The leak, the legal protection and the policy that lets your team use AI safely.
Dropping the wrong data into AI could destroy your legal rights to IP (trade secrets are only protected as long as you take reasonable steps to keep it secret).
So does that mean your team can’t or shouldn’t use AI?
No. Jacques Stemmet is a senior associate at Dommisse Attorneys, where he runs the IP and trademark practice. And he knows how you can let the team use AI in a way that still protects your IP…
The move: control what data goes into which tools
The answer isn’t to ban AI; that just drives it underground. It’s to be deliberate about what data may go into which tools, so your team keeps the productivity without feeding your secrets to a model that might learn from them.
“If you put your source code into a free AI model, it can be used to train the model. You’ve arguably failed to take reasonable steps to keep it secret.”
How to use AI without leaking your secrets
1. Understand that free tools can train on what you paste
The core issue is what happens to your data after you hit send. Many free, consumer-tier AI tools reserve the right to use what you input to train their models. Your confidential input becomes part of the system — potentially surfacing, in some form, to other users.
That’s the mechanism founders miss. It’s not that the tool is malicious; it’s that the free tier’s terms often let it learn from your data. Once you understand that, the risk of pasting in anything confidential becomes obvious.
2. Move sensitive work onto enterprise tiers
The fix isn’t to stop using AI; it’s to use the right version of it. Paid enterprise and business tiers of the major AI tools generally commit not to train on your data, which changes the risk picture entirely.
For anything sensitive (source code, client data, unreleased plans) route the work through an enterprise tier with the right data terms. It’s a small cost against the value of the IP you’re protecting, and it lets your team keep moving fast without the leak.
3. Write a simple AI usage policy
Your team can’t follow a rule they’ve never been given. Put a short, clear AI usage policy in place: which tools are approved for what, what data may never go into a free tool, and where to take sensitive work instead.
Keep it practical, not a lecture: a page people will actually read and follow. “Source code and client data only go into our enterprise tool, never a free one.” That one line, understood by the whole team, closes off the most common way this IP leaks.
The big payoff
Get this right, and your team keeps all the speed AI gives them without quietly bleeding the IP that makes the business worth something. Your trade secrets stay legally protected, your client data stays compliant, and you’ve closed a gap most of your competitors don’t even know they have.
It costs you an enterprise subscription and a one-page policy. It protects the assets a buyer or investor will scrutinise most when it matters most.
You might also be interested in
Want the full playbook?
This is one piece of What You Own vs What You Think You Own, Jacques’s full masterclass inside the Founder Collab. The full session walks through the complete system for proving and protecting your IP:
The full IP Control Stack: the five layers that decide whether your ownership holds up
How to actually own the code you paid a contractor to build
When to use a patent, a trade secret or a trademark and how to let your business model decide
Whether you own what your AI made and what SA law says about it
What “good enough” IP hygiene looks like at pre-seed, seed and growth stage
You’ll also get access to 40+ other masterclasses from SA founders and operators on sales, fundraising, UX, paid media and more inside The Founder Collab.
Get more SA tech and business news, tips and business-building workflows and subscribe to The Open Letter.



