
Sheppard's The Legit Ledger · 2023-09-05 · 34 min
Key moments - from our scoring
Substance score
43 / 100
Five dimensions, 20 points each
This episode addresses the legal minefield surrounding generative AI adoption, distinguishing between user-side risks and developer responsibilities. Jim Gatto explains that machine-generated content lacks copyright protection under U.S. law (confirmed by recent court rulings), while training data sourced from copyrighted material has spawned litigation against tool providers. Users face dual exposure: their own infringing output liability and potential indemnification obligations to tool companies - though vendors like Adobe mitigate this by licensing their training data. Code generators introduce open source compliance obligations that could trigger GPL requirements or attribution mandates. The episode contrasts the EU's comprehensive AI Act, which categorizes applications by risk level (banning unacceptable uses like social scoring, flagging high-risk hiring tools), with America's patchwork approach: voluntary frameworks (NIST AI Risk Management Framework, White House AI Bill of Rights), FTC enforcement actions, and emerging state laws like New York's employment AI restrictions. For M&A and diligence, companies must scrutinize how generative AI was used in target companies, as standard IP questionnaires fail to capture nuanced issues like false copyright registrations on AI-generated works or hidden open source dependencies in model outputs.
Machine-generated content receives no copyright protection under U.S. law; only human-authored portions or embellishments added by users are copyrightable. The Copyright Office and recent court rulings confirm that AI-created expressive content alone cannot be registered or protected.
Liability can fall on either the tool provider, the user, or both. The tool provider may be liable if trained on copyrighted material without license; the user may be liable for copying, publishing, or distributing infringing output. Indemnity clauses in terms of service determine who ultimately bears responsibility.
Many generative AI tools' terms of service grant the tool operator a license to use input data for model improvement. Some tools now present opt-in/opt-out popups for training data use. Without explicit confidentiality terms or opting out, you risk losing control of sensitive business information.
Yes. Open source code in generator output triggers compliance obligations (attribution, disclosure of modifications) and may require your software to be licensed under GPL or similar reciprocal licenses, depending on which open source license applies to the generated code.
The EU AI Act categorizes AI applications by risk level - banning unacceptable uses (like social scoring), regulating high-risk applications (like hiring tools), and leaving others unregulated. The U.S. uses a fragmented patchwork of voluntary frameworks (NIST, White House AI Bill of Rights), FTC enforcement, and state laws rather than comprehensive federal legislation.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers real legal risk categories (copyright non-protectability of AI output, algorithmic disgorgement, API vs. website input distinctions) but moves slowly, with extensive throat-clearing and high-level framing. A few actionable nuggets exist but are buried in repetitive recaps and obvious advice like 'read the terms of service.'
if you run into the remedy that the FCC imposed of what's called algorithmic disgorgement, where you have to delete your models and algorithms, if they were trained on data, you didn't have a right to use, that wipes out the value of those tools
if you're using the API, they'll treat your information as confidential and they won't use it to train models. If you do it through the website, they're going to use it
The content is a standard law-firm-style legal overview of AI risks - copyright, confidentiality, EU AI Act, open source compliance - all widely circulated topics with no contrarian framing, first-principles argument, or unexpected angle. The algorithmic disgorgement point is the only moderately underexplored concept.
there's many lawyers who are talking about what the legal issues are, we're going to cover not just the issues, but some of the ways that companies can manage these issues
a lot of lawyers who are kind of new to the field and are getting up to speed don't feel like they have a good handle on the issues. And so they do what a lot of lawyers do, and they say, don't use it
Jim Gatto is a legitimate practitioner - senior partner, 20+ years AI legal work, adjunct professor - with real client-facing experience on the specific issues discussed. However, this is a law firm's own marketing podcast with an internal guest, and he speaks as an advisor rather than as an operator who has built or scaled AI-driven businesses.
I've been working on AI for over 20 years
He is co-leader of the firm's artificial intelligence team and is leader of the open source team
A handful of concrete, named examples elevate the episode above pure abstraction: the EverAlbum FTC algorithmic disgorgement case, Getty Images' watermark-in-output exhibit, Adobe's indemnity position, and the OpenAI API vs. website terms distinction. However, many claims remain vague ('tens and hundreds of millions of dollars') and the legal landscape overview is mostly illustrative rather than data-driven.
a company called EverAlbum that had a photo app where you could upload pictures... they ended up over time using those images to train a model to create facial recognition technology... the remedy was they had to delete all of the models and algorithms
Getty Images has filed where one of the exhibits is the fact that they're alleging that the AI model was trained on Getty images that were watermarked images... they have output that shows the watermark on it
The host, a junior associate, asks mostly setup and summary questions with no meaningful pushback, probing, or follow-up on contested points. Questions like summarizing 'big umbrellas' or asking Jim to confirm his own framing dominate; the format is closer to a structured monologue than a real conversation.
So is it safe to say big umbrellas to worry about here are copyright, confidentiality, licenses, and I believe the last one was, and I think indemnity was the fourth one
Right. And that ends to be the story of the US regulatory landscape
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the Legit Ledger, Jim Gatto, a partner in Sheppard Mullin's Washington D.C. office and co-chair of its AI team, joins host Sarah Ben-Moussa to discuss what companies should know as they embrace generative AI, including key legal issues, the European Union's Artificial Intelligence Act, and unique due diligence concerns when acquiring or investing in companies that develop or use generative AI. What We Discussed in This Episode: What is generative AI, and why has it become so newsworthy? What are the key legal issues raised by AI? Who is liable if the output
Transcribed and scored by The B2B Podcast Index.
Welcome to the Legit Ledger, a podcast by Shepard Mullen's blockchain team about blockchain related legal issues and practical tips for keeping things legit. In each episode, we cover legal and regulatory issues relating to blockchain technologies and business models. Our podcast features thought leaders and industry professionals who have hands on experience with this evolving legal landscape. Let's get legit.
Hello, everyone, and welcome to another edition of the Legit Ledger podcast. Today, we're going to be covering legal issues with AI, and in particular, generative AI. As many of you are undoubtedly aware, generative AI has really captured the world's attention, one of the fastest growing technologies, and it raises a number of legal issues. And while many lawyers are talking about what the legal issues are, we're going to cover not just the issues, but some of the ways that companies can manage these issues so they can leverage the benefits of generative AI without incurring unnecessary legal risk.
So before we get into the show, I also want to announce that for those of you who haven't heard, we actually have formalized an AI team at our firm. We have many, many attorneys throughout the firm that have been working on AI for a number of years. I've been working on AI for over 20 years, And we have a wealth of experience. So we decided to formalize the team due to the client demand that's out there and the ability to better serve as clients across all industries and in all different legal areas.
So with that, let's get into the episode. My name is Sarah Ben-Moose. I'm an associate with the firm's New York Office. Joining me today is Jim Gatto.
Jim Gatto is a partner in the firm's Washington, D.C. office. He is co-leader of the firm's artificial intelligence team and is leader of the open source team.
He focuses on all aspects of IP and tech regulatory issues. He has over 20 years of experience advising clients on AI issues and is an adjunct professor who teaches a course on artificial intelligence legal issues. Jim, welcome to the show. Thank you, Sarah.
It's great to be back on The French Insider. Great. So today's topic is on artificial intelligence. So Jim, I know this has been a hot button issue in the news.
So just to kind of go into it and orient our listeners, what is generative AI and why has it become so news-oriented? Sure. So there's a lot going on. So artificial intelligence itself has been around and talked about for since the 50s, so many, many decades.
And there's many tools that use different types of AI that are more what's referred to as deterministic. So things that might do a prediction or do sorting or classification or kind of more things where you're using AI in a way to leverage the power of computers to produce some specific result you're looking for. Generative AI is a type artificial intelligence that use some similar underlying technology, but its purpose is to create new content. So that content can be text, images, it can be software code, books, movies, etc.
Anything you want to create that's expressive content, Generative AI is your tool. And the reason it's really taken off lately is that with the introduction last year of ChatGPT, was really the first real high level deployment of a generative AI tool. And it was the fastest growing technology. It was like the fastest technology to get to 100 million users, and it really hasn't slowed down.
It really just literally took the world by storm, and it is incredibly transformative. And so people are using it in their personal lives and throughout business as well. And so it's become kind of a ubiquitous tool that everyone is talking about using and sharing horror stories and benefits about. Right.
Because I think sort of before the onset of chat GPT, I think for us non in the know folks, AI was like sort of a movie. I think that's as far as we've really gotten with the sort of, it was a bit of a sci-fi concept to us, but now it's real and it's here and it's concrete. And so I think what people are wondering, especially on our side of things is what are the key legal issues we're looking at here? Sure.
Well, there's many, so I'll try to keep it at a high level. So we kind of break it down into two kind of worlds, if you will, right? So there's people, companies that are developing generative AI tools that are training the models, creating the algorithms and providing the applications for users. I'll keep that to the side for a second, focus primarily on like how people are using it and what legal issues arise.
So if you are using generative AI, the first thing to understand is you typically will put some kind of a prompt in, which is just an input where you're asking it to create something for you. In many cases, if what you provide contains any confidential information, you may be putting that confidential information at risk. All these tools work in different ways and their terms of service are structured differently. But some of the tools, if you put the information in, you actually grant the license to the tool operator to use that information.
So you don't want to be putting confidential information in unless you know for sure that it's going to be treated as confidential. Second thing is, and this is a real big issue, because we're dealing with expressive content, many people create content and as part of their business model, they license it or want to have exclusive use to it. So if someone uses it without permission, they want to be able to have copyright protection and sue to stop. One of the big challenges with generative AI is that the output, the machine-created elements that are the expressive content are not copyright protectable.
The U.S. Copyright Office has taken this position. There was a case that was just handed down this past Friday.
District Court confirmed in the Copyright Office that only human-authored works can be protectable. So there's very limited, if any, copyright protection available. and typically it's going to be for any embellishments that you do, any creative content you add. You'll get protection for that, what you add, but typically not the underlying part that was created by the generative AI tool.
Also, because we're dealing with content, the models are trained on copyright protected information. And there's a bunch of lawsuits pending right now against some of the tool providers saying that they trained their models using copyrighted material without permission. And the tool providers are saying that it's not copyright infringement or it's a fair use, at least in the US, that that's a defense to copyright infringement. Those cases are pending and they're working their way through.
But again, from the user perspective, if the output of what you get from the generative AI includes someone else's copyrighted material, there's at least a significant risk that you may be liable for infringement. In some cases, the general AI tool providers will provide indemnity to you if there's infringement. But actually, in some cases, if you use an output that's infringing, you indemnify the tool company. So that's a double whammy.
You have risk of infringement and you have to indemnify the tool company. Companies like Adobe have actually stated that they've trained their model on content that they know they have licenses to. And so they're granting indemnity to users. So some people are using their tool in part because it's a good tool, but also in part because it minimizes that infringement risk.
And if there is infringement, the indemnity will typically kick in. One other big area that I want to just talk about, and then I'll kind of pause. I know I'm kind of throwing a lot at you here. Another type of generative AI is what's referred to as an AI code generator.
And the code in that case refers to source code, so software development. So developers are using these AI code generators to assist them in writing computer code. And what happens is literally you have the AI generator working side by side with your development environment And as you typing in some cases it will auto a line of code for you based on using its predictive analytic ability. In some cases, it can check code to see if there's any errors in the code.
And in other cases, you can ask it to write code that performs some function. So there's various types of output that can come out. Most of those code generators are trained on open source code, known existing open source code. And there's a plus and a minus to that.
The good news is pretty much all the open source is licensed and you can use it for really any purpose. So it's not so much of an infringement issue if any open source code gets into the output, but open source licenses typically have what's referred to as compliance obligations. So in some cases, you can freely use the code, but there's certain conditions to that use. Like you might to maintain copyright information.
You might have to give attribution to the copyright owner. You might have to disclose if you've made changes, things like that. And in other situations, if the code is under certain licenses like the GPL, if you use that code in your software, then your software has to be licensed under the GPL. So for any or all of those reasons, It's important to know if you're using a code generator, whether the output includes any open source code, because it may be problematic from a legal perspective under the GPL scenario, or may impose compliance obligations on you.
It's a pretty complex area, working with a lot of developers on these developing policies to kind of manage these risks. And some of the tools have started adding features that can help manage these risks as well. And we can go into that later if you want, or if people want more information down the road, we can talk about that, but it gets pretty nuanced. Let me kind of pause there.
That's a lot of legal issues. So is it safe to say big umbrellas to worry about here are copyright, confidentiality, licenses, and I believe the last one was, and I think indemnity was the fourth one, because that is something I did not think about, the fact that you may in fact be liable if you violate a license. Most people, lawyers not withstanding, are not reading the terms and conditions of most of the software or most of the tools they're using. So I think when it comes to real practical risk, I think especially with this, is it safe to say that you kind of really have to parse through the buckets between what it you're putting in and what it is the AI is generating for you and being able to make that link and sort of trace back that help.
Yes, definitely important to focus both on your input and the outputs. And it really is, to go back to what you said, across the board, people don't really read terms of service, but in this context, it's really important. And that's part of, we can talk about later how companies can manage risk, but part of what they do is develop policies on using generative AI. And one aspect of the policy is to vet the different tools, look at the terms of service, assess what the legal risks are.
And some companies are approving or disapproving certain tools in part based on the terms of service. So the end user doesn't have to read the terms of service, but the company will and will adopt the policy. But one very important caveat, some of these tools now are, they'll have a terms of service, but they'll pop up an option that you can, they'll ask you, do you want to permit the tool to use your input to train the model to make it better? And a lot of people just click yes just to move on.
And so by doing that, you may have granted a license to the tool. Even if the terms of service say one thing, some of these tools now are popping up these little user input boxes, and it can alter the terms with user consent. So both of the reading the terms and being careful about what you accept as you're using the program are very important. Oh, yeah.
I'm thinking specifically for companies that may have really important confidential data, as you mentioned. Again, it's that pop-up. Most of us just kind of click yes to make it go away. I've been guilty of that.
But I think one thing I want to focus in on, because we focused on some of the issues, is liability. And I think we talked a bit about indemnity, but who is liable for the output infringing? That's a good question. It's somewhat fact-specific, but the short answer is it could be either or both of the tool provider or the user.
So if the tool provider, for example, is training on copyrighted material, and they don't have a right to do it, and they output that, arguably, they've made a copy of the work that they trained on without license, and that's copyright infringement. If the user makes additional copies or publishes it or does something else that's an enumerated right under the copyright statute, then they may be liable for infringement as well. So with respect to the IP owner, either or both could be liable.
But as we mentioned earlier, depending on the indemnity as between one or the other, one of them may be actually responsible for the actions of the other because of the indemnity. Okay. And then, you know, I think we've been talking a lot about the American landscape and our audience is pretty, in terms of jurisdiction and geography, we have a lot of investors in the US, but we also have a lot of companies that are based in Europe. And so I think I wanted to take a second and talk about the passage of the AI Act by the European Parliament last June and its attempts to address some of the riskier uses of AI.
So could you kind of give us maybe like a broad overview of the EU AI Act and how it compares to maybe the American landscape? Sure. Yeah, great question. So the AIA, as it's referred to, is working its way through the European system.
And if it's passed, it really would be the first, what I would say, comprehensive law on artificial intelligence. And the approach they take is interesting. What they're doing at the high level that you asked about is that the law is looking at different applications of AI and assigning a different risk category to each of them. And they have three buckets.
So one bucket is applications that use AI that create what is deemed to be an unacceptable risk. And so one example of this that's provided is a reference to the government-run social scoring system like is used in China. So that type of AI use under the AI would be banned as an unacceptable risk. Then there's the second bucket is applications that use AI that are high risk.
So the parameters around this are a little bit subjective, but tools, for example, an example that's given is that use AI to scan someone's CV or resume or job application and rank applicants based on that is deemed to be high risk. And one of the reasons for that is, In some cases, AI is just not accurate. In other cases, it's trained on information and data that is actually shown to have bias in it. And so for things like that, those types of uses, it's deemed to be high risk because it could create an inequity or bias type situation.
And then the third category is kind of like everything else. It's things that are not in one of the first two categories. So it's not either banned or deemed high risk. So those are at a high level or unregulated, the third category.
So the US is kind of, as usual, is a much more fractured system. We don't have like a single AIA that's being put through. What we have is a couple of different things, some of which are voluntary and others are kind of a regulatory patchwork. So one of the prominent things that's been done at the federal level is a passage of what's called the AI Bill of Rights.
And it's really more a... It's referred to often as a blueprint for an AI Bill of Rights. But it has a set of principles that were put forth by the US Office of Science and Technology, and it was updated in 2022 and kind of backed by the White House. But they look at things like the safety and efficacy of the tool, the equity and and non-discriminatory issues.
They focus on privacy and data protection as we in part as we talked about earlier transparency and awareness So transparency is like visibility on what the tool is trained on how it works And then other factors like human oversight, making sure that you don't just have these machines running without people testing them and making sure that they're working properly and accurately and not providing bad results or harmful results in some cases. So it's more like a set of guidelines.
It's not really law. So you have things like NIST, the National Institute of Standards and Technology, which has developed also a AI risk management framework. And so it probably put a little bit of meat on the bones of the AIA and say, okay, well, here's how you can take these broad principles and actually try to apply them and come up with safe use of AI. And then you also have the FTC, which has issued, they are responsible for consumer protection and various other activities.
And they've issued guidance and taken some enforcement actions on some one-off basis against companies that have engaged in things that either were privacy violations related to AI or misuse of information for other purposes, like financial decisions or things like that. So one more level down, you have states. And a number of the states now, like New York was one of the first states to pass a law that's actually come into effect now on severe limitations and conditions on using AI in connection with employment decisions, which is also part of what's in the European Act.
So that part is similar, but it's being implemented at the state level. At a high level, there's just like this very different approach of how the US is a little more scattershot in how it's dealing with this, whereas the AIA would try to be more of a focused, comprehensive regulation if it's enacted and then brought into effect in the different member states. Right. And that ends to be the story of the US regulatory landscape.
So I'm sure we're going to be following this for months and years to come. So I think we have a good sense here of some of the legal considerations as a company who's maybe thinking about using or developing AI. But what about the sort of inverse of that? Is it legal for companies to use your work to train their own AI models?
That's a question that's debated right now. And as I mentioned earlier, there's a number of lawsuits that are testing that very question. There are a number of suits against companies that have created books or images or code and allegedly was trained using copyrighted material without permission. And so those cases are kind of working their way through.
there really hasn't been any kind of a substantive decision in any of those cases yet. So we'll see what happens with that. But some of the tools say that in very limited instances where there actually be an output that's part, that's a copy of something that was trained on, the way they're supposed to work is the training process is really like when we look at a series of pictures, we don't memorize each picture. We memorize things about the picture.
And so we learn information about images. And over time, you see more and more images. And if someone says, hey, create a picture of this, you have a lot of images or information about images in your mind, and you create something new based on what you've learned in the past, for example. And that's how they're supposed to work at a very high level.
It's questionable whether they're all working that way. There's a lawsuit right now that Getty Images has filed where one of the exhibits is the fact that they're alleging that the AI model was trained on Getty images that were watermarked images. So it had a Getty logo on it. And they have output that shows the watermark on it.
So Getty is saying, it's not like there's going to be a watermark if you didn't actually copy the image, right? So there are situations like that where there's been some examples. But in some of these cases, it's hard to know what the model was trained on. So artists are saying, you must be using my information, and it's going to lead to people getting to use my work for free.
But in some of the cases, the plaintiffs haven't actually provided enough specificity to show the court that there actually was use of their content in the training and that it made it into the output. So in some of those cases, there's been some procedural motions to dismiss. And in some cases, the courts have said, yeah, there may not be enough in the complaint right now, but we'll agree that there's not enough, but you can go back and amend the complaint. If you can provide greater specificity, we'll let you take another bite at the apple.
So they're kind of working through the procedural phases right now. That'll be an interesting one, Paula, because I feel like with the Getty one, it's a bit obvious the watermark shows up on the image. But I'm really interested to see whether it's comedians or authors or other people who generate content. How do you prove that something was done in the style of your work and whether or you have rights to that.
Right. Well, and that's another whole issue. One of the lawsuits filed by some of the artists are saying that some of these tools are trained specifically on their work. And you can say, give me a picture of a monkey holding a red umbrella in the style of Sarah's art.
And it will, if you have a style, it'll create an image with those elements that you specify with your style. And so, you know, one of the questions is, you know, is style actually protectable. Because style is... And this is a question under copyright law, it's not necessarily specific to AI, but it's coming up in this context.
But one of the questions is that with copyright, you can protect the expression of ideas, but not the idea. So if the way you're defining the style is an idea for how to present something or an idea for a type of art, it's probably not protectable. But if it's rather, if the style is really embodies specific expression or types of expression, then it's more likely to be copyright protectable because that's what copyright covers as expression. So some of it may be fact-specific, but that's kind of a very high-level framing of the issue.
Gotcha. And so are there unique issues to consider connection with diligence when we're looking at acquisitions or investments in companies that are developing or using generative AI? Absolutely. And that's one of the areas we've been pretty busy in.
So for most deals, there's like a standard list of like IP diligence questions, and those are all still relevant. The problem is some of them are not specific enough to capture some of these nuanced issues that we talked about. And the other problem is that in some cases, the target company doesn't understand the law well enough to answer the question properly. So as a simple example, if you say, identify all the works for which you have copyright protection, and can you rep that that you actually own these and they're valid.
If they outputted stuff from generative AI, they may think, yeah, we created it, we own it, we filed a copyright registration, and so everything's all hunky-dory. But the reality is it's not protectable. And so you have to dig into the way in which generative AI has been used and whether any of the output is significant work that is for which copyright protection was sought, or is an important work or the value of the deal. So that's one area.
All the software stuff we talked about earlier, in general, you'll do an open source diligence if you're buying a company that has software, because almost every company has software that uses open source now. So again, there's standard open source questions, but some of these questions around the output of generative AI and compliance obligations and whether you've kind of vetted whether the code you're using has this open source, Sometimes that needs to be a little bit more specific.
And then there's various other questions. But one of the other areas that's important is that a lot of companies, if they use third-party developers or contractors to create content for them, a lot of times when you get into diligence, like, yeah, this was created, we have an agreement that says we own it, but the same problems can arise. The contractor may not have general AI policies, they may not be managing, they may not know the issues, and they may say, yeah, you own the copyright, when in fact, it's not copyright protectable.
So you need to kind of do additional diligence with respect to the third-party contractors as well. Those are some of the topics. There's various others that can arise. I mean, if a company is training AI models and that's part of you're buying a company and they gotten to the training side one of the most important things to understand is that I mentioned earlier the FTC has done some enforcement In one of the cases there a company called EverAlbum that had a photo app where you could upload pictures It was like an album You can organize stuff and do different things you can typically do with photo apps.
They ended up over time using those images to train a model to create facial recognition technology. They didn't disclose it to users and they didn't have permission to do it. Long story short, the FTC found out, did an enforcement action, and the remedy was they had to delete all of the models and algorithms that they built. And the reason that's important is right now, a lot of companies are investing in AI and AI-based companies.
And if these companies don't have permission to use the data that they're using and they create these models, some companies are spending tens and hundreds of millions of dollars to train these models. And if you run into the remedy that the FCC imposed of what's called algorithmic disgorgement, where you have to delete your models and algorithms, if they were trained on data, you didn't have a right to use, that wipes out the value of those tools, and it can significantly impair your investment.
So that's like one really, really important issue that needs to be considered in connection with diligence. There's others, but that's probably the most, usually top of our list from a business perspective. Right. So get on top of it, get in front of it, get all the information you can at the onset.
You know, it's funny, as we were discussing this, when you were mentioning diligence, that little sort of ring in my head of like open source was just sitting there because I can't tell you the amount of times we've been by side looking at a target and they insist, no, don't worry about it. No IP, no software, nothing to really report. And then you dig in a little bit and it turns out they're relying entirely on open source software because everybody does. And then that's a whole other diligence debacle.
Well, and that's not necessarily a problem because there's many open source licenses are benign. They don't create legal issues for you. There might be some compliance obligations that are pretty minimal. But the key is just at a general level is when you're doing diligence, a company have an open source policy and they follow it.
If a company has a policy and they're on top of it, diligence generally goes a little smoother. But when you ask a company, as you were saying, do you have any open source? and they say, no. Do you have an open source policy?
No. And then you dig in, you realize, okay, well, there is open source. Did you have any policy? No.
How did you determine whether to use open source and whether it was a problem? Well, we did, and we left it up to the developers. So those usually don't go very well. And then you add AI on top of that with these code generators, and it creates another level of potential issues.
So it's definitely, as head of our open source team, I do a lot of that work. And it amazes me that probably over 90-something percent of the companies use open source, according to some of the statistics I've seen. And I'd say at least half the companies we encounter still don't have an open source policy. It's really scary.
Right. And so I think part of the reason we've really wanted to look into doing this episode is just because, one, AI is everywhere and it's really like coming to the mainstream. But I think what we're sort of seeking to do is demystify it and get rid of some of those fears and apprehensions have. So I think one thing as we finish up the episode, I really want to touch on is like What are the most important things that companies can do to minimize the risk when using generative AI?
Sure. It's a great question and really probably a good one to kind of end up with or kind of put at the end here. So a lot of companies hear about a lot of the issues I'm talking about. And a lot of lawyers who are kind of new to the field and are getting up to speed don't feel like they have a good handle on the issues.
And so they do what a lot of lawyers do, and they say, don't use it because there's risk, right? And of course, not using something usually minimizes the risk, but you lose the business benefit of this amazing tool that people are using to save so much time and do all this stuff. So the question is, if you're not going to just ban it, how do you use it in a way that doesn't create undue risk for the company? And really the short answer, this is a lot of what me and some of our other team members are spending our time on right now, is educating in-house legal departments and also boards like officers, directors, C-level people, because a lot of these are big business decisions.
Like I was mentioning earlier, like when you have these risks of algorithmic disgorgement, you're talking about investing money and like, do we have the risk of just having that go out the window? So we're doing training to help companies understand the issues, including some of what we covered on the episode today, but many other issues. And some of it depends on the use cases, what the company wants to use it for. It gets into some additional information.
But once we've helped them understand the issues, The second thing we help them understand is that, as I said earlier, all these tools are different. They have different terms of service and they have different features. So a lot of the responsible tool providers know that managing legal risk is an issue. And so they're building features into their tools that can help companies mitigate legal risk.
So on the AI code generators, on some of the tools, there's what's called a filter that will prevent any known open source code from being output. They also have what's called a reference feature, which you can use in kind of almost the opposite way. It can let code come out even if it's open source, but it'll identify the fact that this matches some known open source code. So it flags it and you can then analyze it and see, is it problematic open source or not?
And are there compliance obligations or not? So once you do that, you can manage the risk, right? So that's just one example. So once we go through the tools and all of that, And then there's also, I mentioned earlier, there's like enterprise versions and individual user versions.
And a lot of the enterprise versions come with different terms and with more safety features. So like with OpenAI, for example, there's two different ways to provide inputs. One is through an API and one is through the website directly. And they state in their terms, if you're using the API, they'll treat your information as confidential and they won't use it to train models.
If you do it through the website, they're going to use it. So understanding the differences in these tools and how they work and the legal issues, what you can then do is put together a policy that makes decisions and say, okay, our company is approving these tools, but not these tools. And if you're going to use this tool, you have to use these features. And in some cases, if you have the enterprise version, like an administrator can lock it down so users can't change some of the settings.
And in other cases, companies are specifying the use cases. So as I mentioned earlier, if you're creating content for like a new character for a video game that you want to be able to protect and commercialize and monetize separately, you wouldn't want that to be not copyright protectable. So in some cases, companies are saying for these purposes, you cannot use generative AI or the output of generative AI. You can use it as inspiration, but not the actual output.
In other cases, it's fine to use it. And then there's various other safeguards. I won't go through all the elements of the policy, but you kind of get the sense. by understanding the legal risk, understanding the tool, understanding the differences, the terms of service, you can make intelligent decisions that help companies manage the risk.
Right. And I think that is something your team specifically is focusing on at this point. Absolutely. And we're doing a lot of that.
I am excited to see where it goes. I really think, you know, when it comes to AI, it's sort of the, I don't want to call it Pandora's box because we're demystifying and getting rid of the stigma, But AI is cool. And I think, you know, we can't move backwards. We are where we are.
And it's going to be interesting to see where it goes. I agree with that. I do not think we're going to move backwards from this. The genie has been unleashed.
The question is, how do we make sure the genie behaves? Right, exactly. All right. Well, thank you so much, Jim.
This was super informative. And I can't wait to see where it goes and some of the issues and challenges and opportunities that come up as a result. Well, I share those sentiments and look forward to seeing new changes pretty much on a daily basis right now. So it has certainly been kind of a fun ride.
As I said, I've been doing this for 20 years. I've been doing artificial intelligence work for over 20 years. And I haven't seen this pace of development really with any technology that I can recall in the 35 years I've been a lawyer. It really is taking the world by storm and it's producing some really good results, but it also has some potentially significant legal ramifications that companies If they just understand them, they can manage them for the most part.
So we look forward to helping people who need help. And I appreciate being on the podcast again. This has been great. All right.
Thanks, Jim. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.