Enterprises are unknowingly accumulating confidentiality, ownership, licensing, and contractual exposure in AI-assisted code, work product, and data faster than management can see it. Most of it is avoidable, and the practices that prevent it are available now.
There is little question that AI presents dramatic opportunities to increase efficiency, profitability, and enterprise strength for virtually every business. Organizational adoption reached 88 percent this year by Stanford’s count;[1] Microsoft reported 4.7 million paid GitHub Copilot subscribers in January, up roughly 75 percent in a year, with GitHub’s own research putting the tool’s share of code on enabled files at 46 percent;[2] and among 400 senior data and technology executives surveyed last fall, 74 percent reported an increase in the quantity of data engineering output over two years and 77 percent an improvement in its quality.[3] Boards have noticed: 91 percent of directors view AI as an opportunity to drive shareholder value.[4]
Meanwhile, countervailing risks are accruing in virtually every scenario where work product is being generated, managed, and, in many cases, functionally automated without complete transparency to organizational management and strategy. These are liabilities that have yet to be priced, and they come due somewhere specific: a customer indemnity demand, a regulator’s inquiry, an adversary’s document request, or the diligence checklist in a sale. Managed, they counterweight the gains; unmanaged, they can dwarf them.
I. The Risks Are Abundant
The promise that sold the investment in enterprise AI is the ability to cut through noise and find signal, and it was the core subject of the data engineering survey: organizations are handing AI a growing share of the work of turning raw information into answers, on a trajectory toward 61 percent of the working day.[5] The general value proposition is real, and it sits on top of a chain of failure points that management may not see: the answer may simply be wrong, because the fidelity of generated output has been measured, and it is sneakily imperfect; the person asking may not be asking the right question; the right answer to the right question may be put to the wrong use; and even a right answer put to the right use may go unmanaged, undocumented, unretained, unreviewed, and invisible to the people responsible for the consequences. Any one of these is survivable; stacked, they are how a business comes to rely on information it cannot vouch for, and often does not know it is relying on at all.
Part of the exposure sits in created content, deliverable work product, the code, documents, designs, and analysis that go out the door to customers. Part sits in internal content, data, and information that may never qualify as work product but that the business depends on, much of it now generated by or passed through AI systems. And part sits in the workflow itself, at the points where AI is shaping decisions and implementing processes that have never been fully disclosed to management. The pattern is familiar: an enterprising employee finds a clever way to do something with an AI tool and simply starts doing it. Nobody knows. It works well, right up until it creates a problem or the employee leaves, and either way the business discovers it has been relying on a process no one documented, approved, or can reproduce.
The tools are no longer assistants making obsequious suggestions for a person to accept or reject. Within the enterprise technology platform they follow instructions that may or may not be complete, and they fill in the blanks where expertise may be critically lacking. Both the capabilities and the methodologies underneath them are evolving daily, often through underlying changes that would generate a materially different work product from the same prompt, in the same model, on different days of the week. A process built on that foundation is not self-documenting, and it does not stand still while policy catches up.
Reliance, meanwhile, runs ahead of measurement. In METR’s randomized trial, sixteen experienced developers forecast a 24 percent speedup, self-assessed a 20 percent gain afterward, and were measured running 19 percent slower; when the group attempted to repeat the study this year it could not field a control group, because a third to a half of recruited developers refused to work without AI.[6] Developers given an assistant wrote less secure code than developers without one and were more confident it was secure,[7] and 75 percent of chief information officers report that implementation costs still outweigh the realized benefits.[8]
II. Code Development
Code development is where both the positive and dangerous dynamics have run furthest, and it deserves its own accounting, without being mistaken for the whole subject of this article. Material enters the enterprise technology platform from every direction: developers begin their coding tasks from a public repository or an AI assistant’s suggestion, agents install models, packages, and tool configurations without a person in the loop, and embedded AI features arrive inside ordinary commercial software through the standard update cycle, a pattern that has led Gartner to advise treating every application as an AI application.[9]
The effects are measurable across the organization’s technological, workflow, and data infrastructure, and the 2026 numbers all moved the wrong way. Black Duck’s audit of 947 commercial codebases found license conflicts in 68 percent of them, the largest single-year jump the study has recorded, which Black Duck attributes in part to assistants reproducing copyleft-derived code with its license information stripped away.[10] Veracode’s spring update, covering more than 150 models including the newest generation, found the security pass rate of generated code stuck near 55 percent while syntactic correctness climbed past 95 percent.[11] GitGuardian counted 28.65 million hardcoded secrets in public GitHub commits last year, with commits co-authored by AI tools leaking credentials at roughly twice the baseline rate.[12] GitClear’s repository data shows duplication at the highest level it has recorded, and a defect duplicated eight times is eight remediations.[13]
The models are creating new technological solutions for the companies that use them every day, and they create the way they were asked to: from instructions that may or may not be complete or well understood, filling gaps and covering expertise deficiencies in ways the user cannot always critically evaluate. Even a technical expert’s ability to comprehensively debug and verify what comes back is naturally limited by the breadth of the task. The research on software dependencies makes the point concretely: nearly one in five of the 2.23 million package references generated across 576,000 code samples in a study presented at USENIX last year pointed to a package that does not exist,[14] a 2026 replication found 127 hallucinated package names produced identically by five frontier models, dozens of which remained open for registration this spring,[15] and researchers have documented npm packages built to harvest credentials from AI coding tools.[16]
Behind the generated code sits a growing body of generated data and content with the same problem and less visibility: model weights and fine-tuned checkpoints, prompt libraries and system prompts, agent configurations, embeddings and the vector stores built from them, synthetic training data, evaluation sets. Each is a corporate asset with ownership, licensing, and provenance considerations; few carry a package identity, a version, or an owner of record; and all of them are missing from the software bill of materials, the component inventory that new European law requires of anyone selling software into the EU and that federal agencies may now require by contract.[17] Review practice has not kept pace: three quarters of organizations check AI-generated code for security, about half check its licensing, and fewer than a quarter review it comprehensively.[18]
III. Confidentiality and Sensitive Organizational Data
A fundamental of trade secret law is that the information for which protection is claimed must not only be secret; the secrecy must be proven by the reasonable measures taken to keep it so.[19] Feeding sensitive information into a publicly available model is the clear case, and it is common: in Verizon’s 2026 analysis of more than 850,000 data-loss events involving uploads to generative AI tools, source code was the leading category of data submitted to unauthorized platforms, and 67 percent of users who access AI services on corporate devices do so through noncorporate accounts.[20] The subtler case does the same damage. Information moved into an approved model but shared across users and systems outside the trade secret management strictures has been externalized from the very controls that prove the secret, and the ability to enforce it weakens accordingly. The same discipline protects patentable subject matter before filing, where an enabling disclosure that escapes confidentiality can start statutory clocks and defeat novelty,[21] so confidentiality is something the enterprise must be able to prove in either case. And the exposure reads on more than the company’s own work product; it reaches information received from others under obligations of secrecy or strict management and control, where mishandling is a breach whether or not a secret is lost.
Simultaneously, the enterprise has to manage what will be discoverable. In the consolidated copyright litigation against OpenAI, the court compelled production of a large, de-identified sample of user conversations over privacy objections,[22] and the holding generalizes: prompts, agent traces, and artifacts held in a vendor’s systems can be reached in litigation, including litigation the enterprise is not a party to. The standard practices of records management, privilege, and work product protection still apply; the methodologies have to catch up to the technology. Classification, retention, and legal-hold procedures need to reach AI inputs and outputs the way they reach contracts and email, privilege discipline needs to account for what is typed into a vendor’s system, and the ability to preserve, retrieve, or delete any of it is a function of contract terms negotiated long before a dispute. We take up the discovery, preservation, and privilege mechanics of AI-generated records in a sister article in this series.
IV. So, Does a Business Actually Own What Its People “Create” with AI?
The enterprise’s ownership position across its proprietary intangible assets is weaker than most executives would logically assume, and the weakness is not confined to copyright. Copyright requires human authorship, a proposition the D.C. Circuit affirmed and the Supreme Court declined to revisit in March, and the Copyright Office treats prompts alone as conveying unprotectable ideas.[23] Patent law runs parallel on inventorship: an AI system cannot be a named inventor, so protection attaches only to what humans actually conceived.[24] Purely machine-generated output, whether code, content, or data, is uncopyrightable and, absent contract or secrecy, effectively un-ownable. Protection attaches to human selection, arrangement, modification, and conception, so the more of the work the machine does, the smaller the surface the enterprise can protect, and the harder it leans on the trade secret measures and contract rights already described.
Obligations also arrive with what comes in the door, and not only through open source licenses. Reciprocal license terms oblige whoever distributes derived code to disclose source, permissive terms require attribution and notice, and generated output can trigger the first and routinely strips the second;[25] in the GitHub Copilot litigation, the dismissed copyright-management claims were argued to the Ninth Circuit in February and remain undecided, while the claims that remain live in the district court are for breach of those licenses.[26] But repositories, prompts, and agents can import contractual obligations of any kind that the user does not know about and does not know to disclose, including received confidential information the enterprise is now obligated to manage. Model licensing extends the point, because open weight is not open source: the Llama license carries attribution obligations, an incorporated acceptable use policy, and a 700-million-user threshold at the licensor’s discretion, and Gemma and OpenRAIL terms impose use restrictions that flow down into derivatives.[27]
Training data is its own problem, and usually someone else’s doing: management rarely trained the model it deploys, but it answers for what the model absorbed. The courts have begun to price the question, and the outcomes are moving quickly; we address the ownership and training-data issues in depth in a dedicated article in this series. One point deserves plain statement, because it is sometimes misunderstood: claiming no ownership in generated output is no defense to infringement. Liability turns on use, not on title, as a generation of file-sharing defendants who owned nothing learned.[28] The enterprise can own nothing in what the machine produced and still be fully liable for what it copied, which is why representations about training data, and records establishing where the company’s own artifacts came from, are presently the only instruments that reach these questions before a court does.
V. Representations, Warranties, and Disclosures
Enterprise providers warrant to their customers, acquirers, and underwriters that developed or delivered work product does not infringe third-party rights, and the same representations of ownership run through M&A agreements, securities disclosures, and every license or conveyance of IP rights. In each case the enterprise is saying it owns something, and it may not own it. Vendors indemnify for AI output on materially narrower terms, and the difference between the promises made and the coverage received is retained risk that is extremely difficult to quantify. The indemnities are enforceable and heavily conditioned: coverage across the major providers requires content filters and safety systems left enabled and rights in the customer’s inputs, excludes trademark claims, modified outputs, and every free and consumer tier, and in at least one widely used tool pairs an uncapped enterprise indemnity with consumer terms, updated this January, that disclaim warranties entirely.[29] Verizon’s 67 percent puts most observed use on the uncovered side of that line,[30] and a developer who disables a filter to reduce friction forfeits coverage for everything generated afterward.
The industry-acceptable standard of care against which those representations will be measured is still emerging, but many of the evolving reference points are already published and already in force, with more to come: NIST’s secure software development framework and its generative AI companion, ISO/IEC 42001, and the OWASP guidance for language-model applications,[31] backed by a 2021 executive order that survives in amended form, though in January the Office of Management and Budget replaced the government-wide secure-software attestation mandate with agency-by-agency, risk-based requirements.[32] A counterparty’s expert will not need to invent a benchmark, and adopting one costs less than distinguishing it in litigation.
Not every regime will reach every business, but where one does, it belongs in strategic management rather than in a compliance binder. The EU’s Cyber Resilience Act begins mandatory vulnerability and incident reporting on September 11, 2026, and applies in full in December 2027, with penalties reaching €15 million or 2.5 percent of worldwide turnover;[33] the amendment deferring the AI Act’s principal high-risk deadlines to 2027 and 2028 was published in the Official Journal on July 24 and entered into force on July 27;[34] and Gartner expects AI governance requirements in every sovereign AI law by 2027.[35] The emerging state statutory regimes, which may conflict with federal law and are creating rights and responsibilities of their own, deserve separate treatment, and we will take them up, along with privacy, employment, and product liability, in subsequent articles. Each of these regimes will ask for inventories that current tooling cannot produce for AI artifacts,[36] and for autonomous agents the doctrine beneath the disclosures is thinner still: under the Uniform Electronic Transactions Act, an organization can be bound by a contract its electronic agent forms even though no person reviewed the action or the resulting terms;[37] the decision everyone cites held an airline responsible for its chatbot’s misrepresentation and rejected the argument that the system was a separate legal actor, though it is a Canadian provincial tribunal ruling rather than a court decision, and we have located no reported decision, as of this writing, examining an agent that ships code without human review.
VI. What’s a Business to Do?
Policy. Start here, and accept that a generic, or even “industry standard” policy is not a silver bullet. The design of that policy, which tools on which tiers, for which data classes and employee groups, and what an agent may do without a person between it and production, is the subject of a separate article in this series. And the policy needs to be managed so that it is actually working, with no rogue or ignorant divergence running invisibly underneath it. The gap between paper and practice is measured:
- 69 percent of organizations suspect or have evidence that employees use prohibited public AI services, even as 64 percent run formal AI governance committees.[38]
- Among organizations breached last year, 63 percent had no operative AI governance policy or were still writing one.[39]
- A fifth of breaches involved unsanctioned shadow AI, at roughly $670,000 in added average cost.[40]
A policy the work outruns is not protection; in the hands of a regulator or plaintiff it can become evidence of notice.
Transparency. Actively manage the use of the systems that are generating work product, content, and data. The control is the ability to identify, internally, every point where the business relies on and interacts with AI technology to operate, which assistants on which tiers, which models under which licenses, which processes and artifacts are already in production, and to manage those points deliberately. Document retention belongs here. Classification, retention, and disposition schedules should reach prompts, outputs, logs, and weights the way they already reach contracts and email, because the same records serve three purposes at once: proof of reasonable secrecy measures, the answer to a regulator’s provenance question, and the corpus an adversary will demand in discovery. Retention cuts both ways: over-preservation compounds breach, privacy, and discovery exposure, so the design problem is a risk-tiered schedule with defensible disposition and a reliable legal-hold override.
Terms and Conditions. Bring the paper into line with the practice. Upstream, the tooling agreements should carry provenance representations about training data, indemnity scope recorded against its conditions and exclusions, no-training and retention commitments, express ownership of outputs, prompts, weights, and embeddings, and preservation and cooperation obligations for records the vendor holds. Downstream, customer warranties should be drafted against what the upstream indemnities actually cover, with any excess a priced decision rather than an accident of two templates, and the obligations should flow down to subprocessors and unprocured tools, where Verizon’s finding that third parties now figure in 48 percent of breaches supplies the reason.[41]
Governance. None of this is machinery for its own sake; it requires a management-level understanding of the technology deployed and how it is governed. The operating controls are concrete: composition scanning in the build pipeline, public-code filters locked at the tenant level so the indemnities survive along with the code, enterprise tenancy with training off and retention configured, existence checks on new dependencies, and a person between an agent and a merge. Above them a product category has matured; Gartner now rates AI governance platforms on thirteen capabilities and cautions that enterprise-workflow platforms and endpoint usage controls sell under the same label, so a purchase can satisfy auditors while controlling nothing at runtime, or the reverse.[42] The platform has to align with the organization, its regulators, its risk profile, and the people who will run it, or it becomes one more policy that cannot see.
Nuance. No single perspective holds a complete answer. That is not unique to AI, but it matters more now, given how pervasive the technology’s influence has become, matched with its transformative potential in virtually every part of a business that deploys it to gain efficiency, change workflow, and transform the data the business relies upon. Engineering knows what was built and how; legal knows what was promised and to whom; the business owns the tradeoff between velocity and retained risk; and any one of them operating alone produces a predictable failure: controls nobody follows, promises nobody checked, or growth nobody insured. The question stays the same in every forum, from regulator to customer to plaintiff to acquirer: show what was used, where it came from, who approved it, and what controls were running at the time. An organization that manages its reliance on AI answers from its records; one that does not will reconstruct its own history, at its adversary’s pace. The distinction is not caution versus ambition. A business that can answer that question is the business that can deploy the next tool without a second thought, price the risk it chooses to keep, and sign the representations its competitors will hesitate over. The discipline is the license to move quickly.
This article is provided by our AI Practice Group for general information and does not constitute legal advice. The authorities discussed are current as of July 27, 2026 in a rapidly developing area of law. Vendor terms, regulations, and case dispositions change frequently and should be verified against current sources before any decision. We welcome the opportunity to discuss how these issues apply to a specific deployment. For more information, contact Ted Theofrastous, Chair of KJK’s AI Strategy, Risk Management & Compliance practice, at tct@kjk.com.
[1]Stanford Inst. for Human-Centered Artificial Intelligence, Artificial Intelligence Index Report 2026 (Apr. 13, 2026) (88 percent of surveyed organizations report AI use in at least one business function).
[2]Microsoft Corp., FY26 Q2 Earnings Call (Jan. 28, 2026) (4.7 million paid GitHub Copilot subscribers, up approximately 75 percent year over year); Microsoft Corp., FY25 Q4 Earnings Call (July 2025) (GitHub Copilot surpassed 20 million all-time users; deployed at 90 percent of the Fortune 100). The 46 percent figure is GitHub’s own research metric for the average share of code written by Copilot on files where it is enabled.
[3]MIT Tech. Rev. Insights, Redefining Data Engineering in the Age of AI (Oct. 23, 2025) (survey of 400 senior data and technology executives conducted June 2025; produced in partnership with, and sponsored by, Snowflake) (74 percent report an increase in the quantity of data engineering output over two years and 77 percent an improvement in quality; 83 percent report deployment of AI-based data engineering tools; time on AI work rose from 19 percent of the workday in 2023 to 37 percent in 2025, projected at 61 percent within two years).
[4]Gartner, Driving AI ROI: How to Track, Manage, and Demonstrate the ROI of AI Investments, G00846542 (Mar. 3, 2026) (citing the 2026 Gartner Board of Directors Survey and the 2025 Gartner AI Survey, CIO and Technology Leader View).
[5]MIT Tech. Rev. Insights, supra note 3.
[6]Joel Becker et al., Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity, arXiv:2507.09089 (July 10, 2025) (randomized controlled trial; 16 experienced developers; 246 tasks; forecast speedup of 24 percent; post-hoc estimate of 20 percent; measured slowdown of 19 percent); METR, We Are Changing Our Developer Productivity Experiment Design (Feb. 24, 2026) (follow-up cohort could not support a reliable estimate because 30 to 50 percent of recruited developers declined to work without AI, compromising the control condition).
[7]Neil Perry et al., Do Users Write More Insecure Code with AI Assistants?, Proc. 2023 ACM SIGSAC Conf. on Computer & Commc’ns Sec. 2785; see also Hammond Pearce et al., Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions, 2022 IEEE Symp. on Sec. & Privacy 754 (approximately 40 percent of generated programs vulnerable).
[8]Gartner, supra note 4.
[9]Gartner, Shadow AI Demands Stricter Endpoint Application Control, G00847538 (May 25, 2026) (identifying employee, developer, and technology-provider shadow AI; reporting that 69 percent of organizations suspect or have evidence that employees use prohibited public AI services, citing the 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey (302 cybersecurity leaders)).
[10]Black Duck Software, 2026 Open Source Security and Risk Analysis Report (Feb. 25, 2026) (audit of 947 commercial codebases across 17 industries; license conflicts in 68 percent of codebases, up from 56 percent, the largest single-year increase in the study’s history; attributing the rise in part to AI coding assistants reproducing copyleft-derived code without its license information; 76 percent of organizations review AI-generated code for security but only 54 percent for licensing, and 24 percent comprehensively).
[11]Veracode, 2025 GenAI Code Security Report (July 2025) (more than 100 models across 80 tasks; a detectable OWASP Top 10 vulnerability in approximately 45 percent of cases); Veracode, Spring 2026 GenAI Code Security Update (2026) (more than 150 models, including the newest generation; security pass rates approximately 55 percent, essentially unchanged, while syntactic correctness exceeds 95 percent; the benchmark’s coding tasks include no explicit security guidance).
[12]GitGuardian, The State of Secrets Sprawl 2026 (Mar. 17, 2026) (28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34 percent increase and the largest recorded; secret leak rates in AI-assisted commits, measured as commits carrying an AI co-author attribution on public GitHub, roughly double the GitHub-wide baseline; exposed AI-service credentials up 81 percent; 24,008 unique secrets in Model Context Protocol configuration files).
[13]GitClear, AI Copilot Code Quality (2025) (analysis of more than 200 million changed lines; copy-pasted code exceeded refactored code for the first time in 2024); GitClear, The Maintainability Gap: 2026 AI Code Quality Research (2026) (block duplication at the highest level recorded, up 81 percent over 2023; copy-pasted code at 15.7 percent of changed lines in the first half of 2026).
[14]Joseph Spracklen et al., We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs, 34th USENIX Sec. Symp. (2025) (576,000 code samples across 16 models, containing 2.23 million package references, of which 440,445, 19.7 percent, were hallucinated; 43 percent of hallucinated names recurred across all ten identical re-runs). The term slopsquatting is credited to Seth Larson of the Python Software Foundation.
[15]Aleksandr Churilov, The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort, arXiv:2605.17062 (2026) (hallucination rates between 4.62 and 6.10 percent across 199,845 prompts on five frontier models released October 2025 through March 2026; 127 package names invented identically by all five models, 53 of which remained available for registration on PyPI and npm as of April 2026 following coordinated review with PyPI Security and Socket). The study is a preprint and identifies available targets rather than observed attacks.
[16]See Gartner, Cybersecurity Threat: AI Application Compromise, G00852901 (May 28, 2026) (citing Safety research documenting npm packages that target an AI coding tool’s provider credentials, and Vercel’s disclosure of an April 2026 incident in which customer data was compromised through an employee’s use of a compromised third-party AI application).
[17]Bill-of-materials conventions identify components by package name and version. Generated code, model weights, prompts, embeddings, and synthetic datasets have neither, and work toward an AI bill of materials has not yet produced a settled standard.
[18]Black Duck Software, supra note 10.
[19]18 U.S.C. §§ 1836, 1839(3)(A). No reported decision, as of this writing, addresses whether submission of source code to a consumer AI tool defeats the reasonable-measures requirement; the tool’s configuration, including training settings, retention, and tenancy, will supply the record on which that question is decided.
[20]Verizon, 2026 Data Breach Investigations Report (May 2026) (22,000 confirmed breaches, the study’s largest dataset; 858,440 data-loss-prevention events involving uploads to generative AI tools, with source code the leading data type submitted to unauthorized AI platforms; 67 percent of users accessing AI services on corporate devices do so through noncorporate accounts; 45 percent of employees are regular AI users, up from 15 percent the prior year; shadow AI the third most common nonmalicious insider data-loss action, a fourfold increase; third parties involved in 48 percent of breaches, up 60 percent).
[21]35 U.S.C. § 102(a)(1), (b)(1) (public disclosure is prior art, subject to a one-year grace period for the inventor’s own disclosures).
[22]In re OpenAI, Inc., Copyright Infringement Litig., No. 1:25-md-03143 (S.D.N.Y. Jan. 5, 2026) (Stein, J.) (affirming order of Wang, Mag. J., compelling production of a 20-million-record de-identified sample of user conversations over privacy objections).
[23]Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. 2025), cert. denied, No. 25-449 (U.S. Mar. 2, 2026); U.S. Copyright Office, Copyright and Artificial Intelligence, Part 2: Copyrightability (Jan. 29, 2025) (prompts function as instructions conveying unprotectable ideas; applicants must disclaim AI-generated material in registration).
[24]Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022) (an inventor under the Patent Act must be a natural person), cert. denied, No. 22-919 (U.S. Apr. 24, 2023). The USPTO reaffirmed in November 2025 guidance that only natural persons may be named inventors, even where AI plays a significant role in the inventive process.
[25]The reciprocal source-disclosure obligations of the GNU General Public License and Affero General Public License, and the notice and attribution obligations of the MIT, Apache 2.0, and BSD licenses, attach to derived code irrespective of how it entered the codebase. For machine-readable license and bill-of-materials conventions, see SPDX Specification v3.0 (Linux Found. 2024).
[26]Doe v. GitHub, Inc., Nos. 4:22-cv-06823-JST, 4:22-cv-07074-JST (N.D. Cal.) (claims under 17 U.S.C. § 1202(b) dismissed January 2024 for failure to plead distribution of identical copies; reconsideration denied April 2024; breach of open source license claims sustained); GitHub, Inc. v. Doe, No. 24-6136 (9th Cir.) (argued Feb. 11, 2026; decision pending as of this writing).
[27]Llama 3.1 Community License Agreement §§ 1(b), 2 (attribution notice; acceptable use policy incorporated by reference; licensees exceeding 700 million monthly active users must request a license that Meta may grant or withhold in its sole discretion); Gemma Terms of Use (Google) (prohibited use policy; flow-down obligations on redistributors); RAIL Initiative OpenRAIL licenses (behavioral restrictions must be reproduced in derivatives). The Open Source Initiative, whose Open Source AI Definition 1.0 issued October 28, 2024, maintains that the Llama license restricts fields of endeavor and is not an open source license.
[28]See A&M Records, Inc. v. Napster, Inc., 239 F.3d 1004 (9th Cir. 2001) (users who reproduced and distributed copyrighted recordings infringed without any claim of ownership in the copies). Liability under 17 U.S.C. § 501 turns on the unauthorized exercise of the exclusive rights, not on the infringer’s assertion of title.
[29]Microsoft Customer Copyright Commitment (eff. Oct. 1, 2023; Copilot Studio added June 1, 2025; conditioned on enabled content filters and safety systems and customer rights in inputs; excludes trademark claims and free and consumer offerings; effective April 3, 2026, GitHub Copilot coverage no longer requires the duplicate-detection filter); OpenAI Service Terms output indemnity (announced as Copyright Shield Nov. 6, 2023; ChatGPT Enterprise, Business, Edu, and the API; excludes free and Plus tiers, known infringement, disabled safety features, modified or combined output, and trademark use in commerce); Anthropic Commercial Terms of Service (defense of third-party IP claims arising from paid use; customer owns outputs; excludes modifications, combinations, and knowing infringement); Google Cloud Generative AI Indemnified Services (training data and unmodified generated output; void where citation or filtering features are disabled or for trademark claims; paid services only); AWS Service Terms, Amazon Q Developer Pro (paid-tier indemnity; reference tracker logs suggestions resembling public code with repository and license information); Anysphere (Cursor) Master Services Agreement § 8(a) (July 17, 2025) (output indemnity carved out of the liability cap); Anysphere Terms of Service (Jan. 13, 2026) (no reciprocal indemnity; all warranties, including non-infringement, disclaimed).
[30]Verizon, supra note 20.
[31]NIST, Secure Software Development Framework, SP 800-218 (Feb. 2022), and SP 800-218A (July 2024) (generative AI companion); ISO/IEC 42001:2023 (AI management systems); OWASP, Top 10 for Large Language Model Applications; NIST, AI Risk Management Framework, AI 100-1 (Jan. 2023), and Generative AI Profile, AI 600-1 (July 2024).
[32]Exec. Order No. 14,028, 86 Fed. Reg. 26,633 (May 12, 2021), as amended by Exec. Order No. 14,306 (June 6, 2025). The 2025 order struck the requirement to embed secure-development attestations in the federal acquisition regulations but left EO 14028 in place, and retained the directive that NIST update SP 800-218 (final update directed by March 31, 2026); NIST issued the initial public draft of SP 800-218r1, SSDF version 1.2, on December 17, 2025. OMB Memorandum M-26-05 (Jan. 23, 2026) subsequently rescinded the government-wide attestation memoranda, M-22-18 and M-23-16, in favor of agency-specific, risk-based requirements.
[33]Regulation (EU) 2024/2847 (Cyber Resilience Act) (published Nov. 20, 2024; in force Dec. 10, 2024; Article 14 reporting obligations apply from September 11, 2026; main obligations from December 11, 2027; penalties up to €15 million or 2.5 percent of worldwide annual turnover).
[34]Regulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) (July 8, 2026; published in the Official Journal July 24, 2026; in force July 27, 2026). The amendment defers Annex III high-risk obligations to December 2, 2027 and Annex I obligations to August 2, 2028, and grants systems on the market before August 2, 2026 a grace period to December 2, 2026 for the Article 50(2) machine-readable marking obligation; the Act’s remaining August 2, 2026 application dates stand.
[35]Gartner, Critical Capabilities for AI Governance Platforms, G00845612 (June 17, 2026).
[36]See supra note 17.
[37] Unif. Elec. Transactions Act § 14 (a contract may be formed by the interaction of electronic agents, or of an electronic agent and an individual, even if no individual was aware of or reviewed the agents’ actions or the resulting terms); adopted in nearly every state.
[38]Gartner, supra note 9 (69 percent); Gartner, Select the Right AI Governance Platform and AI Usage Control Tools, G00857666 (July 14, 2026) (64 percent of organizations operate formal AI governance committees that include both the CISO and the leader responsible for AI, citing the 2025 Gartner survey identified in note 9).
[39]IBM Sec., Cost of a Data Breach Report 2025 (600 breached organizations; 63 percent had no AI governance policy or were still developing one; 20 percent of breaches involved shadow AI, adding approximately $670,000 to average breach cost; 97 percent of organizations reporting an AI-related breach lacked proper AI access controls).
[40]IBM Sec., supra note 39.
[41]Verizon, supra note 20.
[42]Gartner, Critical Capabilities for AI Governance Platforms, supra note 35; Gartner, Select the Right AI Governance Platform and AI Usage Control Tools, supra note 38.
