Protecting Trade Secrets When Employees Use AI | Klemchuk

How Can Companies Protect Trade Secrets When Employees Use Generative AI?

Protecting company trade secrets when employees use generative AI

How Can Companies Protect Trade Secrets When Employees Use

Companies can protect trade secrets while allowing employees to use generative AI, but they should treat AI use as another channel through which valuable confidential information can leave the company’s controlled environment. Effective protection generally requires identifying sensitive information, establishing clear rules for AI use, limiting employees to appropriate tools, reviewing vendor terms and settings, training employees, implementing proportionate technical controls, and responding promptly when sensitive information may have been disclosed.

This matters legally as well as operationally. Under the federal Defend Trade Secrets Act, information qualifies for trade-secret protection only if, among other requirements, its owner has taken reasonable measures to keep it secret and the information derives qualifying economic value from not being

generally known or readily ascertainable through proper means.

Generative AI does not eliminate those traditional requirements. It changes the environment in which companies must satisfy them. A business that carefully restricts access to source code, pricing models, product plans, customer information, formulas, or other valuable information can undermine those controls if employees are simultaneously free to paste the same information into unapproved AI systems without understanding how the information may be retained, accessed, or used.

The objective should not necessarily be to prohibit AI. For many companies, AI can create substantial productivity and innovation benefits. The better objective is to enable useful AI adoption while maintaining a defensible system for protecting the information that gives the business competitive value.

Why Can Employee AI Use Create Trade Secret Risk?

Generative AI tools make it unusually easy to move information outside traditional company systems.

An employee may enter confidential information into an AI tool to summarize a document, analyze data, improve software code, draft a contract, prepare a presentation, develop marketing materials, troubleshoot a technical problem, or answer a business question. The employee may view the interaction as ordinary productivity rather than as a disclosure to an external technology provider.

Depending on the tool and its configuration, information may leave company-controlled systems and become subject to contractual terms, retention practices, access controls, security measures, or data-use practices established by a third-party provider.

The risk is therefore not limited to an employee deliberately stealing information. Ordinary employees trying to work faster can create confidentiality problems without appreciating that they have moved sensitive information into a different environment.

What Information May Qualify as a Trade Secret?

Federal law defines trade secrets broadly enough to encompass many forms of financial, business, scientific, technical, economic, and engineering information when the statutory requirements are satisfied. Examples can include formulas, designs, methods, techniques, processes, programs, and

codes.

For a business, potentially sensitive information may include source code, algorithms, product roadmaps, engineering information, manufacturing processes, formulas, pricing strategies, financial models, customer information, sales strategies, unpublished research, acquisition plans, competitive intelligence, and other commercially valuable information.

But confidential information is not automatically a trade secret merely because the company calls it confidential. The business must satisfy the applicable legal requirements, including taking reasonable measures to preserve secrecy. That makes AI governance part of a larger trade-secret protection system rather than a standalone technology project.

Why Do Reasonable Measures Matter When Employees Use AI?

The reasonable-measures requirement makes company conduct important. Courts evaluating a trade-secret claim may eventually need to consider how the company actually protected the information.

A sophisticated confidentiality policy has less value if employees routinely disregard it, sensitive information is broadly accessible without business justification, or the company’s technology practices materially conflict with its written rules. Generative AI creates another place to examine those practices.

For AI use, that suggests a proportionate approach. A company may reasonably impose stricter controls around highly valuable source code, formulas, product designs, or strategic plans than around ordinary non-sensitive business information.

Does Entering a Trade Secret Into an AI Tool Automatically Destroy Trade Secret Protection?

Not necessarily.

There should not be a categorical assumption that every disclosure to an AI provider automatically eliminates trade-secret status. Companies routinely disclose trade secrets to employees, vendors, licensees, professional advisers, and other parties under circumstances intended to preserve

confidentiality.

The relevant analysis can depend on what information was disclosed, to whom, under what contractual and technical protections, how the system handled the information, who could access it, whether it was retained or reused, and what other measures the company maintained to protect secrecy.

Are Enterprise AI Tools Different From Public Consumer AI Tools?

They can be materially different, but companies should evaluate the particular product rather than rely

solely on labels such as “enterprise.”

AI providers may offer business products with contractual commitments, administrative controls, retention options, access restrictions, encryption, and different treatment of customer data. Those features can be relevant to a company’s risk analysis, but no provider’s marketing label should substitute for diligence.

Legal, security, privacy, IT, and procurement personnel may need to understand the actual product being deployed, its configuration, contractual terms, data practices, available controls, and the type of information employees will use with it.

The appropriate question is not simply whether a tool is “secure.” It is whether the company’s proposed use of that tool is appropriate for the information involved.

What Confidential Information Should Employees Avoid Entering Into AI?

A workable AI policy should help employees recognize information that requires special treatment.

An instruction such as “do not disclose trade secrets” may be legally sensible but operationally weak.

Employees may not know whether the information on their screen is a legal trade secret, and asking them to make that determination every time they use AI can create inconsistent results.

Companies can instead identify practical information categories. Depending on the business, restricted categories might include unreleased source code, credentials, proprietary algorithms, confidential product plans, formulas, customer data, pricing information, financial projections, strategic plans, acquisition information, confidential legal materials, or third-party information subject to contractual restrictions.

The categories should reflect the company’s actual business. Different industries may have very different information that requires heightened protection.

How Should a Company Classify Information for AI Use?

Information classification can translate broad confidentiality obligations into usable employee rules.

A company might distinguish among information that employees may use freely with approved AI tools, information that may be used only with specified enterprise systems, and highly restricted information that should not be submitted to external AI systems without specific authorization.

The terminology matters less than whether employees understand it. Classification should also correspond with existing information-security and trade-secret practices where possible.

The goal is to connect AI rules to the way the company actually handles sensitive information.

What Should a Company’s AI Policy Say About Trade Secrets?

A useful AI policy should tell employees what they may and may not do rather than merely announce that AI presents risk.

Depending on the organization, the policy may identify approved tools, prohibited information categories, permitted business uses, approval requirements for sensitive applications, rules governing personal AI accounts, requirements for reviewing AI output, and procedures for reporting an accidental disclosure.

The policy should also address third-party information. Employees may have access to confidential information belonging to clients, customers, vendors, business partners, acquisition targets, or other parties. A company may have contractual obligations restricting how that information can be used even if it does not qualify as the company’s own trade secret.

The best policy is not necessarily the longest. It is one employees can understand and follow.

Should Companies Limit Employees to Approved AI Platforms?

For many organizations, an approved-tool approach can provide substantially more control than allowing employees to select AI products individually.

Central approval gives the company an opportunity to review contractual terms, security, privacy, retention, administrative controls, data-use practices, and other relevant features before sensitive information enters the system. It can also allow IT and security teams to configure access and monitor

use more consistently.

That does not mean one tool must serve every purpose. Different business functions may have different requirements, and specialized AI systems may be appropriate for particular workflows.

The important point is governance. Employees should not have to conduct vendor diligence themselves each time they discover a new AI application.

What AI Vendor Terms Should Companies Review?

Contract review should focus on how the proposed service will actually interact with company information.

Relevant issues can include rights in customer inputs and outputs, confidentiality obligations, whether customer information is used to train or improve models, retention and deletion, security commitments, subprocessors, access controls, incident notification, data location, audit or compliance information, and termination procedures.

The importance of particular provisions depends on the information and use case. A tool used only for public marketing ideas presents a different risk from a system analyzing unreleased product designs or proprietary source code.

Vendor review should therefore be tied to information classification and intended use rather than conducted as an abstract exercise.

How Should Companies Train Employees About AI and Trade Secrets?

Policies work better when employees understand the reason behind them.

Training can use realistic examples: a developer pasting proprietary source code into an unapproved chatbot; a salesperson asking AI to analyze a confidential customer list; an HR employee uploading compensation data; an executive asking a public tool to summarize an acquisition plan; or a lawyer submitting confidential dispute information.

Those examples help employees recognize that the risk often arises from ordinary work rather than deliberate misconduct.

Training should also explain what employees should do when uncertain. A policy that prohibits risky behavior without giving employees a practical path to obtain approval can encourage workarounds.

What Technical and Administrative Controls Can Support an AI Policy?

Written policies should be supported by controls appropriate to the company’s risk.

Depending on the organization, those measures may include identity and access management, approved-application controls, data-loss prevention, logging, administrative settings, retention controls, access restrictions, security monitoring, or other technical safeguards.

The appropriate controls should remain proportionate. A company should avoid creating so much friction that employees simply move AI use outside approved systems.

Who Should Be Responsible for AI-Related Trade Secret Protection?

This should not belong exclusively to the legal department or IT.

Legal may evaluate trade-secret requirements, contractual obligations, vendor terms, and incident consequences. IT and information security may evaluate systems, access, configurations, monitoring, and technical controls. HR may incorporate expectations into policies, training, onboarding, and discipline.

Procurement may help prevent unapproved tools from entering the organization. Business leaders understand which information and workflows create actual commercial value.

In-house counsel can play an important coordinating role because AI risk crosses those functions.

The objective is not to create a large AI bureaucracy. It is to make responsibility clear enough that important issues do not fall between departments.

What Should a Company Do After a Possible AI Disclosure?

An accidental AI disclosure should be evaluated promptly rather than automatically treated as either catastrophic or harmless.

The company should determine what information was entered, which tool and account were used, when the disclosure occurred, what product configuration applied, whether the information was retained or accessible, what contractual protections exist, whether deletion or other mitigation is available, and whether the information belongs to the company or a third party.

Legal, security, privacy, IT, and other personnel may need to become involved depending on the information. The company should also preserve enough evidence to understand what happened before accounts, logs, or other relevant information disappear.

The response should be proportionate to the risk. Entering publicly available information into an AI system is different from uploading a confidential source-code repository or acquisition plan. If significant trade-secret information may have been exposed, the company should also evaluate what steps can reasonably limit further disclosure and preserve the legal position.

How Can a Company Document Its AI-Related Trade Secret Protections?

Trade-secret protection is easier to demonstrate when the company’s practices are documented.

Relevant records may include AI policies, information-classification standards, approved-tool lists, vendor diligence, contractual protections, employee training, access controls, security configurations, incident-response procedures, and evidence that the company actually enforces its rules.

Documentation should reflect reality. A detailed policy that nobody follows may be less persuasive than a simpler system that the company consistently implements.

This is another reason to integrate AI governance with existing trade-secret and information-security programs. The company should be able to explain not only what its policy says, but how its controls work together to protect commercially important information.

Practical Considerations

The strongest approach is usually risk-based rather than prohibition-based. Generative AI can provide substantial business value, and an absolute ban may be unrealistic for organizations whose employees can access AI tools from personal devices and accounts.

Companies can instead identify the information that matters most, establish which AI tools are appropriate for different categories of information, educate employees, use proportionate technical controls, and create a practical process for exceptions and incident response.

The trade-secret question should remain connected to business value. Companies do not need to protect every internal fact with the same intensity. They should devote stronger measures to information whose secrecy creates meaningful competitive value and whose loss could materially harm the business.

Key Takeaways

  • Generative AI creates a new channel for an old trade-secret problem. Companies still need reasonable measures to protect secrecy, but those measures should now account for how employees use AI tools.

  • AI use does not require an all-or-nothing policy. Companies can distinguish among information types, approved tools, and use cases rather than attempting to prohibit all employee AI activity.

  • Tool selection and configuration matter. Contract terms, training practices, retention, access controls, and data-use commitments can materially affect the risk associated with a particular AI system.

  • Policies need operational support. Training, information classification, approved platforms, technical controls, vendor review, and incident response should work together.

  • The objective is to preserve business value, not create AI bureaucracy. The strongest program enables productive AI use while applying greater protection to information whose secrecy genuinely matters.

Conclusion

Generative AI does not change the basic reason companies protect trade secrets. Valuable confidential information can provide competitive advantage only while the business maintains appropriate control over it.

What AI changes is the number and ease of potential disclosure paths. Employees can now move substantial amounts of information into external systems in seconds while performing ordinary work.

Companies that ignore that reality may create a growing gap between their traditional confidentiality controls and their actual operations.

The better approach is deliberate governance: identify the information worth protecting, provide appropriate AI tools, establish understandable rules, support them with proportionate controls, and respond intelligently when mistakes occur.

That allows companies to capture the benefits of AI without losing sight of the intellectual property and confidential information that help make the business valuable.

Additional Resources:

Related Industry : Technology, Software & AI

Related Practice Area : Technology Law & Trade Secrets

Related Service : Trade Secret Protection, Trade Secret Audits & Technology Counseling

Klemchuk is a litigation-led, full-service intellectual property firm built for sophisticated clients who value business judgment and senior-level relationships.

This article is provided for informational purposes only and does not constitute legal advice. The appropriate legal strategies depend on the facts and applicable law. The law evolves and this article likely will not be edited to reflect any changes in the law. The laws between jurisdictions also conflict. This article may contain mistakes. For all these reasons, you should hire a competent attorney to provide legal advice and you should not rely upon this article for any reason.

© 2026 Klemchuk PLLC | Explore Our Services