AI Copyright 101

5 minute read
summary

AI adoption has outpaced governance, creating problems with proprietary content, copyright ownership, and learner trust. Organizations can address this with internal working standards that define approved tools and clear data policies, implement a mandatory “Human-in-the-Loop” review for content, and create a standardized AI disclosure statement for all courses.

It is a regular day at the office. A member of your team is building a compliance course on a tight deadline. They open the AI tool they’ve been using for months, paste in a section of your organization’s internal policy manual to give the tool some context, and generate a solid first draft in about four minutes. The course is shipped. Leadership is pleased. The learner experience is genuinely better than what you had before.

And somewhere in that process, your internal policy documentation may have just entered a public AI training dataset. No alarm went off. Nobody noticed. The team member did nothing wrong by the norms of how most organizations currently operate. And that’s becoming an emerging problem: AI adoption in L&D has moved faster than the governance structures around it. 

Most teams are somewhere on the spectrum between “we’re experimenting cautiously” and “AI is embedded in how we work”, but very few have clear, written answers to questions like: which tools are approved, how can we interact with them, who owns what we produce, and what do we tell our learners? 

According to research from Cullen International, copyright and AI rules are not settled globally, with only three jurisdictions clearly permitting AI training on copyrighted material, while five prohibit or don’t recognize it under current law. 

But while the global debate continues, organizations can’t afford to wait when a variety of tools are at their employees’ fingertips. A necessary first step is to start defining where your proprietary content (IP) can go, which begins with establishing a working framework.

The data problem: where your IP goes

When it comes to data, the key variable isn’t which AI tool your team is using, but rather which version of that tool they’re using.

The free and browser-based versions of most AI platforms operate under different terms than their enterprise counterparts. Inputs to consumer-grade tools can be used to improve the underlying model. That means proprietary content: a training script, a competency framework, a client’s onboarding materials, potentially becomes training data for the next version of the tool. The chance of exposure scales with how frequently your team uses AI.

The operational fix is straightforward: establish governance that limits AI usage to approved enterprise tools or API-based access. Some providers’ API, for example, have an explicit commitment that data is not used for model training and is deleted from their servers within 30 days. Other major providers have similar enterprise agreements, but the terms vary, because “enterprise” doesn’t actually mean “protected.” You need to ask, and you need the answer in writing.

For organizations in regulated industries, such as healthcare, government, or financial services, even enterprise-grade consumer tools may not be sufficient. Closed-loop, private AI environments are the appropriate standard when the data is sensitive enough that any third-party exposure is unacceptable.

WE SUGGEST

Audit every AI tool your L&D team currently uses. For each one, ask the vendor four questions: Where is our data stored? Is it used to train your models? Who has access to it? What anonymization options are available? If a vendor can’t answer those questions directly, that’s your answer. And be sure to get these in writing.

The ownership problem: who actually holds the rights?

Here’s something most L&D teams haven’t fully internalized: if AI generates a course script, a quiz, or a set of learning objectives, and a human doesn’t meaningfully contribute to the final output, your organization may not own the copyright.

The U.S. Copyright Office has been explicit on this point: copyright protection requires human authorship. The more a piece of content is generated wholesale by AI and published without substantial human editing, the weaker the copyright claim. However, legal guidance in many jurisdictions, including Canada, treats AI copyright as an unresolved grey area, particularly around ownership of AI-generated outputs. Organizations should not assume AI output is copyright-free or automatically owned by the person who prompted it.

There’s a second, less-discussed risk here: output infringement. Even when you’re using a legitimate, licensed AI tool, the model can produce content that’s too similar to existing works, because it was trained on them. This shows up most visibly in image generation but applies to text as well. Teams are increasingly being advised to check AI-generated content for similarity to existing materials before publication, particularly for anything that will be widely distributed.

Both risks have the same solution: genuine human involvement in the work. This doesn’t mean a final proofread 5 minutes before the submission deadline. It requires real editing, restructuring, creative contribution, so that the final output could not have been achieved without the work of the human designers. When an Instructional Designer (ID) actively shapes AI-generated content, applies their professional judgment, and leaves their mark on the output, they become the author.

Authorship is not the only thing at stake when AI drafts your content. The hidden risks of AI writing in eLearning covers the quality and credibility problems that come with it.

WE SUGGEST

Build a mandatory Human-in-the-Loop review phase into your content development process. Make it concrete, not just “someone review this, please,” but make it to evidence active editing, restructuring, or a creative contribution before any AI-assisted content is released. Keep records of that contribution.

The trust problem: what you owe your learners ​

Learners are increasingly good at identifying AI-generated content, the particular cadence of the sentences, the way structure is applied uniformly across every paragraph, and something about the tone and style that says “AI” and feels slightly off. When a learner recognizes AI-generated content and realizes it wasn’t disclosed, the reaction isn’t usually “I’m sure they had a reason to make this decision,”– instead, they experience a loss of trust in the program, and by extension, in the organization behind it.

Transparent disclosure is the straightforward path through this. A clear statement at the start of a module,  something like “Our instructional designers created this course with AI-assisted technology, with rigorous attention to the learning experience, to ensure it meets our high quality standards,” sets accurate expectations and signals that your organization has nothing to hide. It also communicates your stance on AI usage: that AI was a tool in service of producing better learning, not a replacement for the expertise that shaped it.

Many institutions are now moving towards formal citation and attribution practices for AI-generated content, keeping records of both what the AI produced and what the human changed. And this practice goes beyond just good ethics, but it’s becoming an operational standard.

WE SUGGEST

Create a standardized disclosure statement for any eLearning module that made substantial use of AI-generated tools. Build it into your development template or workflow, so it is automatically included (if required) with every course. This avoids your team having to remember to add this on a project-by-project basis.

Where to start

The organizations getting this right aren’t waiting for their legal team to issue a definitive policy, because that policy isn’t coming, not until the law catches up, and the law is years behind. What they’re doing instead is building internal working standards based on what’s known right now.

You don’t need a 40-page governance document. You need three things: a list of approved tools with documented data policies, a Human-in-the-Loop requirement and how to make it happen, and a disclosure standard to be used with every course you create when using AI.

Deciding which parts of the work a person must own, and which can safely be delegated, is the harder half of this. Our Human-AI Delegation Framework for L&D gives you a way to make that call consistently.

Start with the audit. Pull together the tools your team is currently using and spend an hour reading their data policies (and yes, you can use your friendly neighborhood LLM to help you better understand the policies). You’ll know within that hour whether you have a problem worth solving quickly, or whether your current setup is more dangerous than you thought. Either outcome is useful; the key point is to start.

If your team needs to get fluent in this quickly, our AI Accelerator Certificate for L&D covers governance, tooling and hands-on practice in one cohort program.

Sign up for our LinkedIn newsletter to receive updates on new eBooks, exclusive content, and the latest trends in learning and development.

Recent Blog Posts

Rather inconveniently, custom eLearning doesn’t have a rate card. Real projects range from about $4,000 for a focused microlearning piece...

By Garima Gupta, Founder & CEO, CTDPThere is a point in many branching scenario projects where things start to get...

By Aamir Aman, Senior Instructional DesignerThe multiple-choice question has been the comfort food of the L&D industry for decades. Predictable,...