top of page

Who Owns the Code? The New Legal Questions Behind AI Innovation

  • Writer: Cosmonauts Team
    Cosmonauts Team
  • 5 days ago
  • 8 min read



While AI is increasingly embedded into commercial strategies, products, and services, legal disputes are becoming more complex. Questions of ownership, liability, and accountability now arise long before something goes wrong.

Future Disputes UK recently had an exclusive Q&A with Racheal Muldoon, Partner at Ogier, to explore her insights on managing legal challenges where software, AI, and digital assets converge.

Addressing critical factors, she outlines why ownership, risk allocation, and governance need to be established long before a dispute ever reaches the courtroom.

Enjoy the interview below.


1. Early in your career, before digital assets and AI became such a major part of legal practice, what first drew you toward working at the intersection of law and technology?

The people. Founders, developers, investors and entrepreneurs working in this space are visionary, ambitious and determined to build where the market, the law and the infrastructure are still catching up. This intellect, global outlook and positive energy is a joy to be immersed in daily, and contagious.

The scope to be genuinely creative, across litigation strategy (as one of the first to venture into this unfamiliar legal territory), and outside of court, in helping innovative projects advance from ambition to execution and  thereafter, scale. This is not a field where there is always a precedent, a template or a safe, settled answer. The work requires judgement, imagination and pragmatism.

2. Looking at how quickly technology has reshaped the disputes you handle, what’s your opinion on whether the legal profession is innovating fast enough to keep up, or do you think most firms are still playing catch-up?


Most of the legal profession is still playing catch up, but not because lawyers lack talent or technological literacy. The deeper issue is that the profession is structurally trained to look backwards: to precedent, to established categories and toward risk avoidance. Clients in new and emerging technologies are often doing the opposite. They are building forward, embarking into the unknown. That is where the real gap lies.

Innovation in legal practice is not simply adopting a new platform, automating a workflow or calling something “LegalTech” for the sake of it, nor in deploying an AI model motivated by FOMO. It is the ability to bring human creativity, commercial judgement and a healthy dose of technical curiosity, in tandem, to problems for which there is no settled answer. The lawyers and firms that will survive and be indispensable to clients in the years to come will be those that courageously tread the untrodden path emboldened by the progress we have made as a sector already.

3. As AI systems become more embedded in commercial decision-making, how do you personally think liability should be divided between the company deploying the AI, the developer who built it, and the data that trained it? 


AI liability should be addressed at the start of the commercial relationship, not reverse-engineered after something has gone wrong. The parties should decide, in clear contractual terms, who is responsible for the model, the data, the outputs, the deployment environment, ongoing monitoring and the consequences of misuse or failure.

That allocation should reflect the realities of the deal. A developer may be best placed to stand behind the design, performance limits, documentation and known risks of the system. The company deploying the AI will usually be responsible for how it is used in practice, the periodic human oversight and whether reliance on it is appropriate for the particular commercial, investment or governance decision. Where data is central, the parties also need to be clear about provenance, accuracy, permissioned use, bias, confidentiality and whether the data can lawfully be used to train or refine systems.

In other words, I would start with party autonomy: sophisticated parties should be able to allocate risk deliberately from inception through warranties, indemnities, exclusions, audit rights, governance controls and  escalation mechanics. That said, a contract is not a complete answer. Courts, regulators and stakeholders will still look at who had real control, who understood the risk, who benefited from the system and who was best placed to prevent harm.

4. In your opinion, are companies building and deploying AI platforms today doing enough to protect themselves contractually, or do you think most organisations still operate with real blind spots regarding legal risk?


The key blind spot is treating AI legal risk as a documentation issue rather than a business risk. Organisations need to de-risk the product or service itself by scrutinising how it is designed, delivered, integrated and  monitored. That means asking, crucially before launch, where the product could fail, what that might look like, who is relying on it, what promises are being made to customers, what data is being used, what third-party tools sit underneath it and whether the business can evidence how the system reached a particular output. 

For those building AI products, the risk may sit in the model, training data, outputs, security, open-source components, performance claims, customer documentation or failure to define clear limits of use. For those deploying AI, the risk may sit in over-reliance on the tool, poor or limited (to no) human oversight, using AI in regulated or high-impact decisions, inadequate vendor due diligence, weak audit trails or failing to explain to clients, investors or customers how AI is being used. In both cases, the real question is not simply "Who owns the code?" but whether the business has understood and allocated the operational, contractual and reputational risk created by the technology accordingly ahead of time.

5. What makes a dispute involving digital assets harder to resolve than a traditional commercial dispute?


Digital asset disputes are often more complex than disputes involving other more traditional asset classes because the subject matter is often widely misunderstood. Many may reach for familiar legal concepts, but digital assets form a novel asset class, often requiring nuance. That matters in practice. Before anyone can resolve a dispute, they first need to understand what the asset is, how it is controlled, the commercial reality of transactions, how it has moved and what has actually happened to its value. Imposing legal fictions on reality seldom leads to fair equitable outcomes.

The second difficulty is enforcement. Digital asset value can move quickly across wallets, exchanges, protocols, custodians and jurisdictions, but the legal tools available to freeze, trace or recover it remain fragmented. Different jurisdictions may characterise the asset contrarily, recognise different remedies, or have limited powers to compel overseas exchanges, custodians or service providers to act. That creates a real gap between obtaining an order on paper and securing something of value.

That is why these disputes need to be approached with precision from the outset: identify the asset, identify who has practical control, preserve what can be preserved, and pursue remedies in jurisdictions where those remedies can realistically be recognised, enforced and translated into technical action.

6. What’s your take on how the relationship between offshore centres and onshore regulators is likely to evolve over the next few years, particularly as technology and digital asset investment continues to grow?


The relationship between onshore regulators and offshore centres is likely to become more reciprocal, and more experience-led, thereby correcting the imbalance of power to the benefit of us all. Most key offshore jurisdictions are not in the business of purely theoretical positions. While many onshore regulators attract criticism for having taken a hesitant, sceptical or (at times) openly hostile approach to the regulation of technology ventures, jurisdictions such as Cayman have engaged with the space in a much more positive and pragmatic way. The status of products, services, funds, platforms and Web3 businesses have not been abstract policy considerations offshore; they have been live commercial propositions requiring supervision, structuring, governance and, at times, dispute resolution. That matters because the best regulation in this area will not come from hypotheticals, it will come from experience. Offshore centres have experienced how token projects are launched, how:
 
(i) investment structures hold digital assets; 
(ii) custody arrangements work in practice;  
(iii) service providers manage operational risk; 
(iv) failures unfold;  
(v) trustees can effectively exercise their fiduciary duties; and  
(vi) courts and regulators alike respond when value moves across borders upon a voice command. 

The result is that offshore centres that have embraced this space are increasingly legislating and regulating from that lived experience. It follows that the future calls for greater parity in the form of mutually respectful exchange between offshore centres and onshore regulators. They have much to learn from one another.

7. In high-stakes disputes involving cutting-edge technology, you’re often dealing with stakeholders who have very different priorities. How do you approach aligning those interests when they seem to be pulling in opposite directions?


I start by identifying what each stakeholder is really trying to protect, because in a high-stakes technology dispute, the stated position is rarely the whole story. A founder may be focused on strategic control, an investor on value preservation, a board on governance and duties, a regulator on accountability, and a family office on legacy and continuity. In a Cayman context, that analysis often sits alongside the legal reality of the structure itself: the fund, company, foundation company, trust or holding vehicle through which the technology, tokens, equity or economic exposure is held.

My role is to move the parties away from positional arguments and back to the architecture of value and control: who has authority to act, who controls access, who owes duties, what assets must be preserved, what information is confidential, and which remedy will be effective across borders. That is where Cayman is particularly important. In many technology and digital asset mandates, Cayman is not just a neutral offshore wrapper; it is the jurisdiction through which investment, governance, fiduciary responsibility and enforcement  strategy is aligned, in a commercial tax efficient way. The best outcome is one that preserves value, respects the structure and gives stakeholders a path forward, rather than simply allocating blame.

8. If you could go back and tell yourself one thing at the start of your career about advising on emerging technology, what would it be?


Maintain a hearty sense of humour when people ask, with great concern, whether “all this crypto stuff” I am  doing at the Bar is worthwhile. Remember, in law as in business, early conviction often looks unconventional before it looks obvious.
The wider lesson is that legal practitioners and business leaders cannot wait for perfect certainty before engaging with new technology. Lawyers need to understand the technology well enough to challenge assumptions, allocate risk with precision and become strategic enablers rather than enthusiastic blockers. Businesses need advisers who can distinguish genuine innovation from noise and help them move at speed, without losing discipline. The quiet advantage belongs to those who do the hard thinking early, before the terminology becomes fashionable and the market catches up.

9. What do you hope the audience will take away from your session at Future Disputes UK 2026? 


The sense that 'Who owns the code?' is not a narrow software question, but instead one of the defining  commercial questions of our AI era. That question now sits behind far more than software development. It runs through AI tools, open-source dependencies, digital asset platforms, tokenised products, fund structures, custody arrangements, data pipelines and core service delivery. What begins as a technical issue can quickly become a dispute about ownership, licensing, fiduciary duties, investor protection, valuation, tracing, governance and cross-border enforcement. 

For legal practitioners, the message is that technology can no longer be treated as background infrastructure. We need to understand enough to interrogate the architecture: what has been built, who contributed to it, what data trained it, what its capabilities are (as well as its limitations), what open-source components sit beneath it,  who or what can alter or disable it, who owns the economic upside and who is left exposed if it fails. 

For businesses, the takeaway is more practical still: the time to answer those questions is before launch, before funding, before a platform scales and certainly before a dispute. The organisations that will be best placed in this technological age of ours are those that can explain, evidence and defend the architecture of value they have built and deploy.


Throughout the conversation, Racheal explains that the greatest legal risks with AI arise when ownership, accountability, governance, and responsibility are left undefined. For dispute resolution professionals, understanding these interactions is becoming as critical as resolving the disputes themselves.

At the upcoming Future Disputes UK, Racheal will participate in the fireside chat "Who Owns the Code? Software Disputes in the Age of AI and Open Source." The session will cover ownership and accountability in AI-assisted development, open source governance, and the legal standards shaping the next generation of technology disputes.

Register now to join the discussion at Future Disputes UK.





 
 
 

Comments


bottom of page