top of page

Who Owns the Output? IP, Copyright, and AI in Government and Higher Education

  • 6 days ago
  • 4 min read

Two questions follow every AI output your organization produces: who owns it, and what rights did you transfer to the vendor to create it?


Most have answered neither. In our 2026 AI Governance Benchmark of five city governments and three universities, Intellectual Property (Domain 8 of the Securance 11) averaged 1.1 of a possible 9 points — and the higher education institutions in the group scored a flat zero.


Composite AI governance maturity across all 11 domains averaged 11.8 out of 100. This is not because leaders don't care about IP. It's because AI adoption has outpaced the contracts, policies, and legal review that normally surround it. And IP exposure is quiet. Nothing breaks. You simply discover, months or years later, that you don't hold the rights you assumed you held.


What you produce may not be protectable

The U.S. Copyright Office has been consistent: copyright protects only material that is the product of human creativity. Where the traditional elements of authorship come from a machine rather than a person, the Office will not register the work. Creative selection and arrangement, or substantial modification, can support a claim; a prompt alone cannot.


For federal agencies this is more familiar territory, since works of the U.S. government generally aren't subject to copyright anyway. For colleges, universities, and state and local governments, it matters a great deal. These institutions routinely hold and license copyrights: course materials and online curricula, training programs, GIS and data products, published research, software, and public-facing creative work. If a substantial portion of one of those assets was machine generated, the protection you assumed you had may be thinner than you think, or it may be absent entirely. A vendor clause assigning you the outputs does not change this. It settles ownership between you and the vendor; it does not create copyright where none exists.


There is also a filing obligation you may not be aware of. Registration applicants must disclose anything more than de minimis AI-generated content and exclude it from the claim; a registration obtained without that disclosure can be cancelled or disregarded in litigation. Staff who register works need to know this before the application goes in.


What you're giving away to get it

The rights claimed by the vendor may be buried in contract language, and they often depend on which tier you’re running. Enterprise and education agreements from the largest providers generally commit not to train on customer data. But that is something you buy and verify, not a default. Consumer and free tiers of the same products often do train, as does much of the long tail of smaller tools, whether bought on a department credit card or formally approved. In practice, that means public records, citizen communications, investigative material, student records, financial data, and sponsored research can flow into a third party's training pipeline through ordinary, sanctioned use.


Sponsored research adds another layer. The named prohibitions reach both sides of the desk: NIH bars generative AI in peer review outright and now limits how much of an application AI may write. But the binding constraint for most faculty is the award itself — CUI under a DoD award carries safeguarding requirements consumer tools do not meet, and sponsor data protection and IP provisions can rule out commercial AI unless an agreement is in place with both the vendor and the sponsor. A faculty member pasting pre-publication findings into a consumer tool usually isn't tripping a named AI rule. They are breaching award terms and handing a vendor a training license over unpublished work — a compliance problem and a technology-transfer problem in the same keystroke.


Note where this risk usually enters: not through a new procurement, but through software you already run. Microsoft, Google, and Adobe have built AI into products that sit on every desk, sometimes on by default and governed by terms updated by reference. The student information system, the ERP, and the service desk more often make AI tools opt-in features, but the decision arrives at renewal, where it’s easy to accept without review. Embedded AI deserves the same scrutiny as a standalone purchase.


Two adjacent exposures

Employee and faculty work. These are two different problems. Staff output is straightforward, and the answer belongs in writing: work produced with approved tools, on the job, is the organization's. Faculty output is not — though it is not uniformly the faculty member's either. Most university IP policies leave scholarly work with the author while claiming courseware developed with substantial institutional resources. That is the line AI-assisted work will test first. The move is not to claim more ground. It is to state how the existing policy applies when the work is AI assisted, and to say which side of that line AI-built course content falls on.


Public records. Prompts and outputs may themselves be disclosable records — and they may live only in a vendor's logs, outside your retention systems. Records requests for AI conversation logs have already been filed and fulfilled at state and municipal agencies. Whether you can respond depends on decisions made when the contract was signed.


What to lock down

  1. Review vendor agreements for IP and training data clauses, prioritizing vendors that process sensitive or regulated data.

  2. Negotiate amendments with your highest-risk vendors to prohibit training on your data and to state output ownership explicitly.

  3. Issue written IP guidance for staff and faculty covering ownership, approved tools, and disclosure obligations.

  4. Engage sponsored research and technology transfer offices on AI use in grant-funded work before a dispute forces the conversation.

  5. Map where prompts and outputs are retained and confirm you can produce them.


None of this requires slowing adoption. It requires knowing what you own — and what you have already given away.


Intellectual Property is Domain 8 of the Securance 11, the AI governance standard for government and higher education. If you want to know where you stand, the Securance 11 Index scores all 11 domains in six minutes. If you want the standard, download the playbook.


And if you want the plan, download the 90-Day AI Governance Roadmap for local government or higher education — IP falls in Week 12, once ownership, policy, and vendor terms are in place.

 
 
 

1 Comment


nonagratti88
a day ago

The article powerfully highlights the alarming gap between rapid AI adoption and the necessary policies, especially regarding IP ownership for human vs. machine-generated content. The point about embedded AI in existing software, often accepted without review, is particularly insightful; many likely use these powerful features as casually as accessing unblocked games 66, unaware they're potentially ceding rights or breaching terms. How can institutions effectively audit and control these "invisible" AI integrations across their entire tech stack?

Like
bottom of page