If you’re building or deploying AI, the smartest move is layering trade secrets, selective patents, clear copyright documentation, and tight contracts around your AI assets. Not one of those alone. All of them, working together. The first thing to do, starting this week, is build an AI asset and data provenance inventory, then gate access to anything high value. Everything else in this guide builds from that one step.


TL;DR:

  • Prioritize inventorying all AI assets and training data, focusing on high-revenue use cases and assessing their business value and exposure risks.
  • Document human contributions thoroughly for AI inventions to establish inventorship and protect innovations with patents or trade secrets accordingly.
  • Protect model weights and training data as trade secrets through encryption, strict access controls, and continuous logging to prevent insider exfiltration.
  • Use specific contractual clauses with vendors and cloud providers to define data provenance, restrict data use, and secure audit rights for compliance verification.
  • Follow NIST’s governance frameworks by maintaining operational hygiene, managing version control, and assigning ownership to enhance security and IP protection.

tekRESCUE
Build A Safer AI Roadmap
tekRESCUE helps organizations identify AI opportunities, understand deployment risks, and plan secure adoption around their unique needs.
Explore secure AI guidance

Table of Contents

Your initial executive checklist over the coming weeks

Before you touch contracts or filings, you need to know what you actually have. Most companies often overlook this step and face consequences later.

  • Inventory every AI asset and training dataset, then rank each one by business value and exposure risk.
  • Apply technical gating to model weights and sensitive datasets early, before policies are finalized.
  • Rewrite NDAs, work-for-hire clauses, and contractor agreements so they explicitly cover AI outputs and training data.
  • Decide for each asset whether a patent or a trade secret fits better based on value and acceptable disclosure level.
  • Add vendor audit rights and model-use restrictions to every cloud and AI vendor agreement before renewal.

Pro Tip: Start the inventory with your three highest-revenue AI use cases. You’ll learn more from those than from trying to catalog everything at once.

Patents and inventorship for AI-assisted inventions

The USPTO’s revised inventorship guidance is clear on one point: only a natural person can be named as an inventor. AI tools can assist, but a human has to make a significant inventive contribution for the invention to qualify for a patent at all.

That means documentation matters more than ever. Keep lab notebooks, code commit histories, decision logs, and signed inventor declarations that show exactly where a person directed, modified, or solved a problem the AI couldn’t solve on its own. Without that paper trail, you may struggle to prove inventorship if the patent is ever challenged.

Not every AI innovation deserves a patent. Filing publishes your method, which helps competitors as much as it protects you. For architectures or training techniques you want to guard quietly, trade secret protection usually fits better. Reserve patents for inventions where public disclosure gives you a market advantage that outweighs the disclosure risk.

Decision path between patent and trade secret

The Copyright Office’s Part 2 report on copyrightability sets the baseline: copyright protects original expression only when a human author makes a sufficient creative contribution. Purely autonomous AI output, with no meaningful human shaping, doesn’t qualify.

That changes how you should document creative work. Keep prompt logs, but don’t stop there. The Office has indicated that documenting prompts alone may not be enough if there’s no human creative selection or modification behind the final piece. Track how your team edits, arranges, and refines AI-assisted drafts, images, or code. That editing history is often what separates a protectable work from one that isn’t.

When you file a registration, disclose the AI assistance honestly. Describe the human contribution clearly: what was selected, arranged, or rewritten by a person. Leaving AI involvement out entirely risks the registration later; describing your human input accurately protects it.

Trade secrets, insider risk, and protecting the model itself

For most companies, the model weights, fine-tuning datasets, training pipelines, and reward models are the real crown jewels. They’re rarely patentable in a practical sense and often not copyrightable either, which makes trade secret law your main legal tool here. But trade secret protection only holds up if you can show you took reasonable steps to keep things secret, which is where technical controls come in.

  • Encrypt model weights and store them separately from training data, never in the same environment.
  • Enforce least privilege access so only the people who need a given asset can reach it.
  • Require multi-party authorization for any export or deployment of core model artifacts.
  • Log access continuously and run data loss prevention tools tuned to catch model exfiltration attempts.

The legal side has to match the technical side. Use targeted NDAs for anyone touching sensitive model assets, tie access to defined roles, and build a real offboarding process that revokes access the day someone leaves. A federal conviction announced by the Department of Justice for theft of confidential AI technology is a reminder that insider exfiltration isn’t a theoretical risk. It’s prosecuted.

Pro Tip: Treat your model weights like source code for your most valuable product, because that’s effectively what they are.

Contracts, licensing, and vendor or cloud partnership clauses

Your legal exposure often lives inside vendor agreements nobody reads closely. The FTC’s 6(b) study on generative AI partnerships found that large cloud providers partnering with AI developers can end up with access to sensitive technical and business information, which raises real competitive and IP exposure risks. That’s exactly why your contract language has to be specific, not boilerplate.

  1. Define data provenance requirements so you always know where training data originated.
  2. State explicitly what the vendor is and isn’t permitted to do with your data for training purposes.
  3. Prohibit the vendor from using your proprietary data to train its own general-purpose models.
  4. Secure audit and verification rights so you can confirm compliance, not just take their word for it.
  5. Clarify IP assignment and license carve-outs for anything built jointly or on top of your data.

Open-source components deserve the same scrutiny. Check the license terms before you build on them, and confirm whether the license requires disclosure of modifications or restricts commercial use.

Governance and secure development: applying NIST guidance

NIST’s Generative AI Risk Management Profile lays out the governance backbone most companies are missing. It recommends inventorying your AI systems, documenting data provenance, keeping model weights separate from training data, tracking versions, and running robustness checks regularly. None of this is abstract. It’s operational hygiene that happens to double as IP protection, because an attacker who can’t find your weights can’t steal them.

NIST controls for protecting AI intellectual property

The SSDF community profile for generative AI builds on that by adding model-specific secure development practices: secure storage for weights, least-privilege access baked into the development pipeline itself, and versioning controls that catch unauthorized changes.

Turning this into practice means assigning real ownership. Someone specific needs to own the AI asset inventory. Someone specific needs to sign off on access requests. And you need monitorable artifacts, logs, access records, version histories, that prove the controls are actually running, not just written down in a policy document somewhere.

Implementation roadmap: from inventory to enforcement

Here’s how the pieces fit together over a realistic 90 day window. Start with the asset inventory and risk tiering in the first two to three weeks. Update contracts and NDAs in parallel. Then move into technical hardening (encryption, access controls, logging) over weeks four through eight, followed by monitoring, incident response planning, and staff training through week twelve.

Track progress with simple KPIs: percentage of AI assets inventoried, number of vendor contracts updated, and time to revoke access after an offboarding event.

Balancing innovation and protection

Good IP protection doesn’t slow innovation down. It’s what lets you move faster with less fear, because you know what you’re protecting and why. The risk isn’t locking things down too much. It’s not knowing what you have at all.

— Randy Bryan

How tekRESCUE AI helps you put this into practice

tekRESCUE

Most companies know they should protect their AI assets but aren’t sure where to start or what’s actually at risk. The AI Profit and Growth Assessment gives you a clear picture: which AI assets you have, where the data came from, and which ones need protection first. From there, STS: Strategy, Training, Systems and Managed AI Security carry the work forward so protection doesn’t stop at a report. If you want a straightforward next step, start with the AI Profit and Growth Assessment and see what your own inventory turns up.

FAQ

How do you protect your IP from AI?

Combine trade secret protections for model weights and training pipelines with selective patents for disclosable inventions, clear copyright documentation of human contributions, and vendor contracts that restrict how your data gets used. Start with an asset inventory so you know what actually needs protecting, then apply technical controls like encryption and access gating described in NIST’s AI risk management framework.

What is the 30% rule for AI?

Copyright, patent, or trade secret law regarding AI. Definitions circulating online vary and aren’t tied to guidance from the Copyright Office, USPTO, or NIST, so treat any specific percentage threshold you encounter with caution.

How is AI impacting intellectual property?

AI is straining traditional IP categories: the Copyright Office has clarified that purely autonomous AI output lacks copyright protection, while the USPTO has confirmed AI-assisted inventions remain patentable only when a human contributes significantly. Trade secrets have become more important as companies lean on model weights and training data that don’t fit neatly into patent or copyright law.

What are three key concerns for IP protection with AI?

The three recurring concerns are human authorship for copyright claims, inventorship for AI-assisted patents, and insider or vendor exposure of trade secrets like model weights and training data. The FTC’s 6(b) report adds a fourth layer: cloud partnerships that give providers access to sensitive technical information.

Sources