Skip links
ai and trade secrets

AI and Trade Secrets: Confidentiality Risks for Businesses

Employee Risks of using AI to draft, summarize, code, and analyze business information is a concern for both AI and Trade Secrets. Learn about AI, trade secrets, confidentiality, contracts, and privilege.

The Hidden Dangers of Employee AI Use

AI AND TRADE SECRETS
AI and Trade Secrets: Protecting confidential information now means training and educating employees about proper use of AI.

Many businesses assume AI and trade secrets are a software-company problem. They are not. They are becoming a workplace problem for any company whose employees use AI with confidential or competitively sensitive information.

Most companies understand the nightmare version of a data breach. Someone clicks the wrong link. A vendor account is compromised. Passwords are stolen. A hacker gets in. A ransomware note appears.

So businesses prepare. They buy cybersecurity insurance. They use firewalls, multifactor authentication, access controls, employee training, and incident-response plans.

They watch for someone trying to break in.

But AI usage can create a quieter problem.

Confidential information may not be taken by a hacker in the middle of the night. It may be sent out by an employee in the middle of the workday.

Not secretly. Not maliciously. Not with a plan to hurt the company.

A salesperson asks AI to revise a customer proposal. A developer asks AI to troubleshoot source code. An engineer asks AI to analyze prototype data. A manager asks AI to review customer demographics. An executive asks AI to help draft a response to a lawyer’s email.

To the employee, it may feel like better, faster, more efficient work.

To the company, it may later raise harder questions.

What was submitted? Which AI system was used? Was the system approved? Did the system retain the data? What terms applied? Could the information be reviewed, reused, or disclosed? Can the company still claim the information was protected?

Those questions are no longer remote. 75% of knowledge workers are using AI at work, and 78% of those users were using their own AI tools. This trend can put confidential company data at risk for public disclosure. 88% of organizations are using AI in at least one business function.

AI is already part of many company’s typical workday.  That is why, companies need to discuss and train employees on the use of AI and Trade Secrets.

For companies with valuable confidential information, that should be a wake-up call.  To maintain and protect Trade Secrets, any serious discussion about AI and Trade Secrets now has to include employees use of AI.

The issue is not Technology, but Employee Use.

AI is a tool.  It can be useful. It can help employees write more clearly, organize information, compare documents, summarize records, and work through routine problems.  That is not the issue.

The issue is when employees, using AI, enter confidential information which the company does not disclose to others: source code, customer lists, pricing strategy, product designs, technical drawings, prototype test data, formulas, manufacturing processes, legal advice, settlement communications, financial projections, or nonpublic business plans.

A trade-secret problem does not always start with a nefarious act like employee theft. Sometimes it starts with a desire to be more effecient. For example: A salesperson who wanted a better proposal; A developer wanting to fix a software bug; An engineer who wanted a better solution; A manager looking for a simple explanation of her legal options.

If protected information is submitted to others, outside the company using a public, uncontrolled  AI system, the company may have lost its confidential information. That is often the central issue in a trade secret case. Not whether AI is good or bad. Not whether employees mean well. Whether the company has taken reasonable means like rules, contracts, systems, and training to protect its confidential informaiton.

Privilege, Use of AI and Trade Secrets

Recent court cases are dealing with the impact on using AI on confidentiality, attorney privileges, trade-secret protection, and discovery.

In United States v. Heppner, a criminal defendant used Claude to analyze facts and legal issues, including information obtained from counsel. The court held that the written exchanges with the AI platform were not protected by attorney-client privilege or the work-product doctrine. The case is a warning to businesses and executives: legal advice should not be treated like ordinary text that can be dropped into public AI.

In Trinidad v. OpenAI, the plaintiff claimed trade-secret protection for information developed through ChatGPT. The court dismissed the trade-secret claim, explaining that the plaintiff had not alleged reasonable measures to keep the information secret and had voluntarily shared the alleged trade secrets with OpenAI by using ChatGPT.

In Conservation Law Foundation v. Shell Oil, a judge ordered production of AI exchanges used by an expert as part of their expert report. Although the ruling is pending appeal, this may be the first time an expert has had to submit its AI history to the court.

While these cases are different, they point in the same direction. Use of AI can impact confidentiality. When someone uses AI, like an internet browser, that information can become part of the public record and the information can be used as evidence,  even if there is a confidentiality agreement. By submitting information to AI, the information may no longer be confidential. That is why AI and Trade Secrets should be addressed before a dispute begins, not after the company is forced to explain what happened.

Trade Secrets Require More Than Good Intentions

Trade-secret protection generally requires three things: confidential information, which has independent economic value from not being generally known, and the party asserting the right must have used reasonable measures to keep the information secret.

That last requirement is where most cases are fought and where the use of AI becomes important if not determinative. A company may have confidentiality agreements. It may mark documents it wants to protect as confidential. It may restrict access to various folders and systems. It may train employees not to send sensitive information to outsiders. But if employees are free to submit the same information to publicly accessible AI systems, the company’s trade secret rights may fail.

Like putting the toothpast back into the tube, a company cannot allow its confidential information to be publicly disclosed and then expect a court to treat it differently.

Legal Advise Needs to be Protected

In order for an attorney to provide good advice, they often require sensative business and factual information from their clients. Clients sometimes want to use AI to draft an email to counsel, summarize a lawyer’s email, explain a demand letter, simplify a legal memo, or prepare a response to a dispute. That may feel harmless. It may not be.

In order to have open and candid conversations, attorneys have to communicate with their clients about some of the most sensative issues they are facing.  Sometimes this involves legal strategy.  Sometimes this involve bad facts.  As a result, the attorney-client communications are considered confidential and protected as privileged communications even from from courts and adverse parties. However, if an attorney’s advice or legal strategy is voluntarily shared with outhers outside the attorney-client relationship, that priviledge may disappear and the opposing side may gain acces to those communications.

As a practical rule, If the material came from an attorney, was prepared for an attorney, or discusses legal strategy, do not submit it to a public or unapproved AI.

Employee Agreements and Departing Employees

AI should also be addressed when employees join and leave the company.

A departing employee may have used a personal AI account for company work. That account may contain uploaded documents, code snippets, customer information, technical data, summaries, or business analysis.

A new employee may have similar material from a prior employer.

Both situations create risk.

Companies should tell new employees not to bring, use, or disclose a prior employer’s confidential information. Departing employees should return company materials, lose system access, and certify that they have not retained company confidential information.

Where AI was used for company work, the company should consider whether prompts, uploaded files, outputs, account histories, saved chats, or stored materials need to be addressed.

That does not mean every employee is a threat.  It just means businesses should consider this as part of their protection strategy,

Confidentiality Agreements Need to Catch Up

Many confidentiality agreements, NDAs, software-development agreements, consulting agreements, vendor agreements, and employee policies were drafted before generative AI became integrated into the company’s workflow.

They may say confidential information cannot be disclosed.

Most agreements don’t address the possibility that confidential informaiton can be submitted to AI, stored in AI workspaces, used to train or improve AI models or incorporated into AI-generated materials.  When a company hires someone who is provided access to a company’s confidential and proprietary information like a software developer, marketing agency, product designer, engineer, manufacturer, consultant, the Confidentiality Agreeement should address AI use.

For example, the agreement may prohibit the contractor from submitting source code, customer data, security information, technical specifications, financial information, or confidential business materials into an unapproved AI system. The agreement may also need to address ownership of AI-assisted work product, human review of outputs, confidentiality obligations, deletion or return of materials, and what happens when the engagement ends.

Businesses should not wait until it is too late and the confidential information has already been submitted to AI.

Top AI Confidentility Tips for Businesses

A useful AI policy does not need to be long. but it should answer the following questions:

  1. What information should to be protected?
    This may include source code, customer data, pricing strategy, financial information, product designs, technical drawings, prototype data, legal advice, settlement communications, and nonpublic business plans.
  2. What AI system can be used?
    Employees should know which systems are approved for company work and which are not.
  3. Who should maintain confidentiality?
    Employees, contractors, software-developers, consultants, and vendors.
  4. Add AI to onboarding and offboarding.
    Educate new employees about not bringing confidential information from prior employers or using personal AI accounts. Notify departing employees about not retaining company information after departure.
  5. Create a contingency plan for mistakes.
    If confidential information has already been submitted to AI, the company should find out who to contact to address it, how to remove it, and how to evaluate the risk.

The goal is not to ban AI tools.  The goal is to use them without losing control of the company’s valuable proprietary information.

How an IP Attorney can Help With AI and Trade Secrets

An IP attorney can help a business connect AI use to its broader intellectual property and trade-secret strategy.

That may include identifying what information is actually confidential, determining which information may qualify as a trade secret, reviewing how the company protects that information, updating NDAs and contractor agreements, preparing employee AI policies, reviewing AI vendor agreements, addressing ownership of AI-generated materials, and help developing onboarding and offboarding procedures.

This review is especially important when employees use AI to create software, technical documents, marketing materials, product designs, reports, business strategies, or customer-facing materials.

It is also important when a company is hiring from competitors, offboarding employees with access to sensitive information, using outside developers or consultants, adopting enterprise AI, or responding to a possible disclosure of confidential information.

The IP Center assists businesses with patents, trademarks, copyrights, trade secrets, software, confidential information, and technology agreements. For businesses using AI, The IP Center can help review confidentiality risks, prepare AI policies, update agreements, evaluate vendor terms, protect software and technical materials, coordinate patent and trade-secret strategy, and respond to potential disclosure or misuse of confidential information.

Before employees use AI with confidential business information, legal communications, source code, customer data, or technical materials, businesses should make sure their AI and Trade Secrets policies and agreements are ready.