top of page

When Employees Use AI: Protecting Corporate Secrets Through AI Governance

  • Writer: Contact ILS
    Contact ILS
  • 6 days ago
  • 6 min read

Employees increasingly use generative AI to draft code, summarize meetings, analyze customer information, and improve internal workflows. In the process, they may expose proprietary methods, pricing strategies, product plans, and other sensitive corporate information to AI systems.


This is more than a cybersecurity issue. Under U.S. trade secret law, companies must take reasonable measures to protect confidential information. Without clear AI policies, access controls, and employee training, companies may weaken future trade secret claims and face greater difficulty proving whether AI-generated work was independently developed or influenced by protected corporate knowledge.


If you or your company would like to assess the trade secret, data security with employee AI use, or strengthen your corporate AI governance policies and AI vendor agreements, please contact the ILS legal team at contact@consultils.com. We assist companies in developing practical, enforceable AI governance and corporate secret protection strategies tailored to their operations and technology use.



AI Is Changing the Evidence in Trade Secret Disputes

Traditional trade secret cases often involve identifiable conduct: downloading documents, copying source code, forwarding confidential emails, or taking customer lists. Companies can investigate those events through device records, access logs, and email history.


AI changes that evidentiary framework. An employee may never download a complete document. Instead, the employee may gradually provide an AI tool with technical approaches, internal processes, product-development strategies, or pricing methods through a series of prompts. That information may later appear in:

  • Prompt histories;

  • AI-generated summaries;

  • Coding assistants;

  • Automated workflows;

  • Internal AI models;

  • AI agents connected to company systems.


This type of information transfer is more fragmented and less visible than traditional file theft. A company may struggle to establish:

  • What information was entered into an AI system;

  • Whether the provider retained or used that information;

  • How the information influenced later outputs;

  • Whether protected content persists in another tool or workflow.


The legal risk therefore extends beyond whether a corporate secret was disclosed. It also concerns whether the company can later prove the disclosure, trace the information, and demonstrate unauthorized use.



Weak Corporate AI Governance May Undermine Trade Secret Protection

Information does not automatically qualify for trade secret protection simply because a company labels it “confidential.” The company must also take reasonable measures to protect it.


Traditional safeguards may include confidentiality agreements, access restrictions, device controls, document labeling, and employee offboarding procedures. Those measures remain important, but they may no longer be sufficient when employees regularly use AI.


Without a formal corporate AI governance framework, a company may have no clear rules addressing:

  • Which AI tools employees may use;

  • Whether personal AI accounts are permitted;

  • What information may not be entered into AI systems;

  • Which use cases require prior approval;

  • How AI-generated content must be reviewed;

  • How accidental disclosures must be reported;

  • What records of AI use must be retained.


This creates two significant legal problems:

  • The company may be unable to detect or contain confidential information once it enters an external AI system.

  • In litigation, the company may have difficulty proving that it consistently treated the information as secret and implemented reasonable safeguards appropriate to the technology being used.


For this reason, corporate AI governance is not simply an internal technology policy. It may become part of the evidentiary foundation supporting a company’s trade secret claims.



Employee Mobility Creates a New Form of Trade Secret Risk

Employee onboarding and off-boarding have always been critical points of trade secret exposure.


Historically, companies focused on whether an incoming employee brought documents from a former employer or whether a departing employee downloaded company files. AI introduces more complicated questions:

  • Did a new employee use AI to recreate a former employer’s technical or operational process?

  • Was AI-generated code influenced by confidential knowledge from a prior workplace?

  • Were a former employer’s materials entered into the new company’s AI system?

  • Can the new employer prove that its work was independently developed?

  • Did a departing employee retain company information through a personal AI account or AI agent?


AI outputs are often probabilistic and may summarize or reorganize source information rather than reproduce it verbatim. As a result, improper use may be more difficult to identify and prove.


This risk has been described as a form of “invisible contamination.” No obvious file transfer occurs, but protected knowledge may still influence a new system, workflow, or work product.



AI Vendor Agreements Affect How Risk Is Allocated

Using an enterprise AI product does not eliminate legal risk. Companies should carefully review whether their AI vendor agreements address:

  • Whether prompts and outputs may be used to train models;

  • Data retention periods;

  • Data deletion procedures;

  • Storage and processing locations;

  • Access by the vendor, subcontractors, or other third parties;

  • Security-incident notification obligations;

  • Ownership of AI-generated outputs;

  • Indemnification and responsibility for intellectual property disputes;

  • Audit, export, and deletion rights;

  • Restrictions on reuse of customer data.


A general data protection agreement may not adequately address model training, prompt retention, AI agents, generated content, or the reuse of company knowledge.


Companies that use AI to process source code, customer information, product plans, or other corporate secrets should consider negotiating a dedicated AI addendum containing specific confidentiality, use, retention, and deletion obligations.



Cross-Border AI Use May Trigger Additional Legal Requirements

For multinational companies, AI use may implicate more than trade secret law.

Depending on the data, technology, and jurisdictions involved, companies may also need to consider:

  • Data privacy laws;

  • Cybersecurity requirements;

  • Cross-border data-transfer restrictions;

  • Export controls;

  • Intellectual property ownership;

  • Industry-specific regulations.


AI providers often rely on distributed infrastructure, making it difficult for companies to determine where information is processed, stored, or accessed.


For businesses in semiconductors, biotechnology, defense, advanced manufacturing, and other sensitive industries, entering technical information into an AI system may also raise concerns under the International Traffic in Arms Regulations, the Export Administration Regulations, or other U.S. export-control regimes.  


Before deploying an AI tool across multiple jurisdictions, companies should evaluate data flows, vendor locations, system access, and whether the relevant technology is subject to transfer restrictions.



Building an Effective Corporate AI Governance Framework

Companies do not need to prohibit AI, but they should establish clear rules governing how employees use it and what information may be shared:

  • Confidentiality policies should expressly address AI tools, including approved platforms, prohibited data, personal accounts, coding assistants, browser extensions, and employee-created workflows. Employees should receive practical training on what may not be entered into AI systems, particularly source code, product plans, pricing strategies, customer data, legal communications, and export-controlled information.

  • Onboarding and offboarding procedures should also be updated. Incoming employees should not use AI to reproduce a former employer’s confidential information, while departing employees should disclose any personal AI accounts, saved prompts, automated workflows, or AI agents used for company work.

  • Companies should also preserve records supporting independent development, such as project histories, source-code records, data sources, AI approvals, and human-review documentation. These materials may become critical in future trade secret disputes.

  • AI vendor agreements should address model training, data retention, confidentiality, intellectual property ownership, access rights, incident response, and deletion obligations. Effective corporate AI governance requires alignment between internal policies and vendor contracts.



Conclusion

AI is changing how corporate secrets are created, transferred, and potentially misused. Future trade secret disputes may begin not with a stolen file, but with a prompt, coding assistant, or automated workflow containing confidential business knowledge.


Protecting corporate secrets now requires more than traditional confidentiality agreements. Companies need a practical corporate AI governance framework covering employee use, vendor contracts, employee mobility, and evidence preservation.


If you or your company would like to assess the trade secret, data security with employee AI use, or strengthen your corporate AI governance policies and AI vendor agreements, please contact the ILS legal team at contact@consultils.com. We assist companies in developing practical, enforceable AI governance and corporate secret protection strategies tailored to their operations and technology use.


Disclaimer: The materials provided on this website are for general informational purposes only and do not, and are not intended to, constitute legal advice. You should not act or refrain from acting based on any information provided here. Please consult with your own legal counsel regarding your specific situation and legal questions.

As Managing Partner at ILS, Richard Liu ranks among the leading U.S. attorneys in corporate, employment, and regulatory law. He is known for crafting legal strategies aligned with clients’ business objectives and advising Fortune 500 companies, startups, and executives on corporate transactions, financing, privacy, and employment matters across the technology, healthcare, and financial sectors.


Before founding ILS, Richard practiced at top defense firms, where he developed a reputation for anticipating risks and designing strategies that balance protection with growth. He has secured favorable outcomes in contract and intellectual property disputes, represented clients in state and federal courts, and is recognized for combining large-firm expertise with boutique-firm agility. Richard is also a frequent speaker at industry and legal conferences.


Email: contact@consultils.com | Phone: 626-344-8949


Comments


bottom of page