. For example, the Copyright Office distinguishes AI used as an assisting tool from AI that substitutes for human creative choices.
A practical consequence is that disputes will be resolved by applying applicable law to the facts of each case. Where disputes involve contracts between two parties, the contractual definitions carry significant weight.
Courts
There is no specialist AI court or regulator in the United States. Copyright and patent claims are federal-question matters heard first in the US district courts. Patent appeals, including from the USPTO, go to the Federal Circuit, while other IP appeals follow the regional circuits, with the Supreme Court final in either route. As of mid-2026 the leading AI copyright decisions are district court decisions, subject to appeal.
Offices and Regulators
The USPTO examines and grants patents, registers trade marks and has issued inventorship guidance for AI-assisted inventions (see 6.5 Patent Inventorship and Entitlement). The Copyright Office administers registration and requires disclosure of more than de minimis AI-generated content (see 6.4 Registration, Disclosure and Enforcement of AI-Assisted Works). The Federal Trade Commission (FTC) has signalled interest in enforcement against deceptive AI practices, which can intersect with brand and advertising issues (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs).
IP Protection Structure
No standalone IP right subsists in an AI system. Protection is mapped to components: copyright for implementing code and expressive materials; patent for eligible systems and methods; trade secret for weights, datasets and prompts; and trade mark for branding. Protection may not extend to abstract functionality, algorithms or agentic capabilities as such.
Code and Architecture
Source and object code created by a human author and meeting the originality threshold may be protectable as literary works, but copyright protects the expression rather than the underlying functionality, methods of operation or algorithms. Patent protection is available where the claimed subject matter is eligible (see 2.3 Patent Protection for AI Technologies). The overall structural design of a model is an idea and unlikely to be protected by copyright, although the code, configuration files, diagrams and documentation may be, and a system or method embodying an architecture may be patentable.
Weights, Parameters and Embeddings
Trained weights and parameters are generated through training rather than human authorship and are therefore unlikely to be copyrightable. They are also unlikely to be independently patentable because bare numerical values fail the statutory category threshold (Digitech Image Technologies, LLC v Electronics for Imaging, Inc). Embeddings are numerical vectors produced by running content through a model and are likewise unprotected, although an original selection or arrangement may attract a thin copyright that does not reach the individual vectors (Feist Publications, Inc v Rural Telephone Service Co). There is no US database right (see 2.5 Data, Database and Dataset Protection), so these assets are protected in practice through trade secret and contract (see 2.4 Trade Secrets and Confidential Information).
Prompts and Prompt Libraries
A prompt may be protected by copyright if sufficiently original and fixed. In Part 2 of Copyright and Artificial Intelligence, the Copyright Office indicated that short, purely functional prompts are unlikely to qualify, while longer system prompts, prompt chains or curated libraries may.
Datasets, Fine-Tuning Materials, Documentation and Benchmarks
Individual items may be protectable as literary works, subject to originality and human authorship, while synthetic or model-generated material without a human author is unlikely to qualify. A dataset may attract a thin compilation copyright where the selection or arrangement is original. In practice these assets are protected principally as trade secrets and by contract (see 2.5 Data, Database and Dataset Protection).
APIs and Interfaces
Implementing code for application programming interfaces (APIs) is protectable expression, but protection for API structure, sequence and organisation is constrained. In Google LLC v Oracle America, Inc, the Supreme Court held that reimplementation of the Java SE API’s declaring code was fair use, without finally resolving copyrightability. Unlike the underlying functionality, interface elements may be protected where original and separable from function.
Where Copyright Stops
Beyond the component analysis in 2.1 Protectable Elements of AI Systems, the limits of copyright protection are set by the statutory exclusion of ideas, procedures and methods of operation. Algorithms, training techniques and model architectures, as abstract methods, lie outside copyright, although a detailed written architecture description is protected against textual copying. Functional elements dictated by efficiency or by external constraints such as interoperability are generally disregarded when courts assess infringement. As of mid-2026 no US decision has squarely established copyright in model weights, and trade secret and contract remain the primary protections.
Permitted Uses and Access Controls
The DMCA prohibits circumvention of technological protection measures but contains exemptions, including for good-faith security research and reverse engineering for interoperability. The Copyright Act also permits certain reverse engineering as fair use (Sega v Accolade; Sony v Connectix), and fair use may excuse some uses of documentation and published prompts.
Ordinary Requirements, Applied With Particular Force
AI inventions are assessed under the ordinary requirements of the Patent Act: eligible subject matter (Section 101), novelty (Section 102), non-obviousness (Section 103), enablement and written description (Section 112(a)) and definiteness (Section 112(b)). There are no AI-specific patentability requirements; the difference lies in application, as eligibility, disclosure and obviousness bite harder on algorithm-centric and functionally claimed inventions.
Eligible Subject Matter
Under the two-step Alice/Mayo framework, a claim directed to an abstract idea is ineligible unless additional elements integrate it into a practical application amounting to significantly more, and courts frequently treat machine learning (ML) claims as abstract where they recite generic models performing generic functions. In Recentive Analytics, Inc v Fox Corp, the Federal Circuit characterised ML patents as a species of software patent and held that applying generic ML techniques to a new field of use, without improving the ML technology itself, is not eligible; the Supreme Court denied certiorari. The decisive question is therefore whether the claim is directed to a specific improvement in computer or model functionality; improved speed or efficiency alone does not suffice.
USPTO Posture
The USPTO has moved toward a more permissive position within that framework. Building on its July 2024 Guidance Update on Patent Subject Matter Eligibility, the precedential Ex parte Desjardins (2025) rejected categorically excluding AI claims from patent protection and directed examiners to ask whether claims are directed to an improvement in computer functionality or another technical field rather than assessing them at a high level of generality. Recent statements and memoranda from the Director have reinforced that posture and encouraged applicants to build an evidentiary record on eligibility during examination.
Claim Drafting
Functional terms such as “module” or “unit” can trigger means-plus-function treatment under Section 112(f) even without the word “means”, and because the corresponding structure for a computer-implemented function is the algorithm performing it, a specification that does not disclose that algorithm risks indefiniteness. Reciting specific architectures, defined training steps and structural terms tied to a particular technical purpose both improves eligibility and reduces indefiniteness risk.
Disclosure
The specification must enable the full scope of the claimed invention without undue experimentation (enablement) and must show possession of it, assessed by the In re Wands factors and reinforced by Amgen Inc v Sanofi. Black box claims are vulnerable. The Patent Trial and Appeal Board (PTAB) rejected claims in Ex parte Allen where the specification disclosed neither the algorithm nor how scores were generated, but upheld them in Ex parte Kirti where it identified the model type, its training inputs and outputs, and the training methodology. There is no requirement to deposit training datasets, so disclosing dataset characteristics and training procedures may suffice – but this creates real tension with keeping training details secret (see 2.4 Trade Secrets and Confidential Information).
Obviousness Risk for Generic ML Claims
Claims reciting ML only at a high level of generality face heightened risk. In AliveCor, Inc v Apple Inc, where the prior art taught using ML to analyse ECG data, the Federal Circuit upheld a finding that applying ML to arrhythmia detection was obvious. In Intel Corp v Health Discovery Corp, by contrast, the PTAB rejected an obviousness challenge because there was no evidence a skilled artisan would have been motivated to make the particular combination. Applying known techniques to a known problem tends to be obvious; specific algorithms producing technical advances in a field can survive.
Framework
Trade secret protection is available under the federal Defend Trade Secrets Act (DTSA) and under state law, most states having adopted a version of the Uniform Trade Secrets Act; New York is a notable exception and applies common law. Information qualifies as trade secret if it derives independent economic value from not being generally known or readily ascertainable and is the subject of reasonable measures to keep it secret. Model weights, algorithms, architectures, proprietary training data and deployment know-how are all candidates (see 2.1 Protectable Elements of AI Systems).
Why Secrecy Often Outperforms Patenting
Trade secrets require no registration or disclosure, reach subject matter that patent and copyright may not (eg, numerical values, abstract methods, negative know-how) and last indefinitely so long as confidentiality is maintained, but they confer no exclusivity against independent development or reverse engineering. Developers therefore commonly adopt a hybrid approach: protect training data, weights and know-how as confidential, and patent selected technical improvements (see 2.3 Patent Protection for AI Technologies).
Reasonable Measures
AI assets create distinctive leakage risks, including model-inversion and prompt-extraction attacks and employees pasting confidential material into third-party tools, so reasonable measures must include AI-specific controls. What is reasonable is assessed contextually and typically combines technical controls (eg, tiered access, encryption, and monitoring for unauthorised extraction), administrative controls (eg, classification policies, restricted repositories, training, and onboarding and offboarding protocols) and contractual protections.
No Database Right
The United States has no sui generis database right. Copyright does not protect facts or data, although an original selection, co-ordination or arrangement may attract a thin copyright that does not extend to the underlying data. This is a significant contrast with the EU database right, for example, which relies on analysis of the investment made in obtaining, verifying or presenting contents; in the United States the question is originality of selection.
Annotations, Embeddings and Synthetic Data
Original human-authored annotations, labels and commentary may be protected as literary works, subject to the limits on short phrases and facts, while individual embeddings and material generated without a human author are unlikely to be protected (see 2.1 Protectable Elements of AI Systems).
Practical Protection
Datasets, annotation sets and embedding stores are therefore protected principally as trade secrets and through contractual restrictions on access and use, supplemented in some circumstances by state misappropriation or unfair competition theories, subject to federal copyright preemption.
The Default Position
Assembling training, fine-tuning, retrieval-augmented generation (RAG), evaluation or safety-testing methods commonly reproduce copyright works through scraping, downloading, storage, caching, deduplication, tokenisation and indexing. Each reproduction would be an exercise of the owner’s exclusive rights unless licensed or excused. The decisive question is fair use, assessed on the four statutory factors: purpose and character of the use, nature of the work, amount and substantiality used, and effect on the market.
The 2025 Decisions
Two Northern District of California decisions issued days apart in June 2025 held that using copyrighted works to train large language models was transformative and fair use on the facts. In Bartz v Anthropic, training on lawfully acquired books was found quintessentially transformative, but downloading and retaining pirated copies to build a permanent library was a separate, non-transformative use that was not fair. In Kadrey v Meta, the court granted summary judgment for the developer on the record before it, while emphasising that transformativeness does not guarantee fair use and articulating a market dilution concern about outputs flooding the market. Earlier, in Thomson Reuters v Ross Intelligence, the District of Delaware rejected fair use where the defendant used protected material to build a directly competing tool; the Third Circuit heard arguments on 11 June 2026.
The Consequence for Plaintiffs’ Strategy
The Bartz piracy holding drove a settlement of approximately USD1.5 billion, which amount was upheld in a fairness hearing in July 2026. That has encouraged plaintiffs to focus on the source of training copies, in particular downloads from shadow libraries, rather than on whether training is transformative.
What Remains Unsettled
Training on lawfully acquired works can qualify as fair use where the purpose is transformative, and acquiring or retaining pirated copies is unlikely to be excused. Beyond that, these are district court decisions applying different reasoning to particular records. The position remains open on infringing outputs, on the market-harm factor and on non-text modalities such as images, music and code.
Fair Use Analysis is Key
The United States has no text and data mining exception. Fair use serves that function instead and applies across research and product development, with commerciality weighing under the first factor but not dispositively. Google v Oracle, on reimplementation of software interfaces, and Andy Warhol Foundation v Goldsmith, on weighing transformativeness against commercial substitution, frame the current analysis as applied to training in the 2025 Bartz and Kadrey decisions (see 3.1 Use of Copyright Works for Training).
Access Matters as Much as Purpose
How source materials were obtained is a distinct question from how they were used. Downloading and retaining pirated copies exposes the developer to substantial statutory damages (see 8.4 Monetary Remedies and Cross-Border Enforcement); circumventing technological protection measures to obtain works can additionally violate the DMCA.
Other Limitations
Express limitations exist for libraries and archives, certain educational uses and accessible-format copies, but they are institution- and purpose-specific and do not map onto bulk ingestion for commercial AI training.
No Compulsory or Collective Route
There is no statutory or compulsory licence for AI training in the United States and no analogue to extended collective licensing. Licensing is voluntary and, given the unsettled fair use position and the acquisition-side exposure highlighted in Bartz (see3.1 Use of Copyright Works for Training), increasingly a practical way to reduce litigation risk.
Market Practice
A licensing market has developed rapidly and largely through negotiated deals between AI developers and large rights-holders or content controllers such as news publishers, image libraries, music and book publishers, and platforms. Terms typically address the licensed catalogue, permitted uses, duration, territory, fees, audit and reporting rights, and warranties (see 9.1 Training Data and Content Licensing). Payment terms are not standardised and may take the form of lump sums, annual or usage-based fees, or revenue sharing, and some deals include attribution or content-surfacing commitments.
No Statutory Opt-Out
There is no statutory opt-out mechanism. Copyright is reserved by default, and whether a use is permitted turns on fair use and on the rights granted and restrictions imposed by applicable contracts.
What Notices Can Still Do
Robots.txt files, website terms, metadata, content credentials and “do not train” signals are not self-executing IP instruments, but they matter in three ways:
Agents
The analysis does not change if the act was performed by an AI agent (see 5.5 Agentic AI, Tool Use and Autonomous Acts), although an agent that ignores a notice or circumvents an access restriction may worsen the operator’s position on wilfulness, contract and CFAA exposure.
Documentation
There is no federal IP-specific duty to document training data sources, filtering, deduplication, removal requests, rights reservations or model development records. Record-keeping incentives arise indirectly: litigation and discovery exposure (see 8.2 Evidence, Disclosure and Confidentiality), licence warranties and audit rights (see 9.1 Training Data and Content Licensing), and any EU obligations for models placed on the EU market. The Bartz case (see 3.1 Use of Copyright Works for Training) underscores the practical importance of being able to demonstrate lawful acquisition.
Cross-Border
US copyright protection is territorial and generally does not reach reproduction occurring wholly outside the United States, subject to limited theories for predicate domestic acts. The place of infringement is generally considered to be the place where the relevant copying, storage or distribution activity occurs, including scraping infrastructure, cloud storage, training clusters, RAG indexes, caches and user devices. Where training, servers, developers and users span jurisdictions, a claimant may need to establish a qualifying US act.
General Principles
There is no AI-specific liability regime for IP infringement in the US. Copyright infringement is a strict-liability tort, so intent and knowledge are irrelevant to liability, although they bear on remedies including wilfulness and enhanced statutory damages. For patents, an infringing act under the Patent Act must be shown; for trade marks, use in commerce likely to cause confusion must be established (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs).
What Must Be Proved
A claimant must show ownership of a valid copyright and copying of protected expression, typically through access plus substantial similarity. Registration is generally a prerequisite to bringing an infringement lawsuit for US works and impacts the availability of statutory damages and fees (see 6.4 Registration, Disclosure and Enforcement of AI-Assisted Works). Scraping, dataset assembly, tokenisation, caching and loading works into memory during training ordinarily involve reproduction; creating modified versions can implicate the derivative work right; and making works available can implicate distribution, display and performance rights.
Challenges
The claimant must establish a qualifying act of infringement in the United States (see 3.5 Provenance, Transparency and Cross-Border Training), and copying must be proved as fact, which can be complicated in an AI context. Claimants rely on discovery, memorised or regurgitated outputs, dataset documentation and distinctive artefacts such as reproduced watermarks or near-verbatim text.
Weights
US courts have not resolved whether trained model weights themselves constitute infringing copies. The developer-favourable reasoning in Bartz and Kadrey focused on training as transformative rather than on characterising weights as stored copies, and whether weights contain protected expression remains open. A model shown to memorise and reproduce protected works presents a materially different case from one that does not.
Intermediate Copies
Distinct from the weights, the copies made during collection and training (eg, tokenised copies, caches and checkpoints that store works) are generally found to be reproductions and infringing unless licensed or excused, and their legality is analysed separately from any question about the trained model.
Memorisation and De Minimis Copying
There is no AI-specific test. Ordinary substantial similarity analysis applies to outputs, and evidence that a model can regurgitate protected expression (eg, verbatim text, image elements, watermarks) supports both copying and, potentially, wilfulness. US law recognises a de minimis principle in some contexts, but its application is contested across the circuits, and these questions are typically resolved through expert evidence.
Secondary Liability Doctrines
US law recognises contributory infringement (knowingly inducing, causing or materially contributing to infringement), inducement (distributing a device or service with the object of promoting infringement, per MGM v Grokster) and vicarious liability (the right and ability to control the infringing activity coupled with a direct financial interest). Supplying a tool capable of substantial non-infringing uses does not, without more, create liability (Sony v Universal).
What Moves the Needle
A provider is better positioned where its terms prohibit infringement and it implements filters and monitoring tools, and worse positioned where the service is designed or marketed to reproduce identifiable works, or where it controls generation and publication. Plaintiffs in pending output cases frequently combine direct and secondary theories.
Safe Harbours
The DMCA safe harbours can protect qualifying service providers from monetary liability for user-directed storage and related functions, subject to conditions including a registered agent, a repeat-infringer policy and notice-and-takedown. Their application to generative AI is uncertain, because training conducted at the developer’s own behest is unlikely to be at the direction of a user.
Training, Prompting and Storage
Using confidential material to train or fine-tune a model without authority may be trade secret misappropriation where the information was acquired by improper means or used in breach of a duty of confidence, and the extracted value can survive deletion of the sources, which affects remedies (see 8.3 Interim and Final Injunctive Relief). An employee who pastes confidential information into a third-party model may disclose it under the provider’s terms and breach confidentiality obligations, and material an agent retrieves through tool calls or stores in memory or vector stores creates a risk of continuing use.
Outputs and Open Questions
A provider that trains on misappropriated trade secrets risks injunctive relief and damages if it knows or has reason to know of the misappropriation. It remains unresolved whether information a model infers or synthesises, rather than reproduces, is misappropriated, and how the reasonable-measures and improper-means elements apply to model-mediated disclosure. The black box problem aggravates proof of use and derivation, so discovery of prompts, logs and model artefacts is central (see 8.2 Evidence, Disclosure and Confidentiality).
Substantive Defences
Fair use is the primary defence to a copyright infringement claim where there has been transformative training on lawfully acquired works (see 3.1 Use of Copyright Works for Training). Other common defences include lack of copying or lack of substantial similarity, independent creation, functionality limitations on copyright protection and, for outputs, that only unprotectable ideas, facts or style were taken. Express or implied licences, including from platform or website terms, may authorise particular uses. The first-sale doctrine has little relevance to intangible training copies, and the DMCA safe harbours are of uncertain application (see 4.3 Secondary, Authorisation and Intermediary Liability).
Procedural Levers
The Copyright Act’s statute of limitations period is three years, with circuit-level nuance on accrual and the discovery rule following Warner Chappell v Nealy. Trade secret statutes have their own statute of limitations periods. Copyright registration requirements and the scope of statutory damages and fees are significant levers (see 8.4 Monetary Remedies and Cross-Border Enforcement). Innocent intent is not a defence to liability but can reduce statutory damages, while wilfulness increases them. Antitrust and copyright-misuse arguments are occasionally raised but are situation-specific.
The Test
There is no AI-specific rule for copyright infringement in outputs. An output may infringe if it reproduces, or is substantially similar to, protected expression, where independent development cannot be established. The training-stage decisions expressly reserved the position on infringing outputs, which is a principal focus of the pending litigation (see 3.1 Use of Copyright Works for Training).
Outputs Similar to Training Works or Prompts
Where a model has memorised protected expression and an output reproduces it, the output can infringe notwithstanding that the copying is machine-mediated. Where a user supplies a protected work as a prompt or reference and the output retains substantial protected expression, that reproduction may be attributable to the user, and uploading the reference work may itself be a reproduction. Allocation of the restricted act between user, deployer and provider remains an unsettled point in US courts.
Style and Voice
Copyright protects expression, not style, genre or technique, so an output produced in the style of an artist that takes no substantial protected expression from any identifiable work is unlikely to infringe copyright on that basis alone. Style imitation may nonetheless implicate right of publicity, false endorsement or digital replica theories (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs and 7.4 Personality, Publicity, Performers’ and Neighbouring Rights).
There is a strict liability test for copyright infringement, so a user who generates or publishes an output reproducing substantial protected expression, or who deploys an agentic system that carries out a restricted act, can infringe regardless of intent or knowledge, and agent autonomy does not break attribution (see 5.5 Agentic AI, Tool Use and Autonomous Acts). Prompts engineered to elicit a specific work are powerful evidence of copying and of wilfulness. Documented human review and provenance checks reduce practical risk.
Trade Mark and Unfair Competition
Under the Lanham Act, using a mark or confusingly similar sign in commerce in a manner likely to cause confusion as to source, sponsorship or affiliation can infringe, and famous marks may be protected against dilution. Where an AI output incorporates a third-party mark, logo or trade dress in commerce, ordinary likelihood-of-confusion and dilution analysis apply. A user who deliberately prompts a model to apply a third-party mark to marketed goods faces orthodox liability, while a provider’s exposure depends on its role, knowledge and control (see 4.3 Secondary, Authorisation and Intermediary Liability). Expressive uses may attract First Amendment considerations, although Jack Daniel’s v VIP Products narrowed that protection where marks are used as source identifiers.
Endorsement and Advertising
False endorsement claims under the Lanham Act can address outputs that falsely suggest a person’s endorsement, including imitation of a recognisable voice, likeness or persona, and state right of publicity law provides a parallel route (see 7.4 Personality, Publicity, Performers’ and Neighbouring Rights). AI-generated advertising remains subject to federal and state consumer protection and false advertising law, including FTC enforcement against deceptive or unfair practices.
Patents
General principles apply. Making, using, offering to sell, selling or importing a patented invention without authority is direct infringement, even where the design, parameters or synthesis route were AI-generated. Indirect liability can arise through active inducement, or through contributory infringement where a party supplies a component knowing it to be especially adapted for use in an infringement and not a staple article suitable for substantial non-infringing use. Whether generating instructions or candidate designs amounts to supplying a component, or to inducement, is a fact-specific inquiry.
Designs and Code
A design patent can be infringed where an ordinary observer would consider the accused design substantially the same as the patented design, regardless of independent creation by an AI (see 7.1 Designs, Trade Dress and Product Appearance). AI-generated code can infringe copyright where it is substantially similar to protected expression, but functionality is not protected and reimplementation questions are informed by Google v Oracle (see 2.1 Protectable Elements of AI Systems).
US law does not recognise an AI system as a legal actor and has no AI-specific attribution rules. An agent’s autonomous acts are attributed to those who deploy and operate it and who set its objectives, tools and permissions.
Autonomous scraping and retrieval can engage the reproduction right, breach of website terms (which may restrict use even of unprotected data), removal or alteration of copyright management information, circumvention under the DMCA and potentially CFAA exposure where access restrictions are bypassed (see 3.4 Rights Reservations and Opt-Outs). Autonomous transactional or design choices can commit the operating party to patent, design or trade mark infringement (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs and 5.4 Patent, Design and Product-Related Infringement). Secondary liability doctrines apply where the operator induces or materially contributes to a third party’s infringement (see 4.3 Secondary, Authorisation and Intermediary Liability).
The Standard
Copyright protects only works of human authorship, a constitutional and statutory requirement reflected in long-standing authority (Burrow-Giles Lithographic Co v Sarony) and confirmed for AI in Thaler v Perlmutter, where a work described as autonomously generated by a machine was held unprotectable.
Prompts Alone Are Not Enough
The Copyright Office’s position is that prompts, however detailed, do not on current technology give the user sufficient control over the expressive elements of the output to constitute authorship of it, because the model determines much of the expression. Human authorship can nonetheless be present where a human contributes protectable expression: through creative selection, coordination and arrangement of AI-generated material; through creative modification or editing of the output; or where human-authored input is perceptible in the result. Protection then extends only to those human-authored elements (see 6.4 Registration, Disclosure and Enforcement of AI-Assisted Works).
Agentic Pipelines
Greater autonomy weakens the case for human authorship. Where an agent decomposes tasks, generates its own prompts, plans and selects intermediate outputs, and produces the final work without meaningful human expressive control, the authorship link is attenuated and the output is likely unprotectable except as to any perceptible human-authored expression or creative arrangement.
No Protection Without a Human Author
The United States does not recognise copyright, or any separate sui generis right, in works generated without a human author. This is a fundamental divergence from the UK, which deems an author for computer-generated works. A wholly AI-generated work falls into the public domain so far as copyright is concerned, and no ownership, term or scope attaches to it. The Copyright Office has expressly declined to recommend sui generis protection, concluding that existing law is adequate and that protection should track human authorship.
Where a Human Contributes
Ordinary copyright protects the human-authored elements on ordinary terms, generally life plus 70 years, or 95 or 120 years for works made for hire, while the AI-generated portions remain unprotected. The open questions are how much human contribution suffices, and how to delineate protected from unprotected elements within a work for registration and enforcement.
Joint Authorship
To establish joint authorship, US law requires that two or more authors intend to merge their contributions into a unitary whole, and courts generally require each putative co-author to contribute independently copyrightable expression and to intend joint authorship (Childress v Taylor; Aalmuhammed v Lee). An AI system cannot be a joint author, and absent agreement human co-authors hold equal undivided interests.
Derivative Works
An AI output generated from, and incorporating substantial protected expression of, an existing work may be an infringing derivative work unless licensed or excused. A derivative work embodying its own original human authorship may attract a thin copyright, but only in the new material.
Adaptations
For adaptations, an output may attract copyright in new human-authored elements yet still infringe the earlier work that has been adapted, so the creator may own the new elements but be unable to exploit the output without the source owner’s permission.
Copyright Registration
Copyright registration is generally a prerequisite to bringing an infringement suit (Fourth Estate Public Benefit Corp v Wall-Street.com, LLC), and timely registration determines the availability of statutory damages and attorneys’ fees. The Copyright Office requires human authorship and requires applicants to disclose and disclaim more than de minimis AI-generated content.
Consequences of Non-Disclosure
Failing to disclose AI contributions can jeopardise the registration and the enforcement rights that depend on it. A registration may be cancelled, or disregarded by a court, where the applicant knowingly provided inaccurate information that would otherwise have caused the Office to refuse registration, subject to the framework considered in Unicolors, Inc v H&M Hennes & Mauritz, L.P.
Patents
There is no general requirement to disclose that AI was used in connection with development of patentable technology, but the named inventor must be a natural person who conceived the claimed invention (see 6.5 Patent Inventorship and Entitlement). Everyone associated with filing and prosecution owes the USPTO a duty of candour and good faith, including disclosure of information material to patentability. Failing to disclose that an AI system conceived an invention can create an improper inventorship issue which, if incurable, may lead to invalidity or unenforceability. Materially deceptive conduct before the USPTO can also support an inequitable conduct defence, potentially rendering the patent and related patents unenforceable.
AI Cannot be a Patent Inventor
In Thaler v Vidal the Federal Circuit held that the Patent Act requires inventors to be natural persons, and the Supreme Court denied review. An invention is not unpatentable merely because AI was used: the question is whether at least one natural person conceived the claimed invention, and the same standard applies whether or not AI was involved.
What Conception Requires
Conception is the formation in the inventor’s mind of a definite and permanent idea of the complete and operative invention, complete only when the idea is sufficiently defined that ordinary skill would suffice to reduce it to practice without extensive research (Burroughs Wellcome Co v Barr Laboratories, Inc). Determining contribution is highly fact-intensive. Merely owning or running a model, providing infrastructure or routinely validating results may be insufficient, and there may be no valid inventor at all where an AI system autonomously proposes the experiments, selects the parameters and generates the candidate solutions without human conception.
USPTO Guidance
The USPTO’s inventorship guidance analogises AI systems to laboratory equipment or research databases. They are all tools that assist the inventive process. Where one person is involved, the inquiry is whether that person conceived the invention under traditional standards; where several people are involved, traditional joint inventorship principles apply as between the human contributors, including the factors in Pannu v Iolab Corp.
Entitlement
Inventors are the starting point for ownership, and present-tense assignments, including under employment agreements, transfer ownership rights. The employed-to-invent doctrine and shop rights may also apply. For contractors and collaborators, entitlement depends on inventorship and on the relevant contracts, whether or not AI tools were used.
AI Raises the Baseline
For patents, obviousness is assessed from the perspective of the hypothetical person of ordinary skill in the art at the time of the invention, applying the Graham factors and the flexible approach of KSR v Teleflex, and may be obvious to try where the inventor chose from a finite number of identified, predictable solutions with a reasonable expectation of success. That notional person is presumed to know the relevant prior art (In re GPAC Inc), so as AI tools become part of the ordinary toolkit, routine AI-assisted screening or optimisation may raise the obviousness bar. The same logic bears on enablement, where the prevalence of AI tools may affect several Wands factors: the state of the art, the skill level of the notional artisan, predictability and the quantity of experimentation required (see 2.3 Patent Protection for AI Technologies).
AI-Generated Prior Art
AI-generated disclosures and synthetic datasets can constitute prior art if publicly available and accessible before the effective filing date and otherwise meeting the statutory requirements; unlike inventorship, human authorship is not required. Ordinary limits still apply: material confined to private databases or proprietary systems may not be publicly accessible, and a non-enabling disclosure cannot anticipate a claim, although it may still support an obviousness argument.
Design Patents
Ornamental product designs are protected principally through design patents, which cover new, original and ornamental designs for an article of manufacture, including in appropriate cases graphical user interfaces and icons. A design patent requires a natural-person inventor (see 6.5 Patent Inventorship and Entitlement), must be novel and non-obvious, and protects appearance rather than function; the term is 15 years from grant.
Copyright and Trade Dress
Copyright may protect original artistic features separable from utilitarian aspects (Star Athletica v Varsity Brands), subject to the human authorship requirement, which constrains protection for wholly AI-generated designs (see 6.1 Human Authorship and Copyright Protection and 6.2 Computer-Generated or AI-Generated Works). Trade dress, which protects the overall look and feel of a product or its packaging, is protectable under the Lanham Act where it is distinctive or has acquired secondary meaning and is non-functional (Wal-Mart v Samara; TrafFix v Marketing Displays).
Trade mark law is largely indifferent to how a sign was created. An AI-generated name, logo, slogan, sound or motion mark can be registered if it functions as a source identifier, is distinctive inherently or through use, is not merely descriptive or functional, and does not conflict with prior rights. Because protection does not depend on authorship, the human authorship problems affecting copyright and patent protection are not relevant for trade marks.
Federal registration of trade marks additionally requires use in commerce or a bona fide intent to use, and ownership belongs to the person or entity that uses or controls use of the mark, not to the AI or the tool provider.
Narrow Moral Rights
US moral rights are narrow. The Visual Artists Rights Act confers limited rights of attribution and integrity, but only for a narrow class of works of visual art existing in single copies or limited signed editions, which excludes most AI outputs and most commercial content. There is no general statutory paternity or integrity right of the UK kind.
False Attribution Addressed Elsewhere
Outputs merely imitating a creator’s style, without copying protected expression, generally do not infringe copyright (see 5.1 Copyright Infringement in Outputs). Falsely presenting AI output as a particular person’s work is addressed not by moral rights but by Lanham Act false endorsement and false designation claims, state right of publicity law, and unfair competition and consumer protection law (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs and 7.4 Personality, Publicity, Performers’ and Neighbouring Rights). Federal digital replica legislation has been recommended by the Copyright Office but is not yet enacted.
A State-Law Right
The United States recognises a right of publicity, but it is a matter of state law rather than a single federal right, so scope, duration and post-mortem availability vary considerably between states. A right of publicity generally protects against unauthorised commercial use of a person’s name, image and likeness and, in several states, voice, and is variously characterised as a property, privacy or unfair competition right depending on the jurisdiction.
Overlapping Routes
Complementary protections include Lanham Act false endorsement claims (see 5.3 Trade Mark, Passing Off and Brand-Related Outputs), state privacy torts and, where a protected work such as a sound recording is actually copied, copyright. Some states have enacted AI-specific statutes addressing digital replicas of voice and likeness, including in the performer context, and several regulate deceptive deepfakes in electoral and intimate-image contexts.
There is no separate forum for AI disputes (see 1.4 Courts, IP Offices and Regulators). Copyright and patent claims are heard in the federal district courts, USPTO proceedings before the Patent Trial and Appeal Board and the Trademark Trial and Appeal Board, trade mark and unfair competition claims in federal or state court, and trade secret claims under the DTSA or state law. Arbitration is available where the parties have so agreed.
Discovery
There are no AI-specific evidentiary tools. US civil discovery is broad and, subject to proportionality, can reach:
Litigants are subject to preservation duties, and to sanctions for spoliation, extending to logs, checkpoints and datasets that would otherwise be overwritten. Source-code review may be conducted under strict protocols, and expert examination of code, weights or pipelines, together with agreed memorisation testing, is increasingly used.
Protecting Confidential Material
Courts routinely enter protective orders, including attorneys’-eyes-only tiers and source-code review procedures, and permit filing under seal. The DTSA also contains provisions to preserve secrecy in trade secret litigation (see 2.4 Trade Secrets and Confidential Information).
Ordinary Equitable Principles
Preliminary and permanent injunctive relief requires a showing under the eBay v MercExchange framework — likelihood of success, irreparable harm, balance of equities and public interest — and irreparable harm is not presumed.
Model and Dataset Orders
A court may in principle enjoin further infringing reproduction in training, enjoin distribution of an infringing model or service, and order works removed from datasets. Model versions and datasets can be secured through preservation orders. Orders to delete or retrain a model – sometimes described as “algorithmic disgorgement”, a remedy the FTC has sought in some matters – are potentially available but exceptional and, in the copyright context, largely untested.
Output-Side and Ancillary Orders
Orders to disable identified outputs, implement filters or guardrails, suspend agents, revoke tool or API access, or disable autonomous publication or transaction functions may be available where compliance is sufficiently definite. Other relief includes impoundment and destruction of infringing articles and corrective advertising in trade mark cases.
Copyright
A successful claimant may recover actual damages plus the infringer’s profits attributable to the infringement, or elect statutory damages of up to USD30,000 per work infringed, rising to USD150,000 per work for willful infringement, where the work was timely registered; attorneys’ fees may also be available. The prospect of per-work statutory damages across large corpora drove the scale of the Bartz settlement (see 3.1 Use of Copyright Works for Training).
Other Rights
Patent damages are no less than a reasonable royalty and may include lost profits, with treble damages available for wilful infringement. Trade secret remedies include actual loss, unjust enrichment, reasonable royalty and, for wilful and malicious misappropriation, exemplary damages and fees. Lanham Act remedies include profits, damages and, in exceptional cases, fees.
Cross-Border
Damages may capture foreign harm flowing from a domestic infringing act, but US copyright generally does not reach purely foreign conduct (see 3.5 Provenance, Transparency and Cross-Border Training). Enforcement of foreign judgments is governed by state recognition statutes and common law, and the United States is not party to a broad multilateral judgments convention covering these matters.
Given the unsettled fair use position and the acquisition-side risk highlighted by Bartz (see 3.1 Use of Copyright Works for Training), contracts that expressly include training and content licences carry particular weight.
Scope and Permitted Uses
Contracting parties should define the licensed rights precisely, including any rights in metadata and annotations, together with the permitted activities: training, fine-tuning, evaluation, benchmarking, RAG or grounding, embedding generation, vector storage and agentic retrieval. These should be separately permissioned and priced, because retrieval creates distinct inference-time risks: live copying, caching and display. Contracting parties should also identify the permitted models and families (base, fine-tuned, distilled, successor, embeddings, indexes), plus territory, term, infrastructure location, exclusivity and any most-favoured-nation protection.
Commercial and Control Terms
Remuneration may be a lump sum, annual, usage-based, per-run, retrieval-based, revenue share or hybrid, and attribution matters most where content is surfaced to users. Audit rights should be supported by logging of ingestion, filtering, training runs, versions, retrieval events and, for agents, tool calls, API access and autonomous publication. Sublicensing and affiliate, customer and subcontractor access should also be addressed.
Exit and Risk Allocation
Contracting parties should specify what happens on expiry or termination of the rights or broader contract, including requirements to delete or return datasets, caches, embeddings and indexes, and take a realistic position on already-trained models, whether by sunset, retraining or output filtering. Warranties and indemnities should address rights ownership, data provenance and legality, opt-out compliance and agent-mediated downstream uses, and should be read against the output indemnities the provider offers its own customers.
Guidance is Doing the Work of Legislation
There is no comprehensive federal AI-specific IP statute, and in the near-term the legal landscape is being shaped through litigation and agency guidance rather than legislation. The defining reference points remain the Copyright Office’s three-part report and the USPTO’s inventorship and eligibility guidance (see 1.1 AI-Specific or Sui Generis IP Rules and 2.3 Patent Protection for AI Technologies). These are influential but non-binding and subject to revision, congressional override or judicial challenge. The practical significance of the various guidance lies in shaping examiner conduct, informing litigation strategy and signalling the direction of future legislation.
Transparency and Digital Replicas
Various state and federal bills addressing AI training transparency and digital replicas have been introduced, but none has been enacted. The practical consequence is that rights-holders continue to rely on litigation rather than on new statutory rights; developers rely on fair use while carrying exposure both on how training copies were acquired and on outputs resembling protected works; and users remain exposed for infringing outputs they publish or commercialise.
Participation
The United States participates in international co-ordination principally through WIPO’s work on IP and frontier technologies, OECD and G7 processes, standards bodies and trade relationships, rather than through binding harmonisation of AI-specific IP rules.
Divergence
The principal distinguishing factor in the US is the approach to training on copyrighted works. The United States relies on the flexible, litigation-driven fair use doctrine; the EU uses statutory text and data mining exceptions with a rights-reservation mechanism, layered with EU AI Act transparency duties; and the UK has neither a broad commercial text and data mining exception nor US-style fair use. Because infringement is territorial, these differences create incentives for arbitrage in where models are trained and hosted (see 3.5 Provenance, Transparency and Cross-Border Training). The United States also differs in recognising a state-law right of publicity, while lacking the UK’s computer-generated works right and the EU’s database right.
101 California St 35th floor,
San Francisco
CA 94111
United States
+1 415-772-1200
aremis@sidley.com sidley.comIn the United States, the trends on the topic of intellectual property protection and artificial intelligence in the coming year will focus on two key questions. The first question is where a developer’s training material came from. The second question is whether and what an individual contributed to a given output or invention. Neither question is about how the technology works, and neither is answered by any statute written for the specific purpose.
This is a change. Eighteen months ago the expected battleground was training itself: whether using protected works to build a model was different enough in purpose from what those works were made to qualify for a fair use defence. The courts have now given a provisional answer, and it has mostly favoured developers. What the courts divided on was not the purpose, but the manner in which the copies were obtained in the first place.
The ownership side has moved in the same direction, for unrelated reasons. US law requires a human author for copyright protection and a human inventor for patent protection, and neither requirement has softened as AI tools have improved. So as more of the creative and inventive work is done by AI technology, more of what a business produces may fall outside the rights it can claim. What remains depends on identifying the human contribution and being able to show it.
For each question, what protects a business is a record of where material came from, of who did what, and of what was done to keep the rest confidential. This article describes how each half of that shift happened, what has already changed in practice, and how much weight to place on any factor while so much remains under appeal.
Provenance, Not Purpose
In June 2025 the same federal trial court in California decided two cases days apart. Both asked whether training a large language model on copyrighted books was fair use. Fair use is the American doctrine that permits some unlicensed uses of protected works, judged largely on whether the new use serves a different purpose from the original. In Bartz v Anthropic the court held that training on books the developer had purchased was a genuinely transformative use, and lawful. In Kadrey v Meta the court reached a similar view without a trial, on the evidence the parties had assembled, while warning that a different purpose does not by itself win the argument and noting the risk that machine outputs might crowd the market for the works behind them.
Had matters stopped there, developers would have had something close to a general answer. They did not. In Bartz the problem was not the training but the library. The court treated the downloading and retention of pirated copies as a separate act, serving no new purpose and not excused by a later transformative use. The same defendant therefore won and lost on the same facts, depending on which copies were in issue.
A third case marks the opposite boundary. In Thomson Reuters v Ross Intelligence, a federal trial court in Delaware refused the defence where protected material had been used to build a product competing directly with the source of that material. That decision is under appeal to the Third Circuit, one of the intermediate federal appeal courts, which heard argument on 11 June 2026, and practitioners are watching closely for the outcome of that appeal. Read together, the three cases suggest the defence holds where a developer is not building a substitute for the works it used, and did not take them unlawfully.
The effect is a shift of the focus to the facts and circumstances of each use case. Whether a use serves a new purpose is a question of characterisation, on which a developer can take advice and form a view. Whether a particular body of material was lawfully obtained is a question of historical fact, settled at the moment of acquisition and provable only from records kept at the time. A developer’s legal position now rests, to a considerable extent, on its purchasing history.
What a Price Tag Did to Behaviour
The acquisition point carries so much weight because of simple maths. An owner who registered a work in time can ask the court for a fixed sum for each work infringed instead of proving actual loss: up to USD30,000, and up to USD150,000 where the infringement was wilful. For a single book those figures are unremarkable. For a collection of several hundred thousand separately copyrighted works, they produce a number no defendant can responsibly take to trial.
That explains what happened next. The piracy finding in Bartz was followed by a settlement of approximately USD1.5 billion, and in July 2026 the Northern District of California judge ruled that the settlement met the legal standard of being “fair, reasonable, and adequate”. This historic settlement number has established a precedent. It told everyone else in the market what the acquisition question is worth.
The first effect has been on how claims are built. Claimants have moved away from arguing that training is inherently unlawful, which has not gone well for them, and towards where the copies came from. That is the cheaper case to run. It turns on purchase records and file histories rather than on competing expert evidence about what a model does internally.
The second effect has been on licensing. There is no compulsory licence for AI training in the United States, so every arrangement is individually negotiated. Content is increasingly licensed not to clear rights that a court might well have held needed no clearing, but to remove the acquisition question altogether. That changes what the parties bargain over: warranties about where the licensor’s own material came from now matter as much as the fee.
The third effect is in transactions. A model is an asset whose value depends partly on a history that may never have been written down, and that cannot be reconstructed afterwards. Buyers, investors and licensees increasingly examine that history alongside code and freedom to operate, and seek assurances about it and allocate resulting risks via representations, warranties, and indemnification clauses in the relevant transactions. A developer who cannot demonstrate through a well-documented record where its material came from is not only exposed to claims, but also has a product that is harder to sell.
No Duty to Document, and Why That Does Not Help
Intellectual property law in the United States does not expressly require a developer to keep records of its training material, of what it filtered out, or of how it handled requests for removal. There is no register, no deposit requirement and no disclosure regime. Reading the statute book alone, a developer would conclude that record-keeping is merely a matter of good housekeeping.
However, civil procedure in American litigation gives each side broad rights to demand documents from the other, and those rights may reach acquisition records, dataset manifests and internal development material. Once litigation is reasonably anticipated, a party must preserve that material, and courts penalise those who allow it to be destroyed, including engineers overwriting logs and checkpoints in the ordinary course of their work without considering the litigation impact of those actions. Audit rights in a licence may impose a contractual version of the same duty, and models offered in other jurisdictions may carry obligations of their own.
The same logic governs the basis for rights-holders to object. For example, instructions in a website’s robots file, terms of use, embedded ownership information and “do not train” markers may be at issue. None of these is expressly protected under US law. Their principal value lies in the fact that a documented objection that was ignored can help establish that infringement was wilful, which is what moves the needle on a per-work figure from the lower number to the higher number in the United States.
The asymmetry is the point. A developer with complete records can answer the question that now decides these cases. A developer without them cannot, and the absence of any duty to have kept them is not a defence.
The Human Pole
On the other hand, the ownership requirements have not changed. Copyright in the United States protects works with a human author, and that is a principle recognised long before the technology existed, in Burrow-Giles Lithographic Co v Sarony, and applied to AI in Thaler v Perlmutter, where a work said to have been produced autonomously by a machine was refused copyright protection. Similarly, for US patents, in Thaler v Vidal, the Federal Circuit, which is the appeals court for all US patent matters, held that an inventor must be a natural person, and the Supreme Court declined to reconsider the question.
These court holdings are stable precedents. They do not depend on agency guidance that can be rewritten, or on a single trial court decision that may be reversed on appeal. They rest on the constitutional and statutory foundations of both copyright and patents in the United States. For readers comparing jurisdictions, this is the sharpest divergence from the United Kingdom, which treats a computer-generated work as having an author; in the United States such a work has no copyright owner at all.
Within that framework, the US Copyright Office takes the view that prompts alone may not make a user the author of what comes back, however elaborate the prompt, because the model settles too much of the expression. A human can still be an author by contributing expression of their own, for example by arranging generated material creatively, by editing it, or by ensuring that their own input remains visible in the result. But protection extends only to those contributions, and not the work as a whole.
The consequences are procedural and decisive. Registration is normally required before the owner of a copyrighted work in the US can allege infringement of that work, and timely registering determines whether the per-work sums described above are available. The US Copyright Office requires applicants to identify and disclaim any more than trivial machine-generated content, and a registration secured on knowingly inaccurate information can be set aside. The right to enforce therefore depends on an accurate account of who did what.
Patent law asks a parallel question in a different language in the United States. For patents the determinative factor is conception – ie, the moment the inventor forms a definite and complete idea of the invention, as described in Burroughs Wellcome Co v Barr Laboratories, Inc. And the inventor must be human. Owning the model, running it, paying for the infrastructure or routinely checking its results may not be enough. Where a system proposes the experiments, chooses the parameters and produces the candidates with no human conception at any point, there may not be a human who qualifies as the inventor, rendering the invention ineligible for patent protection.
Ownership has therefore become a matter of contemporaneous evidence. What is needed is a record, made at the time by the people doing the work, of which choices were theirs: which selections, which edits, which ideas. Assembling that account later is harder, and defects may put the patent protection at risk.
Where the Value Actually Sits
The assets that make an AI business valuable are mostly not assets that registrable rights protect. A model’s trained weights are produced by a process rather than written by a person, so copyright is unlikely, and they are not patentable on their own, because a set of numbers is not the kind of thing the Patent Act covers (Digitech Image Technologies, LLC v Electronics for Imaging, Inc). Embeddings – ie, the numerical representations a model produces when it processes content – are subject to the same analysis and considerations.
Datasets fare little better. The United States has no standalone database right, a real difference from the European Union, where what counts is the investment behind compiling a database and checking the contents. By contrast, in the United States, the relevant question for copyright protection is whether the selection or arrangement is original, and any protection may be thin and may not reach the underlying data (Feist Publications, Inc v Rural Telephone Service Co). A collection can be large, expensive and commercially indispensable and still enjoy little to no copyright protection.
Businesses in the United States look to protections for confidential information based on trade secret protection as well as negotiated contractual provisions to fill the gap. Trade secret protection is available under federal law, in the Defend Trade Secrets Act, and under the laws of individual states in the United States. It requires no registration, lasts as long as confidentiality is maintained, and reaches material that copyright and patents may not. What it does not do is stop a competitor who develops the same thing independently, or who lawfully obtains access and rights to exploit otherwise protected material.
Trade secret protection is also conditional, and the condition is another evidential burden. The owner must have taken reasonable steps to keep the information secret. What counts as reasonable may be based on facts and circumstances, and information in an artificial intelligence context can leak in ways that older confidential information did not, such as through attacks designed to extract training material or system instructions from a deployed model, and through employees pasting sensitive material into third-party tools. A business may unexpectedly lose trade secret protection as a result.
The trade secret protection strategy then collides with patent protection strategies. A patent specification must explain the invention well enough for a person having ordinary skill in the art to carry it out, and must show that the inventor actually possessed what is claimed, a requirement reinforced in Amgen Inc v Sanofi. That is the well-recognised quid pro quo for US patent protection. Patent office decisions have rejected AI claims where the specification withheld the inner workings of the technology, and have allowed AI claims where the model type, its training inputs and outputs and the training method were more clearly set out. There is no obligation to disclose the training data itself, so describing its characteristics may be enough, but that may be inconsistent with a business strategy focused on trade secret protection in the United States.
That tension has sharpened, because clearing the patentability threshold has become somewhat easier while the disclosure requirement has not moved. The Federal Circuit has confirmed that applying standard machine learning techniques to a new field, without improving the technology itself, is not patentable subject matter (Recentive Analytics, Inc v Fox Corp). But the United States Patent and Trademark Office (USPTO) has directed its examiners not to treat AI claims as excluded as a class, and to ask instead whether a claim improves how the computer works.
The business decision is consequently one that businesses must make on an asset-by-asset basis, and deliberately so: what will be disclosed in order to obtain a patent, what will never be disclosed, and what controls make the second category defensible if it is ever tested. That decision should itself be recorded. The reasonable-steps question is answered years afterwards, on whatever documentation happens to have survived.
Technological Advances May Exacerbate the Challenges
Systems that plan their own tasks, choose their own tools and act without step-by-step human approval make both problems worse at once. US law does not treat an AI system as a legal actor, for copyright or patent purposes, and has no special rules for autonomy. Whatever the system does is attributed to the people who deployed it and who set its objectives, its tools and its permissions.
As it relates to IP ownership, autonomy thins out the human contribution that protection depends on. Where a system breaks a task into parts, writes its own intermediate instructions, plans its own steps and chooses among its own outputs before delivering a result, there may be very little human expression left to protect. The patent position is starker, leaving no human who qualifies as the inventor. The more capable and advanced the AI technology, the less of what it produces may be claimed to be owned by the business that purportedly created it.
On the input side, autonomy increases the number of acts that have to be tracked and explained from a record-keeping perspective. A system that browses, retrieves and calls other services may be copying at the moment of use and not only during training, and may in the process bind its operator to terms it never read, strip out ownership information, or defeat access restrictions in ways carrying separate liability under the Digital Millennium Copyright Act and the Computer Fraud and Abuse Act. None of this raises a novel legal question, but it puts in the spotlight issues that turn on knowledge and intent.
As a result, records of what the system called, retrieved and published are disclosable in litigation, and they may also be the key reliable evidence of where a human being made a decision. A business that logs the first will usually have captured the second, provided somebody decided in advance to keep the logs.
What to Watch in the United States, and How Much Weight to Give It
While there have been numerous recent developments in the area of IP law and artificial intelligence in the United States, it can be challenging to determine what is binding on businesses navigating this area. Commonly cited documents often are the ones that carry the least legal force in the United States. The following are some guidelines for differentiating among them:
Businesses cannot afford to wait for US law to catch up to AI technology. Against this backdrop and given the trends described above, businesses seeking IP protection for AI technology in the United States would be well advised to build a careful record now, including where material came from, of what the individual people contributed, and of what the automated parts of the system actually did and how they were prompted and controlled. Those records are the assets this law currently rewards, and unlike a legal opinion, they cannot be produced retroactively.
101 California St 35th floor,
San Francisco
CA 94111
United States
+1 415-772-1200
aremis@sidley.com sidley.com