Protect Your SME Content Before AI Creates Legal Risk

Protect Your SME Content Before AI Creates Legal Risk — featured image

by

Why Your Business Must Treat AI Content Carefully

You may already be using AI to write product descriptions, prepare social media captions, summarise documents or answer customer questions. For a small business, these tools can save time and help a small team handle more work.

However, a recent lawsuit involving Sony Music Publishing, Warner Chappell and other music publishers against Anthropic shows why convenience should not replace responsibility. The publishers allege that Anthropic used copyrighted material, including books, lyrics and sheet music, to train its Claude AI system. Anthropic disputes the claims and says it intends to defend itself. The case was filed in the United States and does not automatically determine Malaysian law, but it highlights a practical issue you cannot ignore: where did the content used by your AI tool come from, and are you allowed to use the output?

TL;DR: AI can help your SME work faster, but you remain responsible for how you use its outputs. Keep records, avoid uploading confidential or third-party material without permission, review generated content, and create a simple internal AI policy.

What This Means

AI systems are trained and operated using large amounts of information. That information may include material created by authors, musicians, photographers, software developers, businesses and other rights holders. The legal question is often not only whether an AI system produces something similar to existing work, but also whether copyrighted material was obtained or used improperly along the way.

The source article reports that the music publishers accuse Anthropic of “illegally torrenting, scraping, and downloading copyrighted works” to train Claude. Anthropic denies the allegations. The report also refers to an earlier case, Bartz v. Anthropic, in which a judge reportedly found that using copyrighted works for training could be lawful in certain circumstances, while acquiring that material through piracy was not. Anthropic was ordered to pay $1.5 billion in that case, according to the article. Source: TechCrunch

For you, the important lesson is not to decide who will win the court cases. It is to understand that AI use creates several separate risks:

  1. Input risk: you may upload customer data, supplier documents, photographs or internal files to an AI service.
  2. Output risk: generated text, images, code or audio may resemble someone else’s protected work.
  3. Record-keeping risk: you may be unable to show how a piece of content was created or checked.
  4. Contract risk: a client, platform or supplier may have rules about AI-generated material.

AI should reduce repetitive work, not remove your responsibility for the content your business publishes.

How This Applies to Malaysian SMEs

If you run an online retail business, you may ask an AI tool to create product descriptions from supplier information. That is generally more manageable when the facts come from documents you are authorised to use. The risk increases if you ask the tool to “rewrite this competitor’s website” or copy a distinctive description from another seller. Even if the final wording looks different, your business may still be creating avoidable disputes. Use your own product facts, specifications and photographs, then ask AI to organise them into a clear structure.

For a marketing agency, café, event company or local retailer, images and music deserve extra attention. A generated poster may contain a logo, celebrity likeness, brand design or visual style that creates questions about permission. A short social media video may also use music that is not covered by your platform account or business-use rights. Before publishing, check the licence terms for the image, music, font and stock material. Do not assume that because a tool generated an asset, your business automatically owns unrestricted commercial rights.

Professional service firms face a different problem: confidential information. An accountant, recruiter, clinic, property agent or legal support business may want AI to summarise client documents. Uploading names, identification details, medical information, contracts or financial records without checking the service’s data controls can expose your business to privacy and confidentiality issues. Malaysia’s Personal Data Protection Act 2010 applies to personal data processing in commercial transactions, so you should consider whether your workflow has a lawful purpose, proper safeguards and suitable disclosure. Source: Malaysia Personal Data Protection Department

Software and automation companies must also control code usage. Your developer may paste code from a client project into an AI assistant to troubleshoot an error. That can expose proprietary logic or confidential credentials. It may also produce code under licence conditions that do not fit your client agreement. Use redacted examples, remove passwords and API keys, and require a human technical review before deploying generated code.

A Simple Risk Check for Your AI Workflow

AI activity Main question Safer practice
Writing marketing copy Is the source information yours to use? Use your own facts and review claims before publishing.
Generating images Could it contain protected brands or recognisable people? Check commercial-use terms and remove questionable elements.
Summarising documents Does the file contain personal or confidential information? Redact sensitive details and check the provider’s data policy.
Creating code Could the output include restricted or copied code? Review licences, security and client requirements.
Producing audio or video Do you have rights to every music and visual element? Use properly licensed assets and retain proof of permission.

Practical Takeaways for Your Business

  • Create an approved-tools list: Record which AI services employees may use and what each service is permitted to handle.
  • Set a “no confidential data” rule: Unless specifically approved, do not upload customer records, passwords, contracts, identity documents or unreleased business information.
  • Keep a content trail: Save the original brief, source materials, AI prompts where practical, edits and final approval. This makes review easier if a client questions the work.
  • Use human approval: Assign a named person to check facts, originality, tone, privacy and usage rights before publication.
  • Check licences: Read the terms for generated images, music, fonts, stock content and software libraries.
  • Avoid imitation requests: Do not ask AI to reproduce a living artist’s distinctive style, copy a competitor’s campaign or recreate a protected character.
  • Protect customer contracts: If you provide work to clients, state whether AI tools are used and who is responsible for approvals and rights.
  • Train your team briefly: A one-page policy and a 30-minute walkthrough can prevent careless uploads and unreviewed publishing.

Questions to Ask Before You Publish

Before releasing AI-assisted material, ask five simple questions:

  1. Do we own or have permission to use the information supplied to the tool?
  2. Does the output include personal data, confidential information or a third party’s protected material?
  3. Have we checked the accuracy of every important claim?
  4. Does the AI service allow this type of commercial use under its terms?
  5. Can we explain who reviewed and approved the final version?

If the answer to any question is unclear, pause publication and investigate. A short delay is easier to manage than explaining an unauthorised image, inaccurate claim or exposed customer file after it has spread online.

The Bigger Picture

The dispute involving Anthropic and major music publishers is part of a wider discussion about how AI companies obtain training material and how rights holders protect their work. The source article says the latest lawsuit is broader than earlier claims because it alleges the use of millions of copies of books, including works containing lyrics and sheet music. Source: TechCrunch

As these disputes continue, AI providers may change their training practices, licences, documentation and customer controls. Businesses may also see more client contracts requiring disclosure of AI use, proof of content rights and restrictions on confidential information. For an SME, that means responsible AI use will become part of ordinary operations, much like password management, document storage and supplier checks.

You do not need a large legal or technology department to prepare. Start with the tools your team already uses. Identify what information goes in, what content comes out, who checks it and what evidence you retain. That simple discipline lets you benefit from automation while keeping ownership, privacy and publishing decisions under human control.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →