preloader Image

Human craft. Smarter systems. See how we do it →

What Kind of AI Security Does Your Publisher Have?

Jul 21, 2026

Last Updated: July 28, 2026
AI security for publishers black woman with red book in hand and pencil in the other wearing green shirt

Most publishers using AI right now have no formal policy governing how they use it. That's not a theory or a provocative claim. It's what publishers told the Book Industry Study Group in their survey of more than 500 publishing professionals, which Brooke Horn presented at our Summit this past May. Broad, uneven adoption, with almost no oversight.

The lack of AI security for publishers is a major risk. It’s at least as important as the question of AI authorship. So why isn’t this getting more air time?

If we’re going to get real about addressing this issue, we have to get serious about defining our goals for IT security, especially with the new wave of AI tools. AI security for publishers requires three things working in tandem:

  • data that tells you where you stand
  • contracts that define what you own
  • an ethical framework that ensures what you're protecting is worth protecting in the first place

Any two of those without the third leaves a gap your competitors, your vendors, or your readers will eventually find.

How Does the BISG Survey Data Reveal the Scope of the Problem?

The BISG/BookNet survey of more than 500 publishing professionals mapped exactly where the industry stands on AI adoption, and the picture is stark: broad usage sits alongside almost nonexistent oversight. In her session, Brooke’s standout finding was that a clear majority of publishers using AI operate without any formal governance document:  no usage policy, no approval workflow, no record of which tools handle proprietary material. (You can learn more about Brooke Horn's session and findings here.)

You can't protect what you haven't measured. And now that this data exists, no leadership team gets to claim ignorance. Choosing not to look is its own kind of answer, and the good news is we, as an industry, are choosing to look.

Publishers who did establish early governance, we predict, will find a specific operational benefit their competitors are still chasing: clarity. When a new AI tool lands on someone's desk, they already know the approval criteria, the contract terms to check, and who signs off. That translates into efficiencies and compliance benefits you can’t get any other way:

  • Faster tool adoption, because approval criteria already exist
  • Cleaner audits, because AI usage is documented rather than discovered
  • Stronger negotiating position with vendors who know you're paying attention
  • Fewer legal surprises when a partner or acquirer performs due diligence

What Contract Terms Do Publishers Need to Consider Before Deploying AI?

Knowing you have an exposure problem is step one. Making sure your existing contracts don't compound it is step two. Alexandra Andhov's session where she brought up contractual sovereignty surfaced a pattern that's almost certainly repeating across the industry: publishers signing vendor agreements without audit rights, without clear IP ownership terms, without exit clauses that let them take their own data home.

The practical risk is concrete, not theoretical. If your AI vendor trains its models on your proprietary content and you never negotiated language preventing that, you've handed away your competitive advantage for the price of a monthly subscription, and you may have helped train the tool your rivals use next quarter. The fix costs you nothing except the willingness to ask.

Here’s an audit checklist that gives publishers specific contract language to look for and, more importantly, specific language to demand.

  • IP ownership terms that keep your content and any derived outputs yours
  • Training-data restrictions that explicitly bar the vendor from using your material to improve their models
  • Audit rights so you can verify what a vendor actually does with your data
  • Exit and portability clauses that let you retrieve and delete your data when the relationship ends
  • Confidentiality and sub-processor terms that prevent your content from being quietly passed downstream

Our intellectual property costs more than a subscription fee, and it matters enough to get this right. 

Why Do Policies and Contracts Fail Without an Ethical Framework?

Listen, you can hold bulletproof policies and airtight contracts and still lose reader trust if your AI usage contradicts your stated brand values. AI in Publishing Summit speaker Megan Espinal's 5-question AI litmus test serves as the final filter, and its core question is disarmingly direct: does this tool align with what we tell our readers we stand for?

A publisher that champions environmental responsibility while running energy-intensive AI models has opened a gap no policy document will close. A house that centers diverse voices while using tools with uncorrected biases has done the same.

Ethics is not the soft, optional layer of protection, but in actuality, the one your readers actually experience and judge you by. Consider these questions:

  • Does this use of AI match the promises in our brand and marketing?
  • Would we be comfortable explaining this usage to our authors and readers?
  • Does it protect or dilute the human craft our audience values?
  • Are there equity or environmental costs we'd rather not disclose?
  • If this became public tomorrow, would we defend it or scramble?

What Is the Right Order for Building AI Security?

The order of operations matters here. You can't develop an ethical framework if you don't know what your contracts allow. You can't audit usage if you don't know where AI is already operating in your organization.

  1. Audit. Start with this benchmarking question: where is AI showing up in your workflows right now? Inventory every tool across editorial, marketing, production, and rights, including the informal ones staff adopted without approval.
  2. Contracts. Move to a contract review. For each tool you found, ask what’s been allowed and what needs to be discussed. Renegotiate or cancel the agreements that fail the checklist: IP ownership, training restrictions, audit rights, and exit terms first.
  3. Ethics. Apply the litmus test. Now that you know where AI lives and what your contracts permit, ask whether each usage matches the values you communicate to readers. Retire or restructure anything that fails, and document the reasoning so the decision holds when staff turns over.

Why Did NCAI Build an Entire Article Pillar Around Sovereignty?

Brooke, Alexandra, and Megan each address a different face of the same problem. Together, they form what NCAI calls the Protection Stack: data that benchmarks the risk, contracts that contain it, and ethics that ensure you're protecting something worth protecting.

We hope that this pairing reflects a broader trend across the publishing industry, where rights management, data governance, and brand trust are increasingly recognized as core functions of publisher, as much as editorial or sales functions.

At Next Chapter AI, we believe human craft stays central to publishing, and that the role of AI is to help us do all the things that are NOT the art of making books, with less effort (more time for making books, better). Security and data management are core functions of our publishers, and we need to do better on creating organization-wide guidance and principles around these functions. AI may be hastening the need to get these things in place, but really, we probably should have a better handle on this stuff anyway.

Data; contracts; ethics. Publishers who treat these three layers as one connected system protect not only their assets but the reason readers, creators, and their own staff trusted them in the first place. Audit what you have, tighten what you own, and align it all with what you promise, then keep building the next chapter of your work on ground you actually control.

FAQ: AI Security for Publishers

What is the "Protection Stack" in publishing AI governance?

The Protection Stack is NCAI's working framework connecting three layers of AI protection: industry data and benchmarking, legal and contractual safeguards, and ethical brand alignment. All three must work together for meaningful protection.

Why do publishers need all three layers of AI protection?

A policy without legal backing is a suggestion. A contract without ethical alignment protects the wrong things. Data without either is just a wake-up call with no action plan. Each layer addresses a different vulnerability, and gaps in any one of them leave publishers exposed to risks the other two can't cover alone.

What is the recommended order for implementing AI protections?

Start with an internal audit of where AI is already being used in your workflows. Next, review and renegotiate vendor contracts. Finally, apply your own ethical framework to ensure your AI usage aligns with your stated brand values.

How does ethical alignment differ from legal compliance in AI governance?

Legal compliance ensures you own what you create and your vendors can't misuse your data. Ethical alignment ensures your AI practices match the values you communicate to readers. A publisher can be legally compliant while still undermining reader trust if their AI usage contradicts their brand promises around authenticity, equity, or environmental responsibility, as just a few examples.

Where can publishers start if they have no AI governance in place?

Begin with this foundational question: where is AI showing up in your organization right now? Most publishers discover AI usage in departments that never received formal guidance. That inventory becomes the foundation for contract reviews and ethical assessments that follow.

Written by Ayanna

Ayanna Coleman is a publishing strategist and educator who has worked globally across startup, nonprofit, and entrepreneurial spaces since founding Quill Shift in 2013. She built her practice around the conviction that what publishers and creators need most is authentic audience connection and the operational systems to sustain it. Ayanna brings deep expertise in AI workflow integration, content systems, and ethical adoption frameworks.

Pin It on Pinterest

Share This