Trade Secrets Die From the Inside: What Employee AI Use Does to Your Protection
Most confidentiality planning assumes an adversary — a competitor, an intruder, a departing employee with a thumb drive. Trade secret law does not work that way. The protection exists only while the owner takes reasonable measures to keep the information secret, which means the most efficient way to lose it is your own team pasting it somewhere convenient, in volume, with the best of intentions.
The Element Everyone Forgets Is a Requirement
A trade secret is not a registration you obtain and hold. It is a status that persists only while three things stay true: the information derives independent economic value from not being generally known, it is not readily ascertainable by proper means, and the owner takes measures reasonable under the circumstances to maintain its secrecy. That third element is the one under active attack in every organization that adopted AI faster than it wrote policy.
Note how a defendant uses this. In misappropriation litigation, the first move is rarely "we did not take it." It is "there was nothing protectable to take." Discovery into your internal handling practices then becomes the main event, and an environment where engineers routinely pasted proprietary source into a consumer chatbot, sales uploaded the customer list into a free summarizer, and finance ran the unreleased pricing model through an unvetted tool is an environment your opponent will describe in detail to the court.
Where the Exposure Actually Lives
- •Proprietary source pasted into a consumer tier for debugging
- •Architecture diagrams and infrastructure detail used as prompt context
- •Credentials and internal endpoints included in pasted stack traces
- •Unreleased feature specs summarized in an unapproved assistant
- •Browser extensions with page-scraping permission on internal tools
- •Customer lists uploaded for enrichment or segmentation
- •Unreleased pricing and discount matrices used to draft proposals
- •Deal-specific terms pasted in to generate negotiation strategy
- •Competitive win/loss analysis processed in a personal account
- •Recorded calls run through third-party summarizers without consent review
- •Draft financials and board material summarized in an unvetted tool
- •M&A diligence documents processed outside the approved environment
- •Unsigned contracts pasted in for redline suggestions
- •Employee compensation and performance data used as prompt context
- •Privileged material shared with a third party, risking waiver arguments
- •No inventory of which AI tools are actually in use and at which tier
- •Policy that says 'be careful' without naming tools or data categories
- •Approved enterprise tenant exists, but personal accounts are unblocked
- •No offboarding step covering AI accounts and prompt history
- •Vendor terms never read, so retention and training defaults are unknown
The Tier Matters More Than the Vendor
Internal debates tend to fixate on which provider is trustworthy. That is the wrong axis. The same vendor typically offers a consumer product with permissive retention and training defaults alongside an enterprise or API tier carrying contractual confidentiality, no-training commitments, bounded retention, administrative visibility and often indemnification. The legal difference between those two products, using the same underlying model, is enormous — one supports a reasonable-measures argument and one undermines it.
Which means the governance question is not "do we allow AI." It is "does the path of least resistance for an employee at 4pm on a deadline lead into the tenant we contracted for, or into a personal login." If your enterprise tool is slower, requires a separate login, or lacks a capability people need, they will use the consumer one and you will have no record that it happened. Convenience is a security control.
The Contracts That Break at the Same Moment
Trade secret status is only half the problem, and often the less immediate half. Customer agreements commonly restrict disclosure to third parties, require notice or approval before adding a subprocessor, and limit where regulated data may be processed. Partner and vendor NDAs impose parallel duties over material you received. Regulated data brings its own regimes — protected health information, financial account data, student records, controlled technical data with export implications — each with a specific answer to whether an unapproved processor may see it. A single paste can breach a customer contract, violate a data protection agreement, and trigger a notification duty, all while the trade secret question is still hypothetical.
A Governance Structure That Actually Holds
Establish the Record
- ☐Inventory which AI tools are in use, at which tier, by which teams — before writing policy
- ☐Publish an acceptable-use policy that names tools and data categories, not just 'be careful'
- ☐Contract for enterprise terms with confidentiality, no-training and bounded retention on the approved path
- ☐Collect dated acknowledgments and keep training records; both are exhibits later
- ☐Define a fast approval route for new tools so requests come to you instead of routing around you
Make It Hold Under Pressure
- ☐Make the sanctioned tool the easiest one to reach — SSO, no separate login, capable enough to use
- ☐Classify the crown jewels and apply real access controls, not just a policy sentence
- ☐Block or monitor consumer-tier accounts on managed devices and networks
- ☐Add AI accounts and prompt history to offboarding checklists and departure certifications
- ☐Enforce visibly at least once; unenforced policy is worth little as evidence of reasonable measures
Frequently Asked Questions
If an employee pasted our source code into a chatbot last year, is the secret gone?
Probably not by itself. Courts assess the totality of the measures you took, and an isolated incident against a backdrop of access controls, agreements and policy is survivable. What is not survivable is a pattern with no governance around it. If you discover past exposure, the productive response is to document the scope, tighten controls now, and create the dated record you will want to show later.
Do no-training commitments solve this?
They help significantly and do not finish the job. A no-training term addresses one specific fear — your material influencing a model others use — while leaving retention, subprocessor access, incident handling, jurisdiction and your own internal-control story untouched. Read the retention window and the security commitments with the same attention you give the training clause.
Are AI coding assistants a different risk than chat tools?
The risk is similar but the surface is larger and quieter. Assistants with repository context send far more material than a person would paste by hand, and they do it continuously rather than in discrete moments an employee would think twice about. Evaluate them at the tier and configuration level — what is indexed, what leaves the environment, what is retained — rather than by category.
What about output that comes back — do we own it?
Ownership of generated output is a separate question from the confidentiality one, governed largely by the provider's terms and by the limits on protecting material without human authorship. Do not assume the two questions have the same answer, and do not let a favorable output-ownership clause distract from an unfavorable retention clause.
Should the policy differ for regulated data?
Yes, and it should be a bright line rather than a judgment call. Protected health information, financial account data, student records and controlled technical data each carry specific processor requirements that a general acceptable-use policy will not satisfy. Name those categories explicitly and prohibit them outside a specifically approved environment.
How do we handle contractors and agencies?
Extend the same rules by contract and verify them. Agencies, contractors and offshore teams frequently work in their own tooling under their own accounts, which means your material is sitting in an environment you never evaluated. Put AI-use terms into the contract, ask which tools they use at which tier, and include it in vendor review.
Your Public Claims Are Part of the Record Too
Security pages, trust centers, privacy notices and subprocessor lists all describe how you handle confidential material. When those pages promise controls the organization does not actually run — or omit AI processing entirely — the gap is the first thing a counterparty's lawyer will point at.
See what your site currently claims. Run a free scan and review every page that describes how you protect customer and company data.