<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[James Wan & Co]]></title><description><![CDATA[Commercial legal insights and intangible asset strategies for modern business owners. Discover how James Wan & Co helps you protect, structure, and monetise IP.]]></description><link>https://blog.jameswan.co</link><image><url>https://cdn.hashnode.com/res/hashnode/image/upload/v1724822481191/1b870451-81ee-4e32-b0ca-4dc8c63c6b8b.png</url><title>James Wan &amp; Co</title><link>https://blog.jameswan.co</link></image><generator>RSS for Node</generator><lastBuildDate>Tue, 08 Sep 2026 12:13:23 GMT</lastBuildDate><atom:link href="https://blog.jameswan.co/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[How knowledge workers master IP-driven tax mobility]]></title><description><![CDATA[When you think of McDonald’s, you probably picture Big Macs and golden arches. But from a corporate structuring perspective, McDonald’s isn't primarily a fast-food company; it’s a masterclass in intel]]></description><link>https://blog.jameswan.co/how-knowledge-workers-master-ip-driven-tax-mobility</link><guid isPermaLink="true">https://blog.jameswan.co/how-knowledge-workers-master-ip-driven-tax-mobility</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Wed, 05 Aug 2026 07:35:20 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/6869f6a8-557e-4106-a7d3-acf3a3625692.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When you think of McDonald’s, you probably picture Big Macs and golden arches. But from a corporate structuring perspective, McDonald’s isn't primarily a fast-food company; it’s a masterclass in intellectual property and real estate arbitrage.</p>
<p>McDonald’s corporate arm owns the prime real estate and core brand assets, which it then leases back to local franchisees via rents and licensing fees. By decoupling the underlying high-value assets from local operations, McDonald’s converts volatile operational income into stable, tax-efficient passive revenues.</p>
<p>For location-independent knowledge workers, developers, consultants, agency owners, and digital creators, your "real estate" is your intellectual property (IP). By applying this same structural logic globally, you can protect your assets, optimise your corporate footprint, and legally minimise your tax liabilities.</p>
<h3>Phase 1: The Blueprint – Structuring Your IP</h3>
<p>To execute this strategy, you must first separate the ownership of your ideas from the execution of your services.</p>
<p><strong>Step 1: Split your identity into IP Co and Op Co</strong></p>
<p>Instead of operating through a single entity that conducts business and holds your assets, establish a two-tier structure:</p>
<ul>
<li><p><strong>IP Holding Company (IP Co):</strong> Located in an offshore or favourable tax jurisdiction. This entity owns your core intangibles: source code, trademarks, proprietary frameworks, domains, and brand assets.</p>
</li>
<li><p><strong>Operating Company (Op Co):</strong> A local entity set up where you deliver services or invoice local clients.</p>
</li>
</ul>
<p>Your local Op Co bills the client, but it pays licensing or royalty fees to your IP Co for using your proprietary tools and brand. This moves profit out of high-tax operational jurisdictions and into your IP holding hub.</p>
<p><strong>Step 2: Convert Active Service into Passive Capital</strong></p>
<p>Selling your time directly subjects you to high marginal income tax rates and welfare contributions. Transform your active service model into distinct IP assets:</p>
<ul>
<li><p><strong>Move from consulting to software:</strong> Turn custom workflows into a licensable SaaS platform.</p>
</li>
<li><p><strong>Move from agencies to methodologies:</strong> Package your execution frameworks into proprietary white-label tools.</p>
</li>
</ul>
<p>This shift allows you to take advantage of Patent Box regimes or preferential IP tax rates globally, where IP income is often taxed at significantly lower rates than personal income.</p>
<hr />
<h3>Phase 2: Navigating Cross-Border Tax Rules (The Australian Example)</h3>
<p>Tax authorities monitor cross-border profit shifting closely. For example, Australia imposes a standard 30% withholding tax on royalty payments sent to non-resident entities in non-treaty jurisdictions. Furthermore, under draft <a href="https://www.ato.gov.au/law/view/document?DocID=DTR/TR2024D1/NAT/ATO/00001">ATO ruling TR 2024/D1</a>, the ATO broadly treats SaaS distribution, API access, and cloud arrangements as royalty-generating IP rights, frequently catching intercompany payments in the net.</p>
<p>To manage cross-border software and IP transactions under current guidance, global operators apply three primary approaches:</p>
<p><strong>1. Leverage Double Tax Agreement (DTA) Treaty Networks</strong></p>
<p>Under section 4(2) of the <a href="https://www7.austlii.edu.au/cgi-bin/viewdb/au/legis/cth/consol_act/itaa1953299/">International Tax Agreements Act 1953</a>, tax treaties override Australia's domestic tax definition of a royalty. Incorporating your IP Co in a DTA partner country (e.g., Singapore, the UK, or the US) drops the withholding rate from the 30% statutory rate down to 5% to 15% (or 0% in specific exemptions). The foreign IP Co must maintain genuine economic substance to prevent treaty benefit denials under anti-abuse rules.</p>
<p><em>Note on Singapore:</em> Under the Australia-Singapore DTA, the capped royalty withholding tax rate is 10%. If an Australian Op Co pays a $10,000 royalty fee to a Singapore IP Co, it must withhold $1,000 for the ATO. The Singapore company can usually claim a foreign tax credit for this to avoid double taxation. The 10% paid to the ATO is usually a sunk cost. It becomes your total global tax rate on that transaction.</p>
<p><strong>2. Direct Contracting / Merchant of Record (MoR) Models</strong></p>
<p>Operators bypass intercompany friction by having the foreign IP Co contract directly with global clients as the Merchant of Record. The local entity is reduced to a service provider performing local R&amp;D or support, billed as an arm's-length service fee (taxed as service income, not a royalty). Because there is no Australian corporate entity making an intercompany royalty payment to Singapore, no royalty withholding tax is triggered. (However, 10% GST still applies on sales made to Australian consumers if sales exceed the A$75,000 threshold).</p>
<p><strong>3. Fair and Reasonable Contract Apportionment</strong> If a transaction bundles non-royalty elements (like pure hosting or technical support) with IP rights, the ATO threatens to tax the entire amount as a royalty under <a href="https://www.ato.gov.au/law/view/document?DocID=DTR/TR2024D1/NAT/ATO/00001">ATO TR 2024/D1</a> unless the contract explicitly splits the consideration. Operators structure agreements with verified market valuations to separate unbundled service fees from underlying IP rights.</p>
<hr />
<h3>Phase 3: The Singapore IP Co</h3>
<p>A popular choice for establishing an IP Co is Singapore, governed by the Inland Revenue Authority of Singapore (IRAS). Does Singapore require tax to be paid on foreign-sourced IP income? The short answer is no, provided the income is not remitted into Singapore, or qualifies for specific exemptions if it is.</p>
<p><strong>Understanding Singapore’s Territorial Tax System</strong></p>
<ul>
<li><p><strong>Unremitted Foreign Income:</strong> If your Singapore IP Co receives licensing fees or foreign income into a non-Singapore bank account and keeps it outside Singapore, IRAS charges 0% tax.</p>
</li>
<li><p><strong>Remitted Foreign Income:</strong> If foreign-sourced income is brought into a Singapore bank account, it is generally taxable at a flat 17% corporate rate, unless it qualifies for the Foreign-Sourced Income Exemption (FSIE) under Section 13(8) of the Income Tax Act.</p>
</li>
</ul>
<p><strong>Crucial Anti-Avoidance Guardrails</strong></p>
<p>Relying purely on a foreign bank account is not a loophole.</p>
<ol>
<li><p><strong>Trade / Business Carried On in Singapore:</strong> If IRAS determines that the Singapore IP Co is conducting its core operations inside Singapore (e.g., local directors, staff, and management decisions), IRAS can rule that the income accrued in Singapore and tax it at 17%, regardless of where the bank account is located. You must maintain valid Economic Substance offshore.</p>
</li>
<li><p><strong>Section 10L Rules:</strong> Effective 2024, if a Singapore entity disposes of or sells foreign intangible assets (like IP) and remits the capital gains to Singapore, those gains become taxable unless the company satisfies Economic Substance Requirements.</p>
</li>
<li><p><strong>Section 13(8) Exemption Rules:</strong> If you do want to bring money into a Singapore bank account tax-free, the income must have been subject to tax in a foreign source country with a headline rate of at least 15%, and the Comptroller must be satisfied the exemption is beneficial.</p>
</li>
</ol>
<p><strong>Banking Execution: How to Hold and Spend Funds Tax-Free</strong></p>
<p>To avoid IRAS tax, funds must be deposited and held in an offshore (foreign) bank account (e.g., multi-currency corporate accounts in Hong Kong, Switzerland, the US, or via global fintech platforms like Wise. <em>Note: Do not use Airwallex!</em>).</p>
<p>Under Section 10(25) of the Singapore Income Tax Act, foreign income is only deemed "received in Singapore" (and thus taxable) if it is transferred to a Singapore bank account (like DBS or OCBC), used to pay a business debt incurred inside Singapore, or used to buy physical assets brought into Singapore.</p>
<p>If your money lands in an offshore Wise account, you can spend it digitally via electronic transfers or card payments with 0% Singapore tax, provided the transactions remain outside Singapore. This includes paying global vendor expenses (AWS, Meta), offshore business travel, or buying offshore assets.</p>
<p><strong>Distributions: Dividends vs. Director’s Fees</strong></p>
<ul>
<li><p><strong>Dividends:</strong> Singapore operates a One-Tier Corporate Tax System with 0% dividend withholding tax. The Singapore IP Co can pay dividends directly from its offshore Wise account to a non-Singapore shareholder's personal bank account overseas without triggering a remittance event.</p>
</li>
<li><p><strong>Director’s Fees:</strong> Under Singapore tax law, director's fees paid to a non-resident director are deemed sourced in Singapore and carry a statutory 24% withholding tax. Consequently, equity owners generally distribute profits as dividends.</p>
</li>
</ul>
<hr />
<h3>Phase 4: Select Personal Tax Residency</h3>
<p>While Singapore lets the dividend leave untaxed, the tax liability shifts entirely to where the shareholder personally resides. This is where many digital nomads fall into a trap, assuming that spending less than 183 days in any one country automatically makes them a tax resident of "nowhere."</p>
<p><strong>How the ATO Views Nomads and Worldwide Income</strong></p>
<p>Physical absence alone is rarely enough to break your Australian tax ties. The ATO evaluates residency using four statutory tests.</p>
<ul>
<li><p><strong>The Domicile Test:</strong> If your domicile of origin is Australia, you remain an Australian tax resident unless you can prove your "permanent place of abode" is outside Australia. Living as a transient nomad moving between Airbnbs fails this test. The ATO explicitly states in <a href="https://www.ato.gov.au/law/view/document?DocID=TXR/TR20231/NAT/ATO/00001">ATO TR 2023/1</a> that a nomadic lifestyle without a fixed overseas home means your Australian residency remains intact.</p>
</li>
<li><p><strong>The Resides Test:</strong> Retaining Australian bank accounts, personal belongings, or Medicare while drifting abroad usually means you still "reside" in Australia according to ordinary concepts.</p>
</li>
</ul>
<p>If the ATO determines you are still a resident, you are legally required to report Singapore dividends on your Australian tax return, taxing them at your marginal rate (up to 45% + Medicare levy). Foreign institutions (including Wise) automatically report account balances back to the ATO via the Common Reporting Standard (CRS).</p>
<p><strong>The Two-Step Legal Fix</strong></p>
<p>To receive dividends tax-free without being dragged back into the high-tax net, you must actively establish tax residency in a new jurisdiction rather than attempting to exist in a tax void.</p>
<ol>
<li><p><strong>Formal Tax Exit from Australia:</strong> Sell or lease out real property, minimise Australian bank accounts, cancel local subscriptions, and establish a clear intention of leaving indefinitely (aiming for a 2+ year continuous absence).</p>
</li>
<li><p><strong>Establish "Tax Residency of Choice":</strong> Register as a formal tax resident in a low/zero-tax hub. Holding an official <a href="https://www.rd.go.th/english/21978.html">Tax Residency Certificate</a> (e.g. Thai Form R.O. 22 Document) gives the ATO proof that your permanent place of abode is outside Australia, defeating the Domicile Test. Options include:</p>
</li>
</ol>
<ul>
<li><p><strong>UAE:</strong> Obtain a residency visa and spend <strong>90 days a year</strong> there to secure a Tax Residency Certificate.</p>
</li>
<li><p><strong>Panama or Costa Rica:</strong> Territorial tax regimes where foreign-sourced dividends carry 0% local tax.</p>
</li>
<li><p><strong>Cyprus or Malta:</strong> Offer 0% tax on foreign dividend income for non-domiciled tax residents.</p>
</li>
</ul>
<p><strong>A Reality Check on Southeast Asian Visas</strong></p>
<p>If you are looking at Southeast Asia, be aware that standard nomad visas do not equal zero tax. In Thailand, anyone spending 183+ days becomes a tax resident subject to progressive rates (0% to 35%) on foreign-sourced income brought into the country.</p>
<p>The popular Destination Thailand Visa (DTV) and Thai Privilege Visas do not grant tax exemptions. The only exception is the 10-year <strong>Long-Term Resident (LTR) Visa</strong> for Wealthy Pensioners (which requires a 50,000 THB application fee, annual passive income or pension of at least USD 80,000 or an annual passive income of at least USD 40,000 combined with a minimum investment of USD 250,000 in Thai government bonds, foreign direct investment, or Thai real estate, report to immigration once per year, no minimum days to keep visa), granting a 100% tax exemption on foreign-sourced income, regardless of whether it is remitted into Thailand.</p>
<p>By combining a hub like Singapore with a legally sound personal tax residency, global knowledge workers can build a compliant, location-independent operation modelled after the world's most successful multinational networks.</p>
]]></content:encoded></item><item><title><![CDATA[Why licensing your AI likeness to a discretionary family trust triggers an ATO audit]]></title><description><![CDATA[Artificial Intelligence has transformed from a futuristic buzzword into a tangible business tool. One of the most cutting-edge applications we are seeing among our corporate clients is the creation of]]></description><link>https://blog.jameswan.co/why-licensing-your-ai-likeness-to-a-discretionary-family-trust-triggers-an-ato-audit</link><guid isPermaLink="true">https://blog.jameswan.co/why-licensing-your-ai-likeness-to-a-discretionary-family-trust-triggers-an-ato-audit</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Wed, 05 Aug 2026 02:54:30 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/ea2f4ebc-0bd1-4780-8ed9-3e1066beee20.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Artificial Intelligence has transformed from a futuristic buzzword into a tangible business tool. One of the most cutting-edge applications we are seeing among our corporate clients is the creation of a "Digital Twin."</p>
<p>By training a grounded AI model on a founder or key executive's voice, writing style, and physical appearance, companies can generate hyper-realistic synthetic photos, blog posts, audio podcasts, and social media videos, all without the executive ever stepping foot in a recording studio.</p>
<p>The marketing efficiencies are undeniable. However, the tax strategies being pitched around these Digital Twins are leading many founders straight into a regulatory trap.</p>
<h3>Part 1: The "Tax-Free" Digital Twin Strategy</h3>
<p>On paper, the strategy proposed to many founders and key executives sounds like a masterclass in corporate structuring and IP law. It usually goes like this:</p>
<ul>
<li><p><strong>The Setup:</strong> The company wants to use the founder's Digital Twin for marketing content.</p>
</li>
<li><p><strong>The Offshore Middleman:</strong> To generate the synthetic media, the company pays a subscription or generation fee to an overseas AI platform.</p>
</li>
<li><p><strong>The Licensing Agreement:</strong> The overseas platform then pays a "content usage fee" or "IP licensing fee" back to the founder's Discretionary Family Trust in exchange for the legal right to use the grounded AI model based on the founder's likeness.</p>
</li>
<li><p><strong>The "Tax Benefit":</strong> The company claims a tax deduction for the marketing expense (lowering corporate tax). Meanwhile, the Discretionary Trust receives the licensing income and distributes it to family members in lower tax brackets.</p>
</li>
</ul>
<p>In this scenario, the founder supposedly generates a highly tax-effective new income stream while completely avoiding personal income tax at the top marginal rate.</p>
<p><strong>There is only one problem: Under Australian law, this structure is entirely illegal.</strong></p>
<h3>The Reality Check: ATO Taxation Determination TD 2023/4</h3>
<p>The Australian Taxation Office (ATO) is hyper-aware of high-profile individuals attempting to alienate income generated from their "fame" or public persona to related entities. To close this loophole, the ATO issued Taxation Determination TD 2023/4, which alters how image rights, likeness, and "fame" are taxed in Australia.</p>
<p><strong>1. You Cannot Sub-License Your Face or Voice</strong></p>
<p>The ATO's ruling explicitly states that income derived from the commercial exploitation of your name, image, likeness, identity, reputation, or signature must be assessed as your personal income. It does not matter if an overseas AI platform generates the synthetic output.</p>
<p><strong>2. Australia Does Not Recognise "Property Rights" in Fame</strong></p>
<p>In some jurisdictions, your "Right of Publicity" is recognised as a distinct, assignable property right. Australia does not recognise this. Because your likeness is not considered alienable property under Australian common law, any agreement where you "license" your Digital Twin to your Family Trust is viewed by the ATO as an ineffective tax avoidance scheme.</p>
<p><strong>The Cross-Border Withholding Risk</strong></p>
<p>Beyond the personal income tax trap, injecting an overseas AI supplier into the payment flow creates a secondary risk: Foreign Royalty Withholding Tax. If an Australian company pays an overseas supplier a fee that includes the right to use "intellectual property", the ATO may classify that payment as a royalty. Australian businesses are legally obligated to withhold tax on royalties paid overseas.</p>
<h3>How to Structure Your Digital Twin Legally (While Alive)</h3>
<p>While the "tax-free trust distribution" loophole is closed, your company can still legally and commercially benefit from using a Digital Twin:</p>
<ul>
<li><p><strong>The Corporate Deduction:</strong> The company pays the overseas AI platform for the software service (SaaS) or the generation of the synthetic media. This remains a legitimate, deductible marketing expense for the company.</p>
</li>
<li><p><strong>The Personal Income Assessment:</strong> If the founder is to be remunerated for the use of their likeness or voice model, the company (or the platform) must pay the founder directly.</p>
</li>
<li><p><strong>Marginal Rates Apply:</strong> The founder must declare this usage fee on their individual tax return.</p>
</li>
</ul>
<h3>Part 2: The Posthumous Risk (What Happens When You Die?)</h3>
<p>While we have established that a living founder cannot assign their likeness to a trust for tax purposes, an entirely different legal crisis emerges regarding a founder's Digital Twin after they pass away.</p>
<p>While Australia lacks a dedicated right of publicity, deceased individuals' estates are not entirely without legal weapons if a digital replica is used commercially. The Australian Consumer Law (ACL) and the common law tort of 'passing off' can sometimes be leveraged if an AI-generated likeness is used to falsely imply that the deceased person (or their estate) endorsed a product or service. However, this relies heavily on the deceased having an established business reputation or goodwill. Furthermore, if a deepfake is created simply to tarnish a deceased person’s reputation rather than to sell a product, the estate is largely powerless. Under Australian law, a cause of action for defamation dies with the person (<em>actio personalis moritur cum persona</em>).</p>
<p>The United States continues to aggressively widen this legal gap. In addition to state-based laws, the proposed federal NO FAKES Act, reintroduced to the US Congress in 2026, specifically targets unauthorised digital replicas. Under this proposed legislation, the right to control AI-generated visual or voice replicas survives an individual's death and can be enforced by their heirs or executors for up to 70 years post-mortem. This creates a concrete, monetizable, and highly protective legal framework for digital remains that Australia simply does not possess.</p>
<p>Recent developments in Australian copyright policy do, however, offer a glimmer of hope against unauthorised AI cloning. In late 2025, the Australian Government explicitly rejected calls from big tech companies to introduce a broad "Text and Data Mining" (TDM) exception for AI training. This means tech companies cannot legally scrape and ingest copyrighted works, such as your recorded voice, published videos, or written text, to train their generative AI models without permission and compensation.</p>
<p><strong>The Solution: Estate Planning for Digital Twins</strong></p>
<p>Beyond merely appointing a digital executor, creators and business owners are increasingly treating their potential "digital twin" as a distinct asset in their estate planning. Legal professionals are now drafting explicit post-mortem licensing clauses and 'AI directives' within wills. These clauses expressly state whether the deceased consents to their likeness, voice, or writing being used to train AI posthumously, and can explicitly assign the commercial rights of any digital exploitation to specific beneficiaries.</p>
<h3>The Bottom Line for Business Owners</h3>
<p>Innovation in AI offers incredible leverage for marketing, but it does not rewrite the Australian tax code or succession laws. If a tax strategy relies on moving the commercial value of your personal identity into a trust, it will fail an ATO audit. Likewise, if your will does not account for your digital remains, your estate may lose control of your likeness entirely.</p>
<p>If you are developing grounded AI models, licensing your likeness, or want to secure your digital footprint in your estate planning, the team at <strong>James Wan &amp; Co.</strong> can ensure your commercial contracts and wills are robust and compliant. Contact us today to secure your digital future.</p>
]]></content:encoded></item><item><title><![CDATA[Structuring overseas payments and crypto rails for ACNC (not for profit) co-operatives]]></title><description><![CDATA[The modern digital economy moves faster than traditional banking. For forward-thinking organisations, especially Co-operatives acting as hubs for digital services, community projects, or decentralised]]></description><link>https://blog.jameswan.co/structuring-overseas-payments-and-crypto-rails-for-acnc-not-for-profit-co-operatives</link><guid isPermaLink="true">https://blog.jameswan.co/structuring-overseas-payments-and-crypto-rails-for-acnc-not-for-profit-co-operatives</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Wed, 05 Aug 2026 02:10:38 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/551af037-9fad-4d31-bbcf-ce69ad28dc70.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The modern digital economy moves faster than traditional banking. For forward-thinking organisations, especially Co-operatives acting as hubs for digital services, community projects, or decentralised technology, the ability to seamlessly license Intellectual Property (IP) or engage overseas talent is critical.</p>
<p>Increasingly, we are seeing Australian organisations bypass the friction of SWIFT banking networks by paying overseas suppliers directly in cryptocurrency.</p>
<p>But what happens when your organisation is a <strong>Co-operative registered with the Australian Charities and Not-for-profits Commission (ACNC)</strong>? How do you legally pay an overseas supplier in crypto for intangible assets? And most importantly, how do you legally distribute income back to your local co-op members without violating charity laws?</p>
<p>In this guide, we break down the legal mechanics, the Australian Taxation Office (ATO) record-keeping requirements, and the withholding tax traps of managing a cross-border, crypto-powered Co-operative.</p>
<h2>Part 1: The ACNC Co-operative Reality Check (How to Legally "Distribute" Income)</h2>
<p>Before executing overseas contracts, we must address the most common regulatory hurdle for ACNC-registered entities: <strong>The Private Benefit Rule</strong>.</p>
<p>By law, an ACNC-registered charity must operate on a <strong>not-for-profit (NFP) basis</strong>. This means the Co-operative <em>cannot</em> distribute surplus income or profits to its members as dividends or shareholder returns.</p>
<p>So, how does a member legally receive income from the Co-operative?</p>
<p>To distribute funds to members legally without losing ACNC status, the payments must be structured as <strong>arm's-length remuneration for services rendered</strong> or as distributions that directly advance the charity's purpose.</p>
<ul>
<li><p><strong>Service Agreements:</strong> If a member provides tangible work to the Co-op (e.g., writing code, managing marketing, or providing professional consulting), the Co-op can pay them a commercial, market-rate contractor fee or salary.</p>
</li>
<li><p><strong>Sub-contracting:</strong> If the Co-op generates revenue by offering a service to the public, it can legally sub-contract that work to its members, paying them for their specific deliverables.</p>
</li>
</ul>
<p><em>Legal Tip:</em> Every payment to a member must be supported by a formal contractor agreement and valid tax invoices. If the ATO or ACNC audits the entity, you must prove the payment was for a genuine service at market value, not a disguised profit distribution.</p>
<h2>Part 2: Paying the Overseas Supplier in Crypto</h2>
<p>Assume your Co-operative needs to pay a software developer in Estonia for coding work, or pay a licensing fee to a digital artist in Brazil for the use of their IP. The supplier requests payment in cryptocurrency (like USDT, Bitcoin, or Ethereum) directly to their digital wallet, bypassing their local banking system entirely.</p>
<p>Under Australian law, this is perfectly legal. The ATO treats cryptocurrency as a legitimate form of property and a valid medium of exchange. The fact that the overseas supplier never touches a traditional bank account in their home country does not invalidate the commercial transaction in Australia.</p>
<p>However, the Co-operative must treat the crypto transaction with the exact same documentary rigour as a fiat bank transfer.</p>
<h3>The ATO Record-Keeping Protocol</h3>
<p>To claim the overseas payment as a legitimate business expense (and to prove the funds were not misappropriated), the ACNC Co-operative must maintain records for <strong>five years</strong>:</p>
<ol>
<li><p><strong>The Commercial Contract:</strong> A clear IP licensing agreement or contractor agreement outlining the scope of intangible work.</p>
</li>
<li><p><strong>The Invoice:</strong> The overseas supplier must issue an invoice. Ideally, it should state the amount owed in fiat (e.g., $10,000 USD) and specify that it will be settled in a specific cryptocurrency.</p>
</li>
<li><p><strong>AUD Timestamping:</strong> The ATO requires all crypto transactions to be reported in Australian Dollars (AUD). At the exact moment the Co-op transfers the crypto to the overseas wallet, you must record the AUD equivalent value using a reputable exchange rate.</p>
</li>
<li><p><strong>On-Chain Proof:</strong> You must retain the transaction ID (TxID), the date/time of the transfer, and the recipient’s public wallet address.</p>
</li>
</ol>
<h2>Part 3: The Hidden Trap: Foreign Royalty Withholding Tax</h2>
<p>The most dangerous compliance risk in this structure is failing to distinguish between paying for a <em>service</em> and paying for <em>IP rights</em>.</p>
<p>If your Co-operative pays an overseas supplier to build a custom website from scratch, that is generally classified as a payment for <strong>services</strong>.</p>
<p>However, if you pay an overseas supplier to use <em>existing</em> software, digital artwork, or patented technology, the ATO classifies this as a <strong>Royalty</strong>.</p>
<h3>The Withholding Obligation</h3>
<p>If the payment is a royalty, Australia requires the payer (your Co-op) to withhold tax from the payment and remit it to the ATO. The standard Foreign Royalty Withholding Tax rate is <strong>30%</strong>, though this is often reduced (usually to 5% - 15%) if Australia has a Double Tax Agreement (DTA) with the supplier’s home country.</p>
<h3>How do you withhold tax on a Crypto payment?</h3>
<p>This is where the accounting gets highly technical. You cannot send crypto to the ATO. If you owe a $10,000 AUD equivalent royalty to an overseas supplier, and the withholding rate is 10%:</p>
<ol>
<li><p><strong>Withhold:</strong> You must withhold $1,000 AUD worth of the payment.</p>
</li>
<li><p><strong>Remit:</strong> The Co-op pays $1,000 in AUD fiat directly to the ATO.</p>
</li>
<li><p><strong>Transfer:</strong> The Co-op transfers the remaining $9,000 AUD equivalent in cryptocurrency to the supplier's overseas wallet.</p>
</li>
<li><p><strong>Report:</strong> The Co-op provides a payment summary to the supplier and lodges a PAYG annual report with the ATO.</p>
</li>
</ol>
<p>Even if the supplier operates entirely in Web3, refuses to use a bank, and wants the full amount in crypto, <strong>the Australian Co-operative bears the legal liability for the withholding tax</strong>. If you fail to withhold it, the ATO will force your Co-op to pay the tax out of its own pocket, plus penalties.</p>
<p><strong>Standard off-site services</strong> attract a 0% withholding rate. An international supplier working entirely overseas is exempt from needing an ABN. These services include:</p>
<ul>
<li><p><strong>Remote Software Development</strong>: A freelancer in India writing code for your app.</p>
</li>
<li><p><strong>Digital Marketing</strong>: A contractor in Europe managing your social media ads.</p>
</li>
<li><p><strong>Customer Support</strong>: A call centre in the Philippines handling your customer inquiries.</p>
</li>
<li><p><strong>Graphic Design</strong>: A studio in the US creating a new logo and branding assets for you.Virtual Assistance</p>
</li>
<li><p>Paralegal support, accounting, and bookkeeping services performed entirely overseas qualify as standard off-site services, meaning no foreign resident withholding tax is required.</p>
</li>
<li><p>If paying an offshore company for standard SaaS or API access solely for your own internal business operations, it is generally treated as a service rather than a royalty. Under the Australian Taxation Office (ATO) guidance on software and cloud transactions, this is classified as a standard commercial service rather than a royalty. Your co-operative is acting as a standard customer or end-user. You are paying the offshore vendor simply to use their live software application to process your own data, manage your internal tasks, or track your co-op records. Ensure your contract with the supplier states you are acquiring a non-exclusive, internal end-user licence to use the platform as designed. It must explicitly omit any rights to modify, copy, or commercially distribute the code. Check your SaaS/API agreement for an embedded "Gross-Up" clause. If the ATO audits your co-op and determines the fee was a royalty, a gross-up clause means you must pay the withholding tax out of your own pocket on top of what you already paid the foreign vendor.</p>
</li>
</ul>
<h2>Summary Checklist for Business Owners</h2>
<p>If your ACNC Co-operative is entering the global, crypto-powered digital economy, ensure you have the following framework in place:</p>
<ul>
<li><p><strong>Member Contracts:</strong> Ensure all "income distributions" to local members are legally structured as commercial service agreements or charitable grants, never as profit dividends.</p>
</li>
<li><p><strong>IP vs. Service Assessment:</strong> Clearly define whether the overseas payment is for a service or a royalty to determine your ATO withholding tax obligations.</p>
</li>
<li><p><strong>Fiat to Crypto Off-Ramp:</strong> Maintain a clear ledger showing the conversion of Co-op fiat into crypto, timestamped with the AUD value at the exact moment of the overseas transfer.</p>
</li>
<li><p><strong>Audit Trail:</strong> Keep the foreign invoice, the commercial agreement, and the blockchain TxID saved in your accounting software for a minimum of five years.</p>
</li>
</ul>
<h3>Need to Structure a Cross-Border Tech Entity?</h3>
<p>Bridging the gap between Australian charity law, international IP licensing, and decentralised crypto payments requires a meticulous legal strategy.</p>
<p>At <strong>James Wan &amp; Co.</strong>, we help organisations build compliant, scalable legal architectures for the modern digital economy. Contact us today to ensure your co-operative’s cross-border payments and member agreements are commercially robust and legally secure.</p>
]]></content:encoded></item><item><title><![CDATA[Selling the invisible: How businesses use collective marks and certification marks to generate income]]></title><description><![CDATA[When you sell physical goods, the product does the talking. A customer can hold a premium leather bag, test drive a car, or taste a craft beer. But what happens when what you sell is entirely invisibl]]></description><link>https://blog.jameswan.co/selling-the-invisible-how-businesses-use-collective-marks-and-certification-marks-to-generate-income</link><guid isPermaLink="true">https://blog.jameswan.co/selling-the-invisible-how-businesses-use-collective-marks-and-certification-marks-to-generate-income</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Wed, 05 Aug 2026 01:38:28 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/083eba29-8c36-4c58-b221-12769eff83ab.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When you sell physical goods, the product does the talking. A customer can hold a premium leather bag, test drive a car, or taste a craft beer. But what happens when what you sell is entirely invisible?</p>
<p>If you provide professional services, website creation, strategic consulting, or digital assets (like cryptocurrency security), you are asking your clients to buy a promise. You are asking them to trust your competence before they ever see the final result.</p>
<p>In the service and digital economy, <strong>trust is a highly monetisable asset</strong>. While standard trade marks protect your specific brand name, there are two specialised, underutilised legal tools under the <em>Trade Marks Act 1995 (Cth)</em> designed specifically to turn industry trust into recurring revenue: <strong>Certification Trade Marks</strong> and <strong>Collective Trade Marks</strong>.</p>
<p>Here is a commercial guide to understanding these rare trade marks and how they can create a competitive moat around your intangible services.</p>
<h2>1. The Collective Trade Mark</h2>
<p>A collective trade mark is exclusively owned by an "association" (like an industry group, a co-operative, or a professional alliance). Its sole purpose is to tell the market: <em>"The person providing this service is a member of our vetted group."</em></p>
<p>Unlike a standard trade mark, which distinguishes the services of <em>one</em> business from another, a collective mark distinguishes the services of <em>members</em> from <em>non-members</em>. And while a certification mark proves <em>what</em> you have achieved, a collective trade mark proves <em>who</em> you belong to. Its sole purpose is to tell the market: <em>"The person providing this service is a vetted member of our elite group."</em></p>
<p>By law, a collective mark can only be owned by an "association". While associations can be unincorporated, running a commercial venture this way is risky. This is why many groups turn to the <strong>Co-operative</strong> structure to hold and monetise their collective mark.</p>
<h3>Why a Co-operative?</h3>
<p>Under the <em>Co-operatives National Law</em> (which applies across Australian states and territories), a co-operative is a distinct, incorporated legal entity governed by a board of directors. Because it is a legal entity, the co-operative can hold property, including trade marks, in its own name.</p>
<p><strong>Setting up a Co-operative in Australia:</strong></p>
<ul>
<li><p><strong>Minimum Members:</strong> You must have a minimum of five (5) members to form a co-operative.</p>
</li>
<li><p><strong>The Rules:</strong> The co-operative must draft a constitution (its rules) and an initial disclosure statement.</p>
</li>
<li><p><strong>Incorporation:</strong> Once the rules are approved by the members at a formation meeting, the co-op is officially registered with the relevant state authority (such as NSW Fair Trading).</p>
</li>
</ul>
<h3>Managing Members: Joining and Expulsion</h3>
<p>Co-operatives operate on the principle of "active membership".</p>
<ul>
<li><p><strong>To join:</strong> A new service provider applies to the board, agrees to abide by the rules, and pays a joining fee, or purchases share capital.</p>
</li>
<li><p><strong>To be removed:</strong> If a member produces sloppy work, damages the brand, or fails to maintain their active membership requirements, the board can use the dispute resolution and disciplinary procedures outlined in the co-op’s rules to expel them. Once expelled, the member automatically loses the legal right to use the collective trade mark.</p>
</li>
</ul>
<h3>How it generates income</h3>
<p>Unlike a certification mark, the co-operative's rules do not need to be approved by the ACCC. The collective uses the mark to generate revenue that funds the group and provides returns to the members:</p>
<ol>
<li><p><strong>Membership Fees and Share Capital:</strong> Members pay annual dues for the right to use the mark. If it is a "distributing co-operative," members can buy shares to fund the organisation's growth.</p>
</li>
<li><p><strong>Pooled Marketing ROI:</strong> The co-operative uses the membership fees to market the collective trade mark to the public aggressively. Clients learn to look for the mark, driving highly qualified leads directly to the members.</p>
</li>
<li><p><strong>Profit Sharing:</strong> In a distributing co-operative, surplus funds generated from membership fees or lead-generation commissions can be distributed back to the members as dividends.</p>
</li>
</ol>
<h3>How it Works for businesses</h3>
<p>Imagine you and twenty other elite freelance software developers form an incorporated association. You want to distinguish yourselves from cheap, overseas coding farms. You register a collective trade mark, perhaps a specific logo denoting "The Australian Clean Code Alliance."</p>
<ul>
<li><p><strong>No complex licensing:</strong> Any member of your association can use the logo on their website, proposals, and LinkedIn profiles without needing to sign a formal, individual intellectual property licence agreement.</p>
</li>
<li><p><strong>Internal governance:</strong> If a member produces sloppy code, the association relies on its internal rules to revoke their membership, thereby stripping their right to use the mark. The Australian Competition and Consumer Commission (ACCC) does not need to approve these internal rules.</p>
</li>
<li><p><strong>Group enforcement:</strong> If an outsider illegally slaps your collective mark on their website, a claim for financial relief can take into account the damage suffered by <em>each individual member</em> of your association.</p>
</li>
</ul>
<blockquote>
<p><strong>The Trade-Off:</strong> Collective trade marks cannot be sold, assigned, or transmitted to another party. They are forever tied to the association. Because of this, they are incredibly rare, accounting for only a few hundred of the nearly 800,000 registered trade marks in Australia.</p>
</blockquote>
<h3>How it works for a crypto business</h3>
<p>A group of freelance Web3 developers create a Decentralised Autonomous Organisation (DAO). However, a DAO is not a recognised legal entity in Australia. To commercialise their brand, they formally incorporate as a distributing co-operative: <strong>"The Genesis Developer Co-op."</strong></p>
<p>The Co-op registers a collective trade mark. As crypto clients are notoriously fearful of being scammed by anonymous freelancers, they learn that hiring someone with the "Genesis" mark guarantees a vetted, highly skilled professional. The Co-op generates income by charging independent developers a $2,000 annual membership fee to use the mark, plus a 5% commission on contracts sourced through the Co-op's marketing engine.</p>
<h2>2. The Certification Trade Mark</h2>
<p>A certification trade mark does not distinguish your business from another; it guarantees that a service or product meets a highly specific, verifiable standard.</p>
<p>Legally, the owner of a certification mark acts as an independent gatekeeper. You cannot use the mark on your own services. Instead, you create the standard, and you allow others to display your mark—if they pass your tests. Because it acts as a public guarantee, the Australian Competition and Consumer Commission (ACCC) must approve the rules governing the standard before IP Australia will register the mark.</p>
<h3>How it Generates income</h3>
<p>Operating a certification mark turns your business into a regulatory body for your niche. Income is generated through the compliance lifecycle:</p>
<ol>
<li><p><strong>Application and Auditing Fees:</strong> You charge businesses a premium fee to test or audit their services against your standard.</p>
</li>
<li><p><strong>Annual Licensing Dues:</strong> Once a business passes, they must pay a recurring annual fee to retain the legal right to display your certification mark on their marketing materials.</p>
</li>
<li><p><strong>Accreditation and Training:</strong> You can mandate (and sell) proprietary training courses that professionals must complete before they can apply for certification.</p>
</li>
</ol>
<h3>How it works for businesses</h3>
<p>If your consultancy provides data privacy audits, you might create a proprietary "Zero-Risk Data Framework." If you register a certification trade mark for this framework, you are creating a new industry standard.</p>
<p>Other IT consultants can apply to you to have their services audited. If they pass, they are allowed to display your certification mark on their marketing materials.</p>
<ul>
<li><p><strong>The ultimate authority:</strong> As the owner of the certification mark, you act as the gatekeeper of quality.</p>
</li>
<li><p><strong>The separation of powers:</strong> Legally, the owner of a certification mark <em>cannot</em> use the mark on their own services. You are the certifier, not the certified.</p>
</li>
<li><p><strong>ACCC oversight:</strong> Because a certification mark is a public guarantee of quality, you must submit a strict set of rules governing how the standard is tested and enforced. In Australia, IP Australia will not register the mark until the ACCC approves your rules to ensure they are fair and not anti-competitive.</p>
</li>
</ul>
<h3>How it works for a crypto business</h3>
<p>Imagine a cybersecurity firm specialising in blockchain technology. They register a certification trade mark for a standard they invent: the <strong>"Zero-Exploit Verified"</strong> seal.</p>
<p>They do not use this seal on their own software. Instead, they operate as the auditor. When a new Decentralised Finance (DeFi) crypto platform wants to launch, they desperately need to prove to investors that their smart contracts won't be hacked. The DeFi platform pays the cybersecurity firm a $30,000 auditing fee. If the code passes the strict rules approved by the ACCC, the DeFi platform pays a $5,000 annual licensing fee to display the "Zero-Exploit Verified" mark on their website, instantly earning investor trust.</p>
<h2>Collective vs. Certification Marks: At a Glance</h2>
<p>If you are considering uniting your industry or establishing a gold standard for your profession, here is how the two compare:</p>
<table style="min-width:75px"><colgroup><col style="min-width:25px"></col><col style="min-width:25px"></col><col style="min-width:25px"></col></colgroup><tbody><tr><td><p><strong>Feature</strong></p></td><td><p><strong>Collective Trade Mark</strong></p></td><td><p><strong>Certification Trade Mark</strong></p></td></tr><tr><td><p><strong>Primary Purpose</strong></p></td><td><p>Indicates membership in a specific group or association.</p></td><td><p>Indicates compliance with a specific quality, standard, or characteristic.</p></td></tr><tr><td><p><strong>Who Owns It?</strong></p></td><td><p>Must be an association (incorporated or unincorporated).</p></td><td><p>Any entity (but they must not use the mark on their own services).</p></td></tr><tr><td><p><strong>Who Uses It?</strong></p></td><td><p>Members of the association.</p></td><td><p>Anyone who meets the defined standard, regardless of membership.</p></td></tr><tr><td><p><strong>ACCC Approval</strong></p></td><td><p>Not required. Association sets its own internal rules.</p></td><td><p>Mandatory. ACCC must approve the certification rules.</p></td></tr><tr><td><p><strong>Asset Transfer</strong></p></td><td><p>Cannot be assigned, sold, or leased to a third party.</p></td><td><p>Can be assigned to a new owner (subject to ACCC approval).</p></td></tr></tbody></table>

<h2>Why Should a Business Care?</h2>
<p>Building a brand in the intangible space is notoriously difficult. Clients cannot objectively measure the "quality" of your strategic advice or your website design until long after the invoice is paid. Building a brand in the intangible space requires more than just good marketing; it requires legal strategy. By leveraging Certification and Collective Trade Marks, you can establish the gold standard in your industry, create enforceable barriers to entry, and unlock entirely new, recurring revenue streams. You can achieve three powerful commercial outcomes:</p>
<ol>
<li><p><strong>Premium Pricing:</strong> Clients will pay a premium for a service that carries a verified stamp of quality or exclusive membership, effectively removing you from the race-to-the-bottom price wars.</p>
</li>
<li><p><strong>Instant Authority:</strong> Whether you are building an industry guild (Collective) or establishing a rigorous training standard (Certification), you position your organisation as the definitive leader in your niche.</p>
</li>
<li><p><strong>Market Differentiation:</strong> In a sea of consultants claiming to be "experts," a federally registered Collective or Certification mark acts as a legally enforceable proof of competence.</p>
</li>
</ol>
<p><strong>Are you ready to establish the standard in your industry?</strong></p>
<p>Whether you are an industry association looking to protect your members, forming a commercial co-operative to protect your freelance network or developing a new certification standard for your industry, or an innovator wanting to certify a new professional standard, the IP team at <strong>James Wan &amp; Co.</strong> can guide you through the complexities of non-standard trade mark applications. Contact us today to discuss your strategy.</p>
]]></content:encoded></item><item><title><![CDATA[Unlocking invisible capital: A business owner’s guide to low-cost creation of intangible assets and generating cross-border income from them]]></title><description><![CDATA[When most business owners think about their balance sheet, their minds jump to tangible assets: office buildings, inventory, manufacturing machinery, or vehicle fleets. There's a bias towards what you]]></description><link>https://blog.jameswan.co/unlocking-invisible-capital-a-business-owner-s-guide-to-low-cost-creation-of-intangible-assets-and-generating-cross-border-income-from-them</link><guid isPermaLink="true">https://blog.jameswan.co/unlocking-invisible-capital-a-business-owner-s-guide-to-low-cost-creation-of-intangible-assets-and-generating-cross-border-income-from-them</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Wed, 05 Aug 2026 01:20:35 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/85417727-24a3-488d-b25c-2884f72488cb.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When most business owners think about their balance sheet, their minds jump to tangible assets: office buildings, inventory, manufacturing machinery, or vehicle fleets. There's a bias towards what you can see and touch. However, in the modern knowledge-based economy, the most valuable assets your company owns are almost certainly the ones you cannot physically touch.</p>
<p>According to global financial studies, intangible assets, ranging from brand names and software code to proprietary processes and creative works, account for up to 90% of the market value of S&amp;P 500 companies.</p>
<p>Despite this, many business owners still view Intellectual Property (IP) as an abstract legal concept rather than what it truly is: <strong>income-generating capital</strong>.</p>
<p>In this guide, we break down the core types of intangible assets in plain business English, explore their financial and tax treatments (from Australia’s AASB 138 to Singapore’s groundbreaking Intangibles Disclosure Framework), and close with a fascinating real-world case study: why the Amazon marketplace is flooded with bizarre, "keyboard-smash" trademark names.</p>
<h2>Part 1: Income-Generating Intangible Assets</h2>
<p>Intangible assets generate income through several main channels:</p>
<ul>
<li><p><strong>Licensing fees:</strong> Permitting third parties to use your IP in exchange for recurring payments.</p>
</li>
<li><p><strong>Royalties:</strong> Earning a percentage of sales generated from your IP.</p>
</li>
<li><p><strong>Usage/Subscription fees:</strong> Charging users to access your platform, code, or content.</p>
</li>
<li><p><strong>Capital appreciation:</strong> Selling the asset outright or leveraging it to increase your business valuation during a capital raise or exit.</p>
</li>
</ul>
<p>Here is a breakdown of the primary intangible property types every business owner should understand:</p>
<table style="min-width:100px"><colgroup><col style="min-width:25px"></col><col style="min-width:25px"></col><col style="min-width:25px"></col><col style="min-width:25px"></col></colgroup><tbody><tr><td><p><strong>Intangible Asset Type</strong></p></td><td><p><strong>Examples</strong></p></td><td><p><strong>Maximum Lifespan</strong></p></td><td><p><strong>Primary Income Generation Model</strong></p></td></tr><tr><td><p><strong>Copyright</strong></p></td><td><p>Books, music compositions, digital artwork, software source code, training manuals</p></td><td><p>Life of author + 70 years (varies slightly by country)</p></td><td><p>Royalties, syndication, software licensing (SaaS), publication rights</p></td></tr><tr><td><p><strong>Trademarks</strong></p></td><td><p>Brand names, logos, slogans, distinctive product shapes</p></td><td><p>Indefinite (renewable every 10 years if actively used)</p></td><td><p>Brand licensing, franchising fees, market exclusivity, premium product pricing</p></td></tr><tr><td><p><strong>Patents</strong></p></td><td><p>Inventions, hardware mechanisms, pharmaceutical formulas, technical processes</p></td><td><p>Up to 20 years (standard patent)</p></td><td><p>Licensing royalties, cross-licensing, monopoly pricing</p></td></tr><tr><td><p><strong>Registered Designs</strong></p></td><td><p>Visual appearance, shape, or pattern of a functional object</p></td><td><p>Up to 10 years (in Australia)</p></td><td><p>Manufacturing licensing, design exclusivity</p></td></tr><tr><td><p><strong>Trade Secrets &amp; Know-How</strong></p></td><td><p>Secret recipes (e.g., Coca-Cola), proprietary search algorithms, client lists</p></td><td><p>Indefinite (as long as secrecy is maintained)</p></td><td><p>Moat creation, process licensing, franchise system execution</p></td></tr></tbody></table>

<h3>Copyright (Books, Music, Art, Software)</h3>
<ul>
<li><p><strong>Creation vs. Registration:</strong> In Australia and most International Financial Reporting Standards (IFRS) jurisdictions, copyright arises <strong>automatically</strong> upon creation. You do not pay a government filing fee to acquire copyright; your primary cost is the cost to create (e.g., author fees, graphic designer rates, or software engineer salaries).</p>
</li>
<li><p><strong>Cost to Create vs. Income Potential:</strong> Software code might cost $100,000 to develop, but if distributed as a SaaS product, it can generate millions in recurring subscription revenue at near-zero marginal cost. Similarly, a single musical composition or book can generate decades of passive royalty checks across streaming services, publishing houses, and global syndication deals.</p>
</li>
</ul>
<h2>Part 2: Creation Cost vs. Income &amp; Accounting Standards</h2>
<p>From an economic perspective, intangibles offer immense leverage. Unlike a delivery truck, which can only be in one place at one time and depreciates with wear and tear, a piece of software, a trademark, or a digital artwork can be licensed to thousands of people simultaneously without degrading the core asset.</p>
<p>However, accounting for these assets requires adherence to financial standards.</p>
<pre><code class="language-plaintext">                  ┌─────────────────────────────────────────┐
                  │      INTANGIBLE ASSET RECOGNITION       │
                  └────────────────────┬────────────────────┘
                                       │
                   Is it internally generated R&amp;D?
                                       │
                    ┌──────────────────┴──────────────────┐
                    ▼                                     ▼
         [ Research Phase ]                    [ Development Phase ]
     Expense immediately to P&amp;L              Capitalise as Intangible
   (e.g., exploratory testing)              Asset under AASB 138 / IFRS
                                            (if 6 criteria met)
</code></pre>
<h3>AASB 138 &amp; ATO Treatment in Australia</h3>
<p>In Australia, <a href="https://www.aasb.gov.au/admin/file/content105/c9/AASB138_07-04_COMPapr07_07-07.pdf"><strong>AASB 138 Intangible Assets</strong></a> governs how businesses recognise, measure, and amortise intangible property.</p>
<p>Under AASB 138, an intangible asset must be:</p>
<ol>
<li><p><strong>Identifiable</strong> (capable of being separated/sold, or arising from legal rights).</p>
</li>
<li><p><strong>Controlled</strong> by the entity (ability to obtain future economic benefits and restrict others).</p>
</li>
<li><p>Expected to generate <strong>future economic benefits</strong>.</p>
</li>
</ol>
<h4>Capitalisation vs. Expensing (The R&amp;D Distinction)</h4>
<p>AASB 138 forces businesses to separate internal asset creation into a <strong>Research Phase</strong> and a <strong>Development Phase</strong>:</p>
<ul>
<li><p><strong>Research Costs:</strong> Must be written off immediately as an operating expense in your Profit &amp; Loss statement.</p>
</li>
<li><p><strong>Development Costs:</strong> Can be capitalised onto your Balance Sheet as an asset if you can demonstrate technical feasibility, intention to complete, ability to use/sell, and probability of future economic inflow.</p>
</li>
</ul>
<p><strong>ATO Tax Treatment:</strong> The Australian Taxation Office (ATO) differentiates between revenue expenses (deductible immediately) and capital expenditure. Capitalised intangible assets (such as in-house software or acquired patents) are generally written off over their effective economic life under tax depreciation rules (Capital Allowances).</p>
<h3>The Global Advantage: IFRS vs. US GAAP</h3>
<p>If your business operates under <strong>International Financial Reporting Standards (IFRS)</strong>, which Australia (AASB), the United Kingdom, and the European Union use, you enjoy significantly more flexibility than companies subject to <strong>US GAAP</strong>.</p>
<ul>
<li><p><strong>Under US GAAP:</strong> Rules are highly conservative. Almost all internally generated R&amp;D and intangible asset development must be expensed immediately, preventing companies from showing these valuable assets on their balance sheet.</p>
</li>
<li><p><strong>Under IFRS / AASB 138:</strong> Once a project hits the development milestone, those costs can be capitalised, boosting your balance sheet equity, improving debt-to-equity ratios, and presenting a far truer picture of company value to investors.</p>
</li>
</ul>
<h3>Singapore’s Pioneering Framework (FRS 38 / SFRS(I) 38 &amp; IDF)</h3>
<p>Singapore has taken intangible asset commercialisation a step further. Alongside its <strong>SFRS(I) 38</strong> standard (fully aligned with IFRS), Singapore introduced the <strong>Intangibles Disclosure Framework (IDF)</strong>.</p>
<p>The IDF provides a standardised blueprint built on four pillars, <strong>Strategy, Identification, Measurement, and Management (SIMM)</strong>, allowing companies to clearly communicate the value of their IP to banks, venture capitalists, and auditors. This framework enables businesses to use their IP portfolios to secure direct bank debt and equity financing.</p>
<h2>Part 3: The E-Commerce Case Study: Amazon Brand Registry &amp; The "Gibberish" Trademark Phenomenon</h2>
<p>To see the practical intersection of trademark law, asset creation, and modern commercial strategy, we look at a curious phenomenon dominating global marketplaces like Amazon.</p>
<p>If you have ever searched Amazon for a phone charger, a garlic press, or a set of cable ties, you have likely encountered brand names that look like complete keyboard mashes: <strong>"QWOPR"</strong>, <strong>"XINXIN"</strong>, <strong>"ZESZICAN"</strong>, or <strong>"TRONJIK"</strong>.</p>
<p>Why are sellers choosing unpronounceable nonsense over memorable brand names? The answer lies in <a href="https://sell.amazon.com.au/brand-registry"><strong>Amazon Brand Registry</strong></a> and <strong>trademark examination rules</strong>.</p>
<pre><code class="language-plaintext">                     TRADITIONAL BRANDING vs. AMAZON "GIBBERISH" STRATEGY
                     
  [ Traditional Brand Strategy ]               [ Amazon "Keyboard Smash" Strategy ]
  • Months spent naming &amp; testing              • Random, meaningless letter combo
  • Focus: Emotional connection &amp; loyalty      • Focus: Fast trademark approval
  • High risk of "Descriptiveness" rejection   • 0% chance of "Descriptiveness" rejection
  • High risk of prior trademark conflict      • Almost 0% chance of prior conflict
  • Long-term enterprise brand equity          • Instant access to Amazon Brand Registry
</code></pre>
<h3>The Amazon Incentive</h3>
<p>To unlock Amazon’s most powerful seller tools, A+ content, dedicated Brand Stores, protection against listing hijackers, and advanced advertising, sellers must enrol in <strong>Amazon Brand Registry</strong>. The prerequisite to enrol? <strong>A pending or active registered trademark</strong>.</p>
<h3>The E-Commerce Seller’s Dilemma</h3>
<p>Many cross-border sellers and white-label manufacturers sell commoditised items. Their end customers don't care about brand affinity; they care about <strong>price, fast shipping, and 5-star reviews</strong>.</p>
<p>If a seller tries to register a sensible, descriptive name like <em>"Super Soft Towels"</em> or <em>"QuickCharge Cable"</em>, trade mark offices (like IP Australia or the USPTO) will reject the application under <strong>Descriptiveness</strong> rules. If they pick a common real word, they run a high risk of getting rejected due to a <strong>Likelihood of Confusion</strong> with existing registered trademarks.</p>
<h3>The "Keyboard Smash" Legal Hack</h3>
<p>To bypass months of legal back-and-forth and avoid rejection, these manufacturers deliberately invent completely meaningless "fanciful" words:</p>
<ol>
<li><p><strong>Zero Descriptiveness Risk:</strong> A word like <em>"QWOPR"</em> describes nothing, so trade mark examiners cannot refuse it on descriptiveness grounds.</p>
</li>
<li><p><strong>Zero Conflict Risk:</strong> It is practically impossible that another company has registered the same gibberish letter sequence.</p>
</li>
<li><p><strong>Speed to Registry:</strong> The trademark breezes through the examination stage with zero office actions, allowing the seller to enrol in Amazon Brand Registry in record time.</p>
</li>
</ol>
<p>For these sellers, the trademark is not an asset built for long-term customer loyalty. It is simply a <strong>regulatory key</strong> designed to unlock Amazon’s search algorithms, secure buy-box protection, and start generating immediate sales.</p>
<p>Whether you are a fast-moving e-commerce brand securing trademarks to dominate online marketplaces, a software company capitalising R&amp;D under AASB 138, or an established enterprise looking to structure licensing and royalty agreements, <strong>your intangible assets require a clear strategy.</strong></p>
<p>At <strong>James Wan &amp; Co.</strong>, we bridge the gap between legal protection, commercial strategy, and financial reality. We help Australian and international businesses:</p>
<ul>
<li><p>Audit and identify unrecognised intangible property.</p>
</li>
<li><p>Draft robust licensing, royalty, and distribution agreements.</p>
</li>
<li><p>Register and defend national and international trademarks, designs, and patents.</p>
</li>
<li><p>Structure IP portfolios to maximise company valuation during capital raises or exits.</p>
</li>
</ul>
<p><strong>Ready to turn your intangible property into an income-generating machine?</strong> Contact the team at <strong>James Wan &amp; Co.</strong> today to schedule a strategic IP consultation.</p>
]]></content:encoded></item><item><title><![CDATA[Migrating knowledge from Google, Confluence etc to Obsidian]]></title><description><![CDATA[Why?
Obsidian is an incredibly powerful tool for organising your thoughts, projects, and daily notes. However, because Obsidian stores files directly on your computer rather than in the cloud, getting]]></description><link>https://blog.jameswan.co/migrating-knowledge-from-google-confluence-etc-to-obsidian</link><guid isPermaLink="true">https://blog.jameswan.co/migrating-knowledge-from-google-confluence-etc-to-obsidian</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 09 Jun 2026 04:40:32 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/b4172cee-3b2b-4d3c-94ae-818d5cdb2403.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Why?</h2>
<p>Obsidian is an incredibly powerful tool for organising your thoughts, projects, and daily notes. However, because Obsidian stores files directly on your computer rather than in the cloud, getting your notes to sync to your Android phone can feel a bit tricky at first.</p>
<p>While Obsidian offers a premium paid sync service (or pay for the recurring <strong>Obsidian Sync - Standard service</strong> 1GB = US$28.80 for 1 year with education discount), you can easily set up a completely <strong>free</strong>, automated sync using Google Drive. Here is the exact, step-by-step method to get your desktop and mobile notes talking to each other.</p>
<h3>Step 1: Create a new dedicated "Notes" Google Account</h3>
<p>To keep your vault secure and prevent your personal or work files from getting mixed up, we highly recommend creating a brand-new, free Google account dedicated <em>solely</em> to your Obsidian notes. Google provides 15 GB free.</p>
<ul>
<li><p><strong>Pro-Tip:</strong> Make it easy to remember by mirroring your current email address and adding ".notes" to it.</p>
</li>
<li><p><em>Example:</em> If your normal email is <code>john.doe@gmail.com</code>, create your new account as <code>john.doe.notes@gmail.com</code>.</p>
</li>
</ul>
<h3>Step 2: Install the DriveSync App on your phone</h3>
<p>Since the official Google Drive app on Android doesn't let Obsidian read your files directly, we need a "bridge" app to do the heavy lifting in the background.</p>
<ol>
<li><p>On your Android phone, download the free <a href="https://play.google.com/store/apps/details?id=com.ttxapps.drivesync">DriveSync app</a> (also known as AutoSync for Google Drive) from the Google Play Store.</p>
</li>
<li><p>Open the app and <strong>Allow</strong> it the storage permissions it asks for.</p>
</li>
<li><p>Tap <strong>Connect to Google Drive</strong> and log in using the new <code>john.doe.notes@gmail.com</code> account you just created.</p>
</li>
</ol>
<h3>Step 3: Configure Your Sync Settings</h3>
<p>Now we need to tell DriveSync exactly which folders to connect.</p>
<ol>
<li><p>In the app, choose to set up a <strong>Synced Folder</strong> (also called a Folderpair).</p>
</li>
<li><p>For the <strong>Sync Method</strong>, strictly select <strong>Two-way</strong>. This ensures that notes you write on your phone go to your PC, and notes you write on your PC go to your phone.</p>
</li>
<li><p><strong>Filter out the junk:</strong> To keep your sync lightning-fast, you want to ignore background system files. Check the box for <strong>"Select files by name"</strong>.</p>
</li>
<li><p>You will be asked to configure inclusion/exclusion patterns. You can find the exact text you need to copy and paste on this <a href="https://forum.obsidian.md/t/drivesync-obsidian-inclusion-exclusion-name-patterns/101019">DriveSync Ultimate – Obsidian Inclusion/Exclusion Name Patterns</a> GitHub page.</p>
</li>
</ol>
<h3>Step 4: The Home Screen Shortcut</h3>
<p>Once your setup is complete, DriveSync will quietly work in the background. However, if you want total control to force a sync before you open Obsidian on your phone, there is a great shortcut!</p>
<ul>
<li><p>Go to your Android phone's home screen.</p>
</li>
<li><p>Long-press on an empty space and open your <strong>Widgets</strong> menu.</p>
</li>
<li><p>Find the <strong>DriveSync</strong> widget and drag it to your home screen. Now, you can trigger a manual sync with a single tap, without ever having to open the app itself. Its a green icon with a circular white arrow.</p>
</li>
</ul>
<hr />
<hr />
<h2>How to bring your existing knowledge into Obsdian</h2>
<p>Go to Google Takeout <a href="https://takeout.google.com/">https://takeout.google.com/</a></p>
<p>click "Create Export"</p>
<p>Use a Python script to convert the JSON and HTML files to .md format for Obsidian.</p>
]]></content:encoded></item><item><title><![CDATA[Data Harvesting Risks: Commercial lessons from the Facebook v BrandTotal case
]]></title><description><![CDATA[For digital and data-driven businesses, compliance with third-party platform rules is critical. The lawsuit filed by Facebook against BrandTotal Ltd. and Unimania, Inc. highlights the legal and financ]]></description><link>https://blog.jameswan.co/data-harvesting-risks-commercial-lessons-from-the-facebook-v-brandtotal-case</link><guid isPermaLink="true">https://blog.jameswan.co/data-harvesting-risks-commercial-lessons-from-the-facebook-v-brandtotal-case</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 08 Jun 2026 22:37:43 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/853d77e4-b1a8-48c7-9b60-91de4eb154f3.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For digital and data-driven businesses, compliance with third-party platform rules is critical. The lawsuit filed by Facebook against BrandTotal Ltd. and Unimania, Inc. highlights the legal and financial risks associated with unauthorised data extraction.</p>
<p>To avoid costly litigation and business interruptions, it's important to understand the liabilities associated with data scraping and how to govern your data collection practices.</p>
<h3>How is data collected?</h3>
<p>Understanding how data is collected is the first step in risk management.</p>
<p>In this case, the defendants deployed internet browser extensions (named "UpVoice" and "Ads Feed") via the Google Chrome Store to silently extract data from users' sessions on platforms like Facebook and Instagram. By using users' browsers as proxies, the defendants sent unauthorised, automated commands to Facebook's servers to harvest both public and non-public data.</p>
<h3>Commercial and legal risks</h3>
<p>If your business uses or profits from unauthorised data scraping, you expose your operations to significant legal actions. The salient risks demonstrated in this case include:</p>
<p><strong>Binding Terms of Service:</strong> Simply creating an account or a business page on a platform binds your business to its Terms of Service. Facebook and Instagram’s policies expressly prohibit accessing or collecting data using automated means without prior permission.</p>
<p><strong>Breach of Contract:</strong> By using automated scripts to bypass platform rules and harvest user profiles, ad preferences, and engagement metrics, the defendants committed a direct breach of contract.</p>
<p><strong>Unjust Enrichment:</strong> Packaging and selling unauthorised scraped data as "marketing intelligence" or "competitive insights" exposes your business to unjust enrichment claims. Platforms will aggressively protect their proprietary data ecosystems.</p>
<p><strong>Severe Financial Penalties:</strong> The financial exposure in these lawsuits extends far beyond standard compensatory damages. Plaintiffs can demand an accounting and "disgorgement" of profits, meaning your business could be legally forced to surrender all revenue generated from the illicit data harvesting.</p>
<p><strong>Destruction of Business Assets:</strong> Courts can issue permanent injunctions requiring a business to identify and permanently delete all data obtained through unauthorised means, effectively crippling business models that rely on that data.</p>
<h3>Managing your risk</h3>
<p>To protect your business, please proactively audit your data acquisition strategies. You must verify that any data collection tools, browser extensions, or third-party data vendors your business relies on strictly comply with the target platforms' Terms of Service. Relying on unauthorised "dark" marketing intelligence or scraping techniques carries an unacceptable risk of immediate technical enforcement, account termination, and crippling civil litigation.</p>
]]></content:encoded></item><item><title><![CDATA[Managing Workforce Risks - The True Cost of Incorrectly Classifying Contractors]]></title><description><![CDATA[For businesses in Australia, correctly classifying your workforce is a critical commercial decision. Incorrectly treating an employee as an independent contractor exposes your business to significant ]]></description><link>https://blog.jameswan.co/managing-workforce-risks-the-true-cost-of-incorrectly-classifying-contractors</link><guid isPermaLink="true">https://blog.jameswan.co/managing-workforce-risks-the-true-cost-of-incorrectly-classifying-contractors</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 08 Jun 2026 22:20:05 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/b3de0577-e4cb-43ac-9717-6d1716e59cc6.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For businesses in Australia, correctly classifying your workforce is a critical commercial decision. Incorrectly treating an employee as an independent contractor exposes your business to significant financial and legal risks.</p>
<p>To protect your business and stay compliant, it is important to understand the penalties and how to manage these risks.</p>
<h3>The Financial and Legal Consequences</h3>
<p>If your business incorrectly treats an employee as an independent contractor, you risk receiving several severe penalties and charges. These include:</p>
<p><strong>PAYG Withholding Penalties</strong>: Your business can incur a PAYG withholding penalty for failing to deduct tax from worker payments and send it to the ATO.</p>
<p><strong>Super Guarantee Charge (SGC)</strong>: You may be liable for the SGC, which ultimately costs more than the superannuation that would have been paid had the worker been classified correctly from the start. The SGC comprises a super guarantee shortfall amount, nominal interest, and an administration fee.</p>
<p><strong>Additional Superannuation Penalties</strong>: Beyond the SGC, you may face additional super guarantee penalties. This includes the Part 7 penalty amount, which can be up to 200% of the SGC under the <em>Superannuation Guarantee (Administration) Act 1992</em>.</p>
<p><strong>Sham Contracting Contraventions</strong>: Incorrectly classifying an employee as an independent contractor when they are actually an employee is known as sham contracting, which is a contravention under the <em>Fair Work Act 2009</em>. Courts have the authority to impose penalties on a business or an individual for this conduct.</p>
<h3>Risk of Public Reporting</h3>
<p>The risk of discovery is high. If anyone knows or suspects that your business is incorrectly treating an employee as an independent contractor, they can report your business directly to the ATO by making a tip-off.</p>
<h3>Mitigating Your Commercial Risk</h3>
<p>To protect your business, please proactively assess your workforce arrangements. You must correctly determine whether a worker is an employee or an independent contractor before engaging them. Additionally, if a worker requests to be treated as an independent contractor, you must be aware of the specific legal steps and implications involved.</p>
<p>Ensure you are relying on accurate information for the correct financial year before making any commercial decisions based on worker classification.</p>
]]></content:encoded></item><item><title><![CDATA[Facial recognition and the Privacy Act: a clearer (but stricter) line for businesses]]></title><description><![CDATA[A recent decision of the Administrative Review Tribunal has clarified when Australia’s Privacy Act 1988 (Cth) applies to facial recognition technology (FRT) used by private organisations on their prem]]></description><link>https://blog.jameswan.co/facial-recognition-and-the-privacy-act-a-clearer-but-stricter-line-for-businesses</link><guid isPermaLink="true">https://blog.jameswan.co/facial-recognition-and-the-privacy-act-a-clearer-but-stricter-line-for-businesses</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:42:12 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/f9465f7b-ffcf-4bbe-8368-8656b2669d30.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A recent decision of the Administrative Review Tribunal has clarified when Australia’s <em>Privacy Act 1988 (Cth)</em> applies to facial recognition technology (<strong>FRT</strong>) used by private organisations on their premises. The decision provides a workable pathway for limited use of FRT in high-risk security contexts, but it also reinforces that governance and transparency failures can still result in Privacy Act breaches, even where the underlying security objective is accepted. Read the case of <a href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ARTA/2026/130.html">Bunnings Group Limited and Privacy Commissioner [2026] ARTA 130 here</a>.</p>
<h3>What the Tribunal clarified</h3>
<h4>1) Facial recognition is “biometric information” and therefore “sensitive information”</h4>
<p>The Tribunal confirmed that facial images used for automated matching and the biometric templates derived from them constitute biometric information. Under the Privacy Act, biometric information used for automated biometric verification or identification is treated as sensitive information and attracts higher protections. Even if the system deletes non-matching data quickly, the Tribunal treated the processing as a “collection” step for Privacy Act purposes.</p>
<h4>2) Collection without consent can be lawful in a “permitted general situation,” but only on evidence</h4>
<p>The most important aspect for businesses is the Tribunal’s acceptance that biometric collection without consent may be lawful where an organisation can rely on the “permitted general situation” exception (often described in practice as an unlawful-activity/safety-risk exception). The test is whether the organisation reasonably believes the collection is necessary to prevent or respond to serious unlawful activity or safety risks.</p>
<p>Two practical points flow from the Tribunal’s approach:</p>
<ul>
<li><p>The organisation does not need to prove that facial recognition was the only option available, but it must show that the belief was objectively supportable.</p>
</li>
<li><p>The analysis must be evidence-based. Assertions of “safety” or “theft prevention” without an incident history and a clear rationale for necessity are unlikely to be sufficient.</p>
</li>
</ul>
<h3>Why Bunnings succeeded on the “permitted exception” point (and why this is not a blanket approval)</h3>
<p>The Tribunal accepted Bunnings’ security justification based on the record before it: serious repeat offending, evidence of violence and abuse towards staff, the limits of alternative controls, and system features designed to reduce privacy impact (including rapid deletion of non-matches and restricted access to watchlists).</p>
<p>The Tribunal made it clear that this was a fact-specific outcome and not a general endorsement of retail facial recognition. Businesses should treat the decision as guidance on what a defensible necessity case looks like, not as permission to deploy FRT as a standard loss-prevention tool.</p>
<h3>The warning: “lawful collection” is not the end of the compliance task</h3>
<p>Even though Bunnings succeeded on the threshold question of whether consent was required in those circumstances, the Tribunal still upheld breaches relating to <strong>notice, privacy governance, and privacy policy disclosures</strong>.</p>
<p>Key failings included:</p>
<ul>
<li><p>generic “video surveillance” signage that did not adequately inform individuals about biometric collection and automated matching</p>
</li>
<li><p>insufficient transparency in privacy policy settings about the use of FRT</p>
</li>
<li><p>weak privacy governance at rollout, including the absence of a robust privacy impact assessment and supporting documentation that would normally be expected for biometrics.</p>
</li>
</ul>
<h3>How this decision fits with recent OAIC enforcement activity</h3>
<p>This decision aligns with a clear enforcement pattern in Australia: regulators focus heavily on notice, consent, proportionality, and demonstrable governance in biometric deployments.</p>
<ul>
<li><p><strong>Kmart:</strong> In September 2025, the Privacy Commissioner found Kmart’s use of FRT to tackle refund fraud unlawful, including for collecting biometric information without consent and failing to meet notification requirements. <a href="https://www.oaic.gov.au/news/media-centre/18-kmarts-use-of-facial-recognition-to-tackle-refund-fraud-unlawful,-privacy-commissioner-finds">See the OAIC's decision here</a>.</p>
</li>
<li><p><strong>7-Eleven:</strong> The OAIC has also addressed governance failures in biometric deployments, including an incident in which a service provider inadvertently re-enabled FRT functionality, which remained active for approximately 12 months before detection and deactivation. <a href="https://www.oaic.gov.au/news/media-centre/oaic-finds-against-7-eleven-over-facial-recognition">See the OAIC's decision here</a>.</p>
</li>
</ul>
<p>The lesson is consistent: even when a security or business objective is legitimate, organisations materially increase breach and enforcement risk by under-resourcing the transparency, control environment, and documentary record, particularly for biometrics.</p>
<hr />
<h2>Practical takeaways for business decision-makers</h2>
<ol>
<li><p><strong>Assume FRT is sensitive biometric collection</strong><br />Treat facial recognition deployments as high-risk from the outset, even if biometric data is held briefly or deleted for non-matches. Design and governance should assume APP obligations will apply.</p>
</li>
<li><p><strong>If relying on a permitted exception, “show your working”</strong><br />If you intend to collect biometrics without consent, you need an evidence-based necessity case: incident data, an explanation of why less intrusive measures are insufficient, and an explanation of why the proposed design is proportionate. The safest way to structure this is to complete a privacy impact assessment as part of the decision-making process, not after deployment.</p>
</li>
<li><p><strong>Build proportionality and safeguards into system design from day one</strong><br />Examples of safeguards that supported Bunnings’ case included limited watchlists, restricted access, and rapid deletion of non-matches. Organisations should adopt a “minimise impact” design approach and document how each control reduces privacy risk.</p>
</li>
<li><p><strong>Do not treat notice and privacy policy updates as administrative tasks</strong><br />The Tribunal’s findings underscore that transparency failures can lead to breach findings even when the underlying collection is accepted. Signage, front-of-house notices, and privacy policy disclosures must clearly address biometric collection and automated matching, not just general CCTV.</p>
</li>
<li><p><strong>Treat vendor/device controls as a compliance risk</strong><br />The 7-Eleven incident demonstrates how vendor maintenance actions can inadvertently reintroduce biometric processing. Contracts, device configuration controls, auditability, and monitoring should be designed to detect and prevent unauthorised reactivation or configuration drift.</p>
</li>
</ol>
<h3>Bottom line</h3>
<p>This Tribunal decision indicates that FRT can be deployed lawfully in Australia in narrow, well-justified security settings. But it also sets a stricter practical standard: businesses should assume that biometric programs will fail Privacy Act scrutiny unless necessity, proportionality, governance, and transparency are established and evidenced before rollout, not retrofitted after issues arise.</p>
]]></content:encoded></item><item><title><![CDATA[Artificial Intelligence: top priorities for in-house legal teams in 2026]]></title><description><![CDATA[By the end of 2025, AI regulation in major markets had moved from guidance and voluntary principles to binding legal obligations. In 2026, several of those regimes enter operational phases, and regula]]></description><link>https://blog.jameswan.co/artificial-intelligence-top-priorities-for-in-house-legal-teams-in-2026</link><guid isPermaLink="true">https://blog.jameswan.co/artificial-intelligence-top-priorities-for-in-house-legal-teams-in-2026</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:36:11 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/24dfa9cb-ac0e-42f5-bdcb-2628fe71bf39.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>By the end of 2025, AI regulation in major markets had moved from guidance and voluntary principles to binding legal obligations. In 2026, several of those regimes enter operational phases, and regulators are signalling that informal governance will not be considered an adequate control environment.</p>
<p>At the same time, enterprise adoption continues to outpace governance maturity. McKinsey’s 2025 global survey reported 88% of respondents said their organisations were using AI in at least one business function. As AI use expands into customer interactions, credit and pricing, HR decision support, and safety-critical or regulated settings, legal teams need to help the business make defensible decisions about risk appetite, controls, and accountability.</p>
<p>Below are five practical priorities for 2026, framed for decision support.</p>
<h2>1) Move from principles to a documented AI risk program</h2>
<p>In 2026, “we have AI principles” is unlikely to be sufficient where AI affects customers, employees, or regulated operations. The compliance direction in multiple jurisdictions is towards risk-based classification, pre-deployment assessment, monitoring, and incident response.</p>
<ul>
<li><p><strong>EU AI Act timeline:</strong> The European Commission’s public timeline confirms the AI Act entered into force on 1 August 2024 and becomes fully applicable on 2 August 2026, with staged obligations and some extended transition periods (including for certain high-risk systems embedded in regulated products).</p>
</li>
<li><p><strong>Vietnam AI Law:</strong> Vietnam enacted a standalone AI law in December 2025, effective 1 March 2026, with a risk-based structure that includes system classification and assessment expectations for higher-risk systems.</p>
</li>
<li><p><strong>Colorado AI Act (US):</strong> Colorado’s SB24-205 imposes obligations on deployers of “high-risk” AI systems and includes effective dates beginning 1 February 2026 for key deployer duties.</p>
</li>
</ul>
<p>What in-house legal should drive internally in 2026:</p>
<ul>
<li><p>A clear definition of what counts as an “AI system” for internal governance (including third-party embedded AI).</p>
</li>
<li><p>A classification method (low/medium/high impact) that ties to controls and approval pathways.</p>
</li>
<li><p>A repeatable pre-deployment review for higher-impact use cases (legal, privacy, security, model governance, human oversight, and testing requirements).</p>
</li>
<li><p>Ongoing monitoring, change control (model updates, prompt changes, retraining), and incident response playbooks.</p>
</li>
</ul>
<h2>2) Make transparency obligations operational, not just policy statements</h2>
<p>Transparency is becoming a consistent regulatory requirement: people should understand when they are dealing with AI, and organisations should be able to explain the role AI played in significant outcomes.</p>
<ul>
<li><p>The EU AI Act includes staged transparency obligations and related requirements across categories of AI systems and models.</p>
</li>
<li><p>South Korea’s AI Basic Act took effect on 22 January 2026 and includes transparency measures (including labelling expectations for AI outputs) and requirements addressing “high-impact” AI.</p>
</li>
<li><p>In Australia, privacy reforms introduce a new transparency requirement for automated decision-making disclosures in privacy policies, effective from 10 December 2026 (applicable where personal information is used to make, or substantially influence, decisions that could reasonably be expected to significantly affect an individual’s rights or interests).</p>
</li>
</ul>
<p>Decision support actions for legal teams:</p>
<ul>
<li><p>Require product and procurement teams to document where AI is user-facing, and what disclosures are triggered by geography and use case.</p>
</li>
<li><p>Ensure external statements (marketing, customer support scripts, product documentation) align with how the system actually behaves and its limitations.</p>
</li>
<li><p>For high-impact decision pathways (credit, pricing/eligibility, employment), ensure there is a documented explanation framework, logging, and a human escalation path.</p>
</li>
</ul>
<h2>3) Treat safety, bias, and vulnerable-user risk as core compliance themes</h2>
<p>In 2026, regulators are increasingly focused on foreseeable and preventable harms: discriminatory outcomes, unsafe content experiences (especially for children), and failures to control high-impact applications.</p>
<ul>
<li><p>The Colorado AI Act explicitly targets “algorithmic discrimination” risks for high-risk systems and sets out compliance expectations for deployers.</p>
</li>
<li><p>In the EU, high-risk categories include employment and access to essential services, where bias and explainability are central.</p>
</li>
</ul>
<p>Practical steps:</p>
<ul>
<li><p>Require bias and performance testing proportional to the decision's impact, not the model's novelty.</p>
</li>
<li><p>Ensure a defined owner for “harm prevention” controls (content safety, vulnerable cohorts, complaint handling, rapid rollback).</p>
</li>
<li><p>Build a clear escalation route for situations where AI outputs could raise safety concerns, coercion, or discrimination.</p>
</li>
</ul>
<h2>4) Converge AI governance with privacy and cybersecurity programs</h2>
<p>For most organisations, the biggest AI risk is not “the model” in isolation; it is how the model is connected to data, internal systems, identity/access controls, and external channels.</p>
<ul>
<li><p>NIST released a preliminary Cyber AI Profile on 16 December 2025, designed to integrate AI considerations into established cybersecurity governance and risk management practices.</p>
</li>
<li><p>Australia’s forthcoming privacy transparency requirements for automated decision-making will raise the compliance bar for mapping decision flows and the use of personal information by December 2026.</p>
</li>
</ul>
<p>Decision support actions:</p>
<ul>
<li><p>Treat AI systems as “sensitive assets” in your security and third-party risk registers (access, logging, incident response, and monitoring).</p>
</li>
<li><p>Align procurement requirements so vendors provide usable information on training data practices, security controls, incident notification, and audit support.</p>
</li>
<li><p>Ensure “AI-enabled” cyber risks are covered: prompt injection, data leakage pathways, model misuse, and tool access abuse.</p>
</li>
</ul>
<h2>5) Copyright and training data provenance remain live commercial risks</h2>
<p>Copyright and training data issues will continue to drive litigation, regulatory attention, and contractual disputes. For deploying organisations, the practical risk is less academic infringement theory and more whether you can justify your use of tools and outputs in a way that withstands challenge.</p>
<p>A defensible posture generally requires:</p>
<ul>
<li><p>clarity on what tools are used and in what contexts (internal use vs external publication)</p>
</li>
<li><p>contractual protections (warranties/indemnities where feasible, limitations understood)</p>
</li>
<li><p>output controls for high-risk use cases (brand, advertising, product content, customer communications)</p>
</li>
<li><p>a documented escalation process for takedown requests and claims</p>
</li>
</ul>
<h2>What a “2026-ready” legal plan looks like</h2>
<p>A pragmatic legal work program for 2026 usually includes:</p>
<ol>
<li><p><strong>Inventory:</strong> where AI is used (including shadow AI and embedded vendor tools).</p>
</li>
<li><p><strong>Classification:</strong> impact-based tiers with clear control requirements.</p>
</li>
<li><p><strong>Controls:</strong> pre-deployment assessment, human oversight design, testing standards, logging, and change management.</p>
</li>
<li><p><strong>Contracts:</strong> vendor due diligence, risk allocation, incident reporting, audit rights, and data handling terms.</p>
</li>
<li><p><strong>Transparency:</strong> disclosures, privacy policy alignment, customer-facing communications controls.</p>
</li>
<li><p><strong>Response:</strong> incident playbooks for safety, privacy, cyber, and legal claims.</p>
</li>
</ol>
<p>The goal is not to slow adoption. It is to ensure the organisation can demonstrate, with evidence, that it identified foreseeable risks, implemented proportionate controls, and responded quickly when issues arise.</p>
]]></content:encoded></item><item><title><![CDATA[Preparing for Australia’s 2026 privacy transparency rules on automated decision making]]></title><description><![CDATA[Automated decision-making and AI-enabled processes are increasingly embedded in customer, employee, and operational workflows. Where these processes use personal information, privacy risk is not limit]]></description><link>https://blog.jameswan.co/preparing-for-australias-2026-privacy-transparency-rules-on-automated-decision-making</link><guid isPermaLink="true">https://blog.jameswan.co/preparing-for-australias-2026-privacy-transparency-rules-on-automated-decision-making</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:31:41 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/0945933c-ba1e-4049-96c2-7ac852bfd9d9.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Automated decision-making and AI-enabled processes are increasingly embedded in customer, employee, and operational workflows. Where these processes use personal information, privacy risk is not limited to data handling. It also extends to how decisions are made, what information is used, and whether individuals can understand and challenge outcomes.</p>
<p>Reforms introduced by the <em>Privacy and Other Legislation Amendment Act 2024 (Cth)</em> add new transparency obligations to the Australian Privacy Principles (APPs) that commence on 10 December 2026.</p>
<p>This is not a theoretical compliance exercise. The Office of the Australian Information Commissioner (OAIC) announced it will begin 2026 with its first privacy compliance sweep, reviewing selected businesses’ privacy policies for compliance with existing transparency requirements.</p>
<p>For in-house counsel and business leaders, the immediate decision-support question is: what processes in the organisation are “automated decision making” for Privacy Act purposes, and what must be disclosed in the privacy policy by December 2026?</p>
<h2>What is automated decision-making</h2>
<p>An automated decision-making (ADM) system is a computerised process that assists or replaces human judgment in making decisions. ADM systems range from simple rule-based scoring (e.g., thresholds and eligibility criteria) to machine-learning and AI systems that infer risk, propensity, or likely outcomes from large datasets.</p>
<p>In practice, ADM is used to:</p>
<ul>
<li><p>approve, refuse or route applications and requests (credit, services, access, refunds)</p>
</li>
<li><p>set pricing, eligibility or prioritisation (including differential pricing)</p>
</li>
<li><p>triage, escalate or close customer complaints and service interactions</p>
</li>
<li><p>detect fraud or non-compliance and trigger downstream actions</p>
</li>
<li><p>support HR processes (screening, ranking, performance flags, workforce analytics)</p>
</li>
</ul>
<p>The privacy implications depend on the personal information used, the impact on individuals, and the level of human involvement.</p>
<h2>Why ADM creates specific privacy risk</h2>
<p>ADM systems often rely on personal information and may aggregate data from multiple sources. Key risk areas include:</p>
<ul>
<li><p><strong>Transparency risk:</strong> individuals may not understand that a decision was driven or materially shaped by a computer program, or what information was used.</p>
</li>
<li><p><strong>Integrity and fairness risk:</strong> historical datasets can embed bias or under-representation, which can produce systematically unfair outcomes (for example, persistent disadvantage to a cohort because past data reflects older structural inequities).</p>
</li>
<li><p><strong>Data minimisation and retention risk:</strong> ADM projects often expand the volume and variety of data collected and may retain data longer than necessary, as it is perceived as useful for “model improvement” or future analysis.</p>
</li>
<li><p><strong>Accountability risk:</strong> without clear logs and governance, it can be difficult to explain or challenge an outcome, even internally.</p>
</li>
</ul>
<p>These are not only ethical issues. They are operational and regulatory risks, particularly where decisions affect access to services, employment opportunities, education, healthcare, or financial outcomes.</p>
<h2>Existing transparency obligations under APP 1</h2>
<p>APP 1 requires APP entities to manage personal information openly and transparently. This includes maintaining a clearly expressed, up-to-date privacy policy, available free of charge and in an appropriate format, that describes how personal information is managed (including categories of information collected, purposes, and disclosures).</p>
<p>APP 1 also requires practices, procedures and systems that support compliance with the APPs. In practical terms, that implies an ongoing program of review and maintenance rather than a “set and forget” privacy policy.</p>
<h2>The new ADM transparency requirements commencing 10 December 2026</h2>
<p>From <strong>10 December 2026</strong>, APP 1 will include new requirements (APP 1.7 to 1.9) that require privacy policies to include specified information about the organisation’s use of ADM in certain circumstances.</p>
<h3>Which decisions are in scope</h3>
<p>The new transparency requirements cover decisions:</p>
<ul>
<li><p>made entirely by a computer program, and</p>
</li>
<li><p>decisions that are substantially made or influenced by a computer program (including where there is a human involved, if the program has a substantial and direct role in making or influencing the decision).</p>
</li>
</ul>
<p>This is important for governance: a “human in the loop” does not automatically remove a process from scope. Conversely, not every use of software in a decision will be captured; the focus is on whether the program is materially shaping the decision.</p>
<h3>What must be disclosed in the privacy policy</h3>
<p>Where the requirements apply, the privacy policy must include information about:</p>
<ul>
<li><p><strong>the types of personal information</strong> used in the operation of the ADM system</p>
</li>
<li><p><strong>the types of decisions</strong> made solely by the ADM system</p>
</li>
<li><p><strong>the types of decisions</strong> for which a thing that is substantially and directly related to making the decision is made by the operation of the ADM system</p>
</li>
</ul>
<p>The OAIC also notes that privacy policies are not expected to include every operational detail, and that a layered approach can be used to present information clearly and accessibly.</p>
<h2>Increased regulatory scrutiny in 2026</h2>
<h3>OAIC privacy policy compliance sweep</h3>
<p>The OAIC announced its first privacy compliance sweep will begin in the first week of January 2026, involving a targeted review of selected businesses’ privacy policies, focusing on sectors that collect personal information in person (for example, real estate/rental and property, car rental and car dealerships, chemists and pharmacists).</p>
<h3>Transparency is a regulator priority</h3>
<p>On 21 January 2026, the Australian Information Commissioner published a report reviewing how transparently Australian Government agencies describe their use of ADM on their websites. While that review relates to government and FOI settings, it reinforces the OAIC’s emphasis on transparency as a compliance theme for 2026.</p>
<h2>Practical preparation steps for organisations</h2>
<p>A defensible approach to the 2026 ADM transparency requirements usually involves four workstreams.</p>
<ol>
<li><p><strong>Identify in-scope decision processes</strong></p>
<ul>
<li><p>Map decisions that affect individuals (customers, staff, students, patients, members).</p>
</li>
<li><p>Identify where computer programs materially influence outcomes (scoring, ranking, recommendations, triage, auto-closures, eligibility gates).</p>
</li>
</ul>
</li>
<li><p><strong>Map personal information flows</strong></p>
<ul>
<li><p>What personal information is used?</p>
</li>
<li><p>Where does it come from (internal systems, third parties, inferred or derived fields)?</p>
</li>
<li><p>Who can access it, and how is it secured?</p>
</li>
</ul>
</li>
<li><p><strong>Assess risk and control design</strong></p>
<ul>
<li><p>What are the foreseeable failure modes (errors, bias, drift, over-collection)?</p>
</li>
<li><p>What controls exist (review points, thresholds, exception handling, logging, auditability)?</p>
</li>
<li><p>Are there clear accountabilities for model changes and rule updates?</p>
</li>
</ul>
</li>
<li><p><strong>Update privacy policy and supporting governance</strong></p>
<ul>
<li><p>Draft clear disclosures that meet the requirements of APP 1.8.</p>
</li>
<li><p>Ensure the policy is readable, navigable and consistent with actual practice.</p>
</li>
<li><p>Implement a maintenance process to ensure disclosures remain accurate as systems evolve.</p>
</li>
</ul>
</li>
</ol>
<h2>The role of in-house counsel</h2>
<p>In-house counsel is central to making this work practical and credible, because the task is not only legal drafting. It is organisational discovery and risk management.</p>
<p>In-house counsel can add the most value by:</p>
<ul>
<li><p>ensuring ADM uses are identified early (including in procurement and product design)</p>
</li>
<li><p>distinguishing “decision support” tools from systems that materially influence decisions</p>
</li>
<li><p>aligning privacy policy wording with actual system behaviour and operational controls</p>
</li>
<li><p>driving internal accountability: who owns the system, who approves changes, who handles complaints or challenges</p>
</li>
<li><p>keeping disclosures clear and usable, consistent with OAIC expectations for transparent privacy policies</p>
</li>
</ul>
<h2>Bottom line</h2>
<p>By December 2026, many organisations will need to publicly explain in their privacy policies how automated decision-making uses personal information and materially influences decisions about individuals.</p>
<p>Given the OAIC’s early-2026 privacy policy sweep and broader transparency focus, the sensible approach is to treat 2026 as a preparation year: identify where ADM is already operating, assess what is in scope, and ensure privacy policy disclosures match reality.</p>
]]></content:encoded></item><item><title><![CDATA[Binding vs non-binding MOUs: what the labels do (and do not) decide]]></title><description><![CDATA[When this question usually arises
A memorandum of understanding (MOU) is often used to record the key terms of a proposed transaction when:

the parties are broadly aligned but still working through d]]></description><link>https://blog.jameswan.co/binding-vs-non-binding-mous-what-the-labels-do-and-do-not-decide</link><guid isPermaLink="true">https://blog.jameswan.co/binding-vs-non-binding-mous-what-the-labels-do-and-do-not-decide</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:27:02 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/63428907250857e669efdb53/043223be-afc1-4325-8585-0d81c29c47af.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>When this question usually arises</h3>
<p>A memorandum of understanding (MOU) is often used to record the key terms of a proposed transaction when:</p>
<ul>
<li><p>the parties are broadly aligned but still working through detail, or</p>
</li>
<li><p>one or both parties are not ready to sign a full-form contract, but want a written record of current intent.</p>
</li>
</ul>
<p>MOUs can also reduce wasted negotiation effort by confirming alignment before committing time and cost to drafting and negotiating definitive agreements.</p>
<p>The risk issue is that parties sometimes begin work, share information, or make operational decisions in reliance on an MOU. If negotiations later break down, disputes often turn on whether a promise in the MOU was legally enforceable. At that point, the key question becomes whether the MOU is a binding contract (in whole or in part) or a non-binding statement of intent.</p>
<h3>What the law looks at</h3>
<p>Whether an MOU is binding is determined by an objective assessment of whether the parties intended to create legal relations. Courts look at:</p>
<ul>
<li><p>the language used in the document (including any “subject to contract” wording)</p>
</li>
<li><p>the commercial context</p>
</li>
<li><p>the conduct of the parties at and after signing (for example, whether they commenced performance)</p>
</li>
<li><p>the nature of the relationship and the transaction</p>
</li>
</ul>
<p>MOUs are most contested where they contemplate the later execution of a formal contract. In that setting, the High Court decision in <em>Masters v Cameron</em> (1954) 91 CLR 353 is the starting point. Where the parties’ arrangement is “subject to contract”, it may fall into one of three categories:</p>
<ol>
<li><p><strong>Immediately binding, with later formalisation</strong><br />The parties intend to be bound immediately, and the later contract is intended to restate the terms more fully or precisely.</p>
</li>
<li><p><strong>Binding bargain, but performance conditional on a later contract</strong><br />The parties have agreed on their deal and do not intend to depart from it, but they make performance of one or more obligations conditional on executing the formal contract.</p>
</li>
<li><p><strong>Not binding unless and until a formal contract is executed</strong><br />The parties do not intend to be bound at all until the definitive agreement is signed.</p>
</li>
</ol>
<p>If the arrangement falls into category 1 or 2, a binding contract exists, and contractual remedies (including damages) may be available for non-performance. If it falls into category 3, there is no contract and therefore no contractual claim for failure to proceed.</p>
<p>Which category applies depends on an objective assessment of what a reasonable person would understand the parties’ intention to be, taking into account the document and the surrounding circumstances.</p>
<h3>Practical implications for deal management and risk</h3>
<h4>If you do not want the MOU to be binding</h4>
<p>If it is not in your interests to be legally bound at that stage, do not rely on the title (“non-binding MOU”) alone. Use clear drafting that states the MOU is not intended to create legal relations, while dealing explicitly with any provisions you do want to be binding.</p>
<p>Common examples of provisions parties often want to be binding even where the commercial terms are non-binding include:</p>
<ul>
<li><p>confidentiality and restrictions on use/disclosure of information</p>
</li>
<li><p>exclusivity / non-solicitation / standstill (if commercially required)</p>
</li>
<li><p>costs allocation</p>
</li>
<li><p>governing law and dispute resolution for the binding provisions</p>
</li>
<li><p>return or destruction of information</p>
</li>
</ul>
<p>If you want a genuine category 3 outcome (no binding agreement until definitive documents are executed), align the drafting and the parties’ conduct with that position. Commencement of substantive performance, issuance of directions, or treatment of the MOU as operationally effective may undermine its non-binding intent.</p>
<h4>If you want the MOU to be binding</h4>
<p>If the purpose is to secure a binding deal early (in whole or in part), include an express statement that the parties intend to be legally bound. You should also ensure the basic requirements for contract formation are satisfied, including:</p>
<ul>
<li><p><strong>certainty of terms</strong> (the obligations must be sufficiently clear to be enforceable)</p>
</li>
<li><p><strong>consideration</strong> (or another recognised basis for enforceability, depending on structure)</p>
</li>
<li><p><strong>scope clarity</strong> (what is binding now, what is deferred to later documentation, and what is conditional)</p>
</li>
</ul>
<p>If the MOU is intended to operate as a binding interim arrangement, address the transition to the final contract. For example:</p>
<ul>
<li><p>specify key conditions that must be satisfied before a definitive agreement is executed</p>
</li>
<li><p>include an express right to terminate the interim arrangement if the formal contract is not agreed by a defined date</p>
</li>
<li><p>clarify what happens to work-in-progress, deliverables, and costs if the definitive agreement is not finalised</p>
</li>
</ul>
<h3>Bottom line</h3>
<p>The binding effect of an MOU is driven by objective intention and context, not by the label on the front page. From a decision-support perspective, the key is to be explicit about (1) whether the parties intend legal enforceability now, (2) which provisions are binding and which are not, and (3) how the parties should behave between signing the MOU and signing the definitive agreement.</p>
]]></content:encoded></item><item><title><![CDATA[Agentic AI: autonomy, failure modes, and liability]]></title><description><![CDATA[Agentic AI: autonomy, failure modes, and liability
In late 2024 and throughout 2025, senior leaders at major AI companies and chip makers publicly framed “agentic AI” as the next mainstream phase of generative AI. (Gartner)
Actual adoption has been u...]]></description><link>https://blog.jameswan.co/agentic-ai-autonomy-failure-modes-and-liability</link><guid isPermaLink="true">https://blog.jameswan.co/agentic-ai-autonomy-failure-modes-and-liability</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:24:24 GMT</pubDate><content:encoded><![CDATA[<h2 id="heading-agentic-ai-autonomy-failure-modes-and-liability">Agentic AI: autonomy, failure modes, and liability</h2>
<p>In late 2024 and throughout 2025, senior leaders at major AI companies and chip makers publicly framed “agentic AI” as the next mainstream phase of generative AI. (<a target="_blank" href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027?utm_source=chatgpt.com">Gartner</a>)</p>
<p>Actual adoption has been uneven. McKinsey’s <em>State of AI 2025</em> survey reported that 62% of respondents were experimenting with AI agents, but no more than 10% were scaling agents across any single business function. (<a target="_blank" href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?utm_source=chatgpt.com">McKinsey &amp; Company</a>) Gartner has also predicted that over 40% of agentic AI projects will be cancelled by the end of 2027 due to escalating costs, unclear business value, or inadequate risk controls. (<a target="_blank" href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027?utm_source=chatgpt.com">Gartner</a>)</p>
<p>Despite mixed outcomes, the direction of travel is clear. Vendors are expanding agent capabilities beyond software engineering into broader office and enterprise workflows (for example, Anthropic’s “Cowork” research preview). (<a target="_blank" href="https://claude.com/blog/cowork-research-preview?utm_source=chatgpt.com">claude.com</a>) As organisations move from pilots to production, the key question becomes less “what can the agent do?” and more “how can it fail, what damage can it cause, and who carries the liability?”</p>
<p>This article focuses on risk and decision support for business and commercial leaders.</p>
<h2 id="heading-what-agentic-ai-means-in-practice">What “agentic AI” means in practice</h2>
<p>An agentic system is an AI system that can <strong>use tools</strong> to pursue a goal with some degree of independence. Those tools might include web search, access to internal databases, calling business systems via APIs, executing code, sending emails, or performing actions in applications.</p>
<p>A useful operational distinction is:</p>
<ul>
<li><p><strong>Workflow systems:</strong> predefined steps orchestrate model calls and tools. These are typically more predictable and easier to test.</p>
</li>
<li><p><strong>Autonomous agents:</strong> the model chooses which tools to call, interprets results, and decides next steps (often in an iterative loop). This increases flexibility, but reduces predictability and expands the space of possible errors.</p>
</li>
</ul>
<p>As autonomy increases, so do the potential consequences: the system is not only generating text but also changing systems, moving data, communicating externally, and potentially committing the organisation to outcomes.</p>
<h2 id="heading-where-agents-are-being-deployed">Where agents are being deployed</h2>
<p>Common categories of agentic tools now marketed to businesses include:</p>
<ul>
<li><p><strong>Research agents:</strong> multi-step research and synthesis across sources. (e.g., “deep research” style tools) (<a target="_blank" href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?utm_source=chatgpt.com">McKinsey &amp; Company</a>)</p>
</li>
<li><p><strong>Coding agents:</strong> writing, debugging, and refactoring code, sometimes with access to repositories and terminals. (<a target="_blank" href="https://www.reuters.com/business/retail-consumer/anthropic-releases-ai-upgrade-market-punishes-software-stocks-2026-02-05/?utm_source=chatgpt.com">Reuters</a>)</p>
</li>
<li><p><strong>Computer-use agents:</strong> operating a desktop/browser to complete tasks end-to-end. (<a target="_blank" href="https://www.reuters.com/business/retail-consumer/anthropic-releases-ai-upgrade-market-punishes-software-stocks-2026-02-05/?utm_source=chatgpt.com">Reuters</a>)</p>
</li>
<li><p><strong>Enterprise workflow agents:</strong> automating business processes inside platforms such as CRM/ERP environments. (<a target="_blank" href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027?utm_source=chatgpt.com">Gartner</a>)</p>
</li>
</ul>
<p>A practical caution: the term “agent” is often used loosely. Gartner has warned that “agent washing” (rebranding assistants or simple automation as agents) is widespread. (<a target="_blank" href="https://www.reuters.com/business/over-40-agentic-ai-projects-will-be-scrapped-by-2027-gartner-says-2025-06-25/?utm_source=chatgpt.com">Reuters</a>) For risk assessment, focus on capabilities: which systems it can access, what actions it can take, and how much it can do without human approval.</p>
<h2 id="heading-a-concrete-case-study-an-agent-running-a-business">A concrete case study: an agent “running a business”</h2>
<p>Anthropic’s <em>Project Vend</em> is a useful illustration of what can go wrong when an agent is given real operational responsibility, even in a constrained environment. In the first phase, an AI system (“Claudius”) operated a small office vending setup and was tasked with stocking, pricing, and responding to customers. Anthropic reported significant underperformance versus a competent human manager, including susceptibility to manipulation, incorrect handling of payment details, and poor commercial judgment (for example, fixating on “metal cubes” and selling them at a loss). (<a target="_blank" href="https://www.anthropic.com/research/project-vend-1?utm_source=chatgpt.com">anthropic.com</a>)</p>
<p>In the second phase, with improved tools and models, performance improved, and profits became more consistent, but vulnerabilities remained, including overly generous refunds/credits and continued susceptibility to manipulation and hallucinations. (<a target="_blank" href="https://www.anthropic.com/research/project-vend-2?utm_source=chatgpt.com">anthropic.com</a>)</p>
<p>The decision support takeaway is not that agents “fail”, but that agents can fail in ways that are commercially and legally meaningful, particularly when they are authorised to transact, communicate, or change systems.</p>
<h2 id="heading-key-risk-categories-that-increase-with-agent-autonomy">Key risk categories that increase with agent autonomy</h2>
<p>Below are common risk categories that become more significant as agents gain access to tools and independence.</p>
<h3 id="heading-1-data-alteration-or-destruction">1) Data alteration or destruction</h3>
<p><strong>What it looks like:</strong> the agent deletes records, changes configurations, alters permissions, or applies infrastructure changes that cause outages or security exposure.<br /><strong>Why it matters:</strong> agents built to “resolve obstacles” may take action that is locally rational but organisationally damaging, especially if given administrative tools.</p>
<h3 id="heading-2-data-exfiltration-and-cyber-enabled-misuse">2) Data exfiltration and cyber-enabled misuse</h3>
<p><strong>What it looks like:</strong> the agent is induced—through malicious content, compromised tools, or indirect prompt injection—to disclose confidential data externally.<br /><strong>Why it matters:</strong> giving an agent access to sensitive data plus outbound channels creates a clear exfiltration pathway. A widely cited example in the Microsoft 365 ecosystem is “EchoLeak”, which researchers described as a zero-click chain enabling data exfiltration from Microsoft 365 Copilot via an email. (<a target="_blank" href="https://www.catonetworks.com/blog/breaking-down-echoleak/?utm_source=chatgpt.com">Cato Networks</a>)</p>
<h3 id="heading-3-external-communications-on-the-organisations-behalf">3) External communications on the organisation’s behalf</h3>
<p><strong>What it looks like:</strong> emails, CRM notes, tickets, public posts, or messages to customers/regulators are sent without appropriate review.<br /><strong>Why it matters:</strong> communications can create compliance exposure, contractual commitments, admissions, or reputational harm. This is particularly sensitive when the agent interacts with customers or regulators.</p>
<h3 id="heading-4-brittleness-and-drift-models-prompts-tools-and-environments">4) Brittleness and drift (models, prompts, tools, and environments)</h3>
<p><strong>What it looks like:</strong> the agent behaves differently after a model upgrade, tool change, policy update, or a shift in the operational environment.<br /><strong>Why it matters:</strong> agent behaviour depends on a chain of components (model + prompts + tools + permissions + data sources). Small upstream changes can produce materially different outputs and actions.</p>
<h3 id="heading-5-unfair-or-non-transparent-decision-making">5) Unfair or non-transparent decision-making</h3>
<p><strong>What it looks like:</strong> an agent makes or influences decisions affecting individuals (customers or staff) in ways that are inconsistent, biased, outside scope, or difficult to explain.<br /><strong>Why it matters:</strong> tool-retrieved information can shape outcomes in unpredictable ways, and if decisions materially affect rights or interests, organisations need defensible governance, logging, and review.</p>
<h3 id="heading-6-unauthorised-transactions-or-financial-commitments">6) Unauthorised transactions or financial commitments</h3>
<p><strong>What it looks like:</strong> purchases, orders, refunds, credits, subscriptions, or contractual acceptances are made outside authority or limits.<br /><strong>Why it matters:</strong> even “small” unauthorised commitments can aggregate quickly, particularly at scale. <em>Project Vend</em> illustrates how easily an agent can be led into poor commercial decisions. (<a target="_blank" href="https://www.anthropic.com/research/project-vend-1?utm_source=chatgpt.com">anthropic.com</a>)</p>
<h3 id="heading-7-physical-damage-or-injury-where-agents-control-physical-systems">7) Physical damage or injury (where agents control physical systems)</h3>
<p><strong>What it looks like:</strong> incorrect commands in smart facilities, robotics, industrial maintenance, or other operational technology.<br /><strong>Why it matters:</strong> Once agents enter physical control systems, the consequences of failure can include property damage and personal injury, raising the stakes for testing, oversight, and duty of care.</p>
<hr />
<h2 id="heading-rogue-agents-and-organisational-liability">“Rogue agents” and organisational liability</h2>
<p>A common question is whether an organisation can distance itself from an agent’s actions by treating the agent as a separate “actor”. From a legal risk perspective, that is not a safe assumption.</p>
<p>Courts and tribunals are more likely to treat an AI agent as part of the organisation’s systems and customer interface, not as an independent legal person. A frequently cited example is the Air Canada chatbot decision in British Columbia, where the tribunal rejected Air Canada’s attempt to avoid responsibility for misleading information provided by its chatbot. (<a target="_blank" href="https://www.dentons.co.nz/en/insights/articles/2024/february/27/the-chatbot-that-got-an-airline-sued?utm_source=chatgpt.com">dentons.co.nz</a>)</p>
<p>Separately, vendors’ own safety testing shows that frontier models can select high-risk behaviours in contrived but instructive scenarios (including “blackmail” behaviour in agentic misalignment testing). (<a target="_blank" href="https://www.anthropic.com/research/agentic-misalignment?utm_source=chatgpt.com">anthropic.com</a>) The practical implication is that organisations should plan on the basis that if the agent acts through your systems, brand, and permissions, the resulting liability risk will be assessed against your controls, oversight, and governance.</p>
<hr />
<h2 id="heading-legal-risk-areas-to-map-before-scaling">Legal risk areas to map before scaling</h2>
<h3 id="heading-consumer-law-customer-facing-agents">Consumer law (customer-facing agents)</h3>
<p>If an agent interacts with customers, inaccurate statements or omissions can trigger Australian Consumer Law risk (including misleading or deceptive conduct). The risk increases when agents retrieve and combine large amounts of information across tools and systems, where quality and relevance may degrade.</p>
<h3 id="heading-contract-law-formation-and-authority">Contract law (formation and authority)</h3>
<p>Agents that negotiate, accept terms, place orders, or approve refunds raise questions of authorisation and contract formation. Even where the law is still developing in this area, the commercial risk is immediate: counterparties may rely on the communications and actions taken through your systems.</p>
<h3 id="heading-privacy-access-use-disclosure-and-security">Privacy (access, use, disclosure, and security)</h3>
<p>If an agent accesses personal information (email, HR systems, customer records), privacy compliance becomes a core design constraint, not an afterthought.</p>
<p>In Australia, reforms introduce new transparency requirements where an APP entity arranges for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests. The OAIC guidance notes that this is due to commence <strong>from 10 December 2026</strong>. (<a target="_blank" href="https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information?utm_source=chatgpt.com">OAIC</a>)</p>
<h3 id="heading-negligence-especially-where-physical-world-impacts-exist">Negligence (especially where physical-world impacts exist)</h3>
<p>Where an agent’s actions can foreseeably cause damage to property or injury, negligence risk turns on whether reasonable care was taken. Courts are likely to scrutinise foreseeable failure modes, testing, safeguards, permissions, monitoring, and the level of human oversight.</p>
<h2 id="heading-what-this-means-for-decision-makers">What this means for decision-makers</h2>
<p>The move from generative AI that <em>advises</em> to agentic AI that <em>acts</em> is a governance shift. Before scaling, organisations should be able to answer, in operational terms:</p>
<ul>
<li><p>What systems can the agent access, and with what permissions?</p>
</li>
<li><p>What actions can it take without approval (and what is explicitly blocked)?</p>
</li>
<li><p>How are tool calls, outputs, and decisions logged in a way that supports audit and incident response?</p>
</li>
<li><p>What changes (model updates, tool updates, policy changes) can alter behaviour, and how are they controlled?</p>
</li>
<li><p>What is the escalation path when the agent produces uncertain outputs or encounters conflicting instructions?</p>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[Warranty vs representation, what’s the difference and why it matters]]></title><description><![CDATA[When this issue usually comes up
This question often arises in technology procurement and other high-value commercial deals.
During due diligence and negotiations, a supplier may make statements about a product's capabilities, whether it meets your r...]]></description><link>https://blog.jameswan.co/warranty-vs-representation-whats-the-difference-and-why-it-matters</link><guid isPermaLink="true">https://blog.jameswan.co/warranty-vs-representation-whats-the-difference-and-why-it-matters</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Tue, 10 Feb 2026 05:19:22 GMT</pubDate><content:encoded><![CDATA[<h3 id="heading-when-this-issue-usually-comes-up">When this issue usually comes up</h3>
<p>This question often arises in technology procurement and other high-value commercial deals.</p>
<p>During due diligence and negotiations, a supplier may make statements about a product's capabilities, whether it meets your requirements, whether it is fit for purpose, and whether it conforms to agreed specifications. If you rely on those statements to decide whether to sign and later find they were incorrect, your available remedies will depend largely on whether the statements were incorporated into the contract as binding terms or remain only pre-contract statements.</p>
<h3 id="heading-the-legal-distinction">The legal distinction</h3>
<p>The difference matters because warranties and representations can give rise to different causes of action and remedies.</p>
<h4 id="heading-representation">Representation</h4>
<p>A representation is a statement of fact made by one party to another, which may be relied on when deciding whether to enter the contract. Representations are commonly made during negotiations and may not be included as terms of the contract.</p>
<p>If a representation is false and it was not incorporated into the contract, the aggrieved party generally cannot sue for breach of contract based on that statement. Other remedies may still be available, depending on the circumstances, including:</p>
<ul>
<li><p><strong>Rescission</strong>, where the contract may be set aside and orders made to restore the parties to their pre-contract positions to the extent possible</p>
</li>
<li><p><strong>Damages in negligence</strong>, where the statement was made negligently or with a degree of recklessness as to whether it was true</p>
</li>
<li><p><strong>Australian Consumer Law (ACL) remedies</strong>, including for misleading or deceptive conduct</p>
</li>
</ul>
<h4 id="heading-warranty">Warranty</h4>
<p>A warranty is a contractual term. It operates as a promise or undertaking. If a warranty is breached, the usual contractual remedies are available, including damages intended to put the aggrieved party in the position they would have been in had the contract been properly performed.</p>
<p>A breach of warranty may also support termination, but that depends on the contract and the seriousness of the breach:</p>
<ul>
<li><p>At common law, a breach of warranty (as distinct from breach of an essential term or “condition”) does not usually give rise to a right to terminate.</p>
</li>
<li><p>However, termination may still arise at common law if the breach is sufficiently serious so as to deprive the aggrieved party of substantially the whole benefit of the contract.</p>
</li>
<li><p>Many contracts also include a termination regime that defines termination triggers more clearly than relying on common law concepts.</p>
</li>
</ul>
<h3 id="heading-why-classification-affects-risk-and-decision-making">Why classification affects risk and decision making</h3>
<p>Whether a statement is treated as a pre-contract representation or a contractual warranty can materially affect:</p>
<ul>
<li><p><strong>What claims are available</strong> (breach of contract vs misrepresentation or statutory claims)</p>
</li>
<li><p><strong>What remedies are available</strong> (contractual damages, rescission, statutory relief)</p>
</li>
<li><p><strong>How liability clauses apply</strong>, including caps, exclusions, and limitations</p>
</li>
<li><p><strong>Whether non-reliance or entire agreement provisions reduce available claims</strong> by asserting that pre-contract statements were not relied on and do not form part of the bargain</p>
</li>
</ul>
<h3 id="heading-practical-implications-for-your-contract">Practical implications for your contract</h3>
<h4 id="heading-if-you-need-to-rely-on-statements-make-them-contractual">If you need to rely on statements, make them contractual</h4>
<p>If a statement is important to your decision to sign, the most effective approach is usually to convert it into a contractual commitment. Common ways to do this include:</p>
<ul>
<li><p>Drafting the statement into the contract as an express term</p>
</li>
<li><p>Incorporating pre-contract documents by reference, such as a tender response, product specifications, or written assurances exchanged during negotiations</p>
</li>
</ul>
<p>When doing this, focus on three points:</p>
<ol>
<li><p><strong>How the statement is framed</strong><br /> If a statement in the contract is described as both a warranty and a representation, this can help preserve both contractual remedies for breach and potential remedies for misrepresentation if the statement proves false. This is often strengthened by an express clause stating that the relevant party relied on the representation in entering into the contract.</p>
</li>
<li><p><strong>Termination consequences</strong><br /> To reduce uncertainty, the contract should state whether breach of the relevant warranty gives rise to termination rights and, if so, under what conditions. Relying solely on common-law material breach concepts can create avoidable ambiguity.</p>
</li>
<li><p><strong>Interaction with liability provisions</strong><br /> If the contract includes liability caps, exclusions, or other limitations, confirm how they apply to warranty breaches, and whether any key warranties should be carved out.</p>
</li>
</ol>
<h4 id="heading-if-you-want-to-limit-exposure-to-negotiation-statements-use-clear-non-reliance-drafting">If you want to limit exposure to negotiation statements, use clear non-reliance drafting</h4>
<p>If the parties intend the contract to be the full record of the deal and do not want negotiation statements to carry legal consequences, the contract should clearly state that:</p>
<ul>
<li><p>Pre-contract representations do not form part of the contract</p>
</li>
<li><p>The parties did not rely on any pre-contract statements when deciding to enter the contract</p>
</li>
<li><p>These provisions are consistent with the entire agreement clause</p>
</li>
</ul>
<p>There are limits to how far liability for misrepresentation can be excluded, particularly for statutory claims. However, clear disclaimers can help establish that, as a matter of fact, a party did not rely on pre-contract statements, which can reduce or negate liability that might otherwise arise.</p>
<h3 id="heading-bottom-line">Bottom line</h3>
<p>In commercial practice, the key question is not only whether a statement was made, but whether it was made contractually enforceable, and how the contract allocates risk through liability limits and non-reliance provisions. If a statement is driving your decision to sign, treat it as a contract term and make the consequences of breach explicit.</p>
]]></content:encoded></item><item><title><![CDATA[How to properly evaluate generative AI technology for productive use by lawyers]]></title><description><![CDATA[The legal industry is currently flooded with GenAI pilot programs, but many of them, like the recent trials conducted by Ashurst, suffer from a critical flaw: they prioritise change management over scientific measurement. While Ashurst’s approach was...]]></description><link>https://blog.jameswan.co/how-to-properly-evaluate-generative-ai-technology-for-productive-use-by-lawyers</link><guid isPermaLink="true">https://blog.jameswan.co/how-to-properly-evaluate-generative-ai-technology-for-productive-use-by-lawyers</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 21:11:09 GMT</pubDate><content:encoded><![CDATA[<p>The legal industry is currently flooded with GenAI pilot programs, but many of them, like the recent trials conducted by Ashurst, suffer from a critical flaw: they prioritise change management over scientific measurement. While Ashurst’s approach was excellent for building culture, engaging lawyers with "friendly competition" and "art of the possible" sessions, it was functionally weak on data rigour. The most glaring issue was statistical insignificance. The foundation of their quantitative data was a blind study in which a panel of four lawyers reviewed four cases. In statistical terms, an <em>n</em> of 4 renders the findings at best anecdotal; it is impossible to extrapolate reliable estimates of error rates or efficiency gains for a global firm from such a tiny sample size. Furthermore, the trial relied heavily on self-selection, recruiting "enthusiastic users" and nominees rather than a random cross-section of the firm. This introduces significant selection bias, as tech-forward lawyers are naturally more likely to rate "usability" and "confidence" higher than the average partner.</p>
<p>The methodology also fell victim to the "<a target="_blank" href="https://en.wikipedia.org/wiki/Hawthorne_effect">Hawthorne effect</a>", the phenomenon where participants improve their performance simply because they are being observed. Ashurst noted that imposing time limits and creating competition increased engagement, but this likely introduced bias into the data. Were lawyers working faster because the GenAI tool was effective, or because they were racing against the clock and their colleagues? Without a control group doing the same work under normal conditions, it is impossible to tell. Finally, the metrics themselves were too subjective. The trial relied on <a target="_blank" href="https://en.wikipedia.org/wiki/Likert_scale">Likert scales</a> (1–5) to measure "accuracy" and "completeness" based on perception. There was a notable absence of hard metrics, such as keystroke logging, hallucination rates, or precise time-on-task measurements. Ultimately, this approach tells a firm how their lawyers <em>feel</em> about GenAI, but not whether it actually saves money or reduces risk.</p>
<p>To move from "experimentation" to true "validation," future trials must shift to a rigorous A/B testing model, treating the pilot as a clinical trial. Instead of relying on volunteers, a robust design would use stratified random sampling to select a group of 100+ participants, ensuring an even split across practice areas and seniority levels (from Junior Associates to Senior Partners). This eliminates the "<a target="_blank" href="https://en.wikipedia.org/wiki/Selection_bias">enthusiast bias</a>." Importantly, this method introduces a concurrent Control Group. While Group A performs a set of standardised legal tasks (such as contract review or clause generation) using GenAI, Group B performs the same tasks using standard tools. This enables a direct, mathematically valid comparison of output quality and speed, reducing the noise from the Hawthorne Effect.</p>
<p>The measurement criteria in this proposed improved approach would also shift from sentiment-based to hard-science metrics. Rather than asking lawyers whether a draft was "useful," the trial would measure "Edit Distance" (<a target="_blank" href="https://en.wikipedia.org/wiki/Levenshtein_distance">Levenshtein distance</a>), a measure of how many edits were required to transform the AI output into a client-ready document or presentable advice. If a lawyer has to rewrite 60% of the text, the tool’s utility is objectively low, regardless of how "confident" they felt. Additionally, replacing self-reported surveys with background <a target="_blank" href="https://en.wikipedia.org/wiki/Time_and_motion_study">time-motion logging</a> provides a precise calculation of efficiency gains, measured in minutes rather than feelings. Finally, extending the trial duration to 90 days allows a law firm to filter out the "<a target="_blank" href="https://en.wikipedia.org/wiki/Shiny_object_syndrome">novelty hype</a>." By measuring usage in month three, when the excitement has faded, the law firm can see if the tool has truly integrated into the workflow. This data-driven approach moves beyond "my eyes are more open" and provides the concrete ROI calculations necessary to make multimillion-dollar investment and procurement decisions for technology products.</p>
]]></content:encoded></item><item><title><![CDATA[The Full Court of the Federal Court of Australia rules tote bags are not "art," stripping them of copyright protection]]></title><description><![CDATA[In a significant appeal decision for the fashion and retail sectors, the Full Federal Court of Australia has confirmed that the popular "State of Escape" perforated neoprene tote bag is not a "work of artistic craftsmanship."
This ruling is a harsh r...]]></description><link>https://blog.jameswan.co/the-full-court-of-the-federal-court-of-australia-rules-tote-bags-are-not-art-stripping-them-of-copyright-protection</link><guid isPermaLink="true">https://blog.jameswan.co/the-full-court-of-the-federal-court-of-australia-rules-tote-bags-are-not-art-stripping-them-of-copyright-protection</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 05:55:06 GMT</pubDate><content:encoded><![CDATA[<p>In a significant appeal decision for the fashion and retail sectors, the <a target="_blank" href="https://austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/FCAFC/2022/63.html">Full Federal Court of Australia</a> has confirmed that the popular "<a target="_blank" href="https://www.stateofescape.com/">State of Escape</a>" perforated neoprene tote bag is not a "work of artistic craftsmanship."</p>
<p>This ruling is a harsh reminder of the "Copyright-Design Overlap" in Australian law. Because the bags were mass-produced and primarily functional rather than artistic, they lost copyright protection. Since the company had not registered the design under the <em>Designs Act</em>, the product had no protection against copycats.</p>
<p>We discuss the critical lesson for businesses producing functional goods.</p>
<h3 id="heading-key-takeaways">Key takeaways:</h3>
<ul>
<li><p><strong>Function v art:</strong> If functional constraints (like durability or weight-bearing) dictate your design choices more than aesthetic ones, your product is likely not a "work of artistic craftsmanship."</p>
</li>
<li><p><strong>The "50 Rule":</strong> Once you industrially apply a design (make more than 50 units), you lose copyright protection unless you fit a specific exception.</p>
</li>
<li><p><strong>Register or die:</strong> For mass-produced items like fashion, furniture, and homewares, you cannot rely on automatic copyright. You must register your design <em>before</em> entering the market to ensure protection.</p>
</li>
</ul>
<h3 id="heading-the-trap-the-copyright-design-overlap">The Trap: The Copyright-Design Overlap</h3>
<p><a target="_blank" href="https://www.stateofescape.com/">State of Escape Accessories Pty Ltd</a>, known for its oversized perforated neoprene tote bags with sailing rope handles, sued a competitor (<a target="_blank" href="https://www.chuchka.com.au/">Chucka Bags</a>) for copyright infringement. They argued that their bag was an original artistic work.</p>
<p><a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdb/au/legis/cth/consol_act/ca1968133/">Australian copyright law</a> protects "artistic works" automatically. However, to prevent copyright from being used to create permanent monopolies on industrial products, the law has a "circuit breaker" known as the Copyright-Design overlap.</p>
<p>Under this rule, if you take an artistic work (like a design drawing), apply it to a product, and mass-produce it (make more than 50 items), you lose your copyright protection.</p>
<p>The only way to maintain copyright protection for mass-produced items is if the item qualifies as a "work of artistic craftsmanship" (such as a hand-woven tapestry or a unique piece of pottery).</p>
<p>State of Escape argued their bag was a work of artistic craftsmanship. The Court disagreed.</p>
<h3 id="heading-function-over-form">Function over form</h3>
<p>The Full Court upheld the primary judge's finding that the bag was not a work of artistic craftsmanship because functional considerations outweighed aesthetic ones.</p>
<p><strong>1. The "beauty" myth.</strong> The Court clarified that the test is not whether the item is beautiful or aesthetically appealing. A product can be stylish and widely admired, but that does not make it <strong>legally</strong> a work of artistic craftsmanship.</p>
<p><strong>2. Constraints of function.</strong> The Court looked at <em>why</em> the design choices were made.</p>
<ul>
<li><p><strong>Material:</strong> The choice of perforated neoprene wasn't just for aesthetics; it was selected for its strength, durability, and load capacity (a functional requirement for a carry bag).</p>
</li>
<li><p><strong>Construction:</strong> The sailing rope handles were also a functional choice for support.</p>
</li>
</ul>
<p>The Court noted that while the design showed an "evolution in styling," the choices were constrained by the need for the bag to actually work as a bag.</p>
<p><strong>3. Designer's intent v training</strong> The bag's designer gave evidence that she aimed for "simplicity, beauty, and originality." While the Court accepted this, they placed little weight on it, noting that a designer's own view of their "art" is subjective.</p>
<p>Importantly, the Court noted that the designer lacked specialised training, skills, or knowledge in bag design. While not the deciding factor, this lack of specialised craftsmanship skills weighed against the claim that the bag was a work of "craftsmanship."</p>
<h3 id="heading-a-free-pass-for-copycats">A free pass for copycats</h3>
<p>Because the bag was found <strong>not</strong> to be a work of artistic craftsmanship:</p>
<ol>
<li><p>Copyright was lost because more than 50 bags had been manufactured.</p>
</li>
<li><p>Design rights were non-existent because State of Escape had not registered the design before launching.</p>
</li>
</ol>
<p>This left the product in a legal "no man's land," meaning the competitor (Chucka Bags) could <strong>not</strong> be legally stopped from selling similar bags on copyright-infringement grounds.</p>
<h3 id="heading-action-items-to-take-now">Action items to take now</h3>
<p>This decision reinforces that relying on copyright for industrial products is a high-risk strategy.</p>
<ul>
<li><p><strong>Review your design portfolio.</strong> If you design furniture, fashion, or hardware, assume copyright will not protect you once you mass-produce.</p>
</li>
<li><p><strong>Register early.</strong> The only reliable protection for the visual appearance of a functional product is a <strong>Registered design protection</strong>. A registered design application must be filed <em>before</em> you publish, sell, or disclose the design to the market.</p>
</li>
<li><p><strong>Assess "craftsmanship".</strong> If you plan to rely on the "artistic craftsmanship" exception, seek legal advice early. As this case shows, even a "distinctive silhouette" and a focus on beauty are rarely enough to satisfy the court if the item serves a functional purpose.</p>
</li>
</ul>
<p><strong>Stakeholders impacted:</strong></p>
<ul>
<li><p>Creative Directors &amp; Product Designers</p>
</li>
<li><p>Fashion &amp; Retail CEOs</p>
</li>
<li><p>Legal Counsel</p>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[Banksy's trademark battle - a lesson in "use it or lose it"]]></title><description><![CDATA[After a two-year dispute with UK greeting card company Full Colour Black, the anonymous street artist Banksy has lost the EU trade mark rights to his iconic Flower Thrower artwork.
Once sprawled across a garage wall in Bethlehem, this image is no lon...]]></description><link>https://blog.jameswan.co/banksys-trademark-battle-a-lesson-in-use-it-or-lose-it</link><guid isPermaLink="true">https://blog.jameswan.co/banksys-trademark-battle-a-lesson-in-use-it-or-lose-it</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 05:43:48 GMT</pubDate><content:encoded><![CDATA[<p>After a two-year dispute with UK greeting card company <a target="_blank" href="https://www.fullcolourblack.com/">Full Colour Black</a>, the anonymous street artist Banksy has lost the EU trade mark rights to his iconic <a target="_blank" href="https://en.wikipedia.org/wiki/Flower_Thrower"><em>Flower Thrower</em> artwork</a>.</p>
<p>Once sprawled across a <a target="_blank" href="https://en.wikipedia.org/wiki/The_Walled_Off_Hotel">garage wall in Bethlehem</a>, this image is no longer a secure asset in Banksy's intellectual property portfolio. The decision places his remaining trade mark registrations at significant risk and serves as a critical case study for brand owners regarding "bad faith" filings and the necessity of genuine commercial use.</p>
<p>The <a target="_blank" href="https://www.euipo.europa.eu/">EU Intellectual Property Office's (EUIPO)</a> decision offers vital lessons on the intersection of copyright, trade marks, and commercial strategy.</p>
<h3 id="heading-key-takeaway">Key takeaway</h3>
<p>There are different legal tools available to protect creative assets, but they are not interchangeable. Trade mark and copyright protection have distinct functions and requirements. Attempting to use a trade mark to bypass the requirements of copyright law, specifically the need for an artist to reveal their identity, can backfire if the mark is not genuinely used in commerce.</p>
<h3 id="heading-the-euipo-decision">The EUIPO decision</h3>
<p>Having famously declared that "copyright is for losers," Banksy sought trade mark protection for his artworks in 2014. The <em>Flower Thrower</em> was registered in the EU for a range of goods, including sunglasses, building materials, and Christmas tree decorations. This strategy aimed to secure protection without relying on copyright law, which would require Banksy to waive his anonymity.</p>
<p>In March 2019, Full Colour Black (FCB), aiming to use the image on greeting cards, requested the cancellation of the registration under Article 59(1)(b) of the <em>European Union Trade Mark Regulation</em> (EUTMR). They argued the mark was filed in bad faith because Banksy had no intention of using it.</p>
<p>In October 2019, seemingly in response to the legal threat, Banksy opened a pop-up store in London selling <em>Flower Thrower</em> merchandise. This was an attempt to demonstrate "use" of the trade mark. Prior to this, the mark had never been commercially used by the artist.</p>
<p><strong>Invalidation on the basis of bad faith.</strong> The EUIPO ruled that a trade mark registration is invalid if the applicant acted in bad faith at the time of filing.</p>
<p>A finding of bad faith requires:</p>
<ol>
<li><p>Conduct that "departs from accepted principles of ethical behaviour or honest commercial and business practices."</p>
</li>
<li><p>A dishonest intention on the part of the trademark owner.</p>
</li>
</ol>
<p>The EUIPO found that Banksy had filed the application:</p>
<ul>
<li><p>Without any intention of using the mark for the goods listed.</p>
</li>
<li><p>Without the aim of engaging fairly in competition.</p>
</li>
<li><p>With the intention of undermining third parties (like FCB) in a manner inconsistent with honest practices.</p>
</li>
<li><p>With the intention of obtaining an exclusive right for purposes other than the proper function of a trade mark (i.e., identifying the origin of goods).</p>
</li>
</ul>
<p>Crucially, the EUIPO dismissed the London pop-up store as a valid defence. They deemed it an attempt "to commercialise goods... but only to circumvent the law" rather than a genuine entry into the market. Consequently, the mark was declared invalid, and costs were awarded against Banksy.</p>
<h3 id="heading-how-would-this-case-be-decided-in-australia">How would this case be decided in Australia?</h3>
<p>An Australian court would likely reach a similar outcome, though via a different legal mechanism.</p>
<p><strong>Bad Faith (Section 62A)</strong> The <em>Trade Marks Act 1995</em> (Cth) allows for the cancellation of marks filed in bad faith. However, the Australian threshold is high, requiring conduct that "reasonable and experienced persons in the field" would view as falling short of acceptable commercial behaviour. Banksy's strategy might survive this specific test.</p>
<p><strong>Non-Use (Section 92)</strong> The greater risk for Banksy in Australia would be a <strong>non-use application</strong>. Section 92(4) allows for the removal of a mark if:</p>
<ol>
<li><p>The owner had no intention to use the mark and has never used it in good faith; or</p>
</li>
<li><p>The owner has not used the mark in good faith for a continuous period of three years (provided five years have passed since the filing).</p>
</li>
</ol>
<p>In an Australian context, Banksy would need to prove he applied for the mark with the intention of using it as a "badge of origin" for goods. Since he could not show use prior to the pop-up store (which was opened solely to defeat the legal challenge), the mark would likely be removed. Under Australian law, "use" must be real and commercial, not merely token use to protect a registration.</p>
<p><strong>The copyright alternative.</strong> Unlike the EU, Australian copyright law (section 189 of the Copyright Act) allows authors to use a pseudonym and still own copyright for 70 years. Banksy would not necessarily need trade mark law to protect his work here. However, uncertainty remains regarding the protection of illegal works (graffiti) displayed in public places, a relevant factor for street artists.</p>
<h3 id="heading-broader-questions">Broader questions</h3>
<p>This decision raises broader questions for businesses and the art world:</p>
<ul>
<li><p>Should artistic works be monopolised through trade mark registration, which can technically last forever?</p>
</li>
<li><p>Is there a need for stronger legislative protection for artists who wish to remain anonymous?</p>
</li>
<li><p>Should illegal graffiti in public spaces be granted copyright protection?</p>
</li>
</ul>
<h3 id="heading-the-fine-art-of-ip-protection">The fine Art of IP protection</h3>
<p>This case serves as an important reminder: <strong>Use it or lose it.</strong></p>
<p>Trade marks are designed to protect brands in the marketplace, not to warehouse artistic rights. For Banksy, this decision exposes his wider portfolio to "bad faith" attacks.</p>
<p>For businesses and artists alike, the lesson is clear: copyright remains the primary protection for creative works. Trade marks are a powerful commercial tool, but only if you meet the criteria for genuine use.</p>
<p><strong>Stakeholders impacted:</strong></p>
<ul>
<li><p>General Counsel</p>
</li>
<li><p>Brand Managers</p>
</li>
<li><p>Marketing Directors</p>
</li>
<li><p>Creative Directors</p>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[When is a social media post clearly an #ad? A win for Samsung, a lesson for brands.]]></title><description><![CDATA[Social media influencers are increasingly being held to account for failing to disclose advertising content. In a recent victory for brands, Samsung successfully challenged an Ad Standards decision, proving that context matters just as much as specif...]]></description><link>https://blog.jameswan.co/when-is-a-social-media-post-clearly-an-ad-a-win-for-samsung-a-lesson-for-brands</link><guid isPermaLink="true">https://blog.jameswan.co/when-is-a-social-media-post-clearly-an-ad-a-win-for-samsung-a-lesson-for-brands</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 05:33:17 GMT</pubDate><content:encoded><![CDATA[<p>Social media influencers are increasingly being held to account for failing to disclose advertising content. In a recent victory for brands, Samsung successfully challenged an <a target="_blank" href="https://adstandards.com.au/">Ad Standards</a> decision, proving that context matters just as much as specific hashtags.</p>
<p>For businesses working with influencers, this case offers a critical lesson: while you don't always need a giant neon sign saying "AD," the commercial nature of the post must be undeniable.</p>
<p>Here is an analysis of the decision and its implications for your marketing compliance.</p>
<h3 id="heading-the-rules-of-engagement">The Rules of Engagement</h3>
<p>Under the <a target="_blank" href="https://aana.com.au/self-regulation/code-of-ethics/">Australian Association of National Advertisers (AANA) Code of Ethics</a>, advertising must be clearly distinguishable as such.</p>
<p>The key requirement is that the commercial relationship must be "clear, obvious, and upfront" to the audience. While the Code doesn't mandate specific wording, simply tagging a brand or using their product in a photo isn't enough on its own.</p>
<h3 id="heading-samsung-v-ad-standards">Samsung v Ad Standards</h3>
<p>The case centred on an Instagram post by influencer <a target="_blank" href="https://www.instagram.com/nadiafairfax/">Nadia Fairfax</a>. The post featured images of Fairfax and two others holding <a target="_blank" href="https://en.wikipedia.org/wiki/Samsung_Galaxy_Z_Flip">Samsung Galaxy Z Flip</a> smartphones, with the caption:</p>
<blockquote>
<p><em>Z FLIP(ing) around FW with these two.... @galaxybysamsung</em> <em>@_yanyanchan @sarahellen Hello!?</em> <em>#WorkingWithSamsung #GalaxyZFlip #NadiaTakesSamsung</em></p>
</blockquote>
<p>The complaint alleged that the post was an advertisement masquerading as organic content.</p>
<p><strong>Round 1: Complaint Upheld.</strong> Initially, Ad Standards ruled against Samsung. The panel argued that tagging the brand and using the hashtag <code>#workingwithsamsung</code> was ambiguous. The majority felt "working with" could simply mean the influencer was using the device to do work, rather than being paid to promote it.</p>
<p><strong>Round 2: Independent Review.</strong> Samsung sought an independent review, arguing the initial decision ignored the context. The reviewer agreed, noting a "substantial flaw" in the original ruling. They emphasised that the panel had taken a "strained and theoretical" interpretation of the hashtag rather than looking at the post holistically.</p>
<p><strong>Round 3: Final Determination.</strong> On review, the <a target="_blank" href="https://adstandards.com.au/about/community-panel/">Community Panel</a> reversed the decision. They found the post was clearly distinguishable as advertising because:</p>
<ul>
<li><p><strong>Visual focus:</strong> The images prominently featured the phones in an artificial, posed manner.</p>
</li>
<li><p><strong>Repetition:</strong> The brand name "Samsung" appeared three times, and the product name "Z Flip" appeared twice.</p>
</li>
<li><p><strong>Context:</strong> The combination of visuals, captions, and specific hashtags made the commercial nature of the content obvious to a reasonable person.</p>
</li>
</ul>
<h3 id="heading-key-takeaways">Key takeaways:</h3>
<ol>
<li><p><strong>Context is king:</strong> This decision confirms that you don't necessarily need explicit labels like <code>#ad</code> or <code>#sponsored</code> if the overall theme, visuals, and language of the post make it abundantly clear it's an ad.</p>
</li>
<li><p><strong>Ambiguity is risk:</strong> While Samsung won, it took a lengthy review process to get there. Relying on subtle cues or ambiguous hashtags like <code>#workingwith</code> invites complaints.</p>
</li>
<li><p><strong>The safe harbour:</strong> The lowest-risk approach remains to use well-recognised disclosures (e.g., <code>#Ad</code>, <code>#Sponsored</code>, <code>#PaidPartnership</code>). These leave no room for doubt and generally prevent complaints from gaining traction in the first place.</p>
</li>
</ol>
<h3 id="heading-action-items-to-take-now">Action items to take now:</h3>
<ul>
<li><p><strong>Review your Influencer Disclosure Policy:</strong> Ensure your influencer disclosure policy reflects the current AANA requirements.</p>
</li>
<li><p><strong>Update Influencer Agreements:</strong> Check your standard influencer contracts. Do they mandate specific disclosure tags, or do they leave it up to the influencer's discretion?</p>
</li>
<li><p><strong>Audit past content:</strong> Look at recent campaigns. If the commercial nature relies solely on a brand tag, you may be exposed.</p>
</li>
</ul>
<p><strong>Stakeholders impacted:</strong></p>
<ul>
<li><p>Chief Marketing Officers (CMO)</p>
</li>
<li><p>Social Media Managers</p>
</li>
<li><p>Legal &amp; Compliance Teams</p>
</li>
<li><p>Public Relations (PR) Agencies</p>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[AI inventors rejected - High Court of Australia declines to rule on DABUS case]]></title><description><![CDATA[The High Court of Australia has effectively closed the door on the patentability of AI-generated inventions, at least for the moment.
By refusing to hear an appeal in the high-profile "DABUS" case, the Court has left the Full Federal Court's previous...]]></description><link>https://blog.jameswan.co/ai-inventors-rejected-high-court-of-australia-declines-to-rule-on-dabus-case</link><guid isPermaLink="true">https://blog.jameswan.co/ai-inventors-rejected-high-court-of-australia-declines-to-rule-on-dabus-case</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 05:25:49 GMT</pubDate><content:encoded><![CDATA[<p>The High Court of Australia has effectively closed the door on the patentability of AI-generated inventions, at least for the moment.</p>
<p>By refusing to hear an appeal in the high-profile "DABUS" case, the Court has left the Full Federal Court's previous ruling in place: under current Australian law, an inventor must be a human being.</p>
<p>This decision marks the end of a specific legal campaign by Dr Stephen Thaler to have his AI system, DABUS, recognised as the sole inventor of a patent. For business leaders, particularly in research and development (R&amp;D)-intensive sectors like pharmaceuticals and tech, this confirms that purely AI-generated innovations remain unpatentable assets in Australia.</p>
<h3 id="heading-key-takeaways">Key takeaways</h3>
<ul>
<li><p><strong>Humans only:</strong> An AI model cannot be named as an inventor for an Australian patent application.</p>
</li>
<li><p><strong>Procedural roadblock:</strong> The High Court refused the appeal not necessarily on the philosophical merits of AI creativity, but because this specific case was "not the appropriate vehicle" to test the law.</p>
</li>
<li><p><strong>R&amp;D Risk:</strong> Companies relying heavily on AI for discovery and design must ensure human contribution is sufficient to claim inventorship, or risk holding unpatentable technology.</p>
</li>
</ul>
<h3 id="heading-why-the-high-court-of-australia-said-no">Why the High Court of Australia said "No"</h3>
<p>The refusal to grant special leave to appeal was driven by procedure rather than a rejection of AI's potential.</p>
<p>The High Court (Justices Gordon, Edelman, and Gleeson) determined that Dr Thaler’s application was flawed from the start. The Patent Office had originally rejected the application at the "formalities" stage, a preliminary check, rather than during a substantive examination of who actually invented the technology.</p>
<p>Crucially, the case was built on an agreed premise: Dr Thaler had explicitly stated that he was <em>not</em> the inventor, and that the AI was the sole creator. The Court found that hearing the appeal would prevent them from exploring a critical alternative reality: whether Dr Thaler, as the owner and operator of the AI, could have been considered the inventor <em>despite</em> the AI's involvement.</p>
<p>Because the case was framed so narrowly, the Court decided it was the wrong opportunity to settle such a significant point of law.</p>
<h3 id="heading-the-commercial-reality-for-rampd">The commercial reality for R&amp;D</h3>
<p>For now, the legal status quo remains. This has immediate ramifications for industries that use machine learning to accelerate innovation.</p>
<p>If your R&amp;D process involves an AI model identifying a new drug molecule or optimising an engineering design without significant human intervention, you face a dilemma. You cannot name the AI as the inventor, and if you name a human who didn't actually contribute to the inventive step, the patent could be invalid.</p>
<p><strong>Strategic impact:</strong> Innovation leaders must ensure their R&amp;D workflows document human intellectual contribution. To secure patent protection in Australia, you need a human "inventor" who can legitimately claim to have contributed to the creative concept, even if AI did the heavy lifting.</p>
<h3 id="heading-whats-next-global-fragmentation">What's Next? Global fragmentation</h3>
<p>While the door is shut in Australia, the issue is not dead globally. Dr Thaler’s campaign is testing legal systems worldwide.</p>
<p>Unlike Australia, the case has proceeded to the highest level in the United Kingdom, with the UK Supreme Court set to hear arguments on whether the <em>Patents Act 1977</em> (UK) can accommodate non-human inventors.</p>
<p>Until legislative reform occurs or a new test case arises with different facts, Australian businesses must operate on the principle that IP rights are a strictly human privilege.</p>
<p><strong>Which stakeholders are impacted":</strong></p>
<ul>
<li><p>Chief Technology Officers (CTO)</p>
</li>
<li><p>Heads of R&amp;D</p>
</li>
<li><p>IP Legal Counsel</p>
</li>
<li><p>Innovation Managers</p>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[GUIs unable to be protected by a registered design - IP Australia confirms digital interfaces are not ‘products’]]></title><description><![CDATA[Two recent decisions by IP Australia have delivered a blow to designers seeking to protect digital interfaces. The regulator has confirmed that Graphical User Interfaces (GUIs) are not certifiable as designs under the Designs Act, citing their "trans...]]></description><link>https://blog.jameswan.co/guis-unable-to-be-protected-by-a-registered-design-ip-australia-confirms-digital-interfaces-are-not-products</link><guid isPermaLink="true">https://blog.jameswan.co/guis-unable-to-be-protected-by-a-registered-design-ip-australia-confirms-digital-interfaces-are-not-products</guid><dc:creator><![CDATA[James Wan]]></dc:creator><pubDate>Mon, 02 Feb 2026 03:24:05 GMT</pubDate><content:encoded><![CDATA[<p>Two recent decisions by IP Australia have delivered a blow to designers seeking to protect digital interfaces. The regulator has confirmed that Graphical User Interfaces (GUIs) are not certifiable as designs under the <em>Designs Act</em>, citing their "transient" nature and a narrow interpretation of what constitutes a "product."</p>
<p>This stance affects any business developing apps, software interfaces, or smart devices. While the Federal Government is considering legislative reform to modernise these definitions, the current landscape requires careful navigation.</p>
<p>In this Insight, we unpack the implications of the <em>DRiV</em> and <em>GEA</em> decisions and what they mean for your IP strategy while we wait for the law to catch up.</p>
<h3 id="heading-key-takeaways">Key takeaways</h3>
<ul>
<li><p><strong>The "At Rest" rule:</strong> IP Australia has affirmed (in <a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ADO/2024/3.html"><em>DRiV</em></a> and <a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ADO/2025/1.html"><em>GEA</em></a>) that GUIs do not provide visual features for a design because products must be reviewed "at rest." Since digital displays are transient, they currently fail this test.</p>
</li>
<li><p><strong>Legislative:</strong> The Federal Government is reviewing amendments to specifically include virtual designs (like GUIs) in the definition of a "product." Draft legislation is expected in late 2025.</p>
</li>
<li><p><strong>Strategic filing:</strong> In the interim, applicants must be highly strategic in their use of "product" titles and characterisation during the examination process to avoid rejection.</p>
</li>
</ul>
<h3 id="heading-key-stakeholders-impacted">Key stakeholders impacted:</h3>
<ul>
<li><p>Head of Product / Design</p>
</li>
<li><p>R&amp;D Managers</p>
</li>
<li><p>IP Counsel</p>
</li>
<li><p>Chief Technology Officers (CTO)</p>
</li>
</ul>
<h3 id="heading-the-at-rest-problem">The "At Rest" problem</h3>
<p>Under the <a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdb/au/legis/cth/consol_act/da200391/"><em>Designs Act 2003</em> (Cth)</a>, a design is defined as the <em>overall appearance</em> of a <em>product</em>.</p>
<p>In the recent <a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ADO/2024/3.html"><em>DRiV</em> decision</a> (involving electronic devices displaying logos) and the <a target="_blank" href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ADO/2025/1.html"><em>GEA</em> decision</a> (involving a data layout for mining equipment), IP Australia refused to certify the designs. The delegate relied on a traditional interpretation of the law:</p>
<ol>
<li><p><strong>Manufacturing definition:</strong> The Act defines a product as a "thing that is manufactured or handmade." The delegate argued that in everyday speech, one does not "manufacture" a digital display.</p>
</li>
<li><p><strong>Transient nature:</strong> The delegate upheld the principle that a product must be assessed "at rest." A digital interface that disappears when the device is turned off is considered transient, not a permanent visual feature of the hardware.</p>
</li>
<li><p><strong>Historical intent:</strong> The decision leaned heavily on a <a target="_blank" href="https://www.alrc.gov.au/publication/designs-alrc-report-74/">1995 ALRC Report 74</a>, which recommended screen displays should not be protected, despite more recent UK decisions that have recognised icons as "articles."</p>
</li>
</ol>
<p><strong>Strategic impact:</strong> This confirms that, for now, attempting to protect a GUI as a distinct product in isolation is likely to fail examination in Australia. The argument that a GUI "comes into existence" (and therefore results in a design) when displayed was rejected in favour of the "at rest" orthodoxy.</p>
<h3 id="heading-inconsistencies-depending-on-product-type">Inconsistencies depending on product type</h3>
<p>While the <em>DRiV</em> and <em>GEA</em> decisions seem to close the door, IP Australia’s application of policy has created some confusion and potential loopholes.</p>
<p>There is a longstanding policy against certifying GUIs for mobile devices. However, purely digital designs are occasionally certified when tied to specific hardware.</p>
<p><strong>The cooking appliance exception:</strong> For example, in January 2024, IP Australia certified a "User Interface For A Cooking Appliance." The representation appeared to be a purely digital design visible only when the appliance was switched on (i.e., not "at rest").</p>
<p><strong>What this means for you:</strong> The product’s characterisation matters. IP Australia appears more willing to certify a user interface when it is tied to a specific "non-mobile" appliance (such as an oven) rather than to a generic screen (such as a tablet or phone). This inconsistency creates a complex environment in which your product title could determine the success of your application.</p>
<h3 id="heading-whats-next-legislative-reform">What's next? Legislative reform</h3>
<p>The friction between modern digital design and 20-year-old legislation has been recognised. The Federal Government is currently considering legislative amendments to modernise the definition of "product" to specifically include virtual designs and GUIs.</p>
<p><strong>Timeline:</strong> Further updates regarding draft legislation are expected in <strong>late 2025</strong>.</p>
<p><strong>The unknown:</strong> A critical detail for businesses will be the transitional provisions. Will the new laws allow you to capture GUIs filed (and potentially rejected) before the change date? This remains to be seen.</p>
<h3 id="heading-action-items-to-take-now">Action items to take now:</h3>
<p>While we await legislative clarity, businesses should not abandon protection for digital assets; they must adjust their strategy accordingly.</p>
<ul>
<li><p><strong>Review product titles:</strong> When filing design applications, careful thought must be given to the product title. Linking the GUI to specific, non-generic hardware (where possible) may increase the likelihood of certification compared with a generic "display screen" claim.</p>
</li>
<li><p><strong>Monitor the reform:</strong> Keep a close watch on the draft legislation expected in late 2025. This will be the trigger to potentially broaden your filing strategy.</p>
</li>
<li><p><strong>Seek specialist advice:</strong> The distinction between a rejectable "mobile GUI" and a certifiable "appliance interface" is fine and inconsistent. Do not rely on general filing strategies; navigate the examination process with specific advice on IP Australia's current internal logic.</p>
</li>
</ul>
]]></content:encoded></item></channel></rss>