Introduction

Artificial intelligence can be legally protected, but not through one single right. An AI solution combines code, mathematical models, parameters, data, architecture and know-how. Each component should therefore be matched with the appropriate regime: copyright, patent law, trade secrets, database rights or contracts.

This approach must be coordinated with Regulation (EU) 2024/1689, the AI Act, generally applicable since August 2, 2026, and with the GDPR where personal data is involved. These rules do not create ownership rights in AI itself, but they directly affect design, documentation and asset value.

In an AI project, economic value does not lie solely in the code: it may also arise from data selection, training parameters, fine-tuning methods, the integration architecture or internal procedures used to improve system performance. An effective protection strategy should therefore cover the entire value chain.

Copyright: protecting code without monopolising the algorithm

Under French law, software is protected by copyright pursuant to Article L.112-2(13) of the French Intellectual Property Code. Directive 2009/24/EC protects the expression of a program and preparatory design material where original.

The judgment delivered by the Full Court of the French Court of Cassation on March 7, 1986 (French Court of Cassation, Full Court, March 7, 1986, No. 83-10.477 – Pachot) recognised that software may be protected where its author demonstrates an individual creative effort going beyond the mere implementation of automatic and compulsory logic, while the Court of Justice of the European Union, in its judgment of July 16, 2009 (CJEU, July 16, 2009, Infopaq International, C-5/08), more broadly established the requirement that a work constitute the author’s own intellectual creation in order to satisfy the originality criterion. Source code, object code, certain modules and technical documentation may therefore be protected automatically where originality can be shown.

Where AI generates or completes code, evidence of human contribution becomes important. Version histories, repositories and an INPI e-Soleau filing may help document creation. For employees, Article L.113-9 of the French Intellectual Property Code provides, subject to its conditions, for the transfer to the employer of economic rights in software; contractor agreements should contain the necessary assignments.

This is particularly important where several individuals or tools contribute successively to the same development. Businesses should distinguish elements actually created by developers, components taken from third-party libraries, portions generated with AI assistance and pre-existing modules integrated into the product. Copyright protection therefore does not remove the need for a code-provenance and licence audit. Model weights, parameters or training methods that do not themselves constitute original expression of a computer program will often depend more heavily on trade-secret protection, contracts and technical confidentiality measures.

For further insight into the copyright protection of software developed with the assistance of artificial intelligence, we invite you to read our article: “AI-generated software: Is your code really protected by copyright?”

Patents: protecting a technical contribution

Article L.611-10 of the French Intellectual Property Code and Article 52 of the European Patent Convention exclude mathematical methods and computer programs claimed “as such”. An AI-related invention may nevertheless be patentable where it solves a technical problem. The EPO Guidelines for Examination 2026 on AI and machine learning confirm that a model or algorithm may contribute to technical character where it genuinely participates in the technical solution.

The application should identify a concrete technical effect. Merely automating a commercial rule will generally be insufficient. The decision issued by the Enlarged Board of Appeal of the European Patent Office on March 10, 2021 (EPO, Enlarged Board of Appeal, March 10, 2021, G 1/19) confirms that the technical character of a computer-implemented invention cannot arise solely from the fact that it involves calculations or a simulation, but requires those elements to contribute to a technical effect within the claimed invention.

Technical character is nevertheless only one part of the analysis. As with any invention, an AI-related solution must also satisfy the requirements of novelty, inventive step and sufficiency of disclosure. Drafting is therefore critical: the application should explain with sufficient precision how the AI contributes to the claimed technical result and, where that effect depends on particular characteristics of the training data or learning process, disclose the information needed for the skilled person to reproduce the invention. A claim that merely refers to the use of an “AI model” without defining its technical contribution may therefore be inadequate.

For further information on the circumstances in which an artificial intelligence model may benefit from patent protection, we invite you to read our article: “How to protect an AI-trained model?”

Trade secrets, data and contracts: protecting ancillary assets

Beyond intellectual property rights, several mechanisms may protect assets associated with an AI system.

Trade secret protection, governed in particular by Law No. 2018-670 of July 30, 2018 and Article L.151-1 of the French Commercial Code, may apply to confidential information such as model weights, hyperparameters, certain training methods or proprietary datasets. Such protection nevertheless requires concrete confidentiality measures, including restricted access, encryption, traceability and appropriate contractual provisions.

Training databases may also, subject to the applicable conditions, benefit from the sui generis right provided for under Article L.341-1 of the French Intellectual Property Code, where substantial investment has been made in their creation. This protection must be distinguished from rights in the individual materials contained in the database and from the licences authorising their use.

Finally, agreements with employees, contractors or partners should define the conditions governing access to data, fine-tuning, confidentiality and exploitation of the resulting model.

For further insight, see our article: “Protecting data in AI: what lessons can be learned from recent U.S. decisions?”

AI Act and GDPR: aligning protection and compliance

The AI Act does not grant IP rights to an AI system, but it affects documentation. For general-purpose AI models, Article 53 notably requires a copyright-compliance policy and a sufficiently detailed summary of training content.

Where personal data is used, the CNIL recommendations on AI development stress purpose, lawful basis, minimisation and security. Third-party models, open-source libraries and code-generation tools also require licence review: provider terms do not remove the need to assess third-party rights.

Compliance and asset protection should therefore be addressed together. Structured records of data sources, model versions, design choices, licences and security measures can both support regulatory compliance and establish the traceability of the know-how developed by the business.

For further information on the processing of personal data in the development and use of artificial intelligence systems, we invite you to read our article: “AI and Data privacy”

Protection strategy

Businesses should :

  • Map their code, models, data and know-how,
  • Identify contributors,
  • Select the appropriate protection for each asset, and
  • Preserve evidence of ownership, data provenance and licences.

Effective protection of AI therefore results from a combination of rights and organisational measures, rather than from a single registration.

An operational audit can usefully take the form of a matrix recording, for each component, its origin, owner, intended form of protection, licence restrictions, available evidence and authorised users. This approach quickly reveals weaknesses in the chain of rights and facilitates licensing, partnerships, investment and due-diligence exercises.

Conclusion

Can artificial intelligence be legally protected as software? Yes, if protection is structured component by component. Copyright may protect original software expression; patents may cover technical inventions; trade-secret and database law may secure non-public assets; and contracts organise ownership and use rights. AI Act, GDPR and licence compliance should be considered from the design stage.

The strategy should therefore be defined before the product is disclosed and reassessed whenever the system changes materially.

Dreyfus & Associés assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus & Associés works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus with the support of the entire Dreyfus team

Q&A

Can artificial intelligence be protected by copyright?

Original code and documentation may be protected; ideas, functionality and abstract algorithms are not.

Protection focuses on elements reflecting creative choices attributable to a natural person. The more a development relies on automated generation without identifiable creative input, the more important it becomes to document the human choices, corrections and decisions that led to the final version.

How can an AI system incorporating open-source components be protected?

The use of open-source components does not prevent certain proprietary elements of an AI system from being protected, but it requires careful identification of the applicable licences and their obligations. Depending on the licence, specific requirements may apply to redistribution, access to source code or the reuse of modifications.

Maintaining a clear inventory of the components used and their licences helps determine which elements may remain proprietary and which are subject to specific obligations before commercial exploitation.

Who owns code generated with AI?

It depends on human contribution, the developer’s status, contracts, tool terms and possible third-party rights. The use of AI does not, by itself, determine ownership.

The rules applying to employees and contractors, as well as the chain of rights in third-party components, must also be reviewed. An AI tool’s terms may govern the relationship with its provider, but they do not by themselves guarantee that no third-party rights subsist in code used or generated.

How can training data and model weights be protected?

Through trade secrets, database rights and contracts, depending on their nature and confidentiality.

For trade secrets, confidentiality must be supported by effective and proportionate measures. For databases, any protection of the database itself does not automatically mean that the business owns all rights in each individual item contained in it.

Must a business choose between patents and trade secrets?

Not necessarily. A single solution may combine a patent for a technical invention with secrecy for parameters, data or training methods.

The choice will depend in particular on whether infringement can be detected, the risk of reverse engineering and the ability to keep information confidential over time. A patent requires disclosure in exchange for a time-limited exclusive right, whereas secrecy can continue for as long as the legal conditions remain satisfied.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.