Trade Secrets and the AI Talent War: Your Legal Questions Answered
By Babak Akhlaghi on July 25, 2026. Apple’s lawsuit against OpenAI, filed July 10, 2026, is generating a lot of questions from founders, operators, and in-house counsel. Most of the coverage focuses on the headline facts. This FAQ goes deeper — into the legal mechanics, the defenses, the jurisdictional nuances, and the questions that matter most if you are running a company in a competitive hiring market.
I am a patent practitioner. I advise technology startups on IP strategy and teach legal aspects of entrepreneurship at the University of Maryland. I read this case not as a news story, but as a practitioner — and as a playbook, in both directions.
What federal law governs trade secret claims, and does state law still matter?
The Defend Trade Secrets Act (DTSA), enacted in 2016, created a federal civil cause of action for trade secret misappropriation for the first time. Before the DTSA, trade secret claims were governed entirely by state law — typically the Uniform Trade Secrets Act (UTSA), which most states have adopted in some form.
State law still matters significantly. Apple filed in the Northern District of California, which means California’s version of the UTSA applies alongside the federal DTSA claim. California’s trade secret law has its own body of case law, particularly around the tension between trade secret protection and California’s strong employee mobility policy under Business and Professions Code Section 16600, which voids most non-compete agreements.
The practical implication: California employers cannot use non-competes to stop former employees from working for competitors. What they can do — and what Apple is doing — is sue for misappropriation when confidential information is actually taken.
What does “reasonable measures” actually mean in court — and why do most startups fail this test?
This is the element that quietly defeats the most trade secret claims. I tell my students: a trade secret has to satisfy three elements. It has to be confidential. You have to derive value from it. And you have to take measures to protect it. If any one of these things doesn’t happen, then it is not a trade secret.
Most founders assume they are covered on the first two. It is the third one that kills them in court.
Courts do not require perfection. They require reasonable efforts proportionate to the value and sensitivity of the information. From a practical standpoint, measures that tend to hold up include password protection and access controls, confidentiality agreements with employees and contractors, consistent labeling of confidential documents, documented training programs, and physical security for sensitive materials.
Measures that tend to fall short include a general policy buried in an employee handbook with no enforcement mechanism, NDAs that were signed but never explained, inconsistent or absent labeling, and no evidence of training beyond onboarding.
The key question is whether the company treated the information like a trade secret. If you store your most sensitive manufacturing specifications in an unlabeled shared drive accessible to everyone in the company, you will have a very difficult time arguing those specifications deserve protection.
I tell my students: put it in a lockbox and lock it up. Only disclose it to the people that need to know, under the strictest confidentiality. That is not just a metaphor — it is the legal standard translated into practice.
What is the difference between passive receipt and directed misappropriation — and why does it matter so much?
This distinction is central to the Apple v. OpenAI case and determines the depth of a defendant company’s exposure.
Passive receipt occurs when a company hires an employee who happens to bring confidential information from a former employer, without the hiring company soliciting, encouraging, or directing that conduct. The company may still face liability if it knew or had reason to know the information was misappropriated and used it anyway — but the exposure is generally lower.
Directed misappropriation is different. That is when a company actively orchestrates the acquisition of a competitor’s confidential information — through recruiting practices designed to elicit proprietary material, structured interview formats that encourage candidates to bring confidential items for show-and-tell sessions, or direct outreach to suppliers using a competitor’s confidential specifications. Apple’s complaint alleges the latter. If proven, directed misappropriation exposes the company to significantly greater damages, including exemplary damages of up to two times the compensatory award under the DTSA, and opens the door to criminal referral.
There is nothing wrong with hiring employees from another company. But when you hire 400 employees from one competitor, you had better have safeguards in place. And if your managers are asking candidates what they worked on, what they know, what they can bring — even as a joke — that is potential evidence of directed misappropriation. Context disappears in discovery. Words are all that remain.
Where is the line between general knowledge and misappropriation — especially for a long-tenured employee?
This is one of the most important and most misunderstood distinctions in trade secret law. After 24 years at a company, the line between personal expertise and trade secret can feel genuinely blurry. But there is a clear answer to where the line falls.
Employees are free to take their general knowledge, skills, and experience to a new employer. A hardware engineer who worked at Apple can go do hardware engineering at OpenAI. That mobility is legal and protected. The question courts ask is this: are you using your general knowledge, or are you using your former employer’s confidential information?
General knowledge lives in the mind. It does not exist in confidential paperwork. It does not exist in a laptop that was never returned. It does not exist on a disc that was never given back.
If the allegations in the Apple case are true — that an engineer retained a company laptop and downloaded confidential files — I do not think there is a very strong argument that what was taken was general knowledge. The moment the information exists in a file designated as confidential, it belongs to the company. Twenty-four years of tenure does not change that.
There is also a second answer to this question, and it falls on the founder. If you label confidential information as confidential consistently — every time an employee opens that file, every time they access that system — you are giving them a continuous reminder: this is not my general knowledge. This is specific information I obtained from this company. That labeling is not just a legal measure. It is the mechanism that keeps the line visible over time.
What is the independent creation defense, and how do you build it before you need it?
One of the primary defenses to a trade secret misappropriation claim is that the defendant independently developed the information at issue — without access to or use of the plaintiff’s trade secrets. If you can demonstrate that your product, process, or design was developed through your own research and engineering, the misappropriation claim fails even if the resulting information looks similar to the plaintiff’s.
The critical requirement is contemporaneous documentation. You need records created at the time of development — engineering logs, design files with version histories, dated meeting notes, internal communications discussing the development process — that establish a clear timeline of independent creation. Records reconstructed after litigation begins carry almost no weight.
To startup founders: keep meticulous notes. Show how you developed the product. Show how you came up with the design. Show all of that in real time, because if you are ever in a position where you need to prove independent creation, and those records do not exist, there is almost nothing you can do.
For AI companies building hardware, this is especially important. If you hired engineers with deep experience in a competitor’s domain, the absence of contemporaneous records makes it nearly impossible to distinguish independent development from use of confidential knowledge those engineers brought with them.
Does the hardware dimension change the legal calculus compared to a software trade secret case?
Hardware trade secrets are as protectable as software trade secrets — and in some respects, more so. Hardware designs, manufacturing specifications, supplier know-how, and supply chain relationships can all qualify for trade secret protection if the three-part test is satisfied. The confidentiality requirement does not distinguish between physical and digital information.
What makes hardware cases more complex is valuation. In a software case, damages are often tied to licensing rates or market displacement. In a hardware case, the value of the trade secret may be embedded in physical manufacturing processes and supplier relationships that took decades and billions of dollars to develop.
The supplier dimension adds another layer. Some of this information has to be disclosed to suppliers to get products made — and suppliers should be under the strictest NDA. One of the allegations in the Apple case is that a supplier was asked to process materials using Apple’s proprietary manufacturing specifications, apparently believing they were authorized under an existing agreement. That is not just an employee problem. That is a coordinated effort that pulled third parties into the alleged misappropriation. The exposure that creates is substantially greater than a single employee walking out with files.
What criminal statutes are potentially in play, and why doesn’t it feel like a crime?
I use an analogy when I teach this. There was a time when Blockbuster would play a warning at the beginning of every movie: “Unauthorized reproduction of this movie is a criminal offense.” People understood that copying a video without permission was a crime. Trade secret misappropriation carries the same weight — and the value of what is being taken is substantially greater. But it does not feel the same way, because you are doing it behind a computer screen.
At the federal level, the Economic Espionage Act (EEA) of 1996 criminalizes trade secret theft. For domestic commercial misappropriation under Section 1832, individuals face up to 10 years imprisonment and fines, while organizations face fines of up to $5 million or three times the value of the stolen trade secret, whichever is greater. State criminal statutes also apply — California Penal Code Section 499c covers trade secret theft and provides for imprisonment of up to three years. Federal and state criminal exposure can run simultaneously with civil litigation.
Here is a message to the startup founders: remind departing employees of criminal exposure during exit interviews. Not as a threat — as a deterrent. Sometimes the most powerful legal tool is not enforcement after the fact. It is the conversation that makes someone pause before they do something they cannot undo.
What happens in discovery in a trade secret case — and what should founders understand about it?
What founders consistently underestimate is how much of the story gets told through internal communications. Emails, Slack messages, interview notes, internal memos — all of it is potentially subject to discovery. The real story of what was known, and when, often comes out in those records.
This cuts in both directions. If you are the company accused of misappropriation, your internal communications are the first place an opposing counsel will look. And the most dangerous evidence often comes not from the employee who brought the files — it comes from the manager who asked the wrong question.
I tell founders: imagine every email may be scrutinized. Every email, every conversation may be placed in front of the court, in front of a jury. When you are writing that email, ask yourself — are you ready to be deposed on it? Are you going to be comfortable with the words you wrote? A manager who asks a new hire “what was the secret you learned at your last job?” as a joking matter has just created potentially the strongest evidence that the company was involved in directed misappropriation. Context disappears in discovery. Words are all that is left.
Does hiring hundreds of employees from one competitor create independent liability?
Not in California. Hiring employees from a competitor — even hundreds of them — is not independently actionable. There is nothing wrong with hiring employees from another company.
But here is what the volume of hiring does. When more than 400 former employees of a single company work for a competitor, and confidential information from that company appears in the competitor’s products or processes, the inference that some of that information was improperly used becomes harder to rebut. The hiring volume is not the cause of action. It is the context that makes the misappropriation allegations more plausible — and the “we didn’t know” defense much harder to sustain.
What should in-house counsel be doing right now?
Five priorities, in order:
- Audit your trade secret inventory. Identify the confidential information you hold that competitors would value and that gives you competitive advantage. Confirm that labeling, access controls, training records, and NDA coverage are all documentably in place. If someone asks you in court what measures you took to protect your information, you want a real answer — not nothing.
- Review your hiring protocols for competitor hires. If your onboarding does not include a signed acknowledgment that the new hire has not brought confidential information from their former employer, add it immediately. Do not taint your IP ecosystem. That is the standard to hold.
- Brief your managers on communication hygiene. Not just your employees — your managers. Policy without training accomplishes nothing. Training without continuous training accomplishes nothing. You need a constant reminder, and it needs to reach the people writing the emails.
- Review your supplier agreements. Confirm that confidential information shared with suppliers is covered by adequate NDAs, that use is restricted to your explicit instructions, and that there is one authorized contact whose authority is current. When a key employee departs, notify every relevant supplier the same day.
- Build your independent creation record now. If you needed to prove tomorrow that your product was developed independently, could you? If the contemporaneous records do not exist, start building them. This is the defense that saves companies — and the one that almost never exists when it is needed.
The Apple v. OpenAI case will develop over years. The companies best positioned when the next dispute arrives will be the ones that treated this moment as a prompt to act. Trade secrets are some of your most valuable IP. Once a trade secret is gone, it is gone. Put it in the lockbox, limit who sees it, train your people continuously, and build your protocols before you need them.
When you are raising funds, preparing for an exit, or entering a partnership, and someone asks you about your IP — you want to be able to say: it is a combination of patents, trade secrets, and documented know-how. That answer requires building the program now, not after the lawsuit. If you are not sure where to start, working with a startup patent attorney who understands both sides of the IP equation is the right first step.
