🎮 The Next Input — Issue #197

Why Apple is Suing OpenAI for Stolen Secrets

In partnership with

Season 2 Nbc GIF by The Office

⚡ The Briefing — 60 sec

🛠️ The Playbook — AI Intellectual Property Firewall

Mission
Create a practical system for tracking what enters your AI workflows, what the models produce and who owns the resulting output.

Difficulty
Intermediate

Build time
3–5 hours

ROI
Reduces copyright and trade-secret exposure while protecting the proprietary systems, knowledge and content your organisation creates.

0) Why This Matters

AI has made creation extraordinarily cheap.

Ownership has not become any simpler.

Companies are now feeding models:

  • internal documents

  • client material

  • licensed databases

  • source code

  • creative assets

  • confidential processes

Then they are generating new outputs from that mixture and hoping everybody agrees on who owns the result.

Hope is not an IP strategy.

The practical answer is not banning AI. It is establishing provenance, approved-use rules, access controls and an evidence trail before something valuable—or legally radioactive—moves through the system.

1) Architecture

Component

Tool

Purpose

Owner

Failure mode

Asset register

Airtable / SharePoint Lists

Records ownership, licence and permitted use

Legal / Operations

Untracked source material

Controlled intake

Power Apps / Microsoft Forms

Captures files and intended AI use

Staff

Confidential data uploaded informally

Policy retrieval

Azure AI Search

Surfaces applicable IP and usage rules

Legal

Outdated policy guidance

Workflow orchestration

LangGraph

Applies checks before model execution

Engineering

Controls bypassed

Identity layer

Microsoft Entra ID

Restricts models, data and actions by role

IT

Excessive access

Audit trail

PostgreSQL / Microsoft Purview

Records inputs, outputs, approvals and lineage

Governance

Ownership cannot be demonstrated

2) Workflow

  1. Register high-value content, datasets, code and client material with ownership and licence details.

  2. Require staff to submit sensitive AI tasks through an approved intake workflow.

  3. Classify each input as public, licensed, confidential, personal or trade-secret material.

  4. Apply usage rules before sending any material to a model or external provider.

  5. Record the model, prompt, source assets, output and human modifications.

  6. Route uncertain or high-risk cases to legal or governance review before publication or commercial use.

3) Example Prompts

IP Intake Classification

You are an intellectual property intake analyst.

Review the proposed AI use case and classify each supplied asset as:

- publicly available
- internally owned
- client owned
- third-party licensed
- confidential
- personal information
- potential trade secret
- ownership unclear

For each asset, provide:
1. permitted AI use
2. restrictions
3. evidence required
4. approval owner
5. risk level

Do not make assumptions where ownership is unclear.

Output Provenance Review

Review the AI-generated output and its supplied source materials.

Identify:
- phrases or structures closely resembling source content
- third-party material that may require attribution or permission
- confidential information reproduced in the output
- ownership ambiguities
- evidence required before commercial publication

Return:
1. risk summary
2. flagged passages
3. recommended remediation
4. approval requirement
5. confidence level

Trade-Secret Exposure Check

You are reviewing an AI workflow for potential trade-secret exposure.

Assess:
- what proprietary information enters the workflow
- which external providers can access it
- applicable retention and training settings
- whether outputs could reveal internal methods
- employee and contractor access
- logging and deletion controls

Produce a remediation plan ranked by urgency.

4) Guardrails

  • Never treat internet availability as proof that content is free to use.

  • Keep client-owned and internally owned material clearly separated.

  • Do not place trade secrets into unapproved consumer AI products.

  • Record the source and licence status of consequential inputs.

  • Require human review before publishing legally sensitive outputs.

  • Preserve prompts, model versions and material output revisions.

  • Escalate unclear ownership instead of inventing certainty.

5) Pilot Rollout — 3 hours

  1. Select one AI-assisted content, software or research workflow.

  2. Catalogue the source materials it currently uses and identify their owners.

  3. Create a simple intake form with ownership, confidentiality and licence fields.

  4. Add automated risk classification and policy retrieval.

  5. Route high-risk submissions into a named approval queue.

  6. Test the system using one public, one licensed and one confidential asset.

6) Metrics

  • Percentage of AI inputs with recorded ownership

  • Percentage of outputs with complete provenance

  • Unapproved sensitive-data submissions

  • Average IP review turnaround time

  • Ownership exceptions detected before publication

  • Staff compliance with approved workflows

  • Number of third-party licence breaches

  • Audit-trail completeness

Pro Tip: The winning AI companies will not merely generate valuable IP—they will be able to prove where it came from and why they have the right to use it.

🎯 The Arsenal — Tools & Platforms

  • Microsoft Purview · classifies, governs and audits sensitive organisational data · Link

  • Microsoft Entra ID · controls which users and agents can access protected assets · Link

  • Azure AI Search · retrieves approved policies, licences and source records · Link

  • Airtable · provides a lightweight asset, licence and approval register · Link

  • LangGraph · inserts policy and approval checks into AI workflows · Link

Copy-paste prompt block:

You are an AI intellectual property and governance architect.

Design an IP control framework for my organisation’s AI workflows.

Context:
- AI tools currently used: [LIST]
- Proprietary assets: [LIST]
- Client-owned material: [LIST]
- Third-party licensed sources: [LIST]
- Main AI use cases: [LIST]
- Existing policies and approval owners: [LIST]

The framework must:
- classify ownership and usage rights
- protect confidential information and trade secrets
- record input and output provenance
- enforce role-based access
- route ambiguous cases for human approval
- preserve a defensible audit trail
- remain practical enough that staff will actually use it

Return:
1. asset classification model
2. architecture
3. intake workflow
4. approval matrix
5. audit requirements
6. incident-response process
7. rollout plan
8. operational metrics

đź’ˇ Free Office Hours

AI has made it remarkably easy to create something valuable and surprisingly difficult to explain exactly where it came from. A proper provenance and governance layer keeps innovation moving without treating every prompt like an eventual court exhibit.

You've seen the AI demos. Viktor does it without you watching.

The AI tool you tried last quarter waited for a prompt, hallucinated a number, then asked if you'd like a summary.

Viktor opened a PR at 2am, rebased it against main, ran your test suite, and posted a note in #eng: "Two flaky tests in payments service, both pre-existing. Recommended merging after fixing them." Then drafted the customer reply for the support ticket the bug created.

That's 619K autonomous actions per day across 20,000+ teams. Not chat replies. Real work shipped to GitHub, Stripe, Linear, Notion, and 3,000+ other tools, from inside Slack and Microsoft Teams.

You don't supervise him any more than you supervise a senior engineer.

SOC 2 certified. Your data never trains models.

"It's what you probably originally thought AI was going to be when you first heard of it in sci-fi movies." Tyler, CEO.

🕹️ Game Over

The machines may be generating the work.

The lawyers will still want the receipts.

— Aaron Automating the boring. Amplifying the brilliant.

Subscribe: link