On January 29, 2025, the U.S. copyright office published the second part of a report on AI and copyright, answering a question that was no longer theoretical for any company publishing text every day: can AI-generated content be protected as the property of whoever published it? The answer, in the words of the office's own head, Shira Perlmutter: protection exists "where that creativity is expressed through the use of AI systems" — meaning, when a person decided enough of the content. Simply typing a prompt is not enough.
In May 2025, the same office released the third part of the report, on the use of protected works to train AI systems — the other side of the same coin, and the subject of the lawsuits now pitting major news organizations against AI companies. For an ordinary company, the two parts converge on one practical question: what can it actually prove about the text it publishes?
The answer is usually: less than it thinks. A document generated by AI and published with no record of who reviewed it, what changed and who approved it supports neither a claim to protection nor a defense when someone questions where it came from.
What the copyright office actually decided
The January 2025 report didn't create new law — it concluded existing copyright rules already covered the problem, with no need for legislative change. The core point: copyright protection still requires human authorship. A text prompt alone, however elaborate, does not count as sufficient creative contribution to generate rights over the result.
But the report also leaves a door open, and that door is what matters to any company: when a person participates substantially in the creation — selecting, editing, rearranging, combining the AI's output with their own material, deciding what stays and what goes — the part reflecting that human decision can indeed be protected. The line isn't "AI was involved, protection lost." The line is "how much of the creative decision was a person's, and can that be proven afterward?"
That second question is exactly where most companies have no ready answer. A document generated by AI and published with no record of who reviewed it, what changed, and who approved it has no way to prove sufficient human authorship — neither for protection purposes, nor as a defense when something goes wrong.
How you prove a person decided

In practice, the rule became a question of evidence. Claiming there was human review is not enough: months later, the company has to show who took the draft, what they changed, on what criteria, and who signed off on the final version.
Most companies treat this as a matter of common sense. Someone generates a draft, someone reads it, someone publishes it — all over chat, with no trail. When a customer, a competitor or an auditor asks where that text came from, the company is left relying on the memory of whoever was there.
The contrast with the rest of the operation is stark. No company approves a payment without two signatures and a record, yet it publishes text on its own site, under its own brand, whose origin nobody can reconstruct. The difference is that a wrong payment shows up on the statement the next day, while text with no owner only shows up once it becomes a problem.
What has to be in place
Between the protection the copyright report opens up and the liability the Canadian case confirms, what protects a company in both directions is the same thing: being able to show, after the fact, who decided what.
Two-step review and approval for critical documents, with the person who writes separate from the person who approves. Internal policy, contracts, market communications — any text that becomes an official company position benefits from a recorded human step before it circulates.
Company knowledge with sources, so a text generated from internal material cites where it came from — which helps both investigate a mistake and later demonstrate what human contribution went into curating that material.
An audit trail of every step: who generated the draft, who edited it, who approved it, and when. That record — not a claim made after a problem surfaces — is what supports both a legal defense and a claim of protection over the final content.
Access by role in content production, so it's clear who was authorized to approve what, not just who technically clicked "publish."
This is how Skyller was designed: two-step approval for critical content, with the writer separate from the approver, and an audit trail of every step from generation to publication.
Why this matters beyond legal risk

The lawsuit the New York Times has been pursuing against OpenAI and Microsoft since December 2023 — now in discovery, with no trial date set — shows the other side of the same coin. The newspaper alleges its own reporting was used without authorization to train AI systems that later reproduce parts of that content. In March 2025, the presiding judge denied most of OpenAI's motions to dismiss, allowing the core copyright infringement claims to proceed.
The common thread across all three cases — the U.S. report, the Canadian tribunal, the newspaper's lawsuit — is that no one treats "it was AI-generated" as an answer that closes the question anymore. The right question, in all three, is always about provenance: where the content came from, who decided to use it that way, and whether there's a record of it. Companies that already treat this record as routine — not as a scramble to reconstruct after a problem — arrive at any of these conversations in a far more comfortable position.
This matters both for companies that produce content with AI support and for those that eventually need to prove an internal document is original and protected. Without a history of who edited what, a company has no way to demonstrate, to a customer, a competitor, or a court, that a document carries enough human decision-making to be treated as its own property — the same standard the copyright office itself described in January 2025.
A checklist to review before your next official text
Before publishing the next document, notice, or AI-assisted automated reply, it's worth reviewing these points with legal and communications:
- Is there a recorded human review step before any text becomes an official company position? Without that record, there's no way to prove afterward who decided what.
- Who is authorized to approve a critical document, and is that a different person from who drafted it? Combining both roles in one person removes the second layer of checking.
- If a customer is harmed by a wrong answer from an AI assistant, can the company reconstruct in minutes what was said and why? The Canadian case shows "the AI got it wrong" clears no one.
- Does the material used to train or guide an internal AI assistant have known, documented provenance? Without that, a company doesn't know if it's exposed to the same kind of dispute now involving major news outlets.






