This blog/article is written by Aarushi Relan, Learning Manager at Lawctopus Law School
Introduction: The Leaky Box is real
During the early 2023, Samsung made a costly mistake by lifting the ban on its employees using OpenAI’s chatbot ChatGPT. Within 20 days, its data was leaked out including its proprietary source code, semiconductor code, equipment data, confidential meeting transcripts, etc.
One Samsung employee even entered an internal source code into ChatGPT’s training models. Eventually, Samsung had to clamp down by issuing a memo to ban the use of generative AI tools.1
This is not an isolated incident. Today, lots of office workers admit to pasting company secrets into public AI tools without approval. As per global KPMG and University of Melbourne study, more than 57% of employees admitted to hiding their use of AI at work by concealing the information.2
As per a recent report, 34.8% of all corporate data that employees input into AI tools is classified as ‘Sensitive and Confidential’. This matters since companies are now betting their competitive advantage to AI and most do not have a coherent strategy to protect the trade secrets that make their AI work. This gap is growing into a real liability.

Image 1: AI Adoption and Risk Report by Cyberhaven Labs3
Why Trade Secrets Are Critical for AI Companies?
In traditional tech, patents protect inventions, however AI is different. Pursuant to Alice Corp. v. CLS Bank International,4 it was ruled that implementing a generic business or abstract idea on a computer does not make it eligible for patent.
Similarly, AI algorithms are frequently challenged as mathematical formulas which are unpatentable ideas. This shifted the game and now companies rely on trade secrets instead.
A trade secret is anything that gives you a competitive edge and advantage and must be kept confidential. Coca-Cola’s recipe is a famous kept trade secret since 1886.5 However, for an AI company, this could be your training dataset, system prompts especially the confidential data and behaviour, negative know-hows, model weights, fine-tuning methods, etc.
Unlike patents, trade secrets do not expire, require registration or grant and need not be disclosed publicly. The information must possess the necessary confidential character and not be in public knowledge.6
However, the moment someone gains access whether through an employee departure, a leaked dataset or data pasted into a public AI tool, the legal protection evaporates quickly.
The Major Leak Vectors
The most immediate risk is Shadow AI, where employees paste secrets into public tools. For instance, an engineer writes a code for your enterprise to automate certain workflows which has confidential data and pastes it into Claude Code or ChatGPT Codex to debug it or ask for engineering solutions.
The code is now in the training pipeline of ChatGPT and Claude. Similarly, a researcher working for a Government Think Tank uploads a confidential dataset regarding Government budget and tax allocation of citizens for a report analysis.
Or, a product manager transcribes internal strategy notes and feeds them to Claude to summarise. Ideally, this practice has become a norm and none of these employees at first instance think they are doing anything wrong. However, the damage is real.
The departure of employees and competitive hiring is also an old and dangerous leak of trade secret and confidential information. For instance, an engineer working on your model code responsible for training data and prompting website designs leaves your company for a competitor.
In 2025, xAI owned by Elon Musk filed a case against an ex-employee, Xuechen Li who allegedly downloaded the company’s Grok codebase three days before resigning and began uploading confidential and proprietary data to external systems to transfer his new employer.
Judge Rita Lin of the Northern District of California granted a temporary restraining order which required Li to surrender access to his personal devices and accounts for forensic analysis and return of confidential information or written record.7 This is where the springboard doctrine comes in.
Under this principle, a departing employee cannot take documents or deliberate misappropriate secrets, they cannot use such information to gain “springboard” advantage over a competitor. The doctrine even prevents employees from using the general knowledge they have gathered for a competing company.
The most emerging frontier is reverse engineering and prompt injection. In OpenEvidence v. Pathway,8 an AI-powered medical search engine, accused Pathway Medical of utilizing a “prompt injection attack”.
The company claimed violations under the Defend Trade Secrets Act9 where through a generative AI’s internal configurations and strategic prompting, the competitor was able to access confidential and proprietary data or through standard reverse engineering.
This is interesting since courts still have not ruled that a system prompt qualifies as a protectable trade secret or whether extracting it through clever questioning amounts to theft.
Five Practical Steps to Protect Trade Secrets in AI Era

Image 2: Mapping AI threats and defences
Issue-spotting in the modern age gives us five practical steps for better protection of trade secrets:
Step 1: Classify your secrets upfront
Before you can protect something, you need to know what the information is. Conduct an audit such as which datasets, codes, models and processes actually have a competitive advantage. Certain datasets can be made available publicly. Distinguish them from ones which cannot be.
This matters legally as well for protection of trade secrets since courts assess whether a company took “reasonable steps and measures” to keep their trade secrets confidential.10
Step 2: Tighten employment and non-disclosure agreements
Every employee who has access to your trade secret must sign a clear confidentiality, non-disclosure and invention assignment agreement. Be specific in the agreement what is covered as confidential data such as model weights, training data, prompt design, source code, proprietary information, marketing strategy work, etc.
To avoid the complexity of a new employee who might be a potential stealer of former company’s information, take recommendations and certifications of new hires from their former employers.
Step 3: Govern consumer AI tool use
Set a clear policy for consumer AI tool use in the workplace. Such policies can be recommended by lawyers to their clients now that employees cannot paste company data into generative AI tools such as ChatGPT, Claude, Copilot, etc.
For teams that genuinely need these tools, procure an enterprise version or use private deployments with secure cloud servers so that companies can track what is being shared. Training employees on ethical use of AI is becoming the need of the hour.
Step 4: Monitor the high profile departures
When someone who knows your proprietary methods or training datasets leaves the company, especially for a competitor, treat it as a security event. Track their activities making sure they do not download the source code before leaving. Any potential screenshot or photos or AWS key.
Locking down the digital infrastructure to prevent unauthorized downloads is also a good mechanism.
Step 5: Understand the regulatory obligations in your jurisdiction
Trade secrets protection also has limits. In the EU, the AI Act11 and the Trade Secrets Directive12 create tension within the statutory protection. Directive creates tension since regulators increasingly demand transparency about how your model works such as training data, bias, decision logic, etc. yet companies claim trade secret protection.
In India, specifically speaking, common law breach of confidence provides protection but regulators may still demand disclosure for AI governance. Mapping your obligations early and not assuming secrecy will shield you from government requests is important.
Why This Matters Now
If you advise tech companies, AI start-ups or in-house counsel at large enterprises, trade secret protection is becoming as fundamental as employment law or equity structuring. Your clients will ask: Is our algorithm legally protected if we don’t patent it?
What happens to our secrets if an employee leaves? Can a competitor copy our model by reverse engineering? These are not niche questions anymore. They are core business risk questions which need attention and immediate mitigation.
The courts globally are also addressing these questions. A well-structured confidentiality framework can mean the difference between a company retaining its competitive advantage and losing it overnight.
Want to go beyond understanding the risks and learn how law actually responds to AI, technology and intellectual property challenges? Explore Lawctopus Law School’s AI for Legal Professionals Course and Mastering IPR & TMT Laws Course to build practical skills for navigating AI, IP and technology law in real-world legal practice.
References
- Siladitya Ray, Samsung Bans ChatGPT and Other Chatbots for Employees After Sensitive Code Leak, FORBES (Aug 21, 2026, 12:54 PM) https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/. ↩︎
- Eric Anicich and Jeslyn Brouwers, Why Employees Aren’t Transparent About Their AI Usage, HARVARD BUSINESS REVIEW (Aug 20, 2026, 1:30 PM) https://hbr.org/2026/06/why-employees-arent-transparent-about-their-ai-usage. ↩︎
- Cyberhaven Labs, 2025 AI Adoption & Risk Report (2025), https://info.cyberhaven.com/hubfs/Content%20PDF/Cyberhaven%20Labs%20-%202025%20AI%20Adoption%20&%20Risk%20Report.pdf. ↩︎
- Alice Corp. Pty. Ltd. v. CLS Bank Int’l, 573 U.S. 208 (2014). ↩︎
- The Coca-Cola Company, Coca-Cola Formula History (Aug 20, 1:44 PM) https://www.coca-colacompany.com/about-us/history/coca-cola-formula-is-at-the-world-of-coca-cola. ↩︎
- Coco v. A.N. Clark (Engineers) Ltd., [1969] RPC 41 (Ch. 1968). ↩︎
- X AI Corp. v. Li, Order Grating Plaintiffs’ Motion for Temporary Restraining Order, 3:25-cv-07292-RFL, at 1 (N.D. Cal. Sept. 2, 2025). ↩︎
- OpenEvidence Inc. v. Pathway Medical, Inc., 1:25-cv-10471 (D.Mass.2025). ↩︎
- 18 U.S.C. § 1836 et. seq. (Supp. 2016). ↩︎
- U.S. Patent and Trademark Office, Trade Secret Policy (Aug 22, 11:00 AM) https://www.uspto.gov/ip-policy/trade-secret-policy. ↩︎
- Regulation (EU) 2024/1689, 2024 O.J. (L) 1689 (Aug. 12, 2024). ↩︎
- Council Directive 2016/943, 2016 O.J. (L) 157/1 (Jun. 9, 2016). ↩︎
About the Author
Aarushi Relan is an Intellectual Property and Technology Law practitioner with 5+ years of experience. She holds a B.Com. LL.B. (Hons.) from Amity University and an LL.M. in International IP and Technology Laws from the University of Cambridge. She is currently a Learning Manager at Lawctopus Law School, specialising in Trademarks, Copyright and Technology Law.