AI Paste Audit SOP: Know What You Are Giving Away Before You Hit Enter
This is a Small Business SOP, a free, do-this-today standard operating procedure pulled from a real operator on the Unscripted Small Business podcast. This one comes from Richard Gearhart, Esq. of Gearhart Law, an intellectual property attorney who has spent two decades on patents, trademarks, copyrights and trade secrets.
A public AI tool is two problems at the same time. It is a place your unreleased idea gets described out loud, and it is a record someone else may later be entitled to read. Neither one announces itself while you are typing. Run this audit this week.
Scope note
Richard is describing how the law works. He is not advising any specific business, and neither is this page. This SOP is general information, not legal advice, and none of the steps below are legal directives. His own framing on the episode: “It’s better to find somebody that you can trust and get your questions answered.”
The Play in One Line
Write down every place your team pastes unreleased work into a public AI tool, check what each tool’s policy actually allows, and move the sensitive lanes onto a tool that keeps your data to itself.
Why this matters
In Richard’s words: “And you have to appreciate that when you put your ideas into an LLM, if it’s a public LLM, then technically you’re disclosing your invention.” His next line is the one that should worry an operator: “And so that also has consequences, and people don’t appreciate that.”
Then there is the second problem, which is the log itself. Richard described a case his firm wrote up, where a man accused of a white collar crime typed the details of his own situation into a public model. When the other side asked for it, the court agreed, in his telling, that “the opposing side has every right to look at that.” His explanation for why: “It wasn’t done under privilege by attorneys, so it’s not privileged.”
He gave a second example from the same year, an expert witness who built an opinion using models almost exclusively. The whole record went to the other side, and in Richard’s words it “just killed the case for him right there, right then and there.”
You do not need a lawsuit for this to cost you. You need one person pasting one unfiled idea into one tool with a policy nobody read.
The 6 steps
1
List every paste lane
Open a blank doc and write down where unreleased work actually goes into a public AI tool. Product specs. Unfiled invention notes. Client detail. Contract language. Customer lists. Source code. Ask the team, do not guess, because the lanes you do not know about are the ones nobody set a rule for.
2
Read the policy of each tool you already use
Not the marketing page. The actual terms and privacy policy. In the case Richard’s firm wrote up, they read the tool’s privacy policy and found “holes in it large enough to drive a truck through.” His general instruction is the same: “if you’re going to put your ideas into the LLMs, then you need to make sure that the LLM has safeguards.”
3
Mark anything unfiled or unreleased as the highest-risk paste
Go back through your list and flag the rows that describe something you have not filed, launched or published yet. Those are the pastes Richard is talking about when he says a public model means “technically you’re disclosing your invention.” Everything else on your list is a smaller problem than this row.
4
Run the reverse-engineerable question on anything you keep secret
Richard’s test is short: “in general, if something is reverse engineerable to the public, then it’s not really a trade secret anymore.” Take your customer list, your process, your back end, and ask whether an outsider with only what your customers can already see could land on the same answer. His software example is the pattern: if a model can reproduce what the customer is getting without doing the programming, “that would weaken the trade secret protection of the software company.”
5
Give confidential work its own named lane
This is what Richard’s own firm does. One system is allowed anywhere near client information and everything else is kept away from it: “there isn’t any AI system except for Microsoft Copilot that has exposure to our clients’ information.” You do not need his tool. You need his structure, which is one approved lane, named out loud, and a hard line around it. His summary of the whole practice: “all the time we’re very conscious of confidentiality.”
6
Assume the log is readable later, and write the rule down
Write one page: which tool is approved for what, what never gets pasted anywhere, and who to ask when it is not obvious. Do it now, while it is a housekeeping task, because the moment it stops being one it is already a discovery request. Richard’s own closing note on the subject: “it’s going to take us a while to learn how to use these things properly, but if you’re in a legal situation, you need to be very, very careful.”
The numbers behind the play
Richard did not bring a survey to this one. He brought court outcomes and the rule his own firm runs on.
2
court situations he describes where model use backfired on the person who used it
1
AI system at his firm cleared to touch client information
0
privilege on the public chat log in the case he describes
Take the whole SOP with you
One printable page: the play, the six steps, and a fill-in checklist. No email required.
This SOP is distilled from Richard Gearhart’s episode on the Unscripted Small Business podcast, where he also covers why a machine cannot be an author or an inventor, what copyright registration actually buys you, and where a social platform’s reuse rights stop: