The Creator's Guide to Generative AI: How to Prompt Without Giving Away Your IP
POSTED BY Allison N. Berk
For influencers, digital creators, and creative marketing agencies, generative artificial intelligence (AI) has become an essential brainstorming partner. Whether you are using ChatGPT to structure video scripts, Claude to refine marketing strategies, or Gemini to map out a multi-platform social media campaign, these tools provide an extraordinary boost to daily productivity.
However, the way you interact with these platforms matters enormously when it comes to protecting your intellectual property (IP).
Every time a creator inputs a detailed prompt into an AI model, they are sending data across an external network. If a prompt includes a unique, unreleased brand concept, proprietary campaign taglines, or copyrighted visual references, that creative asset could be exposed depending on the platform's terms of service. Without realizing it, creative professionals may be compromising the exclusivity, confidentiality, and legal protectability of some of their most valuable ideas.
The Real-World Risk: Incidents That Prove the Point
If you think data exposure is a purely theoretical problem, documented incidents prove otherwise.
The Samsung Precedent: Samsung's device solutions division officially permitted employees to use ChatGPT on March 11, 2023. Within approximately twenty days, engineers in its semiconductor division exposed confidential information in three separate incidents. In the first, an engineer pasted proprietary source code to fix a bug. In the second, an engineer pasted code to optimize a test sequence for identifying yield and defective chips. In the third, an employee recorded a confidential internal meeting, transcribed it using a speech-to-text application, and fed the transcript to ChatGPT to generate meeting notes. Samsung's response was to ban generative AI tools across company devices and networks on May 1, 2023, and to develop its own internal AI system — later released as Samsung Gauss — with proper data controls.
The CISA Incident (Reported January 27, 2026): In a high-profile investigation reported by Politico on January 27, 2026, Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), uploaded at least four government contracting documents marked “for official use only”—sensitive but not classified—to the public version of ChatGPT between mid-July and early August 2025. The uploads triggered multiple automated security alerts, prompting a Department of Homeland Security review. Gottumukkala had requested and been granted a temporary exception to use the tool by CISA's Office of the Chief Information Officer as part of an initiative to explore AI tools, at a time when most DHS employees were blocked from accessing it due to data retention concerns. The incident demonstrates that even authorized, senior officials can expose sensitive data through consumer AI tools.
For creators, pasting a client's unreleased pitch deck, a confidential campaign calendar, or a unique brand strategy carries the same fundamental risk of unpermitted data exposure.
The Legal Catch: “Reasonable Measures” of Secrecy
Under the Defend Trade Secrets Act (DTSA), 18 U.S.C. § 1839(3), an idea or strategy only enjoys legal protection as a trade secret if the owner takes “reasonable measures” to keep it secret.
Two recent federal court decisions have begun to test this principle in the AI context. In Trinidad v. OpenAI, Inc., No. 4:25-cv-06328-JST (N.D. Cal. Jan. 5, 2026), Judge Tigar dismissed the plaintiff's trade secret claims under the DTSA because she had voluntarily disclosed her allegedly proprietary frameworks to OpenAI while using ChatGPT to develop them—with no confidentiality protections in place. The court applied the longstanding principle from Ruckelshaus v. Monsanto Co., 467 U.S. 986, 1002 (1984), that voluntarily disclosing a trade secret to a party under no obligation to protect it extinguishes the property right. Two caveats are worth noting: the plaintiff appeared pro se, and the court observed that her complaint suffered from multiple other defects, so the decision's precedential weight is limited. Still, the reasoning on disclosure is straightforward and likely to be cited again.
Separately, in United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026), Judge Rakoff ruled from the bench on February 10, 2026—with a written opinion following on February 17—that documents a criminal defendant generated using a consumer version of Anthropic's Claude were not protected by attorney-client privilege or the work product doctrine. The court's reasoning rested on several independent grounds: most fundamentally, Claude is not an attorney, and the court noted that recognized privileges require a trusting relationship with a licensed professional who owes fiduciary duties; further, by inputting confidential case material into the tool, the defendant effectively disclosed it to a third party before those materials ever reached his lawyers, and non-privileged materials do not become privileged merely by being shared with counsel afterward; finally, the defendant had not prepared the materials at counsel's direction—he acted of his own volition, so the work product doctrine did not apply. The decision has drawn academic criticism for potentially sweeping too broadly, and the court itself suggested the analysis could differ had counsel directed the use of the tool. Although Heppner arose in a criminal privilege context rather than trade secret law, the underlying principle is directly relevant to creators: disclosing confidential material to a platform that is under no obligation to keep it secret is difficult to characterize as a “reasonable measure” to protect it.
How the Big Three Handle Your Data
The consumer privacy landscape has shifted significantly since the introduction of AI chatbots. ChatGPT and Gemini have long defaulted to using conversational data from free and standard consumer tiers to train and refine their models. Anthropic had previously stood apart by not using consumer data for training by default, but on August 28, 2025, it announced updates to its consumer terms requiring Free, Pro, and Max plan users to make an affirmative data-sharing election. The updated Privacy Policy took effect September 28, 2025, and existing users had until October 8, 2025 to accept the new terms and make their selection in order to continue using Claude. For users who allow their data to be used for training, Anthropic extended data retention from thirty days to five years. Regardless of provider, if you have not actively reviewed and adjusted your privacy settings, your inputs may be in play.
To keep your assets secure, your agency or creator brand should consider employing active prompt engineering guardrails, including the following:
Toggle Off Model Training. Do not rely on default settings. In ChatGPT, navigate to Data Controls and turn off “Improve the model for everyone.” In Claude, review your model training setting in Privacy Settings. For Gemini, disable your “Gemini Apps Activity.” Note that enterprise and API-tier accounts for all three platforms operate under separate contractual data protections—consumer-tier defaults do not apply.
Keep Prompts Abstract. Use conceptual framing instead of literal, proprietary text. Instead of pasting a client's actual, unreleased slogan into your prompt, ask: “Give me five variations of a punchy, five-word slogan for a luxury eco-friendly footwear brand targeting Gen Z.”
Upgrade to Enterprise-Grade Infrastructure. If you or your agency regularly handles sensitive client data, consumer-tier accounts are a legal liability. Enterprise subscriptions and API-tier access contractually isolate your input data from public training pools—a meaningful legal distinction if your trade secret protection is ever challenged.
Generative AI is a great tool for scaling creative output, but its use should not come at the cost of legal protections. By practicing safe prompt engineering, you can harness the power of these tools without inadvertently risking the intellectual property that is core to your business.
Allison N. Berk is an attorney in DP&F’s Intellectual Property group who helps creators scale their business while protecting their brands, campaigns, and ideas. Questions? Reach out to Allison.
ABOUT THE AUTHOR
Intellectual Property attorney Allison N. Berk focuses on the prosecution and enforcement of client trademark rights, including trademark clearance, prosecution of applications for registration before the United States Patent and Trademark Office, and enforcement. Allison has litigation experience representing clients in federal court and before the Trademark Trial and Appeals Board. Allison also advises student-athletes and influencers on Name, Image, and Likeness (NIL) and rights of publicity matters. She provides strategic counsel on brand-identity protection and contract negotiations, ensuring her clients maintain commercial control over their intellectual property. Drawing on her background in trademark enforcement, Allison helps athletes and creators navigate evolving compliance standards while securing the long-term value of their personal brands.
Allison earned her J.D. from the University of California, Berkeley, School of Law, her B.A. in International Relations and African/African American Studies from the University of California, Davis. She is Chair of the Sonoma County Bar Association’s Intellectual Property and Business Law Section and is also a member of the Executive Committee of the Intellectual Property Law Section of the Bar Association of San Francisco.