In short
Executive Summary
- GenAI creates three IP risks: your data going in (confidential information in prompts), what comes out (copyright status of AI outputs), and what it was trained on (infringement from training data)
- Australian copyright law doesn't clearly cover AI-generated works. If your AI writes it, you may not own it, and you may not be able to protect it from competitors
- The Agentic Browser Governance Framework applies here: AI agents scraping, summarising, and repurposing web content create copyright exposure at machine speed
- Vendor indemnification for IP claims sounds reassuring until you read the caps and exclusions. Most don't cover the real exposure.
Detail
Overview
GenAI copyright risk runs in three directions, and most organisations are only thinking about one of them.
Risk one: what goes in. Every prompt you send to a GenAI tool is data you're sharing with a vendor. If employees paste client contracts, financial data, strategy documents, or customer information into ChatGPT or similar tools, that's confidential information leaving your organisation. Some vendor terms grant them a licence to use your inputs for model training. That means your trade secrets could end up improving a model that your competitor also uses.
Risk two: what comes out. Australian copyright law requires a human author. AI-generated content sits in a legal grey zone. If your AI drafts a report, generates marketing copy, or writes code, the copyright status is uncertain. You may not be able to register it. You may not be able to enforce it against a competitor who copies it. Your IP strategy needs to account for this gap.
Risk three: what the AI was trained on. Large language models are trained on vast datasets that include copyrighted works. When AI output substantially reproduces copyrighted material (and it can, particularly with code and specific text passages), your organisation faces infringement risk. The lawsuits against AI vendors are well documented. But if you're the one publishing the infringing output, you're in the liability chain too.
The Agentic Browser Governance Framework extends this analysis. AI agents that browse the web, scrape content, summarise articles, and compile intelligence are doing at machine speed what a human researcher does slowly. But the copyright implications scale with speed. An AI agent that processes 10,000 web pages in an hour creates 10,000 potential copyright touchpoints. Without governance (what sources are permitted, what can be extracted, what attribution is required), you're generating IP exposure faster than your legal team can assess it.
Vendor indemnification is the false comfort. Most GenAI vendors offer IP indemnification, but read the terms. Caps are often low relative to real exposure. Exclusions carve out common use cases. And indemnification doesn't prevent business disruption from litigation. You need your own risk assessment, not just a vendor promise.
Commercial impact
Why It Matters for Organisations
The commercial implications are significant. If AI-generated content isn't copyrightable, your competitors can freely use anything your AI produces once it's public. That changes the economics of content creation, product development, and competitive intelligence.
IP litigation against AI vendors is accelerating. The outcomes will set precedent for years. In the meantime, organisations using GenAI commercially are operating in legal uncertainty. That doesn't mean you shouldn't use GenAI. It means you need policies, controls, and risk acceptance decisions documented at board level.
The confidentiality risk is the most immediate and the most underappreciated. 53.4% of C-suite executives hide their AI use. That means your senior leaders may be putting sensitive information into GenAI tools without disclosure, governance, or controls. If a CEO pastes a board paper into ChatGPT for "help with wording," that's potentially confidential information shared with a third party. Your GenAI policy needs to cover this explicitly.
For organisations deploying AI agents that browse and extract web content, the Agentic Browser Governance Framework addresses copyright directly. Permitted source lists define where agents can go. Data classification rules define what can be extracted. Attribution requirements ensure your intelligence outputs don't present scraped content as original work. Audit logging creates a record of what was accessed and when.
Australian copyright law is evolving on these questions, but it hasn't caught up with the technology. That gap creates risk. Organisations that document their GenAI use policies, implement appropriate controls, and make informed risk acceptance decisions will be in a stronger position regardless of how the law develops.
Podcast
Listen to how Australian executives are applying AI
Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
In practice
Examples or Practical Context
A professional services firm discovered their consultants were pasting client strategy documents into ChatGPT to generate presentation drafts. The vendor's terms included a licence to use inputs for model improvement. That meant client confidential information was potentially incorporated into a model used by thousands of organisations, including the client's competitors. The firm implemented a GenAI policy within 48 hours: no client data in external AI tools, enterprise AI deployment with data protection, and mandatory training for all staff.
A marketing agency used GenAI to create campaign imagery for a major client. A photographer identified substantial similarity between the AI output and their copyrighted work. The agency's GenAI vendor offered indemnification, but the cap was $100K against a $500K claim. The agency settled from their own funds. They now run all GenAI visual outputs through a similarity check before client delivery.
An AI agent deployed for competitive intelligence (using the Agentic Browser Governance Framework) was configured with source allowlists, extraction limits, and attribution requirements. When a competitor complained that intelligence reports contained verbatim passages from their paywalled content, the audit log showed the agent had only accessed permitted public sources. The attribution trail proved the content was independently sourced. Without that framework, the complaint would have been much harder to defend.
A software company using GenAI for code generation discovered that AI-generated code included verbatim open-source code with GPL licensing obligations. Using GPL code in proprietary software creates an obligation to release your own code as open source. Their code review process caught it before release. They now run licence compliance checks on all AI-generated code.
What to do
Key Takeaways
- Implement a GenAI use policy immediately: no confidential information in external AI tools, no exceptions, enforce it
- Apply the Agentic Browser Governance Framework to any AI agents scraping or summarising web content: source allowlists, extraction limits, attribution, audit logging
- Review vendor IP indemnification critically: check caps, exclusions, and whether coverage matches your actual risk exposure
- Assess the copyright status of AI-generated content in your IP strategy and plan for the possibility that AI outputs aren't protectable
- Run licence and similarity checks on AI-generated code and creative content before commercial use or publication
Newsletter
Get the Executive Brief each week
Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Assessment
Run the AI Readiness Assessment
Check whether policy, accountability, and compliance are keeping pace with deployment. The assessment scores governance and decision control alongside four other dimensions.
The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.
Read next
Behind this page
Related from the archive
Where this sits
Explore This Pillar
Next step