An AI use policy is the set of internal rules that tells staff which generative AI tools they may use, with what information and how to handle the results. From an intellectual property point of view, it is also evidence: under EU trade secrets law, information is only protected if its holder has taken reasonable steps to keep it secret, and pasting confidential material into an unvetted chatbot is hard to reconcile with that. This guide is for companies whose teams already use generative AI and that want to keep control of their know-how, inventions and content.
Update (October 2026): the Digital Omnibus on AI, Regulation (EU) 2026/1744, published on 24 July 2026, rewrote Article 4 of the AI Act: providers and deployers must still take measures to support the AI literacy of their staff, but the text now clarifies that no specific level is required. Cuatrecasas (24 July 2026).
Key takeaways
- A trade secret must have been subject to reasonable measures to keep it secret (Article 1 of Spanish Law 1/2019, transposing Directive (EU) 2016/943). A written AI policy is one of those measures.
- Inventions described to an external tool before filing may raise novelty questions: the state of the art covers everything made available to the public before the filing date.
- Content generated by AI may not be protected by copyright and may reproduce third-party material, so outputs need review before use.
- Since 2 February 2025 the AI Act requires providers and deployers of AI systems to take measures on their staff’s AI literacy.
- The policy only works if it is matched by approved tools, contract checks and training.
Why does an AI use policy matter for intellectual property?
Trade secrets depend on reasonable steps
Under Spanish Law 1/2019 on Trade Secrets, which implements Directive (EU) 2016/943, information qualifies as a trade secret only if it is secret, has business value because it is secret and “has been the subject of reasonable measures by its holder to keep it secret”. If a dispute arises, the company must show those measures. Policies, access controls and confidentiality agreements are the usual evidence; a gap around AI tools, where employees routinely paste source code, pricing models or customer data, weakens that case. Once secrecy is lost, the remedies in Article 9, from injunctions to damages, may no longer be available.
Patents depend on novelty
Both Article 54 of the European Patent Convention and Article 6 of the Spanish Patents Act define the state of the art as everything made available to the public before the filing date. Whether entering an invention into an AI service counts as making it available depends on the facts, including the provider’s confidentiality and data-use terms. Our recommendation is not to test that question: invention details should not go into external tools before filing unless the tool has been approved for confidential use.
Outputs carry their own risks
Copyright in Spain requires a human author, so output generated with little human input may not be protected at all. Outputs can also reproduce protected text, code or images, or imitate a person’s voice or likeness. A policy should decide which uses need human review and records of the human contribution.
What should a generative AI use policy include?
There is no official template. The following clauses cover the IP risks above and can be adapted to the size of the business:
| Clause | What it says | IP risk it addresses |
|---|---|---|
| Information classes | Defines what may never be entered (trade secrets, unfiled inventions, source code, personal data), what needs an approved tool and what is free to use | Loss of secrecy and novelty |
| Approved tools | Lists tools vetted for retention, training on inputs, confidentiality and data location | Disclosure to the provider |
| Output review | Requires human review before external use and checks for third-party content | Infringement claims |
| Records and ownership | Keeps prompts, drafts and edits for content the company needs to own; confirms that rights go to the company | Unprotectable or disputed outputs |
| Inventions | Requires early contact with the IP team before any AI-assisted work on new technical solutions | Novelty and inventorship issues |
| Third parties | Extends the rules to contractors, agencies and partners through contract clauses | Leaks outside the company |
| Training and incidents | Sets AI literacy training and a route to report and contain mistakes | Repeat errors; delayed response |
How does the AI Act fit into an AI use policy?
Since 2 February 2025, Article 4 of the AI Act has required providers and deployers of AI systems to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff using those systems. A company whose employees use generative tools for work is normally a deployer, so the policy and its training are a natural place to show compliance. From 2 August 2026, Article 50 adds labelling duties for deepfakes and certain AI-generated texts published on matters of public interest.
Data protection runs in parallel: entering personal data into an AI tool is processing under the GDPR. META Channel’s AI Act and GDPR practices, within the same group, can align those requirements with the IP rules, so the company ends up with one policy instead of three.
What this means for your business
- Map current use: ask teams which tools they use and for what. The answer is rarely “none”.
- Identify the crown jewels: list the trade secrets, pending inventions and code that must stay out of external tools.
- Review tool contracts: check retention, use of inputs for training, confidentiality and where data is processed.
- Write the policy and train: short rules, concrete examples and a named contact for questions.
- Extend it across the group: subsidiaries and partners in Latin America and Africa should follow the same rules, adapted to local trade secret, labour and data laws.
- Audit and update: tools and terms change; review the policy at least yearly.
Our AI and digital assets IP practice can draft the policy with you and align it with your confidentiality agreements, invention disclosure process and patent strategy, coordinated with our patent filing team where inventions are involved.
Where companies get AI use policies wrong
- Banning AI entirely. Staff tend to keep using personal accounts, which leaves the company with less control and weaker evidence.
- Approving tools without reading the terms on retention and training on user inputs.
- Writing a policy nobody signs or is trained on: a document in a drawer is weak evidence of reasonable measures.
- Forgetting contractors and agencies, who often handle the most sensitive briefs.
- Reacting slowly to a leak. If confidential material has been exposed, speed matters for any action; our trade secret and IP disputes team can assess options.
Frequently asked questions
Is a company legally required to have an AI use policy?
No law in Spain requires a document with that name. However, trade secret protection depends on showing reasonable measures to keep information secret, and the AI Act requires deployers to take measures on staff AI literacy. A written policy with training is the most practical way to meet both expectations and to prove it later.
Does entering a trade secret into a public AI chatbot destroy its protection?
Not automatically. The question is whether the information remains secret and whether the company took reasonable measures. Use of an approved tool under confidentiality terms is very different from an employee pasting data into a free consumer service. Each incident needs a factual assessment, ideally quickly, to contain the damage.
Can we use generative AI when developing inventions?
Yes, with care. Avoid entering unfiled inventions into external tools unless they are approved for confidential use, keep records of who conceived each part of the solution and involve your patent advisers early, so inventorship and novelty can be assessed before filing.
Can IP Global Guard draft our AI use policy?
Yes. We review how your teams use AI, draft the policy and the related confidentiality and assignment clauses, and align it with your patent and trademark strategy. Within the META Channel group, the AI Act and GDPR aspects can be covered at the same time, with a single point of contact.
How IP Global Guard can help protect your know-how
Generative AI makes it easy to share information that used to stay inside the company. A clear policy, backed by the right contracts, keeps your trade secrets, inventions and content defensible. IP Global Guard, the IP services line of META Channel Corporation Limited, works with one strategy and one billing relationship across more than 25 jurisdictions; see our coverage in Europe, Latin America and Africa.
Tell us which AI tools your teams use and what information worries you most. We will propose a policy and an implementation plan and coordinate it across your subsidiaries from a single point of contact. Ask our team for an AI policy review.
This article is general information, not legal advice, and reflects the position on its publication date.
Sources
- BOE, Law 1/2019 of 20 February on Trade Secrets (consolidated text)
- EPO, European Patent Convention, Article 54 (novelty)
- BOE, Law 24/2015 of 24 July on Patents, Article 6
- BOE, Spanish Intellectual Property Act (Royal Legislative Decree 1/1996), Article 5
- AI Act, Article 4 (AI literacy)
- AI Act, Article 50 (transparency obligations)
- Cuatrecasas, Digital Omnibus on AI published (24 July 2026)








