For two decades, IP protection quietly relied on one assumption: a human in the loop who knew what was confidential, what was privileged, and where a draft came from. Agentic AI removes that person. A new white paper from the Governance Institute of Australia, Governance in the age of agentic AI, makes the shift plain — agents don’t just generate outputs, they take action. They access databases, draw on sources no reviewer ever sees, and disclose information at machine speed.
The IP consequences look familiar but behave differently. Copyright risk is amplified because the human signing off has less visibility of what the agent drew from. Confidential information can be disclosed autonomously, raising the prospect of breach of confidence without anyone deciding to share anything. And agents produce a large volume of text about their own actions — discoverable, and unlikely to be protected by legal professional privilege.
The strategic takeaway is that deploying an agent is an act of delegation, not a software rollout — and you don’t hand a delegate your trade secrets without limits. For IP-intensive organisations, three disciplines do real work: give agents minimum viable data access (the narrowest permissions needed, revoked when the task ends); attach provenance and a verification status to AI-generated content, so you know what’s been checked; and log inputs, sources and model versions so any output can be traced to its origin.
None of this is a compliance chore — it’s how you capture the upside while keeping the assets that make the business valuable intact.
Worth a read: https://www.governanceinstitute.com.au/advocacy/governance-in-the-age-of-agentic-ai/

