Tag: AI Governance

  • What Companies Should Do When AI Rules Are Fragmented Across States, Agencies, and Courts

    What Companies Should Do When AI Rules Are Fragmented Across States, Agencies, and Courts

    A lot of companies are still waiting for AI law to become neat.

    They want one federal statute, one regulatory framework, one court doctrine, and one checklist that settles the problem.

    That is not the environment they have.

    The real operating environment is fragmented across states, agencies, courts, sector rules, contract demands, and product-specific risk.

    That fragmentation is frustrating. It is also manageable if companies stop treating AI compliance as a search for one master rule and start treating it as a workflow problem.

    The Short Answer

    • AI law is fragmenting across multiple legal systems at once: state consumer-protection law, federal agency action, court decisions, sector-specific rules, and non-U.S. frameworks.
    • Companies that wait for one unified AI rulebook may fall behind the actual risk.
    • The practical response is not to memorize every rule. It is to build a repeatable intake, classification, review, documentation, and escalation process that can absorb changing legal inputs.

    The Real Problem Is Not Just Volume

    Most companies describe the issue as too many AI rules.

    That is true, but incomplete.

    The harder problem is that the rules are coming from different places and asking different kinds of questions.

    One state may focus on automated decision-making and bias risk.

    Another may focus on chatbot safety, youth access, or emotionally manipulative design.

    The FTC may focus on deception, hidden model steering, or unsupported accuracy claims.

    State attorneys general may focus on product design, vulnerable users, and public-facing marketing.

    Courts may focus on sanctions, privilege, work product, or protective-order restrictions.

    The EU may focus on transparency, labeling, governance, and deployer obligations.

    Patent offices may focus on inventorship and filing practices.

    This is not one compliance lane. It is a stack of overlapping ones.

    The Wrong Response Is To Build A Law List Without A Workflow

    A lot of organizations react by creating a giant AI law tracker and then stopping there.

    Tracking is necessary. It is not enough.

    A list of developments does not tell the company:

    • which products are in scope;
    • which claims matter most;
    • which teams own the response;
    • when an issue should escalate to legal;
    • what documentation should be preserved;
    • how vendor risk connects to product risk; or
    • what happens when two legal signals point in different directions.

    That is why companies with impressive issue tracking can still be weak operationally.

    They know what changed. They do not have a consistent way to act on it.

    Fragmentation Usually Shows Up In Five Operational Problems

    1. No Clear AI Intake Function

    Many organizations still do not have one reliable way for teams to flag:

    • a new AI product feature;
    • a vendor purchase;
    • a model change;
    • a high-risk use case;
    • a public marketing claim;
    • or a new jurisdictional issue.

    Without intake, the company never gets a clean first look at what needs review.

    2. No Risk Tiering

    Not every AI use case needs the same level of scrutiny.

    An internal summarization tool is not the same as a public-facing chatbot for teenagers. A marketing-assist tool is not the same as an automated HR workflow. A contract-analysis system is not the same as a medical advice assistant.

    If the company does not tier AI uses by risk, it will either over-review low-risk tools or under-review the ones that matter most.

    3. No Cross-Functional Owner

    Fragmented law creates fragmented internal ownership unless someone is responsible for pulling the pieces together.

    Legal may track statutes. Privacy may track data use. Security may track model exposure. Product may control deployment. Marketing may control claims. Procurement may control vendor intake.

    That structure is normal. It still needs a coordination point.

    Otherwise the legal risk lives in the gaps between teams.

    4. Weak Documentation

    Fragmented law increases the need for records because the company may later need to explain:

    • why a system was classified one way instead of another;
    • why a disclosure was used;
    • why a vendor was approved;
    • why a feature launched despite known limitations; or
    • why one jurisdictional rule was treated as controlling.

    If those judgments are not documented, later review becomes much harder.

    5. Overreliance On Vendor Assurances

    Many AI compliance gaps start with vendor language.

    A vendor says its product is compliant, enterprise safe, explainable, unbiased, privacy preserving, or ready for regulated use. The buyer takes that statement at face value because the vendor sounds sophisticated and the market is moving fast.

    That is dangerous in a fragmented legal environment because the buyer may still bear downstream risk even when the vendor caused the original representation problem.

    The Better Approach Is A Governance Workflow

    Companies do not need a perfect unified AI law map before they can act.

    They need a usable governance workflow.

    That workflow should do at least six things.

    1. Create One AI Intake Path

    There should be one standard route for teams to raise:

    • new AI features;
    • material model changes;
    • new vendors;
    • sensitive use cases;
    • customer requests involving AI claims or commitments; and
    • incidents or complaints tied to AI outputs.

    The key is consistency, not bureaucracy.

    2. Classify The Use Case

    Every material AI use should be classified by factors such as:

    • internal or external use;
    • consumer-facing or enterprise-facing;
    • use by minors or vulnerable users;
    • impact on employment, health, finance, education, housing, or legal rights;
    • use of sensitive data;
    • degree of autonomy;
    • marketing sensitivity; and
    • jurisdictional footprint.

    This helps decide which legal lanes matter most.

    3. Tie Review To Risk, Not Buzzwords

    Legal review should not be triggered only because something is labeled AI.

    It should be triggered by what the system actually does, what data it touches, what claims are being made, and what decisions may flow from it.

    That keeps the review grounded in real exposure instead of branding alone.

    4. Preserve The Decision Record

    For material deployments, companies should preserve:

    • what the tool or feature was meant to do;
    • what risks were identified;
    • what testing occurred;
    • what mitigations were added;
    • what claims were approved;
    • which jurisdictions or legal frameworks were considered; and
    • who approved the decision.

    That record becomes valuable fast if the system is later challenged.

    5. Review Public And Customer-Facing Claims Separately

    A lot of AI risk is created not by the technical system itself but by the way the system is described.

    Claims about safety, objectivity, transparency, compliance, age appropriateness, human oversight, and accuracy should get their own pass, not just a product review pass.

    6. Build An Escalation Rule

    Some AI issues should escalate automatically.

    For example:

    • systems affecting minors or vulnerable users;
    • high-impact decision systems;
    • products using sensitive personal data;
    • systems marketed as safe, objective, or compliant;
    • incidents involving self-harm, dangerous instructions, or severe output failure;
    • and any state, agency, or court demand tied to AI conduct.

    Companies do not need to improvise those escalation rules in the middle of a problem.

    What Companies Should Do Now

    If the company is already feeling the fragmentation problem, the most useful next steps are practical:

    • create one intake form or intake workflow for material AI uses and changes;
    • define a small number of AI risk tiers instead of trying to classify everything from scratch each time;
    • assign one cross-functional owner or review group for material AI decisions;
    • inventory current public claims about AI safety, accuracy, oversight, and compliance;
    • map which jurisdictions and agency frameworks matter most for the company's actual products;
    • review vendor AI questionnaires and procurement language for overpromising;
    • create an escalation trigger list for high-risk AI incidents and launches; and
    • make sure review decisions are being saved somewhere retrievable.

    This will not eliminate legal fragmentation.

    It will make the company much better at operating inside it.

    Bottom Line

    AI rules are fragmented across states, agencies, courts, sectors, and jurisdictions. That is not a temporary drafting glitch. It is the real operating environment right now.

    The companies that handle it best will not be the ones waiting for a clean universal AI rulebook.

    They will be the ones that build a workable compliance process around intake, classification, review, documentation, and escalation.

    Fragmented law is annoying. Fragmented internal workflow is what turns it into a real problem.

    Sources

  • Why AI-Washing Risk Is Becoming a Real Legal Category

    Why AI-Washing Risk Is Becoming a Real Legal Category

    For a while, AI washing sounded like a cheap shot. A company slapped “AI-powered” on ordinary software. A vendor implied the model could do more than it really could. A marketing team reached for the label because the market wanted to hear it.

    That still happens. What has changed is the legal posture around it.

    AI washing is no longer just a hype problem. It is turning into a substantiation problem. When a company says a product is intelligent, autonomous, safe, accurate, compliant, unbiased, or ready for sensitive work, regulators, customers, investors, and plaintiffs can all ask the same question: what did that claim actually mean, and what evidence supported it?

    That question does not require a new AI-specific statute. Existing deception, unfairness, privacy, procurement, securities, and misrepresentation theories are already enough to create pressure.

    Why This Is Becoming A Real Legal Category

    The reason is straightforward. AI claims now shape material decisions.

    Consumers may rely on them when deciding whether a product is safe, trustworthy, educational, therapeutic, or appropriate for minors. Enterprise buyers may rely on them when deciding whether a system is ready for legal, HR, health, finance, or security workflows. Investors and board members may rely on them when evaluating growth, defensibility, product moat, or operational maturity.

    Once AI language starts influencing those decisions, the claim stops being casual branding. It becomes something closer to a factual representation about capability, safety, governance, or reliability.

    That is why AI washing is becoming a legal category even without a statute labeled “AI washing.” The law already knows how to handle claims that create a misleading net impression.

    “AI” Is Not Just One Claim

    One reason this gets messy fast is that companies often use AI language as if it were a single label.

    It is not. Saying a product uses AI can imply very different things depending on the context. It may suggest the product actually uses machine learning rather than ordinary automation. It may suggest the system is more advanced than a rules engine, improves itself over time, requires less human labor, produces more accurate results, acts autonomously, or has stronger safety and governance controls than competing tools.

    Those are not all the same claim. They create different expectations and different legal exposure.

    A regulator or plaintiff usually does not need to prove that every part of the AI story was false. It is often enough to show that the overall impression was materially misleading for the audience that mattered.

    The Problem Is Broader Than Capability Hype

    The obvious form of AI washing is capability inflation. A company says the product can do things it cannot do.

    The harder cases are broader than that. The claim may not be “our model is magic.” It may be “our system is safe,” “our outputs are objective,” “our workflow is compliant,” “our AI runs with human oversight,” or “our platform is enterprise ready.”

    That is where the risk gets more serious, because those claims are often tied to internal process, governance, testing, escalation, data handling, and product design, not just model performance.

    A company can also create AI-washing risk by hiding the amount of human labor behind the product, downplaying model limitations, overstating bias mitigation, overstating explainability, or suggesting a level of operational control that does not really exist.

    In other words, the legal problem is often not “you said the word AI.” It is “you used AI language to imply a level of performance, safety, or governance that the record cannot support.”

    The FTC Makes The Trend Easier To See

    The FTC's proposed AI accuracy policy statement is not an anti-AI-washing rule by name, but it shows the direction clearly.

    The Commission's point is that a company may create the impression that its AI system is trying to provide the best, most accurate, or most truthful answer for the user's objective. If the system is actually steered toward a different hidden objective, the FTC says that may be deceptive.

    That is a model-design issue, but it is also a claims issue. A company may never use the phrase “objective and neutral” and still create that impression through product design, benchmarking language, sales materials, accuracy messaging, or positioning.

    The same pattern showed up differently in the FTC's Active Listening matter. There, the problem was not just a buzzword. It was the gap between what the product was presented as doing and what the facts supported about the listening function and the related privacy implications.

    Put those together and the pattern becomes clearer. AI-washing risk is not confined to inflated tech language. It can arise whenever the public story about the system outruns the product reality.

    Where The Risk Usually Shows Up

    The public homepage is only one part of the problem.

    Marketing copy is the obvious starting point because words like autonomous, safe, trustworthy, accurate, unbiased, transparent, and enterprise ready can imply a lot more than the company intends. Those words are not off-limits. They just need support.

    The bigger risk often sits in enterprise sales materials, procurement responses, security questionnaires, governance decks, and customer demos. That is where companies make concrete statements about explainability, retention, deletion, human review, model change management, data isolation, safety controls, and compliance readiness. If those statements outrun the actual workflow, the mismatch may surface later in a customer dispute, regulator inquiry, or internal escalation.

    Investor and board communications create another layer. If a company ties AI to measurable gains in safety, efficiency, margins, market position, or defensibility, those statements may later be compared against testing records, incident logs, and internal discussions. Not every optimistic statement creates liability. But specific, repeated, safety-linked claims deserve careful treatment.

    The product experience itself also matters. A system can create strong expectations without saying much at all. A chatbot that speaks with confidence, appears emotionally perceptive, presents itself as a trusted helper, or hides the extent of human involvement may create a stronger impression than any disclaimer in the footer.

    The Internal Record Usually Decides How Bad It Gets

    AI washing tends to look worst once someone asks for the internal record.

    If the company publicly describes a system as safe, accurate, objective, well-governed, or ready for sensitive deployment, the next questions are predictable. What testing supported that statement? What limitations were already known? Were complaints or incidents pointing in the other direction? Did anyone inside the company describe the claim as too aggressive? Was the claim approved because it was supported, or because it sounded good?

    That is the point where puffery arguments start to weaken. The problem stops looking like enthusiastic copy and starts looking like a documentation and governance failure.

    What Companies Should Review Now

    Companies using AI language in public or customer-facing materials should review a few things immediately.

    • Whether the claim is really about the presence of AI, or about performance, safety, autonomy, neutrality, or compliance.
    • Whether current product testing and governance records actually support the claim being made.
    • Whether consumers, enterprise customers, investors, and regulators are hearing different versions of the same product story.
    • Whether the product experience creates stronger expectations than the formal copy.
    • Whether disclaimers change the net impression in a meaningful way, or just try to patch over an aggressive claim after the fact.
    • Whether the rationale behind sensitive AI claims is being preserved in a way the company could defend later.

    The practical question is not “can we argue about this phrase if challenged?” It is “what expectation does this create, and would we be comfortable defending that expectation with the actual record?”

    Bottom Line

    AI washing is becoming a real legal category because AI claims now influence decisions about safety, trust, spending, and risk.

    The law does not need a special AI-washing label to get there. Existing doctrines already give regulators and plaintiffs room to test whether the public AI story matches the product, the workflow, and the record behind it.

    If a company would be uneasy putting its public AI claims next to its testing history, governance records, customer complaints, and known limitations, those claims probably need work.

    Sources

  • AI Litigation Is Increasingly About Governance Records

    AI Litigation Is Increasingly About Governance Records

    For a while, AI legal risk was often framed as a debate about big theories.

    Would copyright claims survive? Would Section 230 matter? Would a new AI statute appear? Would courts treat models as products?

    Those questions still matter. They are no longer the whole story.

    The more immediate litigation and enforcement risk is becoming much more operational. Regulators, state attorneys general, and private plaintiffs increasingly want to know what the company knew, what it tested, what it changed, what it told users, and what records support those answers.

    That is why AI litigation is increasingly about governance records.

    The Short Answer

    • AI legal risk is moving from abstract policy debate into record-based disputes about testing, warnings, internal knowledge, and product governance.
    • Plaintiffs and regulators are using existing consumer-protection, privacy, product-design, and safety theories to ask for concrete documents rather than broad philosophical answers.
    • Companies that cannot produce a coherent record of AI design, review, escalation, and mitigation may look irresponsible even before a court decides the merits.

    The Record Problem Is Showing Up Across Different AI Disputes

    The same pattern is emerging in several different legal lanes.

    Florida's lawsuit against OpenAI is not just about a chatbot existing in the market. The complaint tries to turn product design, youth access, safety controls, warnings, and data practices into evidence-backed state consumer-protection and product-liability questions.

    The reported 42-state OpenAI investigation appears to be asking for information about advertising, engagement, retention, sycophancy, vulnerable users, and treatment of sensitive data. Even at the investigation stage, that is a document-heavy inquiry.

    The FTC's proposed AI accuracy policy statement points in the same direction. If the agency believes a model is being steered away from the user's expected objective, the obvious next question is what internal records show about the product's actual objective, controls, and consumer-facing explanation.

    Companion-chatbot scrutiny also fits the pattern. Once a regulator or plaintiff argues that a system creates foreseeable emotional or behavioral risk, the practical fight becomes whether the company had warnings, testing, age controls, escalation rules, and internal evidence supporting its safety claims.

    These are different legal theories. They are all becoming record fights.

    The New Core Question Is “What Can The Company Prove?”

    That question matters because a lot of AI governance still lives in presentation decks, launch reviews, and broad principles rather than in disciplined operational records.

    A company may say it prioritizes safety, fairness, accuracy, trust, youth protection, or responsible AI use. In litigation, those statements are only the beginning.

    The harder questions look like this:

    • What testing was performed before release?
    • What failure modes were already known internally?
    • What documents show that leadership understood the risk?
    • What warnings were considered and rejected?
    • What product changes were made after incidents or internal escalation?
    • What was done for minors, vulnerable users, or high-risk use cases?
    • What claims were made publicly that went beyond what the internal record supported?

    Those questions do not require a comprehensive AI statute. They fit comfortably inside discovery, civil investigative demands, subpoena responses, and ordinary regulatory investigation.

    The Governing Theory May Be Old. The Evidence Questions Are Newer.

    One reason companies misread this area is that they focus too much on whether the legal theory is novel.

    Often it is not.

    A state AG may use ordinary unfair-practices law. The FTC may use a familiar deception theory. A plaintiff may plead negligence, failure to warn, misrepresentation, or product-design claims. A court may focus on privilege, confidentiality, or sanctions rules that predate generative AI entirely.

    The novelty is frequently in the factual record, not in the legal label.

    The company is being asked to explain a model release, a training pipeline, a ranking system, a safety override, an age-gating decision, a memory feature, a moderation workflow, or a prompt-handling rule in a way that holds up across internal documents, external claims, and product behavior.

    That is harder than reciting a principle.

    The Weakest Record Often Appears In Four Places

    1. Safety Testing

    Many AI companies can say they tested. Fewer can show:

    • what they tested for;
    • which risks were considered material;
    • how red-team findings were escalated;
    • what thresholds blocked release;
    • what mitigations were added before launch; and
    • what remained unresolved at release.

    If a harm later appears that looks close to a known internal concern, the testing record becomes central very quickly.

    2. Marketing And Product Claims

    A lot of AI exposure begins when public claims outrun operational reality.

    That can happen through phrases like:

    • safe
    • trusted
    • accurate
    • objective
    • youth appropriate
    • enterprise ready
    • privacy preserving
    • human supervised

    Those labels can become litigation artifacts. If the internal record shows caveats, unresolved risk, or known inconsistency, a regulator or plaintiff will try to line the two up side by side.

    3. Vulnerable-User Treatment

    Minors, emotionally dependent users, health-related users, older adults, and other vulnerable populations are becoming a major pressure point.

    It is one thing to say the product was not designed for those users. It is another to explain what the company did once it knew those users were present anyway.

    The record questions become concrete:

    • Was usage by minors or vulnerable users anticipated?
    • Were age controls or warnings considered?
    • Were specific escalation or refusal rules added?
    • Were safety incidents tracked separately?
    • Did executives review those incidents?

    4. Model-Change History

    AI systems change. That is normal. It is also legally dangerous when the company cannot explain what changed and why.

    A useful governance record should be able to show:

    • when a material model or policy change was made;
    • why it was made;
    • what known tradeoffs it introduced;
    • whether user-facing claims changed too; and
    • whether the company preserved enough history to explain pre-change versus post-change behavior.

    Without that, later disputes can turn into messy arguments over what version of the system did what.

    AI Governance Records Are Not Just For Regulators

    This is not only an agency problem.

    Governance records matter in:

    • private litigation;
    • state AG investigations;
    • FTC inquiries;
    • insurance disputes;
    • vendor and enterprise customer conflicts;
    • discovery fights over AI-related workflow decisions; and
    • post-incident board or audit review.

    The same internal gap can create problems across all of them.

    A company that cannot explain how it reviewed safety, documented model changes, handled incident escalation, or substantiated its marketing may face very different legal claims built on the same weak operational record.

    What A Better Record Looks Like

    A good AI governance record does not have to be perfect. It does have to be coherent.

    At minimum, companies should be able to locate:

    • release-review materials for major launches and major feature changes;
    • red-team, testing, and evaluation summaries;
    • incident logs and escalation records;
    • change logs for material policy or model updates;
    • records of who approved sensitive decisions;
    • rationale for warnings, disclosures, and refusal behavior;
    • records supporting claims about accuracy, safety, privacy, or guardrails; and
    • documentation showing how minors, vulnerable users, or high-risk contexts were handled.

    This is the difference between a company that can explain its judgment and a company that can only say it cared about responsible AI in general.

    What Companies Should Do Now

    Companies with public-facing or high-impact AI systems should review:

    • whether product, legal, policy, trust and safety, and communications teams are creating one usable record or five disconnected ones;
    • whether launch reviews are preserved in a way that can be understood later;
    • whether known-risk discussions are logged or only discussed in chat threads and meetings;
    • whether incident review produces a retrievable record of action and follow-up;
    • whether marketing language is checked against the internal testing record;
    • whether vulnerable-user issues are tracked explicitly instead of being buried inside generic safety notes; and
    • whether the company can reconstruct what changed in the system over time.

    The point is not to generate paper for its own sake.

    The point is that once litigation or investigation begins, the record exists whether the company designed it or not. If the formal record is weak, the real record will be reconstructed from fragments.

    That is usually worse.

    Bottom Line

    AI litigation is increasingly about governance records because the legal system is moving from theory to proof.

    The governing claims may sound familiar: deception, unfairness, negligence, design defect, failure to warn, privacy failures, or safety misrepresentation.

    What changes the exposure is often much more practical.

    Can the company show what it knew, what it tested, what it changed, what it told users, and why those decisions were defensible at the time?

    That is the record question. It is becoming one of the most important AI law questions on the board.

    Sources

  • German Court Says Google AI Overviews Can Become Platform Speech

    German Court Says Google AI Overviews Can Become Platform Speech

    A German court has delivered one of the clearest early liability signals yet for AI-generated search summaries.

    According to the Munich I Regional Court’s June 12, 2026 press release, the court granted a preliminary injunction application by two publishers over statements shown in Google’s "AI Overview" format.

    The important part is the court’s reasoning.

    The 26th Civil Chamber said the challenged AI Overview was not merely a display or link list of search results. It was content attributable to the search engine operator because the results were presented in the operator’s own summarized and evaluated words.

    That is a meaningful platform-liability signal even though the ruling is only a preliminary injunction and is not yet final.

    The Short Answer

    • The Munich I Regional Court said the challenged Google AI Overview could be treated as content attributable to Google, not just a neutral display of third-party search results.
    • The ruling came in a preliminary injunction proceeding, not a final merits judgment, and the court’s own press release says the decision is not final.
    • Reuters separately reported that Google plans to appeal, but as of Clearon’s last source check there was no official appellate docket or published appellate decision identified.

    What The Court Said

    The court’s press release describes the case as involving two publishers who sought an injunction against statements about them generated in the search engine’s "AI Overview" feature.

    The publishers argued that the AI-generated overview text wrongly associated them with fraud schemes and unserious business practices, which they said violated their corporate personality rights.

    The search-engine operator argued, among other things, that it should not be liable because it was not itself responsible for the data processing and did not adopt the third-party information shown in the overview as its own.

    The court rejected that framing.

    Its key reasoning was direct: the "AI Overview" display was not merely a presentation or linking of search results. It was its own content attributable to the search-engine operator because the search results were summarized and evaluated in the operator’s own words.

    The press release says the wording of the AI Overview showed an independent substantive evaluation of the search results. On the court’s account, that created statements going beyond the later-linked search results themselves, and those statements could be attributed to the operator.

    That is the part other publishers, platforms, and product teams should pay attention to.

    Why Attribution Matters More Than The Injunction Alone

    The legal importance here is attribution.

    Search engines and other intermediaries have long argued, often with some success, that they merely index, rank, display, or link to third-party material. That position can matter a lot in defamation, press-law, and intermediary-liability disputes.

    The Munich court’s description of the AI Overview product cuts against that safe framing.

    If a court sees the output as the platform’s own summarized and evaluated statement, the liability analysis changes. The platform is no longer only pointing a user toward third-party material. It may be treated as making a new statement itself.

    That matters well beyond classic search.

    The same issue can surface anywhere a system takes source material, rewrites it, condenses it, ranks it, or presents it as a single synthetic answer:

    • search summaries,
    • answer engines,
    • shopping and review summaries,
    • publisher-facing AI snippets,
    • enterprise knowledge assistants, and
    • other AI systems that translate multiple sources into one user-facing statement.

    Once the system moves from retrieval into synthesis, the platform’s "we only linked to sources" argument may get weaker.

    This Is Still A Preliminary Ruling

    The procedural posture matters.

    The Munich court press release describes the matter as an application for a preliminary injunction. It does not publish a final appellate holding or a full merits judgment. The court also says expressly that the decision is not final.

    That means companies should not overread the case.

    This is not a final Europe-wide rule that every AI summary automatically becomes platform speech. It is an official court summary of one injunction-stage ruling on one challenged overview display and one set of alleged false implications about specific publishers.

    Still, preliminary rulings matter because they show how at least one court is analyzing the product.

    For legal and product teams, this is exactly the kind of opinion worth watching early. It gives a preview of what judges may find persuasive before a full appellate record ever appears.

    The Appeal Posture

    Reuters reported on the same date that Google said it would appeal the German ruling.

    That reported appeal intent matters, but it should be described carefully.

    The official source Clearon identified is the Munich I Regional Court’s press release confirming the underlying injunction and its reasoning. Reuters is the source for Google’s reported plan to appeal. As of the last official-source check reflected in Clearon’s tracker, no official appellate docket entry, appellate press release, or published appeal decision had been identified.

    So the clean framing is:

    • official source for the injunction and reasoning: yes;
    • official source for a filed appellate result: not yet identified;
    • reported intent to appeal: yes.

    That distinction matters because AI-law reporting is already crowded with headlines that flatten allegations, preliminary rulings, and final holdings into one category.

    What Platforms Should Take From This

    The operational lesson is not "do not build AI summaries."

    It is that platforms should stop assuming synthesis is legally equivalent to linking.

    Teams deploying AI-generated summary products should review:

    • whether the product merely retrieves sources or also rewrites and evaluates them;
    • whether the interface presents the answer as a platform-generated conclusion;
    • whether users are likely to treat the summary as a standalone factual statement;
    • how disputed or reputation-sensitive topics are handled;
    • what guardrails exist for summaries about people, publishers, businesses, or alleged misconduct;
    • what source-review and suppression pathways exist when a summary appears false or distorted; and
    • what internal records show about testing, escalation, and correction workflows.

    This also connects to the broader pattern Clearon has been tracking in AI litigation and enforcement.

    Whether the issue is a state AG probe, a chatbot-safety complaint, or an AI-generated search summary, the pressure point is often the same: did the company merely host a tool, or did it create and present its own legally consequential statement?

    Bottom Line

    The Munich I Regional Court’s press release gives the market a clear early warning.

    At least one German court is willing to treat a challenged AI Overview as content attributable to the search-engine operator because it was presented in the operator’s own summarized and evaluated words.

    That is not a final appellate rule, and the decision is not yet final. But it is a concrete sign that AI-generated summaries can shift a platform from distributor arguments toward speaker responsibility.

    For companies building summary products, that is the part worth taking seriously now.

    Sources

  • What The Reported 42-State OpenAI Investigation Means Before Any Complaint Is Filed

    What The Reported 42-State OpenAI Investigation Means Before Any Complaint Is Filed

    If the Wall Street Journal report is directionally right, the reported 42-state OpenAI investigation matters even before any public complaint appears.

    A subpoena is not liability, and a reported multistate probe is not proof that an enforcement action will follow.

    It still shows what state attorneys general may be trying to learn about consumer AI products before they decide whether to sue, settle, or simply keep watching.

    That phase of the story is easy to underestimate. It is also where a lot of the real regulatory pressure starts.

    The Short Answer

    • A reported multistate AG investigation is not a complaint and not a liability finding.
    • It still matters because it shows what state enforcers may be asking about consumer AI design, data handling, vulnerable users, and engagement incentives before any case is filed.
    • For the broader market, the signal is comparative: if OpenAI is being asked these questions, other consumer AI companies should expect the same categories of scrutiny.

    Start With The Right Level Of Certainty

    At this stage, the key word is reportedly.

    The current public description, as tracked in Clearon's watchlist, is a reported coalition investigation involving 42 state attorneys general, with New York reportedly serving OpenAI with a subpoena seeking information about advertising, engagement and retention, model sycophancy, consumer and health data, and treatment of minors, seniors, and other vulnerable users.

    That should be treated as a reported investigation, not as a finding of misconduct and not as a filed enforcement case. But even at that level, the topic is worth taking seriously.

    Why Multistate AG Probes Matter

    A multistate attorney-general investigation usually tells you three things.

    First, the issue has escaped the lane of ordinary product criticism and entered coordinated enforcement attention.

    Second, the states may believe existing consumer-protection, privacy, child-safety, or unfair-practices laws are enough to start building leverage without waiting for a new AI-specific statute.

    Third, the information-gathering phase is likely to focus on product reality, not just marketing language.

    That means investigators may want to know:

    • what the product was designed to do;
    • what risks were known internally;
    • how the company tested and mitigated those risks;
    • what it told users and parents;
    • what incentives shaped product behavior;
    • what data the system collected and retained; and
    • how the company treated vulnerable populations.

    That is already much closer to enforcement than a generic policy debate.

    The Topic List Tells You What States Are Worried About

    The reported subjects of the inquiry are revealing.

    Advertising points to classic deception and substantiation risk.

    Engagement and retention point to design incentives, compulsion, dependency, and whether the system is optimized for time-on-product in ways that create foreseeable harm.

    Model sycophancy points to the increasingly specific question of whether chatbots reinforce unhealthy beliefs, emotional reliance, or unsafe user behavior rather than challenging it.

    Consumer and health data point to privacy, sensitivity of inputs, retention, sharing, and whether the company used or exposed data in ways users would not reasonably expect.

    Treatment of minors, seniors, and other vulnerable users points to one of the biggest trends in AI enforcement right now: whether the product should have been designed, marketed, tested, warned, or constrained differently for users who are easier to mislead or harm.

    That is a broad field of inquiry. But it is not random. It is a map of where consumer-AI enforcement may go next.

    What Happens Before A Complaint

    Companies often think the real risk begins when a complaint is filed.

    In practice, the pressure starts much earlier.

    Before a public case appears, a multistate probe can force a company to:

    • gather internal records quickly;
    • explain its product architecture and safety systems;
    • reconcile public statements with internal testing and incident history;
    • account for data flows and retention practices;
    • describe product changes over time; and
    • answer hard questions about why certain safeguards did or did not exist.

    That process can shape the eventual outcome even if no complaint is filed immediately.

    An investigation may lead to a settlement, a narrower state action, a broader coalition action, a referral, or simply a longer shadow over the company if the answers are weak.

    The Real Value Of The Probe Is Comparative

    Another reason this matters is comparative benchmarking.

    A multistate inquiry is not only about OpenAI. It is also a signal to the rest of the market.

    If states are asking about:

    • youth access,
    • emotionally sticky engagement,
    • safety testing,
    • vulnerable-user treatment,
    • health-related inputs,
    • memory and retention,
    • or claims about safety and reliability,

    then other consumer AI companies should assume those are no longer niche governance questions.

    They are becoming ordinary enforcement questions.

    That is true even for companies that are smaller than OpenAI or that operate in narrower categories. AG offices often use one high-profile target to surface theories they can later apply more broadly.

    How This Connects To Florida And Companion-Chatbot Scrutiny

    This reported probe also fits the wider pattern already visible in public AI enforcement.

    Florida's lawsuit against OpenAI tries to turn chatbot safety, minors, warnings, data collection, and design choices into a state consumer-protection and product-liability case.

    Companion-chatbot scrutiny in New York, California, and at the FTC is similarly focused on emotionally responsive systems, youth safeguards, retention, and foreseeable harms.

    Those lanes are not identical. But they are converging around a shared idea: states do not need a general AI law to ask whether a consumer AI product was marketed, designed, and governed responsibly.

    That is why a reported multistate probe matters even before anyone sees a filed complaint.

    What Consumer AI Companies Should Do Now

    The safest response is not to wait for a subpoena with your company's name on it.

    Consumer AI companies should review:

    • product claims about safety, reliability, emotional support, suitability for teens, or trustworthiness;
    • engagement and retention metrics and the incentives tied to them;
    • how the system handles vulnerable users, including minors and older adults;
    • memory, personalization, and retention of sensitive conversational data;
    • health-related, crisis-related, and high-risk user interactions;
    • internal records showing what was tested, what was known, and what changed;
    • age-gating, age-estimation, and parental-notice flows; and
    • escalation procedures when serious safety concerns are identified internally.

    The key is not just to have safeguards, but to be able to explain them coherently. That is often what an investigation tests first.

    Bottom Line

    The reported 42-state OpenAI investigation is not a complaint, a liability finding, or a settled enforcement theory.

    It is still a concrete warning about what state AGs may want to see before deciding whether to escalate.

    The likely questions are already visible: consumer AI design, retention, safety testing, vulnerable-user treatment, and whether product incentives match public claims.

    For the broader market, the practical lesson is simple: the inquiry stage is already part of the enforcement story.

    By the time a complaint is filed, many of the most important questions will already have been asked.

    Sources

  • After DABUS, The Real Patent Fight Is Proving The Human Inventor Story

    After DABUS, The Real Patent Fight Is Proving The Human Inventor Story

    The headline question in AI patent law used to be simple: can an AI system be named as the inventor?

    In the major patent systems, that question is now mostly answered. No.

    That means the harder question is no longer formal inventorship. It is evidentiary inventorship.

    When AI tools help generate ideas, optimize structures, write code, search design space, or propose candidate solutions, who exactly did enough human work to count as the inventor?

    That is the fight patent teams should be preparing for now.

    The Short Answer

    • Major patent systems still require a human inventor.
    • AI assistance does not defeat patentability by itself, but it does make the inventorship story harder to prove.
    • The real practical issue is not whether AI was used. It is whether the named humans can show how they significantly shaped, recognized, and claimed the inventive concept.

    The Formal Question Is Mostly Over

    The DABUS campaign forced courts and patent offices to answer the clean version of the issue: can a machine be listed as the inventor?

    Across the United States, the United Kingdom, the European Patent Office, Germany, Australia, and Japan, the answer has converged around a human-inventor rule. In Japan, the operative official ruling is the Intellectual Property High Court's January 30, 2025 judgment, which became final after the Supreme Court of Japan, Second Petty Bench, dismissed the petition for acceptance of final appeal on March 4, 2026. The legal reasoning varies somewhat across jurisdictions, but the practical result is the same: inventorship still attaches to a natural person.

    South Africa remains the narrow outlier most often cited by AI-inventorship advocates, but its registry grant carries much less doctrinal weight because the system does not conduct the same kind of substantive examination as the major patent offices and appellate courts.

    That does not mean AI-assisted inventions are unpatentable. It means the patent system still expects a person on the inventorship line, and that expectation pushes the real dispute into a different place.

    The Next Risk Is Not Naming The AI

    Most sophisticated filers are not going to submit applications naming a model as inventor and dare the office to reject them.

    The bigger risk is subtler.

    A company may name one or more human inventors, but later face questions about whether those humans actually conceived the claimed invention, or whether the claimed invention emerged from a workflow that was too tool-driven, too weakly documented, or too poorly understood to support the inventorship story.

    That can surface in several ways:

    • prosecution questions about inventorship corrections;
    • internal disputes among employees or collaborators;
    • diligence questions in financing or acquisition;
    • ownership fights between companies and departing personnel;
    • inequitable-conduct or invalidity allegations in litigation; and
    • credibility problems if the patent record suggests the humans were only lightly involved.

    The next phase is less about what the application says on its face and more about whether the human story behind it holds up.

    U.S. Doctrine Already Points Toward A Recognition Problem

    U.S. law offers a second reason this issue will matter.

    The Federal Circuit's decision in Thaler v. Vidal gives the statutory answer: an inventor must be a natural person.

    But older conception doctrine suggests something else too. In Silvestri v. Grant, a C.C.P.A. decision that remains part of the Federal Circuit's inherited patent-law precedent, the court drew a distinction between accidental duplication and actual recognition of the inventive subject matter. In Invitrogen Corp. v. Clontech Labs., Inc., the Federal Circuit said conception occurs when the inventor first appreciated what he made.

    That line of authority does not mean an inventor must know every embodiment will work. But it does reinforce a practical idea: merely producing an output is not the whole story.

    Patent law cares about recognition, appreciation, and conception of the inventive subject matter. That matters because many AI-assisted workflows can produce plausible technical outputs long before anyone has clearly identified which feature is actually inventive, what problem was solved, or how the output maps onto the eventual claim set.

    The USPTO Has Already Turned This Into A Practical Question

    The USPTO's February 2024 inventorship guidance for AI-assisted inventions gives U.S. patent practitioners a concrete operational frame.

    The guidance does not say AI-assisted inventions are categorically unpatentable. It says inventorship still turns on whether one or more natural persons made a significant contribution to the claimed invention, using the long-running Pannu v. Iolab framework as the baseline.

    That matters because it moves the issue out of abstraction and into claim-by-claim practice. The real question is not whether AI was used at all. It is which human contributed what, and whether that contribution was significant enough to support inventorship for the claimed subject matter.

    Generic statements like "the team used AI" or "the model suggested the solution" do not answer the question the guidance is pushing applicants to answer.

    The Human Story Needs More Than “We Used AI”

    Patent teams should expect that generic statements about AI assistance will not be enough.

    The real questions are more granular:

    • Who defined the technical problem?
    • Who framed or constrained the prompt, parameters, training inputs, or search space?
    • Who selected the useful output from many nonuseful outputs?
    • Who recognized why a particular output mattered?
    • Who translated that result into a concrete inventive concept?
    • Who decided what to claim and why?
    • Who refined the output into a patentable solution rather than an interesting suggestion?

    Those questions are not just litigation questions. They are invention-disclosure and drafting questions.

    If a team cannot answer them early, it will have trouble answering them later under pressure.

    Germany Offers The Most Practical Conceptual Model

    Germany may be the most helpful jurisdiction conceptually because it preserves the human-inventor rule while still recognizing that AI may have materially assisted the inventive process.

    The German Federal Court of Justice's reasoning is more precise, and more useful, than a loose summary suggesting the human contribution can be trivial. The court said attribution of inventor status "does not require a contribution with independent inventive content," but it also held that "a human contribution that has significantly influenced the overall success is sufficient for the status of inventor in a technical teaching that was discovered with the help of an artificial intelligence system."

    That is an important distinction. The human contribution does not need to be independently inventive in its own right, but it does need to matter.

    The court also observed that, "[a]ccording to the current state of scientific knowledge, there is no such thing as a system that searches for technical teachings without any human preparation or influence." It pointed to activities such as programming, data training, initiating the search process, and checking and selecting among proposed results as examples of qualifying human acts.

    That is closer to what real innovation looks like now.

    Most AI-related R&D is not a machine independently inventing in a vacuum. It is a mixed workflow involving researchers, models, simulations, prompts, iterations, selections, experiments, and downstream judgment calls.

    The legal system does not have to pretend AI played no role. But it will still ask who the legally relevant human contributor was.

    That is the operational lesson companies should take from the global cases. The world is not moving toward AI inventorship. It is moving toward human inventorship with a heavier documentation burden when AI was involved.

    What Companies Should Document Now

    The solution is not panic. It is recordkeeping that is specific enough to be useful later.

    For AI-assisted invention workflows, companies should consider documenting:

    • the problem statement or research objective;
    • the human team members directing the work;
    • the tools used and their role in the process;
    • the prompts, constraints, or design inputs that materially shaped the output;
    • the candidate outputs generated and why some were rejected;
    • the human judgment that identified the promising result;
    • the steps that turned the result into a concrete inventive concept;
    • when the team believed conception occurred; and
    • how the final claim strategy connects back to the named inventors' contributions.

    That does not require saving every keystroke forever. It does require enough evidence to show that the named inventors did more than supervise a black box from a distance.

    Patent Drafting Interviews Need To Change

    One practical implication is that patent drafting interviews should become more explicit about AI use.

    Instead of only asking what the invention is, counsel may need to ask:

    • where did the initial concept come from?
    • what did the model contribute?
    • what did the humans contribute before and after the model output?
    • which step actually produced the claimed inventive insight?
    • did the inventors understand why that step mattered at the time?

    That interview is no longer just about technical substance. It is also about inventorship defensibility. If the interview reveals that the named inventors mostly accepted machine-generated outputs without a clear conception story, that is a warning sign worth addressing before filing.

    Bottom Line

    After DABUS, the main patent-law fight is no longer whether an AI system can be named as inventor.

    It is whether the humans on the application can prove they are the right inventors when AI materially shaped the path to the result.

    For companies using AI in R&D, that makes inventorship less of a naming problem and more of a governance, evidence, and workflow problem.

    The organizations in the strongest position will not be the ones that deny AI played a role. They will be the ones that can explain exactly how human inventors used AI and why the legally relevant inventive contribution still belongs to them.

    Sources

  • AI Privilege Risk Is Becoming a Workflow Problem, Not Just a Confidentiality Warning

    AI Privilege Risk Is Becoming a Workflow Problem, Not Just a Confidentiality Warning

    For a while, the standard legal-AI warning sounded simple:

    Do not put privileged or confidential information into public AI tools.

    That warning is still right. It is also no longer enough.

    Recent federal decisions suggest that AI privilege and work-product issues are turning into workflow questions. Courts are not just asking whether AI was used. They are asking what tool was used, who used it, under whose direction, on what material, with what confidentiality protections, and whether discovery or protective-order obligations changed the analysis.

    That is a much more operational problem than a generic confidentiality lecture.

    The Short Answer

    • AI does not create one uniform privilege or work-product rule.
    • Courts are splitting at least three separate questions: whether confidentiality was lost, whether work-product protection survived, and whether a protective order independently restricted the upload.
    • The practical risk is shifting from abstract “AI waiver” language to concrete questions about tool choice, confidentiality, discovery material, and who approved the use.

    The Cases Are Not Moving In One Direction

    The early federal decisions do not create one simple rule.

    In United States v. Heppner, the Southern District of New York rejected privilege and work-product claims tied to a criminal defendant's use of a consumer AI tool outside counsel's direction.

    In Warner v. Gilbarco Inc., the Eastern District of Michigan treated a pro se civil plaintiff's AI-related materials as protected work product and rejected the idea that AI use automatically destroyed the protection.

    In Morgan v. V2X Inc., the District of Colorado reportedly protected AI-assisted work product but still required disclosure of the AI tool identity and amended the protective order around AI use.

    In Jeffries v. Harcros Chemicals Inc., the District of Kansas approved protective-order restrictions on open AI tools for discovery materials based on retention, training, deletion, privacy, security, and clawback concerns.

    That is the pattern to focus on. The cases are not asking whether AI is good or bad. They are sorting AI use into different legal buckets based on workflow facts.

    That split is the point. A team can lose on confidentiality and privilege, still argue about work product, and separately face protective-order limits on what can be uploaded. It can preserve work-product protection and still be ordered to identify the tool or comply with AI-specific restrictions on discovery material. Treating all of that as one generic waiver question hides the real problem.

    The New Question Is “What Exactly Happened?”

    When AI becomes part of litigation work, the risk analysis turns on details such as:

    • Was the tool public, consumer-facing, or enterprise?
    • Did the platform reserve rights to retain, review, or train on the material?
    • Was the use directed by counsel?
    • Was the material privileged, attorney work product, or discovery produced under a protective order?
    • Did the user expose legal theories or mental impressions?
    • Is the identity of the tool itself discoverable?
    • Did a protective order prohibit or restrict uploads?

    Those are workflow questions. A legal department or law firm cannot answer them well if its internal policy is just “use AI carefully.”

    Privilege, Work Product, And Protective Orders Are Separate Questions

    Another reason the workflow framing matters is that privilege, work product, and protective-order restrictions are not the same issue.

    Attorney-client privilege turns heavily on confidentiality and protected communications made for the purpose of obtaining or providing legal advice. Work product turns on anticipation of litigation, mental impressions, and whether the disclosure was made in a way that substantially increases the likelihood the material will reach an adversary.

    Protective-order restrictions can cut across both. A court may not need to decide that privilege was waived or work product was destroyed before it limits the use of public or open AI tools on produced material.

    That means an AI workflow can create different results across the three lanes. One use pattern may be disastrous for privilege because it undermines confidentiality, while still leaving room for work-product arguments in some civil settings. Another use pattern may preserve internal confidentiality but run straight into a protective-order problem if discovery material was uploaded into a tool that the order does not permit.

    The practical lesson is that “AI waiver” is often the wrong level of abstraction. Teams need to ask which doctrine or restriction is at issue and how the actual workflow maps onto it.

    Protective Orders May Become The Fastest Constraint

    The protective-order cases may be the most immediately important for everyday litigation.

    Even when courts do not say AI use destroys privilege or work product automatically, they may still restrict what can be uploaded into public or open AI tools. That is especially true for discovery material, confidential business information, and materials produced subject to Rule 26(c) orders.

    That makes protective orders one of the fastest ways AI use gets limited in practice.

    Counsel may find that the immediate issue is not abstract doctrine, but whether the governing order:

    • bans public AI tools entirely;
    • bans AI uploads for confidential materials only;
    • permits only closed enterprise tools;
    • requires notice or agreement before AI use;
    • distinguishes between model providers and internal review tools; or
    • treats tool identity as discoverable information in later disputes.

    In many matters, the protective order will be the first real AI policy that matters.

    The Real Failure Mode Is Operational Drift

    Most teams do not deliberately decide to waive privilege.

    The more common failure mode is operational drift.

    Someone uses a familiar public tool to summarize notes. A client pastes in sensitive facts without realizing the downstream implications. A pro se litigant relies on a chatbot to organize case strategy. A discovery team uses AI summarization before anyone asks whether the protective order permits it. Outside counsel and client assume the other side checked the tool terms.

    Each step looks small on its own. Together, they can create a record that is hard to defend later.

    That is why the problem is now better understood as workflow design. If the workflow does not force the right questions early, the doctrine gets tested later under bad facts.

    What A Better AI Litigation Workflow Looks Like

    A usable workflow should answer at least five questions before AI gets used in a matter:

    1. What kind of material is involved? Privileged communications, counsel work product, confidential discovery, trade secrets, personal data, and public material should not all be treated the same way.

    2. What kind of tool is being used? Consumer/public AI, enterprise AI, vendor-hosted tools, internal models, and matter-specific review tools carry different risk profiles.

    3. What do the tool terms say? Retention, training, deletion, human review, security, auditability, and downstream sharing matter.

    4. What do the court orders and client instructions say? Protective orders, outside-counsel guidelines, engagement terms, and client policies may impose stricter limits than the general law.

    5. Who owns the decision? Someone needs to decide whether a particular AI use is allowed, defensible, and documented.

    Without those checkpoints, telling people to "use AI carefully" is not much of a governance system.

    What Firms And Legal Departments Should Do Now

    Legal teams should consider:

    • separating rules for public AI, enterprise AI, and discovery-review tools;
    • prohibiting public-tool use for privileged, confidential, or discovery-protected material unless expressly approved;
    • building matter-opening questions around AI use, tool type, and protective-order restrictions;
    • reviewing outside-counsel guidelines and client instructions for AI-specific terms;
    • preserving enough workflow information to answer later questions about what tool was used and why;
    • training lawyers and staff on the difference between privilege, work product, and protective-order risk; and
    • updating protective-order negotiation positions to address open versus closed AI tools explicitly.

    This is one of those areas where governance that sounds boring is actually what keeps the problem from becoming urgent later.

    Bottom Line

    AI privilege risk is no longer just a warning about confidentiality.

    It is becoming a workflow problem shaped by tool choice, user role, litigation posture, protective-order language, and the facts of how the system was used.

    The early cases do not say “AI always waives protection.” They say something harder and more useful: the legal result depends on what actually happened.

    That means firms and legal departments need workflows that can answer those questions before a court does.

    Sources

  • Can AI Be Named as an Inventor? The Global Patent Answer Is Still Mostly No

    Can AI Be Named as an Inventor? The Global Patent Answer Is Still Mostly No

    If the question is whether a patent office will let you name an AI system as the inventor, the global answer is now mostly settled: no.

    That does not mean AI-assisted inventions are automatically unpatentable. It means patent systems still want a human being on the inventorship line.

    Across the United States, the United Kingdom, the European Patent Office, Australia, Germany, and Japan, the trend is the same. Courts and patent authorities have treated inventorship as a status reserved for a natural person, even when AI played a substantial role in generating the claimed idea.

    That is why the real issue has changed. The headline fight over naming "DABUS" or another model as inventor is fading. The practical fight is about something harder: when AI is deeply embedded in R&D, which human contribution is enough to support inventorship?

    The Short Answer

    • Major patent systems still require a human inventor.
    • AI can assist with invention, but it cannot take the inventor slot itself in the jurisdictions that matter most for examined patent systems.
    • The real legal risk is shifting toward proof: can the company show which human recognized, shaped, and claimed the inventive concept?

    The Global Rule Is Converging

    The DABUS litigation campaign forced a basic question into multiple patent systems: can an autonomous AI system be listed as the inventor on a patent application?

    At this point, the answer from the leading jurisdictions has largely converged.

    In the United States, the Federal Circuit held in Thaler v. Vidal that "individual" in the Patent Act means a natural person. In the United Kingdom, the Supreme Court held that only a natural person may be an inventor and that owning the AI system does not itself create entitlement to a patent. The European Patent Office took the same position in its DABUS appeal decisions, reasoning that the inventor designation must identify a person with legal capacity.

    Australia ultimately joined that group after its Full Federal Court reversed a lower-court ruling that had briefly accepted AI inventorship. Germany and Japan have now reinforced the same direction through court decisions holding that existing patent law requires a human inventor.

    Put simply, the center of gravity is no longer moving toward AI inventorship. It is moving toward human-only inventorship plus growing acceptance that AI may still be used in the inventive process.

    U.S. Law Also Has An "Appreciation" Thread

    The U.S. argument against AI inventorship is not limited to the statutory holding in Thaler v. Vidal that an inventor must be a natural person.

    There is also an older inventorship and conception line of cases suggesting that patent law does not treat bare production of a result as enough. In Silvestri v. Grant, the C.C.P.A. said that "an accidental and unappreciated duplication of an invention does not defeat the patent right of one who, though later in time, was the first to recognize that which constitutes the inventive subject matter."

    That is a useful line in the AI context. It suggests inventorship is tied to recognition of what the invention is, not just mechanical generation of an output.

    The Federal Circuit echoed that logic in Invitrogen Corp. v. Clontech Labs., Inc. when it stated that "[t]he date of conception of a prior inventor's invention is the date the inventor first appreciated the fact of what he made." In that same decision, the court said the district court had "misapplied the law of appreciation when dating conception."

    Again, the point is not simply that something existed in the lab. The doctrine asks whether the inventor appreciated the inventive subject matter. That gives human-only inventorship another doctrinal footing. Even apart from the statutory word "individual," there is a strong argument that current AI systems do not appreciate or recognize the inventive subject matter in the legal sense reflected by U.S. conception doctrine.

    There is an important limit, though. This line should not be overstated as a requirement that the inventor know the invention will work. In Regents of the University of California v. Broad Institute in 2025, the Federal Circuit said the Board erred by requiring inventors "to know their invention would work to prove conception." So the safer formulation is narrower: U.S. law contains authority tying conception to appreciation or recognition of the invention, but not a broad rule that conception requires certainty of operability.

    Germany Shows The Important Nuance

    Germany may be the most useful jurisdiction for understanding where the law is going next.

    The German Federal Court of Justice held in June 2024 that only a natural person can be named as inventor. But German practice also recognizes a practical middle ground: the application may describe that artificial intelligence assisted the inventive process, so long as a human being is still identified as the inventor.

    That is a much more realistic model for current innovation workflows, and it is why Germany is more interesting than a simple "AI cannot be an inventor" headline.

    Most modern AI-related R&D does not look like a robot independently walking into a patent office. It looks like human researchers using large models, design tools, optimization systems, coding assistants, lab automation, and simulation software as part of a broader inventive process. Germany's approach does not collapse that reality into a fiction that AI was irrelevant. It simply keeps the legal act of inventorship attached to a person.

    That distinction is likely to matter more than the headline "AI cannot be an inventor." Companies need to document who framed the problem, selected the inputs, recognized the result, decided what was actually inventive, and reduced the concept into a patentable claim strategy.

    Japan Suggests The Human-Inventor Rule Is Hardening

    Japan is another sign that the human-inventor requirement is hardening rather than softening.

    According to the Intellectual Property High Court's January 30, 2025 judgment, current Japanese patent law recognizes patent rights and procedures only where a natural person is the inventor. The result fits the same structural logic seen elsewhere: inventorship is tied not only to creativity, but also to legal entitlement, procedure, and the ability to hold rights.

    For multinational filers, that matters because Japan is not a marginal jurisdiction. When Japan aligns with the United States, United Kingdom, EPO, Germany, and Australia, the compliance answer for global filing strategy becomes much clearer.

    South Africa Is The Exception, But A Narrow One

    The most commonly cited exception is South Africa, where a patent listing DABUS as inventor was granted.

    That fact is real, but it should not be overstated.

    South Africa's patent system does not generally conduct the same kind of substantive examination that gives decisions in the United States, United Kingdom, EPO, Japan, Germany, or Australia their doctrinal weight. So the South African grant is important as a data point, but weak as a predictor of where major patent systems are heading.

    For practical global strategy, South Africa does not outweigh the much broader line of examined-office and appellate authority rejecting AI-only inventorship.

    What This Means For Patent Strategy

    The operational issue is shifting from "Can we name the AI?" to "How do we prove the right human inventorship story?"

    That requires more than a casual statement that employees used AI in the workflow. Patent teams should expect harder questions about human contribution when AI systems are used to generate options, propose structures, draft code, optimize designs, or identify potential solutions.

    Key questions include:

    • Who defined the problem the system was solving?
    • Who selected or constrained the prompts, parameters, data, or design space?
    • Who recognized which output was meaningful rather than random?
    • Who translated a machine output into the claimed inventive concept?
    • Who made the decisions reflected in the final claim set?

    Those questions already existed in inventorship doctrine in different forms. AI just makes them less theoretical and much more urgent.

    For many companies, the right response is process, not panic: stronger invention-disclosure forms, better records of human decision-making, clearer internal guidance on AI-assisted ideation, and patent-drafting interviews that specifically test whether the named inventors actually conceived the claimed subject matter.

    The Next Debate Is Not Whether AI Can Sign The Form

    The next debate is likely to be about threshold and attribution.

    Courts have mostly answered the simple question of formal inventorship. They have not fully answered the harder one: how much human contribution is enough when AI systems materially shape the output?

    That is where future disputes are likely to emerge. Not in applications brazenly naming a model as inventor, but in challenges arguing that the listed humans did too little, or that inventorship was assigned to the wrong people because the real inventive contribution came from a tool-assisted workflow that no one documented carefully.

    In other words, the formal battle over naming AI may be ending just as the evidentiary battle over human inventorship is beginning.

    Bottom Line

    Globally, the dominant patent-law answer is now clear: AI can help with invention, but AI cannot itself be the inventor in the major jurisdictions that have squarely confronted the question.

    For companies, that is not a ban on AI-assisted innovation. It is a documentation and inventorship-governance problem. The organizations in the strongest position will be the ones that can show exactly how human inventors used AI and why the named inventors still satisfy the law.

    Sources

    Sources

  • FTC’s AI Accuracy Proposal Turns Model Steering Into a Consumer-Protection Issue

    FTC’s AI Accuracy Proposal Turns Model Steering Into a Consumer-Protection Issue

    The Federal Trade Commission's proposed AI accuracy policy statement is not mainly about hallucinations. It is about consumer expectations, model objectives, and undisclosed steering.

    The Commission's theory is that AI companies often market their systems as tools that try to produce the best, most useful, truthful, or accurate output for the user's stated objective. If a company secretly steers the system toward a different objective, the FTC says that may be deceptive under Section 5 of the FTC Act.

    That framing matters because it moves some AI alignment, ranking, suppression, and output-design questions into consumer-protection territory. The proposed statement also takes aim at state AI laws, especially Colorado's revised AI Act, by warning that state-law-driven output changes may still violate Section 5 and may be impliedly preempted if they require deception.

    This is only a proposed policy statement. It is not a final rule, not an enforcement order, and not a litigated holding. But it is still important because it previews how the FTC may analyze AI systems that claim objectivity or accuracy while pursuing undisclosed output objectives.

    What The FTC Proposed

    The FTC issued the proposed policy statement on July 1, 2026. The agency is seeking public comment through July 31, 2026.

    The proposal says consumers reasonably expect AI systems to aim for truthful and accurate outputs that faithfully serve users' stated objectives and the built-in objectives users would reasonably expect from the system.

    The FTC is not saying that every wrong answer is automatically a Section 5 violation. The proposal distinguishes ordinary AI errors or hallucinations caused by technological and resource limits from intentional design choices that suppress accuracy or steer outputs toward unexpected objectives.

    The target is different: undisclosed steering away from the user's expected objective.

    In the FTC's words, an AI company may deceive consumers if it steers AI outputs toward unexpected objectives and away from the objectives set by or reasonably expected by users.

    Why This Is A Deception Theory

    The proposed statement rests on familiar FTC deception principles.

    Under the FTC's deception framework, a practice may be deceptive if there is a representation, omission, or practice likely to mislead reasonable consumers in a material way. The FTC says AI companies can make explicit and implicit representations that their systems are designed to solve users' problems accurately and faithfully.

    Those representations do not have to be magic words. A company may create the same impression through product positioning, accuracy claims, reliability claims, enterprise sales materials, public documentation, benchmark messaging, or statements that the AI is a trusted assistant, truth-seeking system, research tool, or decision-support product.

    If the company then silently optimizes the system for a conflicting objective, the FTC's theory is that consumers may be misled about what they are using and paying for.

    That does not mean an AI system can pursue only one objective. The proposal acknowledges that users may reasonably expect a system to balance accuracy, relevance, clarity, succinctness, safety, formatting, and other product objectives. The legal issue is whether a hidden objective contradicts the claim or consumer expectation that the system is trying to provide the best answer for the user's purpose.

    The Colorado Preemption Signal

    The most aggressive part of the proposal is its treatment of state AI laws.

    The FTC specifically discusses Colorado's AI framework and says an AI company might be tempted to suppress accuracy or interpose other objectives to avoid liability under state law. The Commission then says a company's motive for deception is irrelevant under Section 5, even if the company is acting to comply with state law.

    The proposal goes further: although the FTC Act does not expressly preempt state law, the Commission says state law is impliedly preempted to the extent it conflicts with a federal regulatory scheme. In the FTC's view, a state law that requires an AI firm to deceive consumers would conflict with Section 5's purpose of protecting consumers from deception.

    That is a major federalism signal, not just an AI-marketing point.

    Colorado is already in the middle of AI rulemaking and litigation. Its revised automated decision-making law and chatbot safety law are headed toward implementing rules, while xAI's federal challenge and DOJ's intervention have put the state framework under constitutional pressure.

    The FTC proposal adds another pressure point: even if a state law survives other challenges, the FTC may argue that compliance choices cannot be implemented through undisclosed output manipulation.

    Disclosures May Help, But They Need To Be Real

    The proposal does leave room for disclosure.

    An AI company can shape consumer expectations by truthfully explaining that its system prioritizes objectives different from the user's requested or expected objective. But the FTC says that disclosure would need to be clear and conspicuous enough to change the net impression.

    A buried term in a terms-of-service document is unlikely to do the job. The more the disclosure contradicts the system's marketing, interface, or ordinary value proposition, the more prominent and persistent the disclosure may need to be.

    That matters for product and governance teams. If a model is designed to rank, refuse, demote, rewrite, prioritize, or suppress outputs based on objectives that users would not expect, the disclosure question is not just whether the company has a policy somewhere. It is whether the user is likely to understand the product's actual objective at the moment the user relies on it.

    What This Is Not

    The proposal should not be overread in three ways.

    First, it is not a final rule. It is a proposed policy statement for public comment. The final language could change, and courts are not bound by the FTC's policy framing.

    Second, it is not a general ban on safety controls, content limits, cybersecurity restrictions, or refusal behavior. The proposal expressly recognizes that reasonable consumers would not expect systems to output certain illegal material, and it says nothing should be read to prohibit use limits that prevent cybersecurity attacks.

    Third, it is not a strict-liability rule for AI hallucinations. The proposal distinguishes intentional steering from ordinary incorrect outputs caused by model limitations. Companies can still face risk if they misrepresent hallucination rates or accuracy, but the policy statement's central concern is hidden objective substitution.

    Practical Questions For AI Companies

    Companies operating AI systems should treat the proposal as a prompt to audit objective, accuracy, and neutrality claims.

    Useful questions include:

    • What does the company expressly say about accuracy, truthfulness, objectivity, neutrality, reliability, helpfulness, or user control?
    • What does the interface imply about whether the system is trying to answer the user's actual question?
    • Are there hidden system objectives that can override the user's expected objective in ways that materially change output?
    • Are those objectives disclosed clearly enough for the relevant use case?
    • Are refusal, ranking, suppression, personalization, safety, and compliance policies documented and tied to defensible product rationales?
    • Do enterprise customers receive a different explanation than end users?
    • Do state-law compliance controls change outputs in a way users would not expect?
    • Does the company have evidence supporting claims about accuracy, reliability, model behavior, and output controls?

    The documentation point is especially important. If a regulator asks why a system suppressed, altered, or prioritized certain outputs, the company should be able to show the governing policy, the consumer-facing explanation, the product rationale, and the testing record.

    Why Enterprise Buyers Should Care

    The proposal is not only a model-provider issue.

    Enterprise buyers increasingly rely on AI systems for research, customer service, knowledge management, legal workflows, HR support, financial analysis, education, health information, and other consequential contexts. If an AI vendor's system is secretly optimized for objectives the buyer does not understand, the buyer may inherit operational, compliance, and customer-facing risk.

    Procurement teams should ask vendors how they define accuracy, what objectives can override user instructions, how output policies are disclosed, whether customers can configure those policies, and what logs or documentation are available when an output is challenged.

    For regulated buyers, the question is simple: if the AI system is not trying to answer the user's question in the way the user reasonably expects, who knows that, who approved it, and where is it disclosed?

    Bottom Line

    The FTC's proposed AI accuracy policy statement turns hidden model steering into a consumer-protection issue.

    The proposal does not say every AI error is unlawful. It says companies may deceive consumers when they market AI systems as accurate, objective, or faithful to user goals while secretly steering outputs toward different objectives.

    That is a useful warning even before the statement is final. AI governance should not stop at whether a system is powerful or safe. It should also ask whether the system's actual objective matches what users are told.

    Sources

    Sources

  • EU AI Act Transparency Code Turns AI-Generated Content Labels Into Compliance Work

    EU AI Act Transparency Code Turns AI-Generated Content Labels Into Compliance Work

    The European Commission has published the final Code of Practice on marking and labelling AI-generated content.

    The Code is voluntary. Article 50 of the EU AI Act is not.

    That distinction is the whole story. The Code does not create a new legal duty, and it does not replace the AI Act or the Commission's forthcoming Article 50 guidelines. But it gives providers and deployers of generative AI systems a practical framework for showing how they plan to meet transparency obligations that start applying on August 2, 2026.

    For companies, this is not just a question of adding a watermark. It is a governance project involving content provenance, machine-readable marking, deepfake labels, public-interest text, user notices, human review, editorial responsibility, and evidence of compliance.

    For broader AI law tracking context, see Clearon's Laws, Bills & Regulations page.

    What The Code Covers

    The Code has two main sections.

    Section 1 is for providers of generative AI systems. It addresses marking and detection of AI-generated or manipulated audio, image, video, and text content. The Commission's materials describe the focus as machine-readable solutions that are effective, interoperable, robust, and reliable as far as technically feasible.

    Section 2 is for deployers of generative AI systems. It addresses labelling of deepfakes and AI-generated or AI-manipulated text published for the purpose of informing the public on matters of public interest.

    The EU has also published optional icons that deployers may use for AI-generated-content labels.

    That provider/deployer split matters. Some organizations will sit on both sides. A company that offers a generative AI system may have provider obligations. The same company may also be a deployer when it uses generative AI to publish or distribute content.

    What Starts On August 2, 2026

    The Commission says Article 50 transparency obligations for providers and deployers in scope will apply from August 2, 2026. AI systems placed on the market before that date get a transitional period until December 2, 2026.

    From August 2, key obligations include clear labelling in certain cases. Deepfakes and AI-generated or AI-manipulated text published on matters of public interest must be clearly labelled. Users must also be informed when they are interacting with an interactive AI system, such as a chatbot.

    Those requirements are broader than a technical watermarking problem. They require companies to know what content they generate, where it travels, who publishes it, whether the publication is about a matter of public interest, and whether human review or editorial responsibility changes the compliance analysis.

    Why A Voluntary Code Still Matters

    The Code is voluntary, but signing it can matter.

    The Commission says that, after a positive adequacy assessment by the Commission and the AI Board, providers and deployers that sign the Code can rely on its measures to demonstrate compliance with the AI Act's transparency rules for labelling and detection of AI-generated content, deepfakes, and certain text publications.

    By contrast, companies that comply through other means will have to show that their measures are adequate. Those alternative measures may be assessed individually by different market surveillance authorities.

    That creates a practical choice. Signing the Code may offer predictability and a common EU-wide evidence path. Not signing may preserve flexibility, but companies will need their own substantiated compliance record.

    Either way, the work has to be done.

    What Remains Pending

    The Code is not the last word.

    The Commission says the Code is undergoing adequacy assessment by the Commission and the AI Board. It will also be complemented by Commission guidelines on the scope and implementation of Article 50.

    Those guidelines are expected ahead of August 2, 2026. The Commission says they will clarify which providers, deployers, and AI systems are covered; what types of AI-generated or manipulated content fall within scope; how the obligations should be applied in practice; and how compliance may be demonstrated, including through a Code deemed adequate by the Commission and the AI Board.

    That means companies should not treat the Code as a final standalone compliance manual. They should treat it as the first concrete implementation framework and then reconcile it with the final guidelines when they are published.

    The Compliance Workstream

    Companies should start with an inventory.

    For providers, the inventory should identify which systems generate audio, image, video, or text outputs; what marking or detection methods are already used; whether those methods are machine-readable; and whether they are effective, interoperable, robust, and reliable enough to defend.

    For deployers, the inventory should identify where the organization publishes or distributes AI-generated or AI-manipulated content, including marketing content, public reports, news-like content, social posts, synthetic audio or video, and content that may qualify as public-interest text.

    The harder questions are operational:

    • Who decides whether content is a deepfake?
    • Who decides whether text informs the public on a matter of public interest?
    • What counts as sufficient human review?
    • What records show that editorial responsibility exists?
    • Where should labels, disclaimers, or icons appear?
    • How will labels survive syndication, reposting, formatting changes, or downstream distribution?
    • How will product, legal, trust and safety, marketing, and publishing teams coordinate?

    Those questions should not wait until August 2026.

    What Companies Should Do Now

    A practical Article 50 readiness plan should include:

    • mapping provider and deployer roles for each generative AI system and content workflow;
    • identifying AI-generated and AI-manipulated audio, image, video, and text outputs;
    • documenting existing watermarking, metadata, provenance, detection, and labelling controls;
    • deciding whether the company is likely to sign the Code;
    • tracking the Commission and AI Board adequacy assessment;
    • tracking the final Article 50 guidelines;
    • designing labels, disclaimers, or icons for relevant content types;
    • creating rules for deepfakes, public-interest text, human review, and editorial responsibility;
    • testing whether labels remain visible and understandable across distribution channels; and
    • keeping evidence that the organization evaluated and implemented proportionate transparency controls.

    The key is to treat AI-generated-content transparency as a cross-functional compliance process, not a last-minute design ticket.

    Bottom Line

    The EU AI Act transparency Code turns Article 50 from an abstract deadline into a working plan.

    The Code is voluntary, but it points to the evidence regulators may expect: provider-side marking and detection, deployer-side labelling, clear treatment of deepfakes and public-interest text, and a record showing how the organization chose and implemented its controls.

    Companies do not need to wait for the final guidelines to start the inventory. By the time Article 50 applies, the hard part will not be knowing that labels are required. It will be proving that the right content was identified, labelled, marked, reviewed, and documented.

    Sources

    Sources