Artificial intelligence (AI) may be transforming how we work with information, but it’s also raising a number of questions as to what we ‘own’ – both as to what goes in, and what comes out.

For instance, the Productivity Commission’s interim report into Harnessing Data and Digital Technology identified that restrictions on the use of ‘text and data’, particularly those imposed by copyright law, may impede the advancement of AI, despite the Commission’s assessment that such innovation could deliver strong economic benefits to Australia. Arts and media groups have strongly challenged this position, concerned that these new technologies may exploit artistic content without appropriate attribution or compensation, and without many Australians being any the wiser.

These developments create a number of challenges for businesses developing or procuring AI. There is a tension between taking up the opportunities of these new technologies in a rapid, frictionless manner and the need to manage ownership of key information, both the information organisations put into AI tools (inputs) or generate from AI tools (outputs), and the information used to create those tools in the first place (training data).

This article outlines the status of inputs, outputs and training data in Australian intellectual property (IP) law, offering practical steps for businesses to protect their IP when using or developing AI products.

Rights in data – who owns the data we collect or produce?

Under Australian law, data (whether an input or output) is not classified as property. This is because information is fundamentally fungible, unlike physical assets such as say a house or a car. Rather, ownership of data is governed at the complex intersection of:

Creating some rights and protections in favour of individuals over data that is also personal information. However, this will only apply to a subset of data, being “personal information” (data that can identify someone), meaning a lot of data or code may not be covered by the Privacy Act at all.

For example, a spreadsheet of customer data including names, email addresses and phone numbers will generally be personal information under the Privacy Act. But, a list of customer phone numbers may not be personal information, provided you can’t reasonably identify someone from that number.

Creating some kind of ownership over certain kinds of information. Copyright is particularly relevant when dealing with data, given it, among other things, protects 'literary works'. These cover the unique expression of a range of common data types (e.g. Excel spreadsheets, CSVs, JSON, etc.), as well as code, in a ‘material form’ (i.e. written down), and protects that data/code from being used without the owner’s permission.

For example, raw datapoints are not protected by copyright. However, the underlying expression of that data, such as in a novel database (e.g. a unique description or creative selections/arrangement) may be protected.

Granting ‘personal’ rights which can be exercised against a counterparty. These can include requirements for data to be used or protected in a certain way, including confidentiality obligations, but will fundamentally depend on the specific arrangements agreed to by the relevant parties. 

For example, purchasing a new human resources information system will involve a set of terms and conditions. These may set out conditions as to the kinds of information that can be processed via that system, such as to provide the system, and to permit the supplier to run some general system analytics.

IP rights in AI tools – who owns a developed model?

This complexity applies both to organisations holding a dataset, and to those developing AI tools.

Assuming the source code of an AI tool has not been substantially copied from another, and the source code was written by an individual developer, then it is likely that the individual developer will own copyright in the source code that enables the AI tool to run.  This extends to the source code giving effect to the mathematical ‘model’ used by that AI tool to process inputs and generate outputs.

Whether an organisation owns the copyright for an AI tool depends on the contracts it has with individual developers. For example, employment or contractor agreements may include terms requiring that any copyright created is automatically assigned to the organisation at the time of creation. The ‘owner’ may also seek additional protections, such as a patent or a design registration to protect new innovative AI tools or unique user experiences.

However, an AI tool’s model will also rely on a large amount of training data. These are specific inputs that are used to teach the model how to handle new and unexpected situations, with ownership, or rights to use, each training input being governed by each of the above restrictions.

This is precisely the scenario identified by the Productivity Commission, which proposes expanding ‘fair dealing’ exceptions to copyright, currently only for research and study purposes, to permit the broader training of AI tools from text and data.

Inputs and outputs – an example

Given the above, ownership of inputs and outputs will depend on the specific arrangements in place for a given business, and the AI tool it looks to use. For example:

We note these rights are somewhat unclear however given copyright protection in Australia requires a work to be original, involving some exertion of independent intellectual effort by a human. To that end, there is an open question as to whether outputs are deemed to have been created by a human with the assistance of an AI tool, or by the AI tool itself. The prevailing view however is that the human them self (or their employer or principal, depending on the context) will be the ‘owner’ of that work.

Furthermore, even if you do ‘own’ that output, there is a risk the output could reproduce or echo substantial parts of other copyrighted works (e.g. existing artwork). This may amount to an infringement of the copyright in that other work.

How can you manage your data?

Considering the complex state of data ownership in Australia, businesses need to understand both how their data will be used by AI tools they procure, and how to protect data they use to create those AI tools in the first place.

For developers, it’s important to:

When procuring AI tools, it’s important to:

In either case, it is also critical to ensure alignment with community expectations regarding the use of AI, such as the expectations set out in Australia’s voluntary AI safety standard and AI ethics principles.  While these are not strict legal requirements, they reflect the need to use emerging technologies, and manage inputs and outputs responsibly, noting the potential for significant harm where these tools are developed or deployed carelessly.

We understand that staying on top of new and emerging technologies is an ongoing challenge. To support you on your journey with AI, our team has prepared this useful take away reference document that summarises the key risks and considerations when developing or procuring new AI tools.

Our team will keep sharing AI tips and updates in 2026. In the meantime, please do not hesitate to contact us if your team is working through these requirements or looking for guidance on how to manage AI responsibly.

Insights

This update does not constitute legal advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. You should seek legal or other professional advice before acting or relying on any of the content.