Back to Home

Solutions · Software & engineering

Keep the velocity. Keep the source.

Banning AI coding help doesn't stop it. It moves it to personal accounts. The teams shipping fastest are the ones pasting the most, so the control has to travel with the paste.

The duty you carry

What leaves in a debugging prompt is rarely just code: it's credentials, internal hostnames, customer data riding in logs, and the algorithms your valuation rests on. Trade-secret protection lasts only as long as reasonable secrecy measures do; confidentiality clauses with your customers assume them; patent novelty can be undermined by disclosure before filing. And an approved exception is not a safeguard: in January 2026 the acting head of the US Cybersecurity and Infrastructure Security Agency was granted a waiver from his department's AI block and uploaded documents marked "For Official Use Only" to public ChatGPT (Ars Technica, 2026).

The moment it breaks

Synthetic example. The real version happens on your busiest day.

TypedWhy does this leak memory under load? function acquireSlot(tenantId) { … } Runs on db-prod-04.internal with api_key=sk_live_9f2c44d1a8b3.
SentWhy does this leak memory under load? [CODE] Runs on [HOST] with [SECRET].

The debugging help still arrives. The key, the host, and the proprietary implementation stay home, and the event is on the record.

Caught, in your vocabulary

Credentials and keys

API keys, tokens, and connection strings that grant access to whoever sees them.

Proprietary source and designs

The implementations and architecture your differentiation, and valuation, rest on.

Infrastructure and customer data

Internal hostnames, configs, and the customer records that ride along in logs and stack traces.

The rules you answer to

01

Trade secrets

Protection depends on reasonable secrecy measures. A prompt-level control is such a measure, and its event log is the evidence.

02

Customer contracts

NDAs, DPAs, and security addenda promise customer data won't flow to unapproved processors. An AI tool on a personal account is exactly that.

03

Patent strategy

Public disclosure before filing can compromise novelty. What never leaves the building can't start the clock.

Also relevant: EU AI Act · NIST AI RMF

Answers for your situation

All guides

Governance in practice

Our interns and co-op students use their personal AI accounts for work. What should we do?

Assume they will use AI, and plan for it from day one. Privacy law makes the host organization responsible for training the people who handle personal information and for safeguarding it, whether that person is a permanent employee or a four-month co-op student. Give interns a clear rule on what never goes into AI, an approved tool for ordinary tasks, and a safety net that catches sensitive data before it leaves.

Read the guide
The AI section of an enterprise security questionnaire: how should a SaaS vendor answer?

Split the AI section into two questions and answer each with evidence. The first is about AI in your product: which models you use, which providers process customer data, whether that data trains any model, and how AI is governed. The second, which vendors often answer weakly, is about your employees: what stops staff from pasting customer data into AI tools, and how would you know if they did?

Read the guide

Specific work and data

Can researchers use AI tools on invention disclosures before a patent is filed?

Not with the unfiled technical details, unless the tool is one the institution has approved for confidential research information. A prompt is not automatically a public disclosure, but it hands the invention to a third party under that party's terms, creates novelty questions nobody can fully answer, and Europe offers no general grace period to fall back on.

Read the guide
SR&ED consultants: can you draft client project descriptions with AI?

Yes, if the client's technical data stays out of tools your engagement does not cover. CRA has not published guidance on AI use by claim preparers that we could find, so the limits come from your client contracts and NDAs, privacy law for the personal information in a claim, and any professional code you belong to. Draft with abstracted facts in a vetted tool, and keep source code, experimental results and unreleased product details out of public AI accounts.

Read the guide

From our research