숙련자의 30년 노하우를 AI가 학습했다면 회사의 지식재산일까요? AI 시대 영업비밀 관리의 핵심
공장에서 30년 동안 일한 숙련자가 기계의 진동과 소리만 듣고도 불량 징후를 알아차립니다. 회사가 이 작업자의 판단과 작업방식을 데이터화해 AI에 학습시키고, 이후 AI가 비슷한 판단을 자동으로 수행하게 만들었다면 그 노하우는 누구의 것일까요?

공장에서 30년 동안 일한 숙련자가 기계의 진동과 소리만 듣고도 불량 징후를 알아차립니다. 회사가 이 작업자의 판단과 작업방식을 데이터화해 AI에 학습시키고, 이후 AI가 비슷한 판단을 자동으로 수행하게 만들었다면 그 노하우는 누구의 것일까요?
2026년 9월 23일 지식재산처와 한국공학한림원이 개최한 제2회 지식재산 전략포럼에서는 바로 이 문제가 주요 쟁점으로 논의됐습니다. 산업현장의 숙련자 경험과 노하우의 보호·보상, 고객사의 데이터와 개발사의 기술이 결합된 AI 모델의 권리 귀속, 합성데이터, 데이터 이용계약, 영업비밀 보호 등이 함께 다뤄졌습니다.
다만 이번 포럼이 “AI가 학습한 노하우는 무조건 회사 소유”라는 새로운 법적 기준을 확정한 것은 아닙니다.
오히려 중요한 메시지는 반대입니다.
AI를 도입하기 전에 ‘누구의 데이터인지, 어떤 노하우가 들어가는지, 누가 모델을 사용할 수 있는지’를 계약과 관리체계로 정해두지 않으면 AI가 완성된 뒤 권리관계를 정리하기가 훨씬 어려워질 수 있습니다.
왜 AI 시대에는 ‘숙련자의 노하우’가 더 중요해질까요?
제조업에서 기업의 경쟁력을 만드는 정보가 모두 특허 명세서나 매뉴얼에 적혀 있는 것은 아닙니다.
실제 산업현장에는 오랜 경험을 통해 축적된 이른바 tacit knowledge, 즉 암묵적 노하우가 많습니다.
예를 들면 다음과 같습니다.
- 특정 온도·습도에서 설비 설정값을 미세하게 조정하는 방법
- 원재료의 상태를 보고 공정조건을 바꾸는 판단기준
- 기계 진동이나 소음에서 고장 가능성을 알아내는 경험
- 검사 데이터에서 불량 가능성이 높은 패턴을 찾는 방법
- 고객별 요구사항에 따라 제조조건을 조정하는 방식
- 여러 공정 변수 중 실제 품질에 영향을 미치는 핵심 조합
- 매뉴얼에는 없는 문제 해결 순서와 예외처리 방법
과거에는 이런 노하우가 숙련자의 머릿속이나 현장 관행으로 남아 있는 경우가 많았습니다.
하지만 AI 전환이 진행되면서 상황이 달라지고 있습니다.
회사는 작업자의 행동을 센서로 측정하고, 판단과정을 기록하며, 공정 결과와 연결해 학습데이터를 만들 수 있습니다. 이렇게 축적된 데이터를 이용해 AI 모델을 학습시키면 숙련자의 경험 일부가 조직 차원의 디지털 자산으로 전환될 수 있습니다.
지식재산처도 이번 포럼에서 산업현장의 AI 도입이 확산되면서 양질의 데이터를 확보·활용하는 것이 중요해졌고, 그 과정에서 데이터를 누구에게 보상하고 어떻게 보호할 것인지가 새로운 지식재산 쟁점으로 부상하고 있다고 설명했습니다.
그렇다면 숙련자의 노하우는 자동으로 회사 영업비밀이 될까요?
그렇게 단순하게 볼 수는 없습니다.
현행 「부정경쟁방지 및 영업비밀보호에 관한 법률」은 영업비밀을 공공연히 알려져 있지 않고, 독립된 경제적 가치를 가지며, 비밀로 관리된 생산방법·판매방법 또는 그 밖의 영업활동에 유용한 기술상·경영상 정보로 정의하고 있습니다.
따라서 어떤 숙련자의 경험이나 작업방식이 기업에 매우 중요하다고 해서 곧바로 영업비밀이 되는 것은 아닙니다.
실무적으로는 최소한 다음 세 가지를 검토해야 합니다.
1. 외부에 일반적으로 알려져 있지 않은 정보인가?
업계 누구나 알고 있는 일반적인 기술이나 공개 매뉴얼에 이미 기재된 방법이라면 영업비밀 보호가 어려울 수 있습니다.
반대로 회사 내부에서만 축적된 공정조건, 조합, 판단기준이나 실패데이터라면 비공지성이 인정될 가능성을 검토할 수 있습니다.
2. 경제적 가치가 있는 정보인가?
경쟁사가 그 정보를 확보하면 시행착오를 크게 줄이거나 비용·시간을 절약할 수 있다면 경제적 가치가 있을 가능성이 높아집니다.
특히 AI 학습을 통해 생산수율, 불량예측, 설비 유지보수 또는 공정최적화에 직접 활용되는 데이터와 노하우라면 기업의 경쟁력과 밀접하게 연결될 수 있습니다.
3. 회사가 실제로 비밀로 관리하고 있는가?
이 부분은 AI 프로젝트에서 특히 중요합니다.
회사가 “중요한 노하우”라고 주장하면서 실제로는 전 직원이 자유롭게 접근하고, 외부 AI 개발업체에도 별도 제한 없이 파일을 전달하며, 클라우드 계정에도 접근통제가 없다면 이후 영업비밀 보호 주장이 어려워질 수 있습니다.
기업이 중요하다고 생각하는 정보와 법적으로 보호받을 수 있도록 관리한 정보는 반드시 같은 것은 아닙니다. AI 학습데이터로 사용하기 전부터 비밀관리 체계를 남겨두는 것이 중요합니다.
AI 학습이 시작되면 권리관계가 왜 더 복잡해질까요?
전통적인 영업비밀 관리에서는 “이 파일은 우리 회사의 기술자료”라고 비교적 명확하게 구분할 수 있었습니다.
AI 프로젝트에서는 여러 주체의 정보가 섞일 가능성이 훨씬 높습니다.
지식재산처 포럼에서도 제조현장에서 고객사의 데이터와 개발사의 기술이 결합된 AI 모델, 그리고 가상공장에서 만들어진 합성데이터의 권리 귀속이 실제 쟁점으로 제시됐습니다. 의료분야에서는 환자·의료기관·개발기업 등 여러 주체가 관여하는 데이터에서 누가 데이터를 생성한 것으로 볼 것인지, 데이터 이용계약을 어떻게 체결할 것인지가 논의됐습니다.
예를 들어 제조기업 A가 AI 개발회사 B에게 다음 정보를 제공했다고 가정해 보겠습니다.
- 생산라인 센서 데이터
- 숙련자의 작업기록
- 과거 불량사례
- 고객제품 관련 시험데이터
- 설비별 최적조건
- 문제해결 매뉴얼
B는 여기에 자체 알고리즘과 기존 모델을 결합해 공정최적화 AI를 개발합니다.
이때 최소한 다음 권리가 따로 존재할 수 있습니다.
| 대상 | 권리·관리 쟁점 |
|---|---|
| 원본 공정데이터 | 누가 소유·관리하고 어떤 목적으로 사용 가능한가 |
| 숙련자 노하우 | 회사 내부정보인지, 개인 기여를 어떻게 취급할지 |
| 고객 제공 데이터 | 고객과의 계약상 사용 범위가 어디까지인지 |
| AI 모델 | 개발회사와 고객사 중 누가 어떤 권한을 갖는지 |
| Fine-tuned model | 프로젝트 종료 후 누가 보유·재사용 가능한지 |
| 합성데이터 | 생성 근거와 재사용 범위를 어떻게 정할지 |
| 출력 결과 | 결과물의 저장·재학습·외부 활용이 가능한지 |
따라서 “우리가 돈을 주고 AI를 만들었으니 전부 우리 것”이라는 전제도 위험하고, 반대로 “개발사가 모델을 만들었으니 모든 권리는 개발사에 있다”고 단정하는 것도 위험합니다.
결국 계약에서 무엇을 정했는지가 매우 중요해집니다.
직원의 30년 노하우를 AI가 학습하면 별도의 보상이 필요할까요?
이 부분도 앞으로 중요해질 가능성이 높은 쟁점입니다.
이번 지식재산 전략포럼에서는 숙련자의 경험과 노하우에 대한 보호·보상 방안, 그리고 데이터·AI 모델의 기여자 보상이 직접 논의됐습니다.
다만 이것을 “2026년부터 숙련자에게 AI 학습 보상을 반드시 지급해야 한다는 법이 생겼다”는 의미로 이해해서는 안 됩니다.
이번 발표는 관련 권리관계와 보상 문제를 정책적으로 논의한 것입니다.
실제 기업에서는 다음 문제를 구분해야 합니다.
- 해당 노하우가 근로과정에서 회사 업무로 축적된 것인지
- 개인이 독자적으로 보유하고 있던 경험인지
- 기술이 특허 가능한 발명으로 발전했는지
- 직무발명 규정의 적용 가능성이 있는지
- 취업규칙·보상규정·근로계약에 관련 조항이 있는지
- AI 학습을 위한 인터뷰·시연·데이터 생성에 별도의 기여가 있었는지
특히 숙련자가 자신의 경험을 체계적으로 설명하고 새로운 학습데이터 구축에 적극적으로 참여했다면, 단순히 기존 회사 데이터베이스를 이용한 경우와 기업 내부의 인센티브·보상 설계를 다르게 검토할 수 있습니다.
법적 권리 문제와 별개로 조직 차원에서도 숙련자가 자신의 노하우를 AI에게 이전하면 자신의 역할이 사라진다고 느낀다면 데이터 확보 자체가 어려워질 수 있습니다.
따라서 AX 프로젝트에서 기술적 데이터 수집뿐 아니라 기여자에 대한 보상과 내부 합의를 동시에 설계할 필요가 있습니다.
외부 AI 개발사에 데이터를 넘길 때 가장 먼저 확인할 것은 무엇일까요?
기업 입장에서 가장 위험한 순간 중 하나가 내부 데이터를 외부로 전달하는 시점입니다.
단순 NDA 하나만 체결하고 대량의 생산데이터를 제공하는 방식은 충분하지 않을 수 있습니다.
계약에서는 적어도 다음 사항을 검토할 필요가 있습니다.
- 제공 데이터의 범위를 명확히 정의합니다.
- 프로젝트 목적 외 사용을 제한합니다.
- 제3자 제공 및 재위탁 조건을 정합니다.
- 외부 AI 모델의 추가 학습에 사용할 수 있는지 정합니다.
- 프로젝트 종료 후 데이터의 반환·삭제 의무를 정합니다.
- 백업본과 로그 데이터의 처리방식을 정합니다.
- AI 모델과 fine-tuned model의 이용권을 정합니다.
- 생성된 결과와 합성데이터의 사용범위를 정합니다.
- 사고 발생 시 통지·조사·책임 절차를 정합니다.
- 개발사 내부에서 해당 데이터에 접근할 수 있는 인원을 제한합니다.
- 다른 고객을 위한 모델에 재사용할 수 있는지 명확히 정합니다.
- 계약 종료 후 모델에 남은 정보의 취급방식을 검토합니다.
AI 개발계약에서는 ‘원본 데이터의 소유권’만 정해서는 부족합니다. 학습, 파인튜닝, 모델 재사용, 합성데이터, 출력물, 로그, 백업본까지 데이터 생애주기 전체를 기준으로 권리를 정해야 합니다.
회사 내부에서도 AI용 데이터와 영업비밀을 구분해야 합니다
모든 정보를 동일한 수준으로 보호할 필요는 없습니다.
오히려 중요한 정보를 구분하지 않고 모든 자료를 “기밀”이라고 표시하는 방식은 실제 관리의 실효성을 떨어뜨릴 수 있습니다.
AI 프로젝트를 시작한다면 정보를 예를 들어 다음과 같이 구분할 수 있습니다.
일반 활용 가능 데이터
이미 공개됐거나 외부 활용에 특별한 제한이 없는 정보입니다.
내부 업무용 데이터
외부 공개를 원하지는 않지만 핵심 영업비밀까지는 아닌 자료입니다.
핵심 영업비밀 후보
공정조건, 실패데이터, 레시피, 제조 노하우, 가격전략, 고객별 기술조건 등 외부 유출 시 경쟁력에 직접 영향을 줄 수 있는 정보입니다.
제3자 제한정보
고객, 공동개발사, 공급업체 등으로부터 제공받아 계약에 따라 이용범위가 제한된 정보입니다.
이 분류에 따라 AI 학습 가능 여부와 외부 반출 수준도 달라져야 합니다.
예를 들어 핵심 영업비밀 데이터를 외부 범용 AI 서비스에 그대로 입력하는 행위와, 회사 내부 폐쇄형 환경에서 승인된 모델에 학습시키는 행위는 위험수준이 다릅니다.
AI에 한 번 학습시키면 삭제하면 끝나는 문제일까요?
AI에서는 기존 문서관리와 다른 문제가 생길 수 있습니다.
파일 한 개를 삭제하는 것과 그 파일을 학습에 이용한 모델을 원상태로 되돌리는 것은 같은 문제가 아닙니다.
따라서 처음부터 다음 사항을 확인해야 합니다.
- 학습데이터가 어디에 저장되는가
- 원본과 전처리 데이터가 각각 어디에 남는가
- 모델 학습 후 원본을 삭제하는가
- 해당 데이터가 다른 모델의 학습에 재사용되는가
- 테스트·평가 데이터가 별도로 보관되는가
- 로그에 입력내용이 남는가
- 클라우드 사업자가 데이터를 재사용할 수 있는가
- 계약 종료 시 삭제 증빙을 받을 수 있는가
AI 시스템에 회사의 핵심 노하우를 넣기 전에 이런 구조가 확인되지 않는다면 기술도입 속도보다 데이터 통제가 우선일 수 있습니다.
기업이 지금 만들어야 할 ‘AI 영업비밀 관리 체크리스트’
AI 프로젝트를 준비하거나 이미 진행하고 있다면 다음 항목부터 점검할 수 있습니다.
데이터 측면
- 어떤 데이터를 학습에 사용하는지 목록화되어 있는가
- 각 데이터의 생성자와 출처가 확인되는가
- 회사 소유 데이터와 고객·협력사 데이터를 구분했는가
- 핵심 노하우 데이터를 별도로 표시했는가
- 데이터별 외부 반출 가능 여부를 정했는가
사람 측면
- 숙련자의 참여범위가 정해져 있는가
- 직원에게 AI 학습목적을 설명했는가
- 접근 가능한 담당자가 제한되어 있는가
- 퇴직자·외주인력 접근권한을 관리하고 있는가
- 핵심 노하우의 기여자 기록을 남기고 있는가
계약 측면
- NDA 외에 데이터 이용범위를 별도로 규정했는가
- AI 모델 학습·재학습 허용범위를 정했는가
- 모델과 결과물의 권리를 정했는가
- 프로젝트 종료 시 반환·삭제 조건이 있는가
- 다른 고객 프로젝트에 재사용하는 것을 제한했는가
기술 측면
- 접근권한이 역할별로 나뉘어 있는가
- 다운로드와 외부전송 기록이 남는가
- 중요 데이터가 암호화되어 있는가
- 외부 범용 생성형 AI 입력정책이 있는가
- 로그와 백업에 대한 관리정책이 있는가
특허와 영업비밀 중 어떤 방식으로 보호해야 할까요?
AI와 결합된 산업 노하우라고 해서 모든 것을 영업비밀로만 보호할 필요는 없습니다.
기술의 성격에 따라 특허와 영업비밀을 전략적으로 나눌 수 있습니다.
외부 제품을 분석하면 쉽게 파악할 수 있는 기술이라면 비밀로 유지하기 어려울 수 있으므로 특허출원이 더 적절한 경우가 있습니다.
반대로 제조공정 내부에서만 사용되고 외부에서 알아내기 어려우며 장기간 비밀로 유지할 수 있는 공정조건·레시피·운영 노하우라면 영업비밀 전략을 검토할 수 있습니다.
AI 프로젝트에서는 여기에 한 단계가 더 추가됩니다.
모델의 구조나 핵심 알고리즘은 특허대상이 될 수 있는지 검토하고, 학습에 사용된 공정데이터와 숙련자의 판단기준은 영업비밀로 관리하며, 소프트웨어나 데이터베이스와 관련된 다른 권리도 함께 살펴보는 IP-MIX 전략이 필요할 수 있습니다.
즉 하나의 AI 시스템 안에서도 보호수단이 달라질 수 있습니다.
이번 지식재산처 발표에서 기업이 읽어야 할 핵심은 무엇일까요?
2026년 9월 23일 포럼에서 지식재산처는 산업현장의 AI 전환 과정에서 데이터와 AI 모델의 권리관계를 명확하게 하고 기여자에게 정당한 보상이 이루어질 수 있도록 제도개선을 추진하겠다는 방향을 밝혔습니다. 제조현장의 숙련자 노하우, 고객 데이터와 개발사 기술이 결합된 모델, 합성데이터와 영업비밀 보호 등이 실제 쟁점으로 제시됐습니다.
중요한 것은 이 발표를 이미 새로운 권리제도가 확정됐다는 의미로 해석하지 않는 것입니다.
현재 기업이 해야 할 일은 미래의 법 개정을 기다리는 것이 아니라, 지금 보유한 정보와 AI 프로젝트의 권리구조를 먼저 정리하는 것입니다.
AI가 회사의 노하우를 학습한 뒤에 권리관계를 고민하는 것보다, 학습시키기 전에 데이터 출처·비밀등급·기여자·이용범위·모델 권리·반환과 삭제 조건을 정하는 것이 훨씬 중요합니다.
핵심 정리
숙련자의 오랜 경험과 노하우는 AI 시대에 오히려 더 중요한 자산이 될 수 있습니다.
기존에는 개인의 경험에 머물렀던 판단과 기술이 데이터화되고 AI 모델에 학습되면서 기업 전체가 반복적으로 사용할 수 있는 디지털 자산으로 변하기 때문입니다.
하지만 이 과정에서 그 정보가 자동으로 회사의 영업비밀이나 독점적 지식재산이 되는 것은 아닙니다.
현행 부정경쟁방지법상 영업비밀 보호를 검토하려면 해당 정보가 공공연히 알려져 있지 않고 독립된 경제적 가치를 가지며 실제로 비밀로 관리되어야 합니다.
또한 AI 프로젝트에서는 원본 데이터뿐 아니라 숙련자의 기여, 고객 데이터, 외부 개발사의 기술, 학습된 모델, fine-tuned model, 합성데이터, 결과물과 로그까지 다양한 층의 권리관계가 발생할 수 있습니다.
따라서 AI 도입계약을 단순한 소프트웨어 구매계약으로 보는 것은 위험할 수 있습니다.
기업은 AI 학습을 시작하기 전에 최소한 다음 네 가지를 명확히 해야 합니다.
첫째, 무엇이 우리 회사의 핵심 데이터와 노하우인지.
둘째, 그 정보를 누가 만들었고 누가 사용할 수 있는지.
셋째, AI 개발사나 외부 서비스에 어디까지 제공할 수 있는지.
넷째, 학습이 끝난 뒤 모델과 데이터에 대한 권리를 누가 갖는지.
AI가 기술을 대신 만들어주는 시대가 아니라, 기업이 가진 지식과 경험을 AI가 빠르게 흡수하는 시대가 되고 있습니다.
그럴수록 AI 도입과 지식재산 전략을 별개의 문제로 다루지 않는 것이 중요합니다.
본 글은 2026년 9월 30일 현재 공개된 지식재산처 자료와 현행 「부정경쟁방지 및 영업비밀보호에 관한 법률」을 바탕으로 작성한 일반적인 정보입니다. 실제 영업비밀 해당 여부, AI 개발계약의 권리귀속, 직무발명 및 기여자 보상 문제는 구체적인 계약관계와 사실관계에 따라 달라질 수 있습니다.
English Version
A senior engineer who has worked in a factory for thirty years may be able to detect a manufacturing problem simply from a subtle vibration, sound or change in the behaviour of a machine.
If a company records that expert’s decisions, converts the process into data and trains an AI model to make similar judgments, who owns the resulting knowledge?
This was one of the key questions discussed at the Second Intellectual Property Strategy Forum held by Korea’s Ministry of Intellectual Property and the National Academy of Engineering of Korea on September 23, 2026.
The forum addressed the protection and compensation of experienced workers’ know-how, ownership of AI models combining customer data with a developer’s technology, synthetic data, data-use agreements, contributor compensation and trade secret protection.
The forum did not establish a new rule stating that all know-how learned by AI automatically belongs to the company.
The more important practical point is that companies should define the relevant rights and restrictions before valuable industrial knowledge is transferred into an AI system.
Once training has already taken place, it may be much harder to determine who may use the data, model and resulting know-how. Data ownership, contribution, permitted use and confidentiality should therefore be addressed before AI training begins.
Why Does Expert Know-How Matter More in the AI Era?
Not every valuable manufacturing technique is written in a patent specification or operating manual.
Industrial sites often depend on tacit knowledge accumulated through years of experience.
Examples may include:
- subtle adjustments to machine settings under particular environmental conditions
- judgments based on changes in raw materials
- detecting failure from vibration or noise
- identifying patterns associated with defects
- adjusting production conditions for particular customers
- knowing which combination of process variables actually affects quality
- problem-solving procedures and exceptions that never appear in a manual
Historically, much of this knowledge remained in the minds of experienced workers or in informal shop-floor practice.
AI changes that.
Companies can record actions through sensors, document decision-making, connect process behaviour with outcomes and build structured training datasets.
An AI model can then learn from some of the experience that was previously available only through a particular worker.
The Ministry of Intellectual Property noted at the September forum that, as industrial AI adoption expands, access to high-quality data is increasingly important and questions are emerging about how data should be protected and who should be compensated for its contribution.
Does Expert Know-How Automatically Become a Company Trade Secret?
No.
Under Korea’s Unfair Competition Prevention and Trade Secret Protection Act, a trade secret is information that is not publicly known, has independent economic value and is managed as confidential, including technical or business information useful for business activities.
The fact that knowledge is commercially important does not automatically make it a legally protected trade secret.
Three basic issues should be considered.
1. Is the information genuinely non-public?
A technique that is already widely known within the industry or described in publicly available manuals may be difficult to protect as a trade secret.
By contrast, internally developed process settings, combinations, decision criteria or failure data may raise a different analysis.
2. Does the information have independent economic value?
If a competitor obtaining the information could avoid significant trial and error, reduce development time or improve production results, the information may have substantial economic value.
Data used to improve yield, predict defects, maintain equipment or optimise manufacturing can be particularly important.
3. Is the company actually managing it as confidential?
This is especially important in an AI project.
A company may describe information as critical know-how, but if every employee can access it freely, it is transferred to outside AI vendors without restrictions, and no meaningful access controls are applied, protecting it later as a trade secret may become more difficult.
Information that a company considers important is not automatically the same as information that has been managed in a manner capable of supporting trade-secret protection.
Why Does AI Make Ownership More Complicated?
Traditional trade-secret management often involved identifiable technical documents or files.
AI projects combine information from many different parties.
The September forum specifically raised questions about AI models combining customer data and developer technology, as well as ownership of synthetic data generated in virtual factories.
In healthcare examples, the forum also considered situations in which patients, hospitals and AI developers all contribute to data creation and asked how data-use agreements should be structured.
Consider a manufacturer that gives an AI developer:
- production sensor data
- expert work records
- historical defect data
- customer test information
- equipment optimisation settings
- troubleshooting manuals
The developer then combines these materials with its own algorithms and pre-existing model.
Different rights issues can arise at each layer.
| Asset | Key Question |
|---|---|
| Original process data | Who controls it and for what purposes may it be used? |
| Expert know-how | Is it company information and how should individual contribution be treated? |
| Customer data | What uses are permitted under the customer agreement? |
| AI model | What rights belong to the developer and the customer? |
| Fine-tuned model | Who may retain and reuse it after the project? |
| Synthetic data | How may generated data be used? |
| Outputs | May outputs be stored, reused or used for further training? |
A company should therefore not assume that paying for development automatically gives it every right in the resulting system.
Likewise, the developer cannot necessarily assume that creating the model gives it unrestricted rights to use customer data.
The contract becomes critical.
Should an Employee Be Compensated When AI Learns Decades of Know-How?
This is likely to become an increasingly important issue.
The September forum specifically discussed protection and compensation for experienced workers’ know-how and broader contributor-compensation questions relating to data and AI models.
That does not mean that a new law now automatically requires payment every time an employee’s knowledge is used for AI training.
The forum was discussing policy and industry issues rather than announcing such a mandatory compensation rule.
Companies should instead examine questions such as:
- whether the know-how developed through the employee’s assigned work
- whether the employee possessed the knowledge independently
- whether the contribution resulted in a patentable invention
- whether employee-invention rules apply
- what the employment agreement and compensation policies provide
- whether the employee made a separate contribution to creating AI training data
An employee who actively structures decades of experience, performs demonstrations and creates a new training dataset may present a different internal compensation issue from a project that merely uses an existing corporate database.
There is also a practical organisational issue.
If experienced employees believe that transferring their knowledge into AI will eliminate their own role without recognition, they may be reluctant to share the information required to build a high-quality system.
AI governance may therefore need to consider both legal rights and internal incentives.
What Should Be Addressed Before Giving Data to an Outside AI Developer?
One of the most sensitive moments occurs when internal company information is transferred to an outside vendor.
A basic NDA alone may not be enough.
An AI development agreement should consider matters such as:
- precisely defining the data being provided
- limiting use to the agreed project
- controlling disclosure to subcontractors or other third parties
- determining whether the data may be used for additional model training
- requiring return or deletion at the end of the project
- addressing backups and logs
- defining rights in the AI model and fine-tuned model
- determining rights in generated outputs and synthetic data
- establishing incident notification and investigation procedures
- restricting internal access at the vendor
- determining whether information can be reused for other customers
- addressing residual information after termination
AI agreements should not stop at ownership of the original dataset. They should address the entire lifecycle of the information, including training, fine-tuning, model reuse, synthetic data, outputs, logs and backups.
Companies Should Classify Information Before AI Training
Not every piece of information requires the same protection.
Treating every document as “confidential” can actually reduce the effectiveness of information governance.
Companies can consider separating AI-related data into categories.
Generally usable information
Information that is public or otherwise free from significant internal restrictions.
Internal-use information
Information the company does not wish to make public but that may not constitute a core trade secret.
Core trade-secret candidates
Process conditions, recipes, failure data, manufacturing know-how, pricing strategies and customer-specific technical conditions that may directly affect competitiveness if disclosed.
Third-party restricted information
Customer, supplier or joint-development information subject to contractual restrictions.
The rules for AI training and external transfer should vary according to these classifications.
Entering core process know-how into a public generative AI service creates a very different risk profile from training an approved model in a controlled internal environment.
Is Deleting the File Enough After AI Training?
Not necessarily.
Deleting the original file and reversing the effect of that file on a trained model are not the same thing.
Before valuable information is used for training, a company should understand:
- where the training data is stored
- where original and processed data remain
- whether original data is deleted after training
- whether it will be reused for other models
- whether test and evaluation copies are retained
- whether prompts or inputs remain in logs
- whether a cloud provider can reuse information
- whether deletion can be verified after termination
If these questions cannot be answered, the company may need to address data governance before accelerating AI deployment.
AI Trade Secret Management Checklist
Companies beginning or reviewing an AI project can start with four areas.
Data
- Is there an inventory of the training data?
- Can the origin and creator of each important dataset be identified?
- Are company data and customer data separated?
- Are core know-how datasets classified?
- Are rules for external transfer defined?
People
- Is the role of experienced employees documented?
- Have employees been informed about the AI training purpose?
- Is access limited to authorised personnel?
- Are former employees and contractors removed from access?
- Are key contributors identified?
Contracts
- Does the agreement go beyond a basic NDA?
- Are training and retraining rights defined?
- Are model and output rights addressed?
- Are return and deletion requirements included?
- Is reuse for other customers restricted where necessary?
Technology
- Are permissions divided by role?
- Are downloads and external transfers logged?
- Is sensitive information encrypted?
- Is there a policy for public generative AI services?
- Are backups and logs governed?
Patent or Trade Secret?
Not every AI-related industrial innovation should be protected only as a trade secret.
The appropriate strategy depends on the nature of the technology.
Technology that can easily be discovered by examining a product may be difficult to keep secret and could be a stronger candidate for patent protection.
By contrast, internal manufacturing settings, recipes, process combinations and operational know-how that cannot easily be reverse-engineered may be candidates for trade-secret protection.
AI adds another layer.
The model architecture or a technical AI solution may raise patent questions, while the underlying manufacturing data and expert decision criteria may be protected through confidentiality and trade-secret controls.
Different elements of the same AI system may therefore require an IP-mix strategy rather than a single form of protection.
What Should Companies Take From the September 2026 Policy Discussion?
At the September 23 forum, the Ministry of Intellectual Property identified industrial expert know-how, combined customer-and-developer AI models, synthetic data, contributor compensation and trade-secret protection as important issues in Korea’s industrial AI transition. The Ministry also indicated that it intends to continue examining ways to clarify rights relating to data and AI models and support appropriate compensation.
This should not be interpreted as an announcement that a new ownership regime is already in force.
The immediate practical task for companies is to organise their own rights before waiting for future legal reforms.
The safest time to decide who contributed the data, who may use it, which information is confidential, who controls the resulting model and what happens after termination is before the AI is trained—not after.
Key Takeaways
Decades of industrial experience may become even more valuable in the AI era.
Knowledge that once remained in an individual worker’s judgment can be converted into data, incorporated into models and repeatedly used across an organisation.
But the conversion does not automatically make everything an exclusive corporate intellectual property right.
Under Korea’s current trade-secret law, relevant information must be non-public, possess independent economic value and be managed as confidential in order to fall within the statutory definition of a trade secret.
AI projects can also create multiple overlapping layers of rights involving source data, employee know-how, customer information, developer technology, trained models, fine-tuned models, synthetic data, outputs and logs.
An AI implementation agreement should therefore not be treated merely as an ordinary software-purchase agreement.
Before training begins, companies should be able to answer at least four questions:
What information constitutes our core know-how?
Who created or contributed the information, and who is permitted to use it?
What information may be transferred to an outside AI developer or service?
Who may retain and use the data and model after training or termination?
AI is increasingly capable of absorbing and reproducing the knowledge accumulated within an organisation.
That makes AI strategy and intellectual-property strategy increasingly difficult to separate.
This article is based on publicly available information from the Ministry of Intellectual Property and Korea’s Unfair Competition Prevention and Trade Secret Protection Act as reviewed on September 30, 2026. Whether particular information qualifies as a trade secret, how rights in an AI development agreement should be allocated, and whether employee-invention or contributor-compensation issues arise will depend on the specific facts and contractual relationships.