Shadow AI and Intellectual Property: The Ownership Problem Your Business Doesn’t Know It Has
Most of the conversation about shadow AI risk focuses on data — what data employees are submitting to consumer AI tools, which data categories carry regulatory consequences if exposed, and how to implement controls that prevent sensitive business and client data from leaving the organization through ungoverned AI channels. These are real and significant risks, and the attention they receive is warranted. But they are not the only category of shadow AI risk that small businesses need to understand, and in some contexts they may not even be the most consequential one.
The intellectual property consequences of shadow AI use represent a distinct risk category that receives substantially less attention — and that may be more immediately material for small businesses whose primary commercial output is work product delivered to clients rather than goods manufactured or services rendered through physical processes. When a marketing agency’s writers use consumer AI tools to draft client deliverables, when a consulting firm’s analysts use AI to structure and populate client reports, when a software development firm’s developers use AI coding tools to generate client-owned code, or when a legal services provider uses AI to assist with client documentation — in each case, shadow AI use creates intellectual property complications that the business, its clients, and potentially its insurers need to understand but that most small businesses have not yet analyzed in the context of their AI governance programs.
Understanding shadow AI risk for small business in the intellectual property dimension requires engaging with questions that most small business owners have not previously needed to consider: What is the copyright status of work product that was substantially generated by AI? What representations are being made to clients about the ownership and originality of deliverables, and do those representations remain accurate when AI is involved? What happens to a business’s proprietary methodologies and trade secrets when they are processed through consumer AI tools that were trained on vast amounts of external content? The answers to these questions have direct implications for the legal relationships small businesses maintain with their clients, their employees, and their competitors — and they apply whether or not the business has any formal AI policy in place.
The Copyright Ownership Gap in AI-Generated Work Product
The foundational principle in U.S. copyright law is that copyright protection extends to original works of human authorship. The human authorship requirement has been tested repeatedly as AI-generated content has proliferated, and the U.S. Copyright Office has issued guidance establishing that content generated by AI without sufficient human creative control does not qualify for copyright protection. This is not a minor technical distinction — it means that work product substantially generated by AI may be in the public domain from the moment of its creation, regardless of how much the business invested in producing it, and regardless of what the contract with the client says about ownership of the deliverables.
What This Means for Client Deliverables and Service Agreements
Most professional services contracts include intellectual property provisions that assign ownership of deliverables to the client upon payment, warranting that the deliverables are original work product of the service provider and that the provider has the right to make the assignment. These provisions were written in a world where “original work product” meant work created by human professionals employed or engaged by the service provider. When a portion of that work product is substantially generated by AI — where the AI, not the human professional, is the author of the text, structure, or creative expression in the deliverable — the originality warranty may no longer be accurate in the way the contract assumes it to be.
A client that receives a deliverable under a contract warranting original human authorship, and later discovers that a substantial portion of the deliverable was AI-generated without disclosure, has a potential breach of warranty claim against the service provider. The business cannot assign copyright it does not hold, and it cannot warrant originality that the Copyright Office has determined does not exist for AI-generated content. The shadow AI use that seemed like a productivity enhancement at the time of delivery becomes a contractual liability that the client can assert — potentially well after the project was considered complete and payment was received — if the AI-generated nature of the work comes to light.
The practical governance implication is that any small business whose client contracts include IP representations about deliverables needs to know which AI tools are being used to generate those deliverables, under what terms, and to what degree human professionals are exercising the kind of creative control over AI outputs that copyright law requires for the human authorship threshold to be satisfied. Shadow AI use makes this analysis impossible — when AI use is ungoverned, there is no record of which deliverables involved AI, how extensively, or whether the human review and modification that occurred was sufficient to establish the human authorship copyright requires. Governing AI use in professional services contexts is not just about data protection. It is about maintaining the legal integrity of the IP representations that underlie the business’s client relationships.
Patent Inventorship and AI-Assisted Innovation
Patent law has its own human inventorship requirement parallel to copyright’s human authorship requirement. The Supreme Court has affirmed that only natural persons — humans — can be inventors for purposes of U.S. patent law, and the U.S. Patent and Trademark Office has issued guidance establishing that AI cannot be listed as an inventor on a patent application. The inventorship question becomes complicated for AI-assisted innovations: when a human engineer uses an AI tool to identify a technical approach they would not have identified independently, and then develops and implements that approach into a patentable invention, the degree to which the AI’s contribution affects the human inventorship analysis is an unsettled question with significant practical implications.
For small businesses in technology, engineering, or any field where patentable innovations are part of the business’s competitive value, shadow AI use in the innovation process creates patent validity risk. A patent application that fails to disclose the role of AI in the inventive process when that role may have been material could face invalidity challenges if the AI’s contribution is later discovered. A patent that is granted but later found to have misrepresented the inventive process — because the humans listed as inventors used AI in ways that may affect the inventorship analysis but the application did not reflect this — may be unenforceable against infringers who raise the inventorship issue as a defense.
Trade Secret Exposure Through Shadow AI Processing
Trade secrets — the proprietary methodologies, formulas, processes, customer lists, pricing models, and competitive intelligence that give a business its market advantage — derive their legal protection in significant part from the measures the business takes to keep them secret. The Defend Trade Secrets Act and state trade secret laws protect trade secrets only when the business has taken reasonable measures to maintain their secrecy. When employees use consumer AI tools to process proprietary business information — loading proprietary methodologies into an AI tool to get assistance applying them, submitting pricing models to an AI for analysis, or processing competitive intelligence through an AI tool — the information is transmitted to an external system under consumer terms of service that provide no trade secret protection and that may permit the provider to use submitted content to train future models.
The trade secret exposure risk from shadow AI processing is compounded by the aggregation problem. A single employee submitting a single piece of proprietary information to a consumer AI tool may not, on its own, constitute a disclosure sufficient to extinguish trade secret protection. But when multiple employees, across multiple interactions, over an extended period, are submitting different components of the business’s proprietary methodology to consumer AI tools — each interaction individually seeming minor — the cumulative disclosure of the proprietary information through ungoverned AI channels can be substantial. Shadow AI’s invisibility to the business makes this cumulative exposure impossible to assess without a discovery and remediation process specifically designed to identify what proprietary information has been submitted to external AI tools and under what terms.
The trade secret implication for client work is parallel to the copyright implication. When a consulting firm’s proprietary methodology is a trade secret that forms the basis of client engagements, and employees use consumer AI tools to apply that methodology in client work, the firm may be simultaneously eroding its trade secret protection in its own proprietary methods and creating a channel through which client confidential information is co-processed with the firm’s proprietary methodology in an external AI environment. Both categories of information are at risk through the same ungoverned AI interaction.
The U.S. Copyright Office’s AI and copyright resources document the Office’s evolving guidance on copyright protection for AI-generated content — including the human authorship requirements that determine whether AI-assisted work product qualifies for copyright protection and the registration guidance that addresses how AI’s role in creating a work must be disclosed in copyright applications, establishing the legal framework within which professional services businesses must evaluate the IP status of AI-assisted deliverables.
The NIST AI Risk Management Framework provides the organizational governance structure for identifying and managing the IP risks that shadow AI creates — including the MAP function’s risk identification processes for AI use in work product creation contexts and the GOVERN function’s accountability and policy frameworks that ensure AI use in client-facing and innovation workflows is tracked, documented, and consistent with the IP representations the business makes to its clients and partners.
The intellectual property dimension of shadow AI risk does not resolve itself through data security controls alone. Blocking employees from submitting client data to consumer AI tools addresses the data exposure risk. It does not address the copyright questions about work product already delivered, the patent questions about innovations already filed, or the trade secret questions about proprietary information already processed through consumer AI channels. A complete shadow AI governance program that accounts for IP risk requires understanding not just what data is at risk but what legal representations the business is making — and whether shadow AI use has created gaps between those representations and the legal reality that the business’s AI governance program has not yet closed.