This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 12 minute read

AI May Be the Missing Link to Your Company’s Trade Secret Theft: What In-House Counsel Should Know

As a business and intellectual property attorney, I spend much of my practice helping corporate clients protect and enforce their intellectual property through patents. But patents are not the only game in town. Trade secrets offer an equally valid, and in many cases, a more practical and affordable means of protecting valuable proprietary information, provided a company implements and maintains reasonable protective measures.

That calculus is shifting, however, in the wake of artificial intelligence (AI). AI has quickly become the latest workflow disruptor that companies are deploying to automate routine business processes, expedite favorable outcomes, and realize critical cost savings. Yet the same technology that accelerates legitimate business operations has also introduced a significant new risk, an increase in internal trade secret theft by the very employees and executives entrusted with a company’s most sensitive information.

This is not a hypothetical concern or even a scare tactic. In recent months, we have fielded several concerns about a similar scenario: a senior executive with authorized access to highly confidential information appears to have exfiltrated trade secrets, and AI may have played a role in enabling the theft or in allowing a competitor to reconstruct the stolen information from incomplete fragments. The pattern is troubling and novel enough that in-house counsel should understand the legal framework, recognize how AI changes the risk profile and threat landscape, and take concrete and proactive preventive steps now.

The Legal Framework: The UTSA and DTSA

A. Common Elements Under the UTSA and DTSA

Trade secret misappropriation was historically treated as a common-law tort. Today, most states have enacted a version of the Uniform Trade Secrets Act (UTSA), with notable exceptions such as New York and North Carolina. At the federal level, the Defend Trade Secrets Act (DTSA), 18 U.S.C. § 1836 et seq., enacted in 2016, provides a parallel federal cause of action. Because the two statutes largely mirror one another, they are discussed together below, followed by the key features unique to the DTSA.

Under both statutes, a trade secret is information, such as a formula, pattern, compilation, program, device, method, technique, process, or code, that: 1) derives actual or potential independent economic value from not being generally known or readily ascertainable through proper means; and 2) is the subject of reasonable efforts to maintain its secrecy. Improper means include theft, bribery, misrepresentation, breach or inducement of a breach of a duty to maintain secrecy, or espionage through electronic or other means.

Misappropriation under both statutes means either 1) the acquisition of a trade secret by a person who knows or has reason to know it was acquired by improper means, or 2) the disclosure or use of a trade secret without consent by a person who acquired it improperly, knew or had reason to know it was improperly derived or subject to a duty of secrecy, or, before a material change of position, knew or had reason to know it was acquired by accident or mistake.

Both statutes provide for injunctive relief, compensatory damages (including actual loss and unjust enrichment, or a reasonable royalty), enhanced or punitive damages of up to two times actual recovery, and attorney fees where bad faith or willful and malicious conduct is established. The UTSA displaces other tort claims based on misappropriation, but does not preclude contractual remedies, unrelated civil remedies, or criminal liability.

B. Features Unique to the DTSA

The DTSA adds several distinct requirements and tools. First, the trade secret must relate to a product or service used in, or intended for use in interstate or foreign commerce. Second, the DTSA applies only to misappropriation occurring after May 11, 2016, and an action must be brought within three years after the misappropriation is discovered or reasonably should have been discovered. Third, reverse engineering is expressly permitted and cannot support a misappropriation claim.

The DTSA also offers a powerful additional tool: ex parte seizure. A court may order seizure of misappropriated trade secrets to prevent their dissemination when, among other requirements, an injunction would be inadequate because the opposing party would likely evade it, immediate and irreparable injury would otherwise occur, the applicant is likely to succeed on the merits, and the opposing party has actual possession of the trade secret.

Finally, the DTSA grants civil and criminal immunity to individuals who disclose trade secrets in confidence solely to report or investigate a suspected violation of law to a government official or attorney, or in a sealed court filing. Employers must give notice of this immunity in agreements governing the use of trade secrets or confidential information.

AI Facilitates Trade Secret Misappropriation

Traditionally, trade secret theft depended on an employee exfiltrating a complete package of proprietary information: a physical prototype heisted out of the lab, a laboratory notebook photographed page by page, and/or the step-by-step recitation of an entire secret formulation or process, so that a third-party entity or a competitor could reproduce the trade secret in full. The theft was often binary, meaning the wrongdoer either took enough proprietary information to reconstruct the secret or they did not, and ensuring a single employee did not know the full trade secret was often a great mitigation factor. AI changes that former equation in two critical ways.

First, AI can bridge the gap. An employee who exfiltrates only portions of a trade secret, such as mere fragments of a proprietary source code, partial datasets, or selected process parameters, may no longer need the complete picture. Modern AI systems, particularly large language models and code-generation tools, are capable of analyzing partial inputs and inferring or reconstructing the missing elements. A competitor who obtains several key modules of a proprietary sales-prediction algorithm may be able to feed those fragments into an AI tool and have the AI fill in the gaps. Therefore, AI is utilized to generate the connecting logic, the data-handling routines, or the calibration parameters that were never stolen in the first place. What once would have been an incomplete and unusable amount of theft can now become a fully functional competing product with AI providing the missing links.

Second, under the holding in Heppner (25-cr-00503-JSR, S.D.N.Y. Feb. 17, 2026), the inputting or uploading of confidential information to a publicly available AI system constitutes third-party disclosure sufficient to waive attorney-client privilege or protections under the work-product doctrine, and AI tools themselves also create new leakage pathways for trade secrets. More specifically, when employees paste proprietary information into public or unprotected AI tools, a third-party disclosure of the trade secret may have occurred. Regardless of whether the employee intended to debug code, draft documentation, analyze data, or simply ‘ask a question’ about a process, those trade secrets may be ingested into the AI system’s training data or otherwise exposed beyond the company’s control. This unregulated use of AI undermines the “reasonable measures” requirement that is central to trade secret protection under both the UTSA and the DTSA. If a company cannot demonstrate that it took reasonable steps to prevent its secrets from being uploaded to third-party AI platforms, particularly those AI tools that are public or unprotected, the uploaded information may lose its protected status entirely.

In short, AI lowers the threshold of what a wrongdoer needs to steal for the theft to be commercially valuable, while simultaneously creating new channels for leakage.

Analyzing A Trade Secret Misappropriation Fact Pattern

A. The Scenario

Consider the following fact pattern, which closely mirrors the situations several of my clients have recently confronted. A high-level executive with secure, authorized access to one or more trade secrets, such as a proprietary code for a software program being internally developed to provide sales predictions for the company’s customers. The executive sends portions of that code to a personal email address over the course of several months. The employer’s internal IT system flags these transmissions as unauthorized. The executive subsequently provides notice of resignation. Months later, the same executive is hired by a competitor, which then develops and releases a suspiciously similar software product. The company suspects trade secret theft by its former employee with the new employer possibly having knowledge of the same.

B. Applying the Misappropriation Elements to the Scenario

To support a misappropriation claim under the UTSA and the DTSA, the company must establish that: 1) the sales-prediction code constitutes a trade secret, 2) the executive acquired or disclosed it through improper means or in breach of a duty of confidentiality, and 3) the company took reasonable measures to protect the code. For the DTSA claim, the interstate commerce nexus is readily satisfied for most commercial software products.

The proprietary sales-prediction code likely qualifies as a trade secret. It derives independent economic value from not being generally known or readily ascertainable by third parties. Assuming the company implemented access controls, confidentiality agreements, IT monitoring of the code, as well as other protective measures, it has likely satisfied the requirement of reasonable protective efforts. The executive’s act of emailing portions of the code to a personal email address, without authorization and with full knowledge of the code’s proprietary nature, likely constitutes acquisition by improper means that would breach both a duty of confidentiality and any applicable nondisclosure provisions of their executed employment agreement.

C. How AI Could Have Bridged the Gap

A critical question in this scenario is how the competitor was able to develop a “suspiciously similar” product when the executive sent only portions of the code external to the company. This is precisely where AI may supply the missing link. The competitor and/or the executive may have used AI code-generation tools to analyze the stolen code snippets, infer the architecture and logic of the full program, and generate the missing components. The result is a functional competing product built on a foundation of misappropriated fragments, with AI filling in the remainder. 

D. Investigation Steps

This theory of any AI-facilitated trade secret misappropriation should be explored extensively during discovery. A thorough investigation is essential. Specifically, the company should examine the executive’s email (both corporate and personal, if possible), desktop and laptop computers, handheld electronic devices, office files, calendar entries, computer and telephone logs, records of office and building access, travel and expense records. Additionally, and critically in today’s environment, the executive’s use of AI tools, including any prompts, uploads, or outputs involving proprietary information, should be reviewed as potential evidence.

E. Whom to Sue

The company should consider claims against both the individual executive and the new employer. Starting with the individual ensures accountability for the person who directly misappropriated the trade secrets. Including the competitor organization in a trade secret misappropriation claim is also important, because the competitor likely received the misappropriated information, and naming it as a defendant facilitates the return of the information and/or avoids the procedural difficulties of pursuing third-party subpoenas. Additionally, the competitor company is likely the party that will have the financial resources to actually pay any damages awarded as a result of a successful trade secret misappropriation claim.

F. Expected or Likely Defenses

The company asserting trade secret misappropriation claims should expect the executive and/or the competitor to raise several defenses:

  • The information does not qualify as a trade secret (counsel should avoid overreaching in defining the scope of the claimed secrets).
  • The company maintained insufficient security to justify trade secret protection.
  • The company provided insufficient training to employees on trade secret obligations.
  • The company lacked adequate controls over access to and transmission of the confidential information constituting the trade secret.
  • Existing trade secret policies, if any, were not actually known, followed, or enforced.
  • The three-year statute of limitations from discovery of the trade secret misappropriation to bring the claim is time-barred.

Each of these defenses underscores the importance of a robust, well-documented, and consistently enforced trade secret policy and protection program, which is the focus of the practical recommendations below.

Six Practical Tips for In-House Counsel to Protect Trade Secrets

1. Inventory and Score Your Trade Secrets

The foundation of any effective trade secret program is knowing what you have. Establish criteria to identify and “score” possible trade secrets based on their economic value, competitive sensitivity, and vulnerability to theft. Create a centralized database that: 1) catalogs each trade secret by a unique identifier, 2) records its physical and/or electronic locations, 3) documents the security regime applied to it, and 4) lists every individual authorized to access it. Conduct regular maintenance reviews and audits to confirm that each secret is being properly protected and that the catalog remains current. Trade secrets that have become stale or are no longer competitively significant should be retired, so that resources can be focused on the secrets that matter most to the business’s competitive and market share advantage.

2. Adopt an AI Acceptable-Use Trade Secret Policy

Companies should adopt a clear, written, and known AI acceptable-use policy that explicitly prohibits employees from entering trade secrets, proprietary code, confidential business data, or other sensitive information into unapproved or public-facing AI tools. This policy should be integrated into the company’s broader trade secret protection program, so that it is recognized as a “reasonable measure” under both the UTSA and DTSA. The policy should specify which AI tools, if any, are approved for use by the company, the categories of information that may and may not be input into the tool, and the consequences for employee violations. Folding AI-specific provisions into existing trade secret policy ensures that, in the event of litigation, the company can demonstrate a comprehensive and contemporaneous approach to protecting its secrets in the AI era.

3. Tighten Access Controls and Technical Safeguards

Technical controls are essential. Limit employees’ ability to offload information from company systems by restricting the use of USB drives, external storage, and unapproved cloud services. Consider requiring that trade secret information be accessed only on dedicated, company-controlled machines. Implement two-factor authentication and, where warranted, biometric access controls for systems containing the most sensitive information. Monitor access to controlled data and implement automated alerts that flag suspicious activity, such as transfers of proprietary files to personal email addresses or uploads to AI tools. Cross-reference individuals with access to trade secrets and increase diligence and vigilance over their activities, particularly when those individuals are in sensitive roles or approaching the end of their employment.

4. Train Employees and Obtain Regular Acknowledgments

Training is both a legal requirement and a cultural imperative. Conduct regular, mandatory training sessions that teach employees the company’s established trade secret protection systems, emphasize the importance of information control, and remind them of their obligations to keep protected information confidential. Training should now include AI-specific modules that address the risks of inputting proprietary information into public or unapproved AI tools and the company’s AI acceptable-use policy. Require employees to sign periodic (e.g., annual or biennial) written acknowledgments confirming their understanding of and compliance with these policies. Reiterate contractual obligations and the potential penalties associated with violations, including termination and personal or criminal liability. Include cybersecurity, data privacy, and phishing awareness training, and emphasize that employees should not discuss or disclose trade secrets casually with internal colleagues who do not have a need to know the secret.

5. Regularly Update and Vet Third-Party Agreements 

Review and update all relevant agreements, such as nondisclosure agreements (NDAs), employment agreements, consulting agreements, and vendor contracts, to include AI-specific confidentiality language addressing the use of AI tools with the company’s proprietary information. Include the DTSA-required notice of whistleblower immunity, as the statute conditions the availability of exemplary damages and attorney fees on the employer’s provision of this notice. Vet all third parties, vendors, and business partners, specifically including AI platform vendors who may access or handle the company’s trade secrets.

6. Strengthen Departing-Employee Protocols and Act Quickly

The departure of a key employee is the single most dangerous moment for trade secret security. Develop a comprehensive exit interview checklist that is consistently implemented. Before the employee’s last day, conduct a forensic review of the employee’s computer activity, including any use of AI tools, to identify potential exfiltration. Collect all access cards, credentials, badges, and company devices, and promptly change access codes, passwords, and permissions to confidential locations and systems. If misappropriation is suspected, act immediately: seek injunctive relief and, where warranted, DTSA ex parte seizure, and remember that the three-year limitations clock begins to run upon actual or constructive discovery.

Conclusion

AI is transforming the trade secret landscape in ways that in-house counsel cannot afford to ignore. It enables the reconstruction of complete trade secrets from partial fragments, and unregulated employee use of AI tools creates new and often invisible channels for leakage. The UTSA and DTSA provide powerful enforcement tools, but only to companies that can evidence they took “reasonable measures” to protect their secrets.

As one practitioner observed, when a good trade secret protection policy and program are implemented by a company, its employees will not want to be bothered or burdened with access to the trade secret. That principle should guide every aspect of your company’s approach. If access to the trade secret feels like a bother or a burden because it requires training, acknowledgments, monitored systems, and strict protocols, then you are likely doing it right.

Finally, remember that confidential information is not necessarily a trade secret. A robust program distinguishes between the two, allocates resources accordingly, and ensures that the company’s most valuable secrets receive the protection they deserve.

Proactive prevention is required. Review your policies, update your agreements, train your people, and prepare for the reality that AI is not only a tool for innovation; it may also be the missing link in your company’s trade secret theft. The time for in-house counsel to act is now. 

Tags

intellectual property, artificial intelligence