The New York Times Features Sarah Tishler’s Analysis of Legal Gray Areas of AI Distillation

New York Times

Sarah Tishler was quoted in a New York Times article about concerns that American AI companies are being targeted by Chinese copycats.

The story is titled “American A.I. Companies Say Chinese Copycats Are Quickly Catching Up.” The June 6, 2026, article was written by Cade Metz, who writes about technology for The New York Times.

he article details allegations by leading American artificial intelligence companies, such as Anthropic, that Chinese rivals are illegally using a technique called “distillation” to harvest proprietary U.S. data and rapidly narrow the technological gap between the two nations. It also explores the technical and legal complexities of curbing this practice.

In the article, Sarah is quoted as follows:

Is that illegal?

That’s not clear, said Sarah Tishler, a partner at the law firm Beck Reed Riden who specializes in trade-secret litigation.

Some legal scholars argue that the practice violates the Defend Trade Secrets Act, a 2016 law that allows businesses to sue over the theft of trade secrets, but courts have not explicitly decided that.

Copyright law does not necessarily apply because distillation is an effort to copy the behavior of the system, as opposed to copying text verbatim.

***

Even if U.S. law did bar illicit distillation, Ms. Tishler said, it would most likely have little effect on behavior in China.

“So much of this conduct is happening outside the United States,” she noted. “It would be very challenging to address it through a U.S. court.”


Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising. She frequently writes and lectures about the intersection of AI and trade secrets law.


Beck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Russell Beck’s work in this area is well recognized, and includes:

  • Over thirty years of experience working on trade secret, noncompete, and unfair competition matters
  • Assisting the Obama White House as part of a small working group to develop President Obama’s Noncompete Call to Action
  • Authoring the book Negotiating, Drafting, and Enforcing Noncompetition Agreements and Related Restrictive Covenants (6th ed., MCLE, Inc. 2021), used by other lawyers to help them with their noncompete matters
  • Authoring the book Trade Secrets Law for the Massachusetts Practitioner (1st ed. MCLE 2019), covering trade secrets nationally, with a focus on Massachusetts law
  • Drafting and advising on legislation for the Massachusetts Legislature to define, codify, and improve noncompetition law
  • Teaching Trade Secrets and Restrictive Covenants at Boston University School of Law
  • Founding and administering the award-winning blog, Fair Competition Law
  • Establishing and administering the Noncompete Lawyers and Trade Secret Protection groups on LinkedIn, with over 1,660 and 870 members, respectively, around the world
  • Founded and chaired the Trade Secret / Noncompete Practice for an AmLaw 100 firm

In addition, Russell was honored for his work in this area of law in the 2020 Chambers USA Guide, which stated that Russell Beck is “an expert in the field of trade secret and restrictive covenant law,” and is also noted for his “ability to adjust and come up with successful solutions.” Chambers noted that Russell “basically wrote the new Massachusetts statute on noncompetes” and that “he’s an expert in employee mobility and nonrestrictive covenants.”

Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

File first, pay later: xAI’s dismissal, Apple’s new complaint, and the potential cost of getting it wrong

Two trade secret complaints against OpenAI, both filed in the Northern District of California, now sit on opposite sides of the line that separates a viable DTSA claim from one that gets dismissed. xAI’s lawsuit against OpenAI was thrown out on June 15, 2026, following Judge Rita Lin’s order granting OpenAI’s motion to dismiss without leave to amend. Apple’s lawsuit against OpenAI, filed July 10, reads as though its drafters had Judge Lin’s order open on the desk beside them. And on July 13, OpenAI filed a motion for more than a million dollars in attorney’s fees against xAI, on the theory that xAI’s dismissed trade secret claim never should have been filed.

Read in sequence, the three filings are a lesson in what the DTSA requires a plaintiff to plead in a talent-raiding case, and what it costs to guess wrong.

xAI’s pleading failures

xAI’s theory narrowed, by the end, to a single event: former engineer Xuechen Li allegedly disclosed xAI’s reinforcement learning and post-training techniques for Grok 4 during an OpenAI recruiting presentation. Judge Lin found the theory deficient twice over.

First, on knowledge. OpenAI’s continued interest in Li could show inducement only if OpenAI knew or had reason to know he had disclosed trade secrets. xAI built that knowledge allegation on an inferential chain: that Li displayed or read aloud a slide marked “confidential”; that OpenAI’s engineers understood “confidential” to mean xAI confidential rather than Li’s own nondisclosure obligation to OpenAI about the recruitment process; and that they further understood the marked material to be a trade secret rather than merely sensitive. Each link had an innocent explanation. Under In re Century Aluminum Co. Securities Litigation, 729 F.3d 1104, 1108 (9th Cir. 2013), a plaintiff facing an equally plausible innocent explanation must plead facts tending to exclude it. xAI pleaded none.

Second, and with the longer reach, on the nature of the conduct. Even assuming disclosure, xAI alleged only that OpenAI received what Li presented. Under the DTSA, misappropriation requires acquisition, disclosure, or use; passive receipt is at most acquisition, and the court held that acquisition requires active conduct to be actionable. The reasoning tracks Silvaco Data Systems v. Intel Corp., 184 Cal. App. 4th 210, 223 (2010): one does not “acquire” something inadvertently, and treating passive receipt as acquisition edges toward liability for mere possession, which is not misappropriation. See also Bus. Sols. LLC v. Ganatra, No. SACV181426DOCKESX, 2020 WL 1279209, at *6 (C.D. Cal. Jan. 22, 2020) (“a person acquires a trade secret when they actively seek to gain ownership or control of the trade secret, but not when they are merely a passive recipient.”). A candidate who volunteers a former employer’s secrets creates exposure for himself; he does not, without more, create acquisition liability for the new employer.

How Apple overcame those obstacles

Apple’s complaint is captioned Apple Inc. v. Chang Liu, Tang Yew Tan, OpenAI Foundation, OpenAI Group PBC, and io Products, LLC, No. 5:26-cv-07078, assigned to Magistrate Judge Virginia K. DeMarchi. It pleads four separate DTSA claims—one each against Liu, Tan, OpenAI, and io—plus two breach-of-contract claims against the individuals under Apple’s Intellectual Property Agreement (there is no claim under the California Uniform Trade Secrets Act, keeping the trade secret theory entirely federal).

Where xAI alleged passive receipt, Apple alleges active acquisition. Liu, a former Apple electrical engineer, allegedly failed to return an Apple laptop authenticated to the company network, exploited an authentication bug to reach Apple’s shared network folders after his departure, and downloaded dozens of confidential files while working for OpenAI—celebrating the access to a still-employed colleague (“LOL, I found out I can access the [network storage], so funny”) and coaching her to copy files so as to “avoid trouble with the security team.” That is acquisition by unauthorized access, not inadvertent receipt.

Where xAI could not plead that OpenAI knew what it was getting, Apple pleads documented knowledge. Its scienter centerpiece is an internal Apple managers’ document marked “Need to Know,” describing the company’s security procedures for departing employees, which Chief Hardware Officer Tang Tan and his OpenAI colleagues allegedly circulated to recruits before they gave notice, previewing Apple’s forensic checks. The complaint uses that document to close the knowledge gap directly: Tan’s “possession and distribution of Apple’s internal departure procedures—which expressly reference Apple’s IPA obligations—foreclose any defense of ignorance” (¶ 107), with a parallel allegation against OpenAI (¶ 120).

And where xAI alleged only a routine interview presentation, Apple alleges an interview process that was designed to extract trade secrets. Tan allegedly used Apple’s internal project codenames to ask candidates “What’s the plan[?]” for unreleased products, and directed them to bring “Actual parts”—batteries, systems-in-package, logic boards—along with “CAD/design artifacts” and “prototypes” for “show and tell” (¶¶ 69–70, 75). One candidate reportedly noted he “didn’t even know we could take those from the office.” This is the “something more” that Century Aluminum demands: an alleged solicitation of identified, physical confidential material. Apple also pleads active use through a supplier—OpenAI, on its own or through io, allegedly had a trusted Apple partner perform Apple’s proprietary metal-finishing technique, “misleading the partner to believe they had Apple’s permission to do so” (¶¶ 12, 80–81)—and an alter-ego theory attributing io’s conduct to OpenAI (¶¶29–32).

None of this means Apple wins. Its allegations are still just that – allegations – and  OpenAI’s strongest response sits in Apple’s own litigation history: Hooked Media Group, Inc. v. Apple Inc., 55 Cal. App. 5th 323 (2020), where Apple prevailed as the defendant on the principle that hiring an employee who retains a competitor’s knowledge is not, without an independent wrongful act, misappropriation. See id. at 331 (“Allowing an action for trade secret misappropriation against a former employee for using his or her own knowledge to benefit a new employer is impermissible because it would be equivalent to retroactively imposing on the employee a covenant not to compete.”) (emphasis in original). But Apple’s complaint contains a catalogue of the affirmative conduct—unauthorized access, documented knowledge, directed exfiltration, downstream use—whose absence defined the failure of xAI’s lawsuit.

OpenAI’s motion for attorney’s fees

On July 13, OpenAI moved for $1,041,859.90 in attorney’s fees against xAI under the DTSA’s fee-shifting provision, 18 U.S.C. § 1836(b)(3)(D), and CUTSA’s parallel provision, Cal. Civ. Code § 3426.4. The standard is the two-prong California test for a bad-faith trade secret claim: objective speciousness and subjective bad faith.

On objective speciousness, the motion quotes Judge Lin’s holding back at xAI—that its allegations “at most amounted to ‘passive receipt of trade secrets,’ which is ‘not enough.’” What was a ruling in June has now become the predicate for OpenAI’s requested fee award. On subjective bad faith, the motion leans on the pre-suit timing of OpenAI’s interactions with xAI. OpenAI says it wrote to xAI before suit, explained the absence of evidence, and asked for any factual basis; rather than engaging, xAI sued instead. OpenAI also notes that xAI’s CEO Elon Musk tweeted about the lawsuit before it had been served or a copy provided to OpenAI’s counsel, “illustrating that the public message was more important than the actual litigation.” After the first dismissal, xAI moved for a six-month stay to hunt for the evidence it lacked; a request that was denied, with the court noting that “a plaintiff must investigate the facts underlying their allegations before filing suit, not after.” xAI then filed a Second Amended Complaint reasserting the rejected theory, which was dismissed a second time.

OpenAI represents that its request for $1,041,859.90 is a deliberately conservative slice of its actual spend, excluding several timekeepers and its entire pre-litigation investigation, which includes partner rates up to $1,573 an hour. Whatever the court awards, the motion demonstrates how a failed misappropriation claim can transform into a price tag.

Important takeaways for talent competition

These new developments arrive at a time when several factors are converging to incentivize filing a trade secret lawsuit. Federal trade secret filings hit an all-time high in 2025—1,552 new cases, up roughly 20% over 2024 and the most since the DTSA took effect in 2016, according to Lex Machina’s 2026 Trade Secret Litigation Report. California is the center of gravity: the Central District of California was the single most active trade secret federal district in 2025, with 100 new filings, and AI-related trade secret cases have climbed sharply as the talent wars intensify.

Part of the pressure is due to California’s other legal frameworks. Most importantly, California voids employee noncompetes under Business and Professions Code § 16600, a ban the Legislature strengthened effective January 1, 2024 through SB 699 and AB 1076—adding a private right of action, reaching agreements signed out of state, and requiring employers to notify employees that their noncompete clauses are void. When a company cannot stop an engineer from walking across the street to a competitor, trade secret law is one of the few levers left. It is widely assumed that the noncompete ban therefore drives California’s trade secret docket, though the empirical support is thinner than the assumption suggests; the one study to test it directly found the apparent correlation fades once state population is taken into account (Giri, Dang & McKiernan, ABA Landslide, 2024). However, as an anecdotal observation, it does appear that employers who have lost the noncompete feel a gravitational pull toward the courthouse, when they feel their business interests are threatened. And this gravitational pull is strongest when the battle for top talent in the AI and tech industries is more ferocious than ever.

Nonetheless, the absence of other remedies is not an invitation to file first and investigate later, as Judge Lin made abundantly clear in her order dismissing the xAI lawsuit. The same conditions that make trade secret litigation a powerful tool in California—constant lateral movement, high-value technical knowledge, and no noncompetes—also make it tempting to move quickly to litigation. xAI and Apple both sued OpenAI on very similar talent-raiding theories. xAI pleaded receipt and hoped discovery would supply the rest; it ended up with a dismissal and a seven-figure fee demand. Apple, by contrast, pleaded the specific alleged conduct. The DTSA rewards the difference, and through its fee-shifting provision, it charges for the failure to observe it.


Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

Sarah Tishler to Speak at AIPLA’s 2026 Spring Meeting

On May 14, 2026, Sarah Tishler will be speaking at this year’s American Intellectual Property Law Association’s Spring Meeting. The AIPLA’s Spring Meeting is taking place in San Francisco.

Sarah will be joining a panel of experts on a panel titled “The Impact of AI on Trade Secrets: What Every Lawyer and Client Needs to Know” to discuss the rapidly evolving intersection of artificial intelligence and intellectual property law.

As generative AI becomes a mainstay in corporate operations, the legal frameworks protecting proprietary information face new and complex challenges. Sarah’s panel will explore the critical risks AI poses to trade secret protection and offer practical strategies that every lawyer and client should implement to safeguard their most valuable assets.

The AIPLA Spring Meeting is a premier destination for IP professionals, featuring insights from top-tier private practitioners, in-house counsel, and government officials.

For the full program schedule or to register for the event, please visit the official AIPLA website: AIPLA 2026 Spring Meeting Information

The AIPLA is a bar association of lawyers in private and corporate practice, government service, and the academic community. AIPLA represents individuals, companies and institutions involved in the practice of patent, trademark, copyright, and unfair competition law, as well as other fields of law affecting intellectual property.


Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.


For up-to-the-minute analysis of legal issues concerning noncompete agreements in Massachusetts and across the United States, read Russell Beck’s blog, Fair Competition Law.


Beck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Russell Beck’s work in this area is well recognized, and includes:

  • Over thirty years of experience working on trade secret, noncompete, and unfair competition matters
  • Assisting the Obama White House as part of a small working group to develop President Obama’s Noncompete Call to Action
  • Authoring the book Negotiating, Drafting, and Enforcing Noncompetition Agreements and Related Restrictive Covenants (6th ed., MCLE, Inc. 2021), used by other lawyers to help them with their noncompete matters
  • Authoring the book Trade Secrets Law for the Massachusetts Practitioner (1st ed. MCLE 2019), covering trade secrets nationally, with a focus on Massachusetts law
  • Drafting and advising on legislation for the Massachusetts Legislature to define, codify, and improve noncompetition law
  • Teaching Trade Secrets and Restrictive Covenants at Boston University School of Law
  • Founding and administering the award-winning blog, Fair Competition Law
  • Establishing and administering the Noncompete Lawyers and Trade Secret Protection groups on LinkedIn, with over 1,660 and 870 members, respectively, around the world
  • Founded and chaired the Trade Secret / Noncompete Practice for an AmLaw 100 firm

In addition, Russell was honored for his work in this area of law in the 2020 Chambers USA Guide, which stated that Russell Beck is “an expert in the field of trade secret and restrictive covenant law,” and is also noted for his “ability to adjust and come up with successful solutions.” Chambers noted that Russell “basically wrote the new Massachusetts statute on noncompetes” and that “he’s an expert in employee mobility and nonrestrictive covenants.”

Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

Understanding AI Distillation In The Trade Secret Context

For most of the past year, when AI companies have talked about distillation, they have talked about it as a Chinese problem. In February 2026, OpenAI told the House Select Committee on China that DeepSeek employees had developed methods to circumvent OpenAI’s access restrictions and programmatically harvest outputs to train a competing model. Anthropic’s public technical disclosure went further, naming DeepSeek, Moonshot AI, and MiniMax, and quantifying the activity: roughly 24,000 fraudulent accounts, more than 16 million exchanges, focused on extracting Claude’s reasoning, coding, and agentic capabilities.

By April, the White House Office of Science and Technology Policy had adopted a national-security framing, accusing China of running “deliberate, industrial-scale campaigns” to distill American frontier models. Throughout this timeline, the narrative was that of foreign actors using proxy infrastructure to extract capabilities the United States had spent billions to build.

Recently, however, that narrative got more complicated. On the stand in Musk v. Altman in the Northern District of California, Elon Musk admitted under cross-examination that his AI company, xAI, had “partly” distilled OpenAI’s models. “It is standard practice,” Musk said, “to use other AIs to validate your AI.” There were, by the reporters’ account, audible gasps in the courtroom.

Whether or not it is in fact standard practice, distillation is now a topic that trade secret practitioners should understand. The legal frameworks for how courts will treat it are not yet settled, and the questions it raises map onto familiar trade secret doctrine in ways that are sometimes intuitive and sometimes not.

What Is Distillation?

In the technical literature, knowledge distillation is a method developed in the mid-2010s for transferring capabilities from a large, expensive model (the “teacher”) into a smaller, cheaper model (the “student”). The student is trained to reproduce the teacher’s outputs across a broad range of inputs, with the result being a model that approximates the teacher’s behavior at a fraction of the size and cost. As Anthropic’s own disclosure acknowledges, distillation is “widely used and legitimate,” and frontier labs routinely distill their own models to create smaller, cheaper versions for production deployment.

The contested form of distillation, sometimes called adversarial or unauthorized distillation, takes the same technique and applies it to someone else’s model. The distiller does not need to steal weights or breach servers. Access to the teacher model’s API is sufficient. The distiller submits a large volume of carefully constructed queries, captures the outputs, and uses those outputs as training data for a competing student model. The technique converts what would otherwise be a public-facing inference service into a training corpus for a rival system.

The finances of this technique are compelling, to say the least. To take one example, ChatGPT-5 reportedly cost more than $2 billion to develop. DeepSeek’s R1, which OpenAI alleges was built in part through distillation of ChatGPT outputs, reportedly cost approximately $6 million of marginal training compute. 

The Trade Secret Theory

The question for trade secret lawyers is whether what gets extracted through distillation can be a trade secret, and whether the extraction can constitute misappropriation.

First, it is always worth starting from first principles. A trade secret must be information that derives independent economic value from not being generally known or readily ascertainable, and that the owner has taken reasonable measures to keep secret. 18 U.S.C. § 1839(3). Frontier model weights and the proprietary training methodologies that produced them comfortably satisfy these criteria, just as compiled software and machine-learning architectures have for years. See, e.g., Camilla A. Hrdy, Trade Secrecy Meets Generative AI, 100 Chi.-Kent L. Rev. 317 (2025). The harder question is whether the outputs of a model, accessed through a public API, can carry trade secret status. And if they can, whether systematically harvesting them to reconstruct the underlying capabilities is misappropriation, or merely a novel form of reverse engineering.

Of course, that distinction matters. Reverse engineering of a publicly available product is a textbook proper means of acquisition under both the DTSA and the UTSA. See 18 U.S.C. § 1839(6)(B). If a frontier model is made available to the public through an API, and a competitor pays the access fees and queries it to learn how it behaves, the surface analogy to traditional reverse engineering is obvious: buy the product, study how it works, and build a competitor.

On the other hand, traditional reverse engineering targets a finished good, the embodied capability. Distillation targets the model’s underlying reasoning processes, learned representations, and capability distributions. As one recent analysis framed it, the trade secret on this theory is “the aggregate of learned representations that required billions of dollars in compute, proprietary training data, and years of research to develop, and that the owner has chosen to make available only through controlled inference access rather than” by distributing the model itself. That looks less like buying a product to take apart and more like extracting something the owner specifically chose not to release.

The terms-of-service overlay further complicates the analysis. OpenAI’s terms expressly prohibit using outputs to develop “imitation frontier AI models.” Anthropic’s terms contain similar restrictions. A user who agrees to those terms and then engages in mass output extraction is not an arms-length reverse engineer, but a contracting party using a service contrary to its agreed restrictions. Whether this transforms the conduct from “proper means” reverse engineering into misappropriation by improper means is, to my knowledge, an open question. 

hile there is no published decision directly on point, prior cases provide useful guidance. For example, in Compulife Software, Inc. v. Newman, 959 F.3d 1288 (11th Cir. 2020), defendants used a bot to submit automated queries to a public insurance-quote website, harvesting more than 43 million quotes in four days; a feat the court recognized would have taken a human “thousands of man-hours” to replicate. Id. at 1310. The Eleventh Circuit held that even though each individual quote was publicly available and not itself a trade secret, the compilation obtained at machine scale could be misappropriated through “improper means.” Id. at 1313–14. The Court wrote:

“Nor does the fact that the defendants took the quotes from a publicly accessible site automatically mean that the taking was authorized or otherwise proper. Although Compulife has plainly given the world implicit permission to access as many quotes as is humanly possible, a robot can collect more quotes than any human practicably could. So, while manually accessing quotes from Compulife’s database is unlikely ever to constitute improper means, using a bot to collect an otherwise infeasible amount of data may well be—in the same way that using aerial photography may be improper when a secret is exposed to view from above.” 

Id. at 1314. Applying the Compulife framework to distillation, one could easily see how a court would also find that adversarial distillation constitutes misappropriation.

Three Hypotheticals 

For practitioners advising clients on either side of these issues, three scenarios illustrate where the doctrine may soon be tested in a courtroom near you.

ypothetical One: The departing employee. A senior research engineer at a frontier lab leaves to join a competitor, taking with him knowledge of the prompt strategies and query patterns that most efficiently elicit the teacher model’s distinctive capabilities. He then directs his new employer’s distillation pipeline using that knowledge, achieving extraction efficiency the new employer could not have achieved on its own. Even if every individual query is permissible, and even if the employee discloses no model weights or training data, the prompt engineering methodology itself may be a protectable trade secret. This fits neatly into traditional employee mobility doctrine, with the wrinkle that the misappropriated information is a method of extracting third-party model capabilities rather than information about the former employer’s own operations.

Hypothetical Two: The validation defense. A company is sued by a frontier lab on the theory that it engaged in unauthorized distillation. The defendant responds: it was using the teacher model to validate its own model’s outputs, not to train on them. Validation is a real and legitimate practice in AI development. Distillation and validation can also look very similar, with both involving large volumes of structured queries and capture of outputs. The forensic question becomes: how does a plaintiff prove that captured outputs ended up in a training pipeline rather than a benchmarking dashboard? (This is a particular flavor of the black box problem that I have written about before.)

Hypothetical Three: The downstream user. A startup builds a product on top of an open-source model that, it later emerges, was itself distilled from a frontier model in violation of the frontier lab’s terms of service. The startup did not perform the distillation, did not know the upstream provenance, and is many steps removed from the original conduct. Does the DTSA’s “knew or had reason to know” standard, 18 U.S.C. § 1839(5)(B), reach the downstream user? At what point does the diligence obligation attach? The “innocent acquirer” framework was designed for a world in which trade secrets traveled through identifiable human or corporate intermediaries. It is not obvious how it applies when the trade secret allegedly travels through model weights that have been released to the public on Hugging Face.

The Bottom Line

As the AI industry continues its arms race, it seems likely that distillation is here to stay.

Companies whose AI offerings are accessible through APIs should be evaluating their terms-of-service architecture, their detection capabilities for anomalous query patterns, and their internal documentation of the resources invested in developing the underlying capabilities, because all of those will matter for any misappropriation case down the line. Companies that build on top of third-party models should be developing diligence practices around the provenance of those models, because of the DTSA’s constructive-knowledge standard. And practitioners on both sides should be watching the Musk v. Altman docket with interest. Formally, the case is about a charitable trust dispute. But the testimony it has produced may turn out to be the most candid public record we are going to get, for some time, of how distillation (and other AI-specific issues) actually works between sophisticated AI developers.

We will continue to monitor the docket and report on developments as the case progresses, and as the broader question of how trade secret law applies to model outputs begins to work its way through the courts.

 


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

Russell Beck and Sarah Tishler to Speak at AIPLA’s Trade Secret Summit

On April 23 and 24, 2026, Russell Beck and Sarah Tishler will be speaking at this year’s American Intellectual Property Law Association’s Trade Secret Summit. The AIPLA’s Trade Secret Summit is taking place in Fort Worth, Texas.

On April 23, Russell Beck gave a presentation titled “Government Enforcement and Legislation of Noncompetes: Enforcement actions by NLRB and FTC, State Attorney General Enforcement and New State Laws.”

On April 24, Sarah Tishler will give a presentation titled “AI and Trade Secrets.”

The AIPLA Trade Secret Summit is the leading trade secret conference in the nation, with speakers from across the spectrum of private practitioners, in-house counsel, government, and academia. More information and registration is available here.

The AIPLA is a bar association of lawyers in private and corporate practice, government service, and the academic community. AIPLA represents individuals, companies and institutions involved in the practice of patent, trademark, copyright, and unfair competition law, as well as other fields of law affecting intellectual property.


For up-to-the-minute analysis of legal issues concerning noncompete agreements in Massachusetts and across the United States, read Russell Beck’s blog, Fair Competition Law.


Beck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Russell Beck’s work in this area is well recognized, and includes:

  • Over thirty years of experience working on trade secret, noncompete, and unfair competition matters
  • Assisting the Obama White House as part of a small working group to develop President Obama’s Noncompete Call to Action
  • Authoring the book Negotiating, Drafting, and Enforcing Noncompetition Agreements and Related Restrictive Covenants (6th ed., MCLE, Inc. 2021), used by other lawyers to help them with their noncompete matters
  • Authoring the book Trade Secrets Law for the Massachusetts Practitioner (1st ed. MCLE 2019), covering trade secrets nationally, with a focus on Massachusetts law
  • Drafting and advising on legislation for the Massachusetts Legislature to define, codify, and improve noncompetition law
  • Teaching Trade Secrets and Restrictive Covenants at Boston University School of Law
  • Founding and administering the award-winning blog, Fair Competition Law
  • Establishing and administering the Noncompete Lawyers and Trade Secret Protection groups on LinkedIn, with over 1,660 and 870 members, respectively, around the world
  • Founded and chaired the Trade Secret / Noncompete Practice for an AmLaw 100 firm

In addition, Russell was honored for his work in this area of law in the 2020 Chambers USA Guide, which stated that Russell Beck is “an expert in the field of trade secret and restrictive covenant law,” and is also noted for his “ability to adjust and come up with successful solutions.” Chambers noted that Russell “basically wrote the new Massachusetts statute on noncompetes” and that “he’s an expert in employee mobility and nonrestrictive covenants.”

Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

Russell Beck and Sarah Tishler to Speak at PLI Noncompete Agreement Program

On Tuesday, April 21, 2026, Russell Beck and Sarah Tishler will be speaking at Practising Law Institute’s program on noncompete agreements. Russell is the Chairperson of the event.

The program, which will be held in New York City and is also available online, is titled “Fundamentals of Noncompetes 2026.”

The program starts at 1:30 p.m. ET on April 21, 2026. More information and registration is available here.

Speakers will provide a “broad-based, foundational introduction to the core concepts of restrictive covenant law, including the different types of restrictive covenants that are generally enforceable but sometimes not enforceable, the interests they can protect, the rules for their use, and basic drafting and litigating techniques.”

In addition, according to the course description, attendees will learn how to:

  • Identify the key issues concerning restrictive covenant law and the various kinds of restrictive covenant agreements
  • Understand the basics of trade secrets, goodwill, and other protectable business interests
  • Evaluate and update agreements to protect your company’s business interests from departing employees
  • Manage through the common issues in litigation concerning noncompetes and other restrictive covenants

The presentation is for any “lawyer or human resources personnel that will be assisting companies or individuals in drafting, evaluating, enforcing, and defending against noncompetes and other restrictive covenants, anyone involved in the hiring of employees, and anyone else responsible for an organization’s internal hiring policies.”

ussell will be giving the opening remarks for the program. Sarah will be speaking on a panel titled “The Essentials of Drafting Noncompete Agreements and Related Restrictive Covenants in 2026.” This panel will discuss the basic components and strategies of litigating matters concerning restrictive covenants. The panelists will provide valuable information to help attendees:


For up-to-the-minute analysis of legal issues concerning noncompete agreements in Massachusetts and across the United States, read Russell Beck’s blog, Fair Competition Law.

Beck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Russell Beck’s work in this area is well recognized, and includes:

  • Over thirty years of experience working on trade secret, noncompete, and unfair competition matters
  • Assisting the Obama White House as part of a small working group to develop President Obama’s Noncompete Call to Action
  • Authoring the book Negotiating, Drafting, and Enforcing Noncompetition Agreements and Related Restrictive Covenants (6th ed., MCLE, Inc. 2021), used by other lawyers to help them with their noncompete matters
  • Authoring the book Trade Secrets Law for the Massachusetts Practitioner (1st ed. MCLE 2019), covering trade secrets nationally, with a focus on Massachusetts law
  • Drafting and advising on legislation for the Massachusetts Legislature to define, codify, and improve noncompetition law
  • Teaching Trade Secrets and Restrictive Covenants at Boston University School of Law
  • Founding and administering the award-winning blog, Fair Competition Law
  • Establishing and administering the Noncompete Lawyers and Trade Secret Protection groups on LinkedIn, with over 1,660 and 870 members, respectively, around the world
  • Founded and chaired the Trade Secret / Noncompete Practice for an AmLaw 100 firm

In addition, Russell was honored for his work in this area of law in the 2020 Chambers USA Guide, which stated that Russell Beck is “an expert in the field of trade secret and restrictive covenant law,” and is also noted for his “ability to adjust and come up with successful solutions.” Chambers noted that Russell “basically wrote the new Massachusetts statute on noncompetes” and that “he’s an expert in employee mobility and nonrestrictive covenants.”

Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

Verbatim Recall in LLMs: A New Study Raises Important Questions For Trade Secret Protection

For years, AI companies have told courts, regulators, and the public the same thing: their models don’t store copies of training data. OpenAI put it plainly to the U.S. Copyright Office in 2023: “the models do not store copies of the information that they learn from.” Google said much the same, as did numerous commentators. This prevailing wisdom has been the basis of numerous significant legal decisions in the copyright space. See, e.g., Tremblay v. OpenAI, Inc., 716 F. Supp. 3d 772, 778 (N.D. Cal. 2024) (dismissing vicarious copyright infringement claim, holding, “Distinctly, Plaintiffs here have not alleged that the ChatGPT outputs contain direct copies of the copyrighted books.”).

A new preprint from researchers at Stony Brook University, Carnegie Mellon, and Columbia Law School suggests those assurances were wrong, and that in fact, LLMs can reproduce verbatim content from books that it had previously ingested, leading to the conclusion that copies of the information have actually been stored. 

The Experiment

The researchers designed a finetuning task with a deceptively simple setup: take a copyrighted book, break it into 300-500 word excerpts, generate a plot summary of each excerpt, and train a model to expand those summaries back into full text. The task looks completely legitimate, and is the sort of thing a commercial writing assistant might do. No actual book text appears at inference time. The model receives only a semantic description of what happens in a passage, and is asked to write it out.

The output was verbatim reproduction of the source text.

Across 81 copyrighted works by 47 contemporary authors, ranging from The Handmaid’s Tale to Sapiens to Twilight, finetuned versions of GPT-4o, Gemini-2.5-Pro, and DeepSeek-V3.1 reproduced up to 85-90% of a held-out book’s content, with single verbatim spans exceeding 460 words. Before finetuning, aligned models produced almost no verbatim content from the same prompts.

The most striking finding is the cross-author result. The researchers finetuned GPT-4o exclusively on Haruki Murakami’s novels, then tested it on Cormac McCarthy, Ta-Nehisi Coates, Suzanne Collins, and dozens of others. Finetuning on Murakami unlocked memorized content from authors he has nothing to do with. In some cases, the model reproduced over 80% of a completely unrelated book it had never seen during finetuning. The same result held when the researchers used Virginia Woolf’s public-domain novels as training data, but not when they used synthetic text. The conclusion is difficult to avoid: the books were already encoded in the weights from pretraining, and finetuning reactivated the retrieval pathway.

Why This Matters Beyond Copyright

The copyright implications are significant, and the paper’s legal section, co-authored by Columbia Law’s Jane Ginsburg, is worth reading carefully for practitioners in that space. But the trade secret implications deserve attention as well.

As noted above, courts evaluating fair use have looked at whether the AI models can reproduce copies of the ingested works. For example, the Bartz et al. v. Anthropic and Kadrey v. Meta decisions conditioned favorable fair use outcomes partly on the absence of evidence that models reproduce source works. See Bartz et al. v. Anthropic PBC, 787 F.Supp.3d 1007, 1018 (N.D. Cal. June 23, 2025), (“Authors do not allege that any infringing copy of their works was or would ever be provided to users by the Claude service . . . But Claude created no exact copy, nor any substantial knock-off. Nothing traceable to Authors’ works.”); Kadrey v. Meta Platforms, Inc., 788 F. Supp. 3d 1026, 1036 (N.D. Cal. 2025) (“They contend that Llama is capable of reproducing small snippets of text from their books.  . . . As explained below, both of these arguments are clear losers. Llama is not capable of generating enough text from the plaintiffs’ books to matter . . .”). This paper provides exactly that evidence, at scale and across multiple providers.

For trade secret practitioners, there are also significant implications.  For example, if an LLM ingested your client’s confidential documents, through a training pipeline, through employees using consumer AI tools, through any of the many ways proprietary information flows into these systems, this paper suggests that the information may not just be “learned from.” It may be stored in a form that can be retrieved by anyone else.

While the paper shows that aligned models don’t surface stored content under ordinary prompting, finetuning on a completely benign task, with no adversarial intent whatsoever, reactivated the LLMs’ latent memorization at an alarming scale. And the finetuning task the researchers used is commercially available and accessible through a standard API.

This creates at least two problems for trade secret owners. First, companies that rely on vendor assurances that “models don’t store data” as part of their reasonable measures argument may be resting on a factual premise this paper directly challenges. Second, what happens if a company finetunes a commercial model on its own proprietary data to build a specialized tool, and the finetuning reactivates memorized content from someone else’s confidential information that happened to be in the pretraining corpus of data? The researchers found that finetuning on one author’s work could unlock content from over thirty unrelated authors. There is no reason to believe that the same mechanism would not apply to confidential business information.

The Bottom Line

This paper raises more questions than it answers, with hugely important implications for both copyright and trade secret law. We will continue to monitor the dockets for new developments in this area as the research progresses.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.


[1] The academic literature on AI-generated trade secrets is still developing, but has advanced significantly in the past two years. For the most comprehensive recent treatments, see (for example) Camilla A. Hrdy, Trade Secrecy Meets Generative AI, 100 Chi.-Kent L. Rev. 317 (2025); John G. Sprankling, Trade Secrets in the Artificial Intelligence Era, 76 S.C. L. Rev. 181 (2024); John Villasenor, Artificial Intelligence, Trade Secrecy, and the Challenge of Transparency, 25 N.C. J.L. & Tech. 495 (2024).

[2] This is a related issue to the “black box” problem, as described in my previous piece: “if the people who build these systems cannot fully explain how they work or how specific inputs influence specific outputs, how is a plaintiff supposed to plead that a specific stolen file contributed to a specific capability in a deployed model?”

[3] To read the cautionary tale of the Samsung incident, see Mark Gurman, Samsung Bans Staff’s AI Use After Spotting ChatGPT Data Leak, Bloomberg (May 1, 2023), available at https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak.

 

Who owns an AI-generated trade secret?

Imagine a pharmaceutical company that deploys a network of AI agents to accelerate early-stage drug discovery.

The agents work autonomously, analyzing biological datasets, running simulated trials, identifying molecular structures that human researchers had not considered.

After six months, the system surfaces a novel compound with significant therapeutic potential. No human directed it to find that compound.

No human understands, step by step, why the system arrived at it. The company’s scientists can observe the output and validate its promise. But the process that generated it, and the intermediate analytical steps the agents took to get there, exist only inside the model.

Now ask a deceptively simple question: who owns that discovery as a matter of trade secret law?

The answer is not obvious, and no court has yet supplied one. Patent law cannot help, at least not directly: the human inventorship requirement means any patent claim must trace back to a person who conceived the invention. Copyright is similarly unavailable for purely AI-generated outputs. What remains, and what is quietly emerging as the most important intellectual property framework for AI-generated innovation, is trade secret law.

Trade secret law is uniquely positioned to fill the AI ownership gap. Unlike patent and copyright, neither the Defend Trade Secrets Act nor the Uniform Trade Secrets Act (nor any case law at the time of this article’s publication) contains a human-creation requirement. An algorithm, a dataset, a molecular structure, or a process that derives economic value from not being generally known qualifies for protection if the holder takes reasonable measures to keep it secret, regardless of whether a human or an AI generated it. As scholars have begun to recognize, trade secrecy has become the default IP regime for AI-generated competitive intelligence, essentially by process of elimination. [Fn. 1]

That structural advantage comes with a set of unresolved questions about how ownership vests, the risks that attend using commercially available AI platforms to generate proprietary information, and the steps companies can take today to protect some of their most valuable IP. This post examines each of those questions in turn.

The statutory framework says almost nothing about who creates a trade secret

The DTSA, 18 U.S.C. § 1839(4), defines “owner” in a fairly circular manner: “the person or entity in whom or in which rightful legal or equitable title to, or license in, the trade secret is reposed.” It does not explain how title is initially acquired, who vests it, or whether the owner must have created the information. The UTSA (adopted by 48 states and D.C.) — does not define “owner” at all; it uses the phrase “trade secret of another” in its misappropriation definition and leaves ownership to common-law principles.

Both statutes define a “trade secret” through two functional requirements: (1) the information derives independent economic value from not being generally known or readily ascertainable, and (2) the owner has taken reasonable measures to maintain secrecy. Neither statute requires human creation, registration, or even identification of the specific trade secret.

critical and underappreciated question is whether the owner must know what the trade secret is. The statutory answer is no (as argued by Professor John Villasenor in Artificial Intelligence, Trade Secrecy, and the Challenge of Transparency, 25 N.C. J.L. & Tech. 495, 509 (2024)). However, knowledge of what a trade secret actually is becomes essential at the enforcement stage. Courts require plaintiffs to describe alleged trade secrets with “sufficient particularity” to separate them from general knowledge. See, e.g., Oakwood Labs., LLC v. Thanoo, 999 F.3d 892 (3d Cir. 2021). The Eastern District of Texas rejected a plaintiff’s description of its trade secrets in T2 Modus LLC v. Williams-Arowolo, No. 4:22-CV-00263, 2023 WL 6221429, (E.D. Tex. Sept. 25, 2023), where the trade secrets were only described as “artificial intelligence,” “machine learning,” or “proprietary software.” The takeaway is that you can own a trade secret you don’t know about, but you cannot sue over one you cannot describe.

No court has decided who owns an AI-generated trade secret

As of the publication of this post, no reported case directly adjudicates ownership of a trade secret autonomously generated by an AI system. Neither the DTSA nor the UTSA contemplates non-human creators, but crucially, neither excludes them. 

Under current frameworks, the deploying user or company is the most likely owner under current frameworks. By analogy to the employer-employee relationship, the person or entity that deploys the AI, maintains the computing infrastructure, and takes reasonable measures to protect secrecy holds what the DTSA calls “rightful legal or equitable title.” 

he employee who prompted the AI generally would not own the output if standard employment agreements assign IP and confidential information rights to the employer. The AI vendor typically disclaims ownership of outputs under current terms of service (discussed below), but may retain rights to use inputs for model training — a fact with potentially devastating trade secret consequences for the unwary.

Given the statutory silence, contract law will be the primary mechanism for allocating AI-generated trade secret ownership. Professor John Sprankling’s Trade Secrets in the Artificial Intelligence Era, 76 S.C. L. Rev. 181 (2024), concludes that the AI system owner should own AI-generated trade secrets in order to “encourag[e] innovation for the benefit of the public,” but acknowledges the question is open.

The tool-versus-agent distinction matters practically even though current law does not formally address it. When AI functions as a tool (a human directs, evaluates, and selects outputs), ownership vests through the same mechanisms as any employee-created trade secret. When AI operates autonomously (e.g., a self-learning trading algorithm evolving its own strategies, a drug-discovery model identifying novel compounds) the human may not have directed the creative act and may not even know what the AI produced. Current law does not distinguish these scenarios doctrinally, but the degree of human involvement may affect the practical ability to satisfy “reasonable measures” and to identify trade secrets with “sufficient particularity” in litigation. [Fn. 2]

Vendor terms assign output ownership but create serious confidentiality risks

Every major AI platform assigns output ownership to the user. However, the details vary enormously, and the risks pertaining to trade secret protection are substantial.

Most platforms take a tiered approach that tracks the distinction between consumer and enterprise accounts. At the consumer tier, the default position across the industry is that inputs may be used for model training, typically with an opt-out mechanism that users must affirmatively invoke. At the enterprise tier, the standard commitment is the reverse: training on customer content is prohibited unless the customer explicitly agrees. Some platforms go further at the enterprise level, offering comprehensive IP indemnification that extends beyond copyright to cover trade secret, patent, and related claims.

The critical risk for businesses lies at the boundary between these tiers. Paid individual accounts (even premium ones) are frequently classified as consumer rather than commercial products, meaning the more protective enterprise terms do not apply. A company whose employees use individually-licensed accounts, even expensive ones, may find that its inputs are being used for model training under the default settings, with no enterprise-grade confidentiality protections in place. The trade secret implications are direct: if proprietary information input into a consumer-tier platform is incorporated into a model’s training data, that information may become accessible to other users — potentially rendering it “generally known” or “readily ascertainable” and destroying its trade secret status entirely. Samsung experienced this hazardous scenario firsthand in 2023 when three engineers input confidential source code into ChatGPT.  [Fn. 3]

January 2026 decision from the Northern District of California illustrates the stakes. In Trinidad v. OpenAI, Inc., No. 25-cv-06328-JST (N.D. Cal. Jan. 5, 2026), the court dismissed a pro se plaintiff’s DTSA claim on the ground that by developing her alleged trade secrets through ChatGPT, she had voluntarily disclosed them to OpenAI and could not satisfy the secrecy requirement. The court also rejected her argument that OpenAI’s Terms of Use (which assigned output ownership to the user) saved her claim, holding that ownership and secrecy are independent requirements: “for the trade secrets claim, like the copyright claim, it is not sufficient for [plaintiff] to establish ownership. Rather, she must show that the information misappropriated by OpenAI was ‘secret’ within the meaning of 18 U.S.C. § 1839(3).” Id. at 6–7. While the factual circumstances of Trinidad are unusual, the doctrinal point is broadly applicable: a vendor’s assignment of output ownership does not insulate a user from the argument that inputs shared with the platform were never secret to begin with.

Using enterprise-tier AI with contractual protections such as no-training commitments, confidentiality provisions, and data processing addenda, is far more defensible. This parallels sharing trade secrets with any third-party service provider under an NDA, which courts have long accepted as consistent with reasonable measures. But even enterprise tiers retain data temporarily for abuse monitoring (typically 30 days), and authorized vendor personnel may access content for limited purposes.

What companies should do right now

As described above, the law is unsettled, but the risk is immediate. More and more companies turn to using AI and agentic AI every day. There are at least seven concrete steps that companies using AI should consider taking:

  • Use enterprise tiers exclusively for any work involving proprietary data. Consumer tiers at every major vendor carry material trade secret risks, and these policies can change with little notice. 
  • Audit and update employment agreements to include explicit provisions addressing ownership of AI-generated outputs, assignment of AI-derived trade secrets, and restrictions on inputting confidential information into unauthorized AI tools.
  • Negotiate AI vendor agreements to include no-training commitments, confidentiality obligations, data processing addendums, and appropriate data retention and deletion terms. Do not rely on default terms of service.
  • Implement AI-use policies that specify which tools are authorized, what data can be input, and how outputs should be classified and protected. Samsung’s 2023 incident illustrates the cost of failing to do this.
  • Apply systemic security measures (e.g., access controls, encryption, logging, and information classification) to AI-generated outputs, even those not individually identified as trade secrets. This supports the “reasonable measures” requirement for trade secrets the company may not yet know it possesses.
  • Document human involvement in AI-assisted innovation to preserve patent and copyright eligibility where possible, while treating all AI-generated outputs as potential trade secrets.
  • Monitor the “readily ascertainable” frontier. As AI tools become more powerful, information previously protectable may lose trade secret status. Regularly reassess whether competitive intelligence that was once difficult to compile is now obtainable through a single AI prompt.

Where to go from here

Several fundamental questions remain unresolved. No court has addressed who owns a trade secret generated autonomously by an AI agent. No legislation specifically addresses AI-generated trade secret ownership. The “readily ascertainable” standard has not been recalibrated for AI capabilities. The boundary between “reasonable measures” and the impracticability of protecting unknown information remains undefined. And the adequacy of contractual frameworks as the primary mechanism for allocating AI-generated trade secret rights has not been tested in litigation. The law will certainly need to catch up. For now, contract, policy, and proactive governance are the most reliable tools available.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.


[1] The academic literature on AI-generated trade secrets is still developing, but has advanced significantly in the past two years. For the most comprehensive recent treatments, see (for example) Camilla A. Hrdy, Trade Secrecy Meets Generative AI, 100 Chi.-Kent L. Rev. 317 (2025); John G. Sprankling, Trade Secrets in the Artificial Intelligence Era, 76 S.C. L. Rev. 181 (2024); John Villasenor, Artificial Intelligence, Trade Secrecy, and the Challenge of Transparency, 25 N.C. J.L. & Tech. 495 (2024).

[2] This is a related issue to the “black box” problem, as described in my previous piece: “if the people who build these systems cannot fully explain how they work or how specific inputs influence specific outputs, how is a plaintiff supposed to plead that a specific stolen file contributed to a specific capability in a deployed model?”

[3] To read the cautionary tale of the Samsung incident, see Mark Gurman, Samsung Bans Staff’s AI Use After Spotting ChatGPT Data Leak, Bloomberg (May 1, 2023), available at https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak.

 

Bloomberg Law Features Sarah Tishler on AI and the Future of Trade Secrets

Sarah Tishler was recently quoted in a Bloomberg Law article about the intersection of artificial intelligence and trade secrets.

he article, titled “AI Will Force Trade Secret Calculus Shift, Escalate Tactics,” addresses the impact of AI on trade secret law and related concerns about the technology’s ability to generate, uncover, and replicate proprietary information.

In the article, Sarah is quoted as follows:

AI-related secrets are already at the center of lawsuits that mirror more traditional trade secrets cases, as in X.AI’s lawsuit accusing OpenAI Inc. of poaching its staff. But more interesting questions arise when AI intersects with different stages in the lifecycle of trade secrets, affecting what information is protectable and how hard companies have to work to keep it secret—two key questions in trade secrets law—attorney Sarah Tishler of Beck Reed Riden LLP said.

“These big picture questions will take a while to percolate through the courts, but it’s just a matter of time before we see more definitive case law on it,” Tishler said. “In the 1990s, commentators feared the internet would also destroy trade secrets. But they raised the bar for protection, and I think AI is going to have the same effect.”

***

Tishler said there are already powerful monitoring systems that can aid early detection of potential trade secrets theft. Whereas before you’d have to comb through access logs and print histories after the fact, now certain activities can trigger notifications or even shut down access before the theft can be completed, she said.

The March 16, 2026, article was written by Kyle Jahner, a reporter on intellectual property for Bloomberg Law.


Sarah Tishler is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

The Wall Street Journal featured Beck Reed Riden LLP’s noncompete agreement experience. In 2016, the White House issued a report entitled, “Non-Compete Agreements: Analysis of the Usage, Potential Issues, and State Responses,” relying in part on Beck Reed Riden LLP’s research and analysis, including its 50 State Noncompete Survey.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

The Black Box Problem in AI Trade Secret Litigation: How Do You Prove Use?

The dismissal of xAI’s trade secret claims against OpenAI earlier this month meant that the court never reached what will surely be one of the thorniest questions in AI trade secret litigation: at the end of the day, how would xAI be able to prove that OpenAI actually used any stolen trade secrets? My earlier coverage discussed Judge Lin’s order dismissing the case, finding that xAI had failed to plead facts connecting OpenAI’s own conduct to the alleged misappropriation by its former employees. There was no plausible inference that OpenAI induced the theft, and no allegation that it ever received or incorporated what was stolen.

However, had xAI survived the motion to dismiss, it would have eventually faced a second and perhaps harder problem: how do you demonstrate (particularly before discovery) that a specific stolen file or methodology shaped anything inside a frontier AI model? That is the question this post examines. 

The Traditional Playbook Falls Short

In a conventional trade secret case, proving use can be tricky, but achievable. A former employee takes a customer list and joins a competitor. Six months later, the competitor is calling your customers. The causal inference is not difficult to draw. A departing engineer takes manufacturing specifications to a rival. The rival’s next product incorporates design features it had no prior capability to produce. Again, the inference is visible from the outside.

Courts have built a substantial body of case law around these kinds of observable signals. For example, in Applied Biological Laboratories, Inc. v. Diomics Corp., the defendant had no prior experience in the relevant industry before allegedly obtaining the plaintiff’s trade secrets and suddenly releasing a competing product. No. 20-cv-02500-AJB-LL, 2021 WL 4060531 (S.D. Cal. Sept. 7, 2021) (denying motion to dismiss trade secret claims). In Autodesk, Inc. v. ZWCAD Software Co., the court denied a motion to dismiss trade secret claims where defendant’s “products display identical idiosyncrasies and bugs that could have been introduced only through the wholesale copying of significant portions of misappropriated Autodesk code.” No. 14-cv-01409-EJD, 2015 WL 2265479 (N.D. Cal. May 13, 2015). And in Yeiser Research & Development LLC v. Teknor Apex Co., the defendant had no prior capability to build a compact hose before receiving the plaintiff’s confidential designs, then released one that incorporated the plaintiff’s concept. 281 F. Supp. 3d 1021 (S.D. Cal. 2017) (denying motion to dismiss trade secret claims). In each case, the signal of use was observable from outside the defendant’s systems.

The Black Box Problem: Even the Builders Don’t Know

What makes AI trade secret cases unique is that even the people who build these systems openly admit they do not fully understand how they work.

For example, at the International Telecommunication Union’s AI for Good Global Summit in May 2024, OpenAI CEO Sam Altman was asked directly how his company’s large language models function. “We certainly have not solved interpretability,” he said, acknowledging that the company has yet to figure out how to trace back its AI models’ output to the decisions that produced it.

Anthropic CEO Dario Amodei has been even more direct. In an April 2025 essay on interpretability, he wrote that “people outside the field are often surprised and alarmed to learn that we do not understand how our own AI creations work,” and that “this lack of understanding is essentially unprecedented in the history of technology.” He went further, describing how even the basic architecture of these systems produces cognitive mechanisms that emerge organically from training in ways that researchers struggle to explain: “the model’s actual cognitive mechanisms emerge organically from these ingredients, and our understanding of them is poor.”

These are admissions from the CEOs of the two most prominent frontier AI companies in the world. The significance for trade secret law is clear: if the people who build these systems cannot fully explain how they work or how specific inputs influence specific outputs, how is a plaintiff supposed to plead that a specific stolen file contributed to a specific capability in a deployed model?

This opacity is not incidental—it is structural. As one scholar has observed, AI-based inventions are “even more difficult to reverse engineer” than traditional software “because they are neither explainable nor scrutable.”¹ The same inscrutability that frustrates would-be reverse engineers also frustrates potential plaintiffs trying to trace stolen information through a model’s training pipeline.

What the Black Box Means for Plaintiffs

Large language models, training pipelines, and proprietary AI architectures are not like customer lists or manufacturing processes. They are extraordinarily complex systems whose internal workings are, by design, largely opaque. Whether a specific piece of stolen source code contributed to a specific capability in a deployed model is a question that may be genuinely unanswerable without deep access to the defendant’s internal systems, training data, model weights, and development history.

onsider the specific allegations in the xAI case. Li allegedly uploaded xAI’s entire source code base to a personal cloud account. Fraiture allegedly copied source code and internal materials to his personal device before joining OpenAI. Assuming for the sake of argument that those allegations are true and that the materials constituted protectable trade secrets, how would xAI demonstrate that any of that information made its way into OpenAI’s models or systems? The source code for a frontier AI model runs to millions of lines. Training pipelines involve complex interdependencies. Even if a specific piece of xAI’s code appeared somewhere in OpenAI’s development environment, tracing its influence on a deployed model’s capabilities would require the kind of forensic access that simply is not available before discovery (and it is hard to imagine how it would be outwardly observable).

This challenge is compounded by the pleading standards plaintiffs already face. Courts—including a growing number of federal courts—require that misappropriation complaints identify the alleged trade secret with “sufficient particularity” to allow the defendant to understand what specific information is at issue and to respond.² For an AI algorithm whose very operation may be opaque even to its own designers, meeting that standard while simultaneously showing how the stolen information was incorporated into a frontier model creates a burden with no clear analogue in traditional trade secret litigation.

Despite this challenge, prior cases in analogous technology contexts offer some instructive lessons about how courts have approached the problem, and what strategies have worked.

How Courts Have Handled Analogous Complexity

The black box problem is not entirely new. Courts have encountered versions of it in prior cases involving complex software and autonomous systems, and their approaches offer a roadmap, imperfect but useful, for AI trade secret plaintiffs.

WeRide Corp. v. Kun Huang, 379 F. Supp. 3d 834 (N.D. Cal. 2019)

The WeRide litigation arose when the company’s former CEO and Head of Hardware Technology allegedly copied proprietary autonomous vehicle source code and founded a competing company called AllRide. On WeRide’s motion for preliminary injunction, the core evidentiary challenge was proving that AllRide’s self-driving capabilities actually incorporated WeRide’s stolen code rather than being independently developed. The defendant’s systems were complex, and direct code comparison was unavailable before discovery.

he court’s solution was to reason from impossibility rather than from direct evidence. WeRide’s expert opined that it would have been impossible to independently develop the advanced driving capabilities AllRide publicly demonstrated just ten weeks after the former employee’s last day at WeRide. The court found this sufficient to support a preliminary injunction, noting that implausibly fast development of technology can itself contribute to a finding of misappropriation. The court also pointed to a hardware configuration detail that reinforced the inference: AllRide positioned its radar component on the front center of the vehicle roof, just like WeRide, rather than on the front bumper or rear view mirror like most competitors. WeRide’s expert testified that this placement was consistent with use of WeRide’s source code, which would only be useful with the radar in that specific location.

The WeRide case offers two practical lessons for AI plaintiffs. First, the speed-of-development inference is a powerful tool when a defendant demonstrates capabilities that would have required substantial independent development time it demonstrably lacked. Second, observable product-level details that are consistent with use of specific stolen information, and inconsistent with independent development, can bridge the gap between theft and incorporation even without direct code comparison. For AI cases, the analog could be a capability, architecture choice, or benchmark performance that reflects specifically what was stolen in ways that cannot be explained by independent development. That may be a harder case to make, but the analytical framework is the same.

What Has Worked So Far

When no smoking gun is available, several categories of circumstantial evidence have proven effective in trade secret disputes, and offer a template for AI trade secret plaintiffs doing pre-filing investigation.

Of course, the clearest signal of use is a product capability that mirrors the plaintiff’s alleged trade secrets and that the defendant had no prior ability to produce independently. The speed-of-development inference from WeRide is particularly powerful when it can be quantified. If a defendant can be shown, by credible expert analysis, to have demonstrated capabilities that would have required more time or resources than it actually had, that gap is difficult to explain without misappropriation. 

Patent filings are another potentially useful signal. If a defendant files patents in the period following the alleged misappropriation that cover technical ground closely related to the plaintiff’s alleged trade secrets, that is observable from outside the defendant’s systems and can support a plausible inference of use. 3D Systems, Inc. v. Wynne, No. 21-cv-01141-LAB, 2022 WL 21697345 (S.D. Cal. Mar. 9, 2022), turned in part on exactly this kind of allegation.

The challenge for AI plaintiffs is that all of these signals are harder to read in the AI context. AI companies release products with new capabilities constantly. It would be genuinely difficult to distinguish a capability jump that results from misappropriation from one that results from independent research and development, particularly in a field where progress is rapid across the entire industry. And the sheer complexity of frontier AI systems makes product-level comparison far more difficult than comparing two pieces of software with identical interfaces.

There is also an important threshold question that pre-filing investigation must address: the protectability of the stolen information itself. Not every category of information related to a frontier AI system qualifies as a trade secret, even if kept confidential.³ Plaintiffs who fail to distinguish protectable trade secrets—such as proprietary training data, novel architecture choices, and non-public source code—from information that is generally known or readily ascertainable in the field risk dismissal on grounds wholly separate from the use-proof problem.

What Plaintiffs’ Counsel Should Be Doing

Given this landscape, there are several practical steps that trade secret plaintiffs in AI cases should consider before filing.

The most important is pre-filing technical investigation. This means engaging forensic experts not just to document what was taken, but to analyze the defendant’s publicly available products, papers, and patent filings for signs that the stolen information was put to use. The WeRide approach of quantifying development timelines and identifying product-level details inconsistent with independent development is a useful template. If the misappropriated materials related to a specific technical capability, model architecture, or training methodology, the investigation should focus on whether the defendant’s public outputs reflect that capability in ways that would be surprising absent access to the plaintiff’s information. As in the 3D Systems case, patent filings are another useful area of research.

Early preservation demands are also essential. The WeRide litigation is a powerful reminder that in complex technology cases, the most probative evidence of incorporation—specifically internal engineering records, development histories, and communications about technical decisions—is precisely what defendants are most motivated to destroy. A preservation demand issued at or before the time of filing is not a formality; it is a substantive litigation strategy.

Counsel should also think carefully about the limits of what can be proven. In AI trade secret cases, the question of use may ultimately be unanswerable through circumstantial evidence alone, no matter how skillfully assembled. The goal of pre-filing investigation is not to achieve certainty but to build a plausible inference strong enough to survive a motion to dismiss and reach discovery—where the evidence needed to answer the use question, if it exists, will actually be found.⁴

Looking Ahead

As talent continues to move rapidly between AI companies and as the competitive stakes in the industry grow, we can expect to see more disputes that raise the black box issue. The cases discussed above offer a consistent lesson: where direct evidence of use is unavailable, courts look for circumstantial evidence such as product-level similarities, implausibly fast development, and observable details that can only be explained by access to the stolen information.

We will continue to monitor developments in this area and will report on any significant rulings as they emerge.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.


¹ The academic literature on this intersection is still developing, but scholars have begun to identify the structural problem. As Professor Tabrez Ebrahim has noted, AI-based inventions are “even more difficult to reverse engineer” than traditional software “because they are neither explainable nor scrutable”—an observation that applies with equal force to plaintiffs trying to trace stolen information through a training pipeline. See Tabrez Y. Ebrahim, Artificial Intelligence Inventions and Patent Disclosure, 125 Pa. St. L. Rev. 147, 184 (2020), as discussed in Camilla A. Hrdy, Trade Secrecy Meets Generative AI, 100 Chi.-Kent L. Rev. 317, 342 (2025).

² As Professor John Villasenor has discussed, a growing number of courts are requiring that misappropriation complaints identify the alleged trade secret with “sufficient particularity,” a standard that could pose real difficulty when the trade secret at issue is an AI system whose operation may be opaque even to its own designers. See John Villasenor, Artificial Intelligence, Trade Secrecy, and the Challenge of Transparency, 25 N.C. J.L. & Tech. 495, 514–16 (2024).

³ As Profs. Hrdy and Villasenor have each discussed, not every category of information related to a frontier AI system qualifies for trade secret protection (even when kept confidential) and there is a tendency toward overinclusion in the AI context. See Hrdy, supra note 1, at 337–40; Villasenor, supra note 2, at 508.

⁴ As Professor Villasenor has put it, it is not sufficient for a plaintiff to allege, in effect, that “we are not sure how the AI algorithm works, but whatever it is doing, it is our trade secret, and the defendant has misappropriated it.” See Villasenor, supra note 2, at 512.

1 2 3 4