When AI Helps, Who Owns the Work?
You may not be running a mathematics laboratory, but you probably rely on AI for customer replies, sales proposals, product descriptions, internal documents, or business analysis. The difficult question is no longer whether AI can produce useful work. It is whether you can clearly explain where that work came from, who reviewed it, and whether your information was handled appropriately.
A recent dispute involving OpenAI, university mathematician Tristan Buckmaster, and Anthropic mathematician Levent Alpöge shows why this matters. The controversy concerns an important unsolved mathematics problem, competing claims about research timing, the use of AI models, and concerns about whether private interactions with an AI system could have influenced later work. You can read the original report from TechCrunch.
TL;DR: AI output is not automatically independent, private, or reliable. For your business, keep records of prompts, source documents, approvals, and model settings. Do not place confidential customer or company information into an AI tool until you understand its data-use terms.
The lesson is straightforward: AI adoption needs a chain of responsibility, not just a login and a prompt.
What This Means
The reported dispute centres on the Navier–Stokes existence and smoothness problem, one of seven Millennium Prize mathematics problems. Each problem carries a US$1 million prize from the Clay Mathematics Institute for an accepted solution. The equations are important in fluid mechanics, but their theoretical behaviour remains difficult to establish.
Buckmaster and Alpöge announced several proofs, including preliminary progress related to the problem. Shortly afterwards, OpenAI published what it described as a full proof produced with help from an unreleased model. OpenAI said its effort began on September 1 after hearing that two Millennium Prize problems might have been solved. The reported effort used 300 billion output tokens, according to the article, and OpenAI disputed any claim that it accessed the researchers’ private work.
The disagreement is not only about who solved what. It raises three practical questions:
- Provenance: Can you show how an AI-generated answer was created?
- Confidentiality: Could information entered into a tool be retained, reviewed, or used to improve future systems?
- Attribution: Who deserves credit when a human team and several AI tools contribute to the final result?
For an SME, these questions appear in less dramatic forms. Your marketing agency may use AI to draft your campaign. Your sales employee may paste a customer request into a chatbot. Your operations team may ask AI to summarise supplier documents. If the final output contains an error, copied wording, confidential information, or an unverified claim, responsibility still rests with your business.
AI can accelerate the work, but it cannot replace your responsibility for the work.
How This Applies to Malaysian SMEs
First, protect customer and business information. A Malaysian trading company might ask an AI tool to summarise a customer list, rewrite a quotation, or analyse monthly sales. That information could include names, phone numbers, addresses, purchase patterns, or special terms. Before using an external AI service, check whether your plan allows business data to be excluded from model training and whether administrators can control access. This is especially relevant under Malaysia’s Personal Data Protection Act 2010, which regulates the processing of personal data in commercial transactions; consult the Personal Data Protection Commissioner for the applicable framework.
Second, keep an audit trail for important documents. Suppose you use AI to prepare a tender response, product specification, tax-related explanation, or employment policy. Save the original source material, the prompt or instruction, the generated draft, and the person who approved it. You do not need an elaborate technical system. A dated folder in your document platform can be enough to show how the text was developed. This helps when a customer asks for clarification or when your team needs to update the document later.
Third, separate low-risk assistance from high-risk decisions. Asking AI to suggest five social-media captions is different from asking it to decide whether a customer qualifies for credit or whether an employee breached company policy. Use AI more freely for brainstorming and formatting, but require human review for legal, financial, hiring, safety, medical, and contractual decisions. If an answer could affect someone’s rights, obligations, or access to your service, a responsible manager should check the evidence before action is taken.
Fourth, treat originality as something to verify. The mathematics dispute includes allegations about whether one research direction may have been inferred from information connected to earlier AI usage. The facts remain contested, but the concern is relevant to business content. AI can produce wording similar to material already found online, and it may present unsupported statements with confidence. Before publishing a technical article, product claim, or competitor comparison, ask a staff member to check the sources and rewrite the content in your own business voice.
Fifth, be careful when several AI tools are involved. Your team may use one tool for research, another for writing, and a third for translation. That creates more places where documents may be uploaded and more uncertainty about access rights. Keep a simple approved-tools list. State which tools may be used for public information, internal information, customer information, and confidential information. This is manageable even for a five-person company.
A Simple AI Control Framework
| Business activity | Suggested AI use | Required control |
|---|---|---|
| Public marketing ideas | Draft captions, headlines, and content angles | Human review for accuracy and brand fit |
| Internal meeting notes | Summarise non-sensitive discussions | Remove personal or confidential details first |
| Customer enquiries | Suggest reply structure and tone | Staff approval before sending |
| Contracts and policies | Plain-language explanation or checklist | Qualified review before adoption |
| Business analysis | Identify patterns in cleaned data | Verify calculations against the source system |
The table is a starting point, not a substitute for professional advice. Your controls should match the sensitivity of the information and the possible impact of a mistake.
Practical Takeaways
- Create a one-page AI usage policy covering approved tools, prohibited information, and review responsibilities.
- Classify information as public, internal, personal, or confidential before entering it into an AI service.
- Use placeholders instead of real names, identification numbers, account details, or private addresses during drafting.
- Record the date, tool, purpose, source documents, and reviewer for important AI-assisted work.
- Ask AI to show assumptions and identify uncertainty instead of accepting a polished answer immediately.
- Verify figures, quotations, legal claims, product specifications, and references independently.
- Keep a human approval step for customer-facing, contractual, financial, employment, and safety-related outputs.
- Review the privacy and data-use settings of each AI tool before employees adopt it.
- Tell staff that copying confidential material into a chatbot is a business decision, not a harmless shortcut.
- Update your approved-tool list whenever a provider changes its terms, features, or data controls.
The Bigger Picture
The long-term issue is not whether AI deserves credit as a worker. It is whether businesses can maintain trust when software contributes to decisions and documents. Customers, suppliers, employees, and regulators may increasingly ask how an answer was produced. A company that can explain its process will be in a stronger position than one that simply says, “The AI generated it.”
AI providers will also face pressure to offer clearer controls around training data, private interactions, attribution, and research provenance. OpenAI’s reported position was that specific user data was not accessed for the mathematics effort, while acknowledging that de-identified data could, although unlikely, have helped improve models. For your business, that distinction reinforces the need to read the provider’s actual settings and terms rather than rely on assumptions. The OpenAI data-use policy explains how different account types may be handled, while other providers publish their own rules.
You do not need to stop using AI. You need to use it deliberately. Start with a small number of repeatable tasks, define what information may enter the tool, and require a named person to approve the result. This gives you the speed of assistance without giving up control of your business knowledge or customer relationships.
The practical standard is simple: if you cannot explain what the AI saw, what it produced, and who checked it, the process is not ready for important business work.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
