Every time an employee pastes a code snippet, a contract or a pricing table into a US-hosted AI assistant, a piece of your business leaves the country. Not a backup copy: the very substance of what sets you apart from competitors. This article explains why that is an intellectual-property problem before it is a compliance problem, and how Mili was designed so the question never arises.
Key points
- Your prompts to an AI are your intellectual property: source code, negotiated clauses, roadmap, margins, client lists.
- A US provider remains subject to US law (including the CLOUD Act) regardless of where its servers are.
- Trade-secret protection depends on the reasonable measures taken to keep information confidential. Handing it to a third party under terms you never read weakens that protection.
- With Mili the software runs on your hardware, only the prompt travels — to servers we operate ourselves, never a US AI service — and nothing is logged or used for training.
What you actually send to an AI
We talk about "data" as if it were an abstraction. Look instead at what concretely moves when a team adopts a general-purpose AI assistant:
- Source code a developer asks it to debug or document — the literal expression of your product.
- Contracts a manager has summarized, with negotiated clauses, agreed prices and counterparty names.
- Plans: product roadmap, pricing strategy, competitor analysis, tender preparation.
- Client data slipped into a request to draft an email or a report.
- Indexed documents, once the assistant is pointed at a shared drive so it "knows the company".
That is not noise. It is the inventory of what a lawyer would call your intangible assets — and it is precisely what an AI service receives in the clear, prompt after prompt, often without anyone in charge ever deciding to entrust it.
Why geography matters: the law follows the provider
A common reflex is to take comfort in server location: "the data is hosted in Canada". That protects against some risks, but not the main one. The Clarifying Lawful Overseas Use of Data Act (CLOUD Act), passed by the US Congress in 2018, allows US authorities to compel a provider under their jurisdiction to produce data in its control wherever in the world it is stored. What matters is not the datacenter's address but the nationality of the company controlling it.
Put differently, choosing a US service's "Canada region" changes latency, not jurisdiction. Your prompts remain within reach of an order you will not be party to and may never be told about.
Honesty about scale: the vast majority of businesses will never be the subject of such a request. But intellectual property is protected by construction, not by probability. Nobody files a patent betting that no one will copy the invention.
Terms of service: the contract nobody reads
The second exposure is more mundane and more frequent. AI services' terms vary by plan, country and year; some consumer tiers let the provider retain conversations and use them to improve models, others exclude it — for an enterprise contract and a price to match. The problem is not that a clause is always unfavourable; it is that your protection depends on a text you do not control and that can change.
In a small business, the AI assistant rarely arrives through the legal department. It arrives through an employee opening a free account on a Tuesday afternoon. From then on, the terms of that free account govern the fate of everything pasted into it.
Trade secrets are lost through carelessness, not theft
This is where the question becomes intellectual property in the strict sense. In Canada and Quebec, information is protected as a trade secret only if it is actually treated as one: restricted access, confidentiality agreements, reasonable measures against disclosure. The protection is not a title you register; it is conduct you must be able to demonstrate.
Picture a dispute where you must establish that your pricing algorithm was a trade secret. The other side's first question: "Who had access?" If the honest answer includes "a foreign AI provider, under standard terms we never negotiated, through an account an employee opened", your position has weakened — not because the provider did anything wrong, but because you skipped the simplest reasonable measure: not sending it.
The best confidentiality clause is the one you never need, because the document never left the building.
Law 25 adds an obligation, not an exception
Quebec's Law 25 requires, before any personal information is communicated outside Quebec, a privacy impact assessment that considers the legal regime of the destination. A provider subject to the CLOUD Act is exactly the case that assessment must examine. You may conclude the risk is acceptable — but you must have done the exercise, documented it, and be able to show it to the Commission d'accès à l'information.
Intellectual property is not covered by Law 25 as such. But both questions arise at the same point: the moment information leaves your control. An architecture that settles one generally settles the other.
How Mili settles it by construction
We did not design Mili to "minimize" these risks. We designed it so the question does not arise. Four architectural decisions:
1. The software lives with you
Mili installs on your workstation, your server or a Raspberry Pi. Your files, your credentials, the agent's memory, the indexes of your documents: all of it sits on your hardware. When Mili reads a contract to extract its deadlines, the contract does not move. When it indexes your mailbox to answer questions, the index is on your disk. Uninstall it and nothing of yours remains anywhere else.
2. Only the prompt travels — to us, not to a US provider
Inference — the moment the model "thinks" — needs GPUs few businesses own. That part therefore travels, TLS-encrypted, to servers Quebec Agentique operates itself, in an ISO 27001 certified datacenter outside US jurisdiction. No US AI service is in the loop. The exact location and each of our processors are named in our privacy policy, because a privacy promise that hides its own details is not one.
3. Nothing logged, nothing trained
The content of your prompts and the model's responses is never logged, retained, analyzed or used to train anything. We keep only the metadata needed for billing and reliability: model used, token counts, timestamp, IP address. Your code, your clauses and your margins pass through our GPUs' memory and leave no trace. That is a contractual commitment written into our terms of service, not a configuration preference.
4. Access is granted tool by tool, and everything is traceable
Mili touches only what you have explicitly enabled: this folder, this mailbox, this connected application. Every action the agent takes is recorded locally with its reasoning. The day an auditor, a client or a court asks "who had access to what", the answer is in a log that belongs to you.
What this changes for intellectual property
Back to the dispute. With this architecture, the answer to "who had access to your pricing algorithm?" becomes: authorized people, on our systems, and a software agent running on our own machines whose vendor is contractually bound to retain nothing. That is a defensible answer. It is also one you can give an institutional client, an insurer or a research partner who insists on knowing where their information goes before signing.
And it is an answer that does not depend on careful reading of a third party's terms, nor on a privacy impact assessment to redo at every vendor change. It depends on a decision made once, at the architecture stage.
Next: bringing inference home to Quebec
We do not claim everything is solved. Inference runs today on our own servers outside the United States; our founding mission is to bring it onto Quebec soil, on GPUs powered here, serving organizations here. The architecture was built so that move is invisible to you — same agent, same endpoint, same guarantees. We say so openly on our About page, because sovereignty is built in the open or not at all.
Three questions to ask before adopting any AI
- Who controls the company receiving my prompts, and which law is it subject to? Not where the servers are: who controls them.
- What does the contract say about retention and training — and who can change it? If the answer is "the provider, unilaterally", you do not control your intellectual property.
- What remains of my data with them the day I leave? The right answer is one word.
To see what those answers look like with Mili, installation is a single command. To talk first, write to us — in French or English.