Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Two IP questions, one breath: does my company own the AI outputs your platform generates for us — and can you warrant that your AI stack isn't built on someone else's stolen training data that ends up in my board pack?
The question a General Counsel / Chief Legal Officer (CLO) asks.
The short answer
You own your outputs by assignment, nobody trains on your data, and on training-data provenance we tell the truth: no one can warrant a frontier model's corpus — so you get the upstream copyright indemnities passed through, plus an architecture where outputs synthesize YOUR data against licensed sources, not open-ended generation.
The full executive answer
Ownership first, because it's clean: your inputs remain yours, and the analyses, reports, and board packs generated for your organisation are assigned to you under our terms — we claim no ownership interest in your outputs, and no right to use your content beyond providing the service. The tenant-isolation architecture enforces the same principle technically: your outputs live in your organisation's partition, and — worth stating explicitly — we do not train models on your data, nor do our AI providers under their commercial API terms, so nothing derived from your board's thinking leaks into anyone else's results, including other tenants'. One precision a good GC will appreciate: pure AI-generated text has contested copyright status in most jurisdictions (US Copyright Office guidance requires human authorship), so the contractual assignment plus trade-secret protection — your packs are confidential business information held in an access-controlled, audit-logged system — together do the work that copyright alone might not.
Training-data provenance is the harder question, and precision matters about what we can and cannot warrant. We build on foundation models from Anthropic and OpenAI via commercial APIs; the training-data provenance of those models is theirs, litigation about it is ongoing industry-wide, and no honest downstream vendor can warrant a clean chain of title for a frontier model's training corpus — anyone who offers you that warranty is either lying or hasn't read their own upstream terms. What we CAN do: flow down the providers' commercial protections — both offer copyright indemnification for API customers on covered outputs — and add our own architectural mitigation, which is real: our outputs are grounded analyses of YOUR data against licensed frameworks, with our numeric-provenance system forcing figures to trace to identified sources and framework citations validated against a catalogue of properly licensed content. The product's design minimises the "model regurgitates someone's copyrighted text into your board pack" vector because outputs are structured syntheses of your inputs, not open-ended generation.
Contractually, then: you get output assignment, confidentiality, our warranty that we've licensed the frameworks and content sources WE bring to the analysis, and pass-through of the upstream indemnities — and we'll be transparent about their boundaries rather than papering over them. The EU AI Act's general-purpose-AI transparency provisions are also forcing upstream training-data disclosure in our favour over time, which is a tailwind for every deployer's diligence including yours.
Grounded in: US Copyright Office AI authorship guidance (2023); EU AI Act Art. 53 (GPAI training-data transparency); trade-secret doctrine (confidential information); upstream API copyright indemnities (Anthropic/OpenAI commercial terms).
The natural next questions
Related governed answers
- If a regulator or opposing counsel demands the complete history of a decision made on your platform two years from now, what can you actually produce — and can anyone have edited it?
- Enumerate every third party that touches my data. Vendors always forget two — don't be that vendor.?
- You're hosting my European board's data in Japan. Walk me through your Article 44 transfer basis — and don't tell me "the cloud is global.?
Want this answered live, on your data?