AI Verification and Trade Secrets: A Cross-Border Framework

“AI regulation should not force policymakers to choose between meaningful oversight and protection of IP.”

trade secretsImagine a U.S. AI developer preparing to license its system abroad. A prospective customer wants independent testing, a regulator wants evidence of safeguards, and the developer wants to protect its model weights, training records, and proprietary techniques. Providing more information might help demonstrate compliance, but it could also expose assets that support the company’s value.

Three questions are entangled; namely: (1) Does the system meet a technical requirement? (2) Were the relevant materials used lawfully? and (3) Who may examine the evidence, and under what restrictions? A favorable answer to one does not resolve the others.

One possible framework is an International AI Assurance and Access Compact, organized around “verifiable reciprocity.” Participating jurisdictions would recognize defined compliance findings in exchange for comparable verification obligations, alongside commitments to fund regulatory capacity. This is a proposed arrangement, not existing law. Its consequences for intellectual property (IP) turn on what evidence travels across borders and what rights remain unaffected.

1. Treaty Lessons

The Uruguay Round produced a package of agreements, not one “Uruguay Round Treaty.” Article II of the Marrakesh Agreement places trade agreements within the World Trade Organization’s institutional framework. Its relevance here is that it negotiates obligations and reciprocal benefits together. For AI, the proposed benefit would be less duplication of qualifying compliance work, not unrestricted market access.

Arms-control instruments address a different problem: verifying commitments between rivals. The Strategic Arms Limitation Talks (SALT) provide one example. Article V of the 1972 SALT I Interim Agreement provided for national technical means of verification and commitments against interference and certain concealment. That was not a general on-site inspection regime, and counting missile launchers does not translate directly into measuring software risk.

The Chemical Weapons Convention’s Confidentiality Annex supplies a distinct precedent: limiting information collection and securing sensitive material while verifying compliance. For AI, that suggests examining the necessary evidence under controlled conditions rather than automatically demanding public disclosure of proprietary technology.

Finally, Article 10 of the Montreal Protocol couples implementation with financing for qualifying developing-country parties. An analogous AI arrangement would raise concrete questions about who pays for independent laboratories, evaluator training, and smaller firms’ access to testing.

These mechanisms illuminate separate institutional functions. None establishes that a combined AI agreement would attract participation or produce dependable assessments.

2. A Passport for Findings, Not Blanket Approval

The Compact’s operational tool would be a modular “assurance passport”: a verifiable record of specified findings tied to a model version, responsible operator, configuration, and use. Modules could cover security testing, documented limitations, incident procedures, and the process used to assess relevant IP obligations.

Consider a model evaluated in one jurisdiction and deployed for employment screening in another. The receiving authority might recognize the security testing while separately examining local-language performance, discrimination risks, and available remedies. Recognition would cover identified evidence, not every consequence of deployment.

Material changes would trigger an audit of affected modules. Independent accreditation, conflict-of-interest controls, and reviewable suspension procedures would form part of the proposed system. A certificate would neither convey a patent license nor resolve a copyright dispute.

This design could reduce repeated work, but it would introduce accreditation costs and disputes about equivalence. Its usefulness would depend on whether accepted findings remain relevant to the actual deployment.

3. Confidentiality Is Part of Verification

Under 18 U.S.C. Section 1839(3), federal trade-secret protection requires reasonable secrecy measures and independent economic value arising from information’s secrecy and lack of ready ascertainability through proper means. The audit process therefore belongs in the company’s trade-secret analysis, not just its regulatory checklist.

Internationally, Article 39(2) of the Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS) protects qualifying undisclosed information against acquisition, use, or disclosure contrary to honest commercial practices. It is not a universal exemption from lawful regulatory examination. Nor does it automatically establish a complete confidentiality regime for AI regulators.

The proposed Compact would use restricted-access testing, limits on copying, purpose-specific permissions, secure retention, and remedies for unauthorized disclosure. Inspectors would receive evidence sufficient for their assigned inquiry, rather than a standing right to collect every proprietary asset.

Those controls present a countervailing concern: excessive secrecy could prevent meaningful scrutiny. The design would preserve lawful access to relevant evidence through courts or independent reviewers under protective procedures. A developer could contest an overbroad demand without controlling the investigation’s outcome.

For counsel, the primary questions are concrete: who receives the information, whether subcontractors can access it, whether a laboratory may reuse it, and which disclosure or public-records rules apply. A confidentiality label alone does not answer them.

4. Safety Testing Does Not Clear Training Rights

A model can pass technical testing while its training materials remain the subject of an IP dispute. Likewise, licensed inputs do not establish safe performance. The passport would keep those inquiries separate.

In the United States, 17 U.S.C. Section 107 supplies a case-specific fair-use framework; a technical certificate does not decide whether training qualifies as fair use. In the European Union, Articles 3 and 4 of Directive 2019/790 distinguish specified scientific-research text-and-data mining from a more extensive exception subject to conditions, including appropriately expressed reservations of rights under Article 4.

An IP module would document the asserted legal basis for relevant uses, such as a license, public-domain status, or statutory exception. It would distinguish verified documentation from pending legal conclusions and would not require every jurisdiction to accept the same copyright analysis.

Voluntary licensing registries could help organize permissions, but nonregistration would not itself authorize copying. Berne Convention Article 5(2) prohibits formalities for the enjoyment and exercise of the rights it protects. A proposed registry cannot simply become a condition of retaining those rights.

5. Access Without Automatic Technology Transfer

The financing component would support testing infrastructure, regulator training, and safeguarded research access. Participating states would account for both delivered assistance and implementation progress. Funding commitments would not substitute for licenses or authorize access to confidential datasets.

Recognition arrangements also face existing trade-law constraints. Article VII of the General Agreement on Trade in Services addresses recognition of service-supplier qualifications and certifications, opportunities for other interested members to negotiate participation or comparable arrangements, and restrictions on discriminatory recognition. Its application would require analysis of the particular AI service and measure.

Under this design, an equivalence pathway would allow applicants to demonstrate comparable compliance rather than treating non membership alone as proof of noncompliance. Affordable independent assessment could assist smaller firms; concentrated accreditation markets could produce the opposite result.

National implementation would specify inspection authority, recordkeeping duties, safeguards, sanctions, and judicial review. The international layer would coordinate accepted findings and disputes, not replace domestic courts or create immunity from private claims.

6. The Audit Contract Is an Immediate Starting Point

Even without a new treaty, the hypothetical developer and its evaluator can specify authorized access, retention periods, permitted recipients, and uses of the resulting report. A negotiated clause might provide:

Access is granted solely to perform the agreed evaluation. No rights are granted to train another model, commercialize disclosed materials, or disclose them beyond authorized recipients, except as required by applicable law. Required disclosures are subject to notice and protective procedures where legally permitted.

The above clause is only a starting point. The full evaluation agreement should also state among other factors: (1) How the evaluator must secure the developer’s information; (2) Whether subcontractors may see it; (3) How quickly a breach or other incident must be reported; (4) What records must be preserved; (5) When confidential materials must be returned or deleted; (6) Who bears responsibility for misuse or unauthorized disclosure; and (7) Who owns or may use the testing results. Counsel must also confirm that the developer has the right to disclose the materials being tested. For example, a dataset or software component licensed from a third party may be subject to confidentiality or use restrictions that limit what the developer can provide to an outside evaluator.

The proposed international framework applies to the same discipline at the treaty level. A regulator should be able to rely on clearly defined compliance findings without treating a certificate as a transfer of intellectual-property rights or a release from legal liability. The advantage would be that a company could reuse verified findings across participating jurisdictions instead of repeating the same testing everywhere. The risks are equally clear: the testing may be unreliable, confidential information may be mishandled, smaller countries or firms may lack meaningful access to the system, and jurisdictions may disagree about whether a foreign finding is equivalent to their own requirements. For IP Counsel, the practical rule is simple: proving that a system satisfies a regulatory requirement, granting another party rights to use protected technology, and accepting responsibility for legal harm are three (3) separate matters. A compliance certificate should address only the first unless the parties expressly agree otherwise.

The Way Forward

AI regulation should not force policymakers to choose between meaningful oversight and protection of IP. The more workable approach is to separate those functions. Technical assurance should establish only what has actually been tested and verified; IP rights should continue to depend on licenses, statutory rights, exceptions, and other applicable law; and liability should remain governed by the conduct and obligations of the responsible parties.

That separation is the article’s principal takeaway. A cross-border assurance passport could make AI compliance evidence more portable, but it should never be treated as blanket approval of a model, permission to use protected technology, or immunity from legal claims. For IP practitioners, the immediate task is therefore to build verification arrangements that give regulators enough evidence to act while preserving trade secrets, honoring third-party licenses, and defining responsibility with precision. International AI oversight should allow regulators to verify compliance while protecting IP and preserving legal accountability. For example, the European Union’s “AI Act – Regulation (EU) 2024/1689 “- offers a concrete example of this balance. Article 53 requires providers of general-purpose AI models to maintain a copyright-compliance policy and publish a sufficiently detailed summary of training content. Article 78 requires authorities and other covered participants to protect confidential information, including trade secrets, and limits authorities’ information requests to what is strictly necessary to exercise their regulatory powers. These provisions connect transparency with safeguards for proprietary information.

The proposed cross-border assurance framework would build on that approach by allowing jurisdictions to recognize specified, verified findings while retaining authority to examine local risks and legal requirements. An assurance passport would document compliance evidence, it would not grant a copyright license, transfer technology rights, or eliminate liability for harm.

For IP practitioners, the takeaway is straightforward: document regulatory compliance, establish the legal basis for using protected materials, and define responsibility for disclosure and harm. Each requires separate attention. A credible international framework should make verification more efficient while preserving the rights of innovators, creators, and affected people.

If international AI governance is developed along those lines, verification can become a tool for trust without becoming a vehicle for compulsory technology transfer or diluted accountability.

Image Source: Deposit Photos
Author: AlexInPh
Image ID: 852488530 

Share

Warning & Disclaimer: The pages, articles and comments on IPWatchdog.com do not constitute legal advice, nor do they create any attorney-client relationship. The articles published express the personal opinion and views of the author as of the time of publication and should not be attributed to the author’s employer, clients or the sponsors of IPWatchdog.com.

Join the Discussion

No comments yet. Add my comment.

Add Comment

Your email address will not be published. Required fields are marked *

Varsity Sponsors

From the IPWatchdog Institute

From IPWatchdog