The Black Box Problem in AI Trade Secret Litigation: How Do You Prove Use?

The dismissal of xAI’s trade secret claims against OpenAI earlier this month meant that the court never reached what will surely be one of the thorniest questions in AI trade secret litigation: at the end of the day, how would xAI be able to prove that OpenAI actually used any stolen trade secrets? My earlier coverage discussed Judge Lin’s order dismissing the case, finding that xAI had failed to plead facts connecting OpenAI’s own conduct to the alleged misappropriation by its former employees. There was no plausible inference that OpenAI induced the theft, and no allegation that it ever received or incorporated what was stolen.

However, had xAI survived the motion to dismiss, it would have eventually faced a second and perhaps harder problem: how do you demonstrate (particularly before discovery) that a specific stolen file or methodology shaped anything inside a frontier AI model? That is the question this post examines. 

The Traditional Playbook Falls Short

In a conventional trade secret case, proving use can be tricky, but achievable. A former employee takes a customer list and joins a competitor. Six months later, the competitor is calling your customers. The causal inference is not difficult to draw. A departing engineer takes manufacturing specifications to a rival. The rival’s next product incorporates design features it had no prior capability to produce. Again, the inference is visible from the outside.

Courts have built a substantial body of case law around these kinds of observable signals. For example, in Applied Biological Laboratories, Inc. v. Diomics Corp., the defendant had no prior experience in the relevant industry before allegedly obtaining the plaintiff’s trade secrets and suddenly releasing a competing product. No. 20-cv-02500-AJB-LL, 2021 WL 4060531 (S.D. Cal. Sept. 7, 2021) (denying motion to dismiss trade secret claims). In Autodesk, Inc. v. ZWCAD Software Co., the court denied a motion to dismiss trade secret claims where defendant’s “products display identical idiosyncrasies and bugs that could have been introduced only through the wholesale copying of significant portions of misappropriated Autodesk code.” No. 14-cv-01409-EJD, 2015 WL 2265479 (N.D. Cal. May 13, 2015). And in Yeiser Research & Development LLC v. Teknor Apex Co., the defendant had no prior capability to build a compact hose before receiving the plaintiff’s confidential designs, then released one that incorporated the plaintiff’s concept. 281 F. Supp. 3d 1021 (S.D. Cal. 2017) (denying motion to dismiss trade secret claims). In each case, the signal of use was observable from outside the defendant’s systems.

The Black Box Problem: Even the Builders Don’t Know

What makes AI trade secret cases unique is that even the people who build these systems openly admit they do not fully understand how they work.

For example, at the International Telecommunication Union’s AI for Good Global Summit in May 2024, OpenAI CEO Sam Altman was asked directly how his company’s large language models function. “We certainly have not solved interpretability,” he said, acknowledging that the company has yet to figure out how to trace back its AI models’ output to the decisions that produced it.

Anthropic CEO Dario Amodei has been even more direct. In an April 2025 essay on interpretability, he wrote that “people outside the field are often surprised and alarmed to learn that we do not understand how our own AI creations work,” and that “this lack of understanding is essentially unprecedented in the history of technology.” He went further, describing how even the basic architecture of these systems produces cognitive mechanisms that emerge organically from training in ways that researchers struggle to explain: “the model’s actual cognitive mechanisms emerge organically from these ingredients, and our understanding of them is poor.”

These are admissions from the CEOs of the two most prominent frontier AI companies in the world. The significance for trade secret law is clear: if the people who build these systems cannot fully explain how they work or how specific inputs influence specific outputs, how is a plaintiff supposed to plead that a specific stolen file contributed to a specific capability in a deployed model?

This opacity is not incidental—it is structural. As one scholar has observed, AI-based inventions are “even more difficult to reverse engineer” than traditional software “because they are neither explainable nor scrutable.”¹ The same inscrutability that frustrates would-be reverse engineers also frustrates potential plaintiffs trying to trace stolen information through a model’s training pipeline.

What the Black Box Means for Plaintiffs

Large language models, training pipelines, and proprietary AI architectures are not like customer lists or manufacturing processes. They are extraordinarily complex systems whose internal workings are, by design, largely opaque. Whether a specific piece of stolen source code contributed to a specific capability in a deployed model is a question that may be genuinely unanswerable without deep access to the defendant’s internal systems, training data, model weights, and development history.

onsider the specific allegations in the xAI case. Li allegedly uploaded xAI’s entire source code base to a personal cloud account. Fraiture allegedly copied source code and internal materials to his personal device before joining OpenAI. Assuming for the sake of argument that those allegations are true and that the materials constituted protectable trade secrets, how would xAI demonstrate that any of that information made its way into OpenAI’s models or systems? The source code for a frontier AI model runs to millions of lines. Training pipelines involve complex interdependencies. Even if a specific piece of xAI’s code appeared somewhere in OpenAI’s development environment, tracing its influence on a deployed model’s capabilities would require the kind of forensic access that simply is not available before discovery (and it is hard to imagine how it would be outwardly observable).

This challenge is compounded by the pleading standards plaintiffs already face. Courts—including a growing number of federal courts—require that misappropriation complaints identify the alleged trade secret with “sufficient particularity” to allow the defendant to understand what specific information is at issue and to respond.² For an AI algorithm whose very operation may be opaque even to its own designers, meeting that standard while simultaneously showing how the stolen information was incorporated into a frontier model creates a burden with no clear analogue in traditional trade secret litigation.

Despite this challenge, prior cases in analogous technology contexts offer some instructive lessons about how courts have approached the problem, and what strategies have worked.

How Courts Have Handled Analogous Complexity

The black box problem is not entirely new. Courts have encountered versions of it in prior cases involving complex software and autonomous systems, and their approaches offer a roadmap, imperfect but useful, for AI trade secret plaintiffs.

WeRide Corp. v. Kun Huang, 379 F. Supp. 3d 834 (N.D. Cal. 2019)

The WeRide litigation arose when the company’s former CEO and Head of Hardware Technology allegedly copied proprietary autonomous vehicle source code and founded a competing company called AllRide. On WeRide’s motion for preliminary injunction, the core evidentiary challenge was proving that AllRide’s self-driving capabilities actually incorporated WeRide’s stolen code rather than being independently developed. The defendant’s systems were complex, and direct code comparison was unavailable before discovery.

he court’s solution was to reason from impossibility rather than from direct evidence. WeRide’s expert opined that it would have been impossible to independently develop the advanced driving capabilities AllRide publicly demonstrated just ten weeks after the former employee’s last day at WeRide. The court found this sufficient to support a preliminary injunction, noting that implausibly fast development of technology can itself contribute to a finding of misappropriation. The court also pointed to a hardware configuration detail that reinforced the inference: AllRide positioned its radar component on the front center of the vehicle roof, just like WeRide, rather than on the front bumper or rear view mirror like most competitors. WeRide’s expert testified that this placement was consistent with use of WeRide’s source code, which would only be useful with the radar in that specific location.

The WeRide case offers two practical lessons for AI plaintiffs. First, the speed-of-development inference is a powerful tool when a defendant demonstrates capabilities that would have required substantial independent development time it demonstrably lacked. Second, observable product-level details that are consistent with use of specific stolen information, and inconsistent with independent development, can bridge the gap between theft and incorporation even without direct code comparison. For AI cases, the analog could be a capability, architecture choice, or benchmark performance that reflects specifically what was stolen in ways that cannot be explained by independent development. That may be a harder case to make, but the analytical framework is the same.

What Has Worked So Far

When no smoking gun is available, several categories of circumstantial evidence have proven effective in trade secret disputes, and offer a template for AI trade secret plaintiffs doing pre-filing investigation.

Of course, the clearest signal of use is a product capability that mirrors the plaintiff’s alleged trade secrets and that the defendant had no prior ability to produce independently. The speed-of-development inference from WeRide is particularly powerful when it can be quantified. If a defendant can be shown, by credible expert analysis, to have demonstrated capabilities that would have required more time or resources than it actually had, that gap is difficult to explain without misappropriation. 

Patent filings are another potentially useful signal. If a defendant files patents in the period following the alleged misappropriation that cover technical ground closely related to the plaintiff’s alleged trade secrets, that is observable from outside the defendant’s systems and can support a plausible inference of use. 3D Systems, Inc. v. Wynne, No. 21-cv-01141-LAB, 2022 WL 21697345 (S.D. Cal. Mar. 9, 2022), turned in part on exactly this kind of allegation.

The challenge for AI plaintiffs is that all of these signals are harder to read in the AI context. AI companies release products with new capabilities constantly. It would be genuinely difficult to distinguish a capability jump that results from misappropriation from one that results from independent research and development, particularly in a field where progress is rapid across the entire industry. And the sheer complexity of frontier AI systems makes product-level comparison far more difficult than comparing two pieces of software with identical interfaces.

There is also an important threshold question that pre-filing investigation must address: the protectability of the stolen information itself. Not every category of information related to a frontier AI system qualifies as a trade secret, even if kept confidential.³ Plaintiffs who fail to distinguish protectable trade secrets—such as proprietary training data, novel architecture choices, and non-public source code—from information that is generally known or readily ascertainable in the field risk dismissal on grounds wholly separate from the use-proof problem.

What Plaintiffs’ Counsel Should Be Doing

Given this landscape, there are several practical steps that trade secret plaintiffs in AI cases should consider before filing.

The most important is pre-filing technical investigation. This means engaging forensic experts not just to document what was taken, but to analyze the defendant’s publicly available products, papers, and patent filings for signs that the stolen information was put to use. The WeRide approach of quantifying development timelines and identifying product-level details inconsistent with independent development is a useful template. If the misappropriated materials related to a specific technical capability, model architecture, or training methodology, the investigation should focus on whether the defendant’s public outputs reflect that capability in ways that would be surprising absent access to the plaintiff’s information. As in the 3D Systems case, patent filings are another useful area of research.

Early preservation demands are also essential. The WeRide litigation is a powerful reminder that in complex technology cases, the most probative evidence of incorporation—specifically internal engineering records, development histories, and communications about technical decisions—is precisely what defendants are most motivated to destroy. A preservation demand issued at or before the time of filing is not a formality; it is a substantive litigation strategy.

Counsel should also think carefully about the limits of what can be proven. In AI trade secret cases, the question of use may ultimately be unanswerable through circumstantial evidence alone, no matter how skillfully assembled. The goal of pre-filing investigation is not to achieve certainty but to build a plausible inference strong enough to survive a motion to dismiss and reach discovery—where the evidence needed to answer the use question, if it exists, will actually be found.⁴

Looking Ahead

As talent continues to move rapidly between AI companies and as the competitive stakes in the industry grow, we can expect to see more disputes that raise the black box issue. The cases discussed above offer a consistent lesson: where direct evidence of use is unavailable, courts look for circumstantial evidence such as product-level similarities, implausibly fast development, and observable details that can only be explained by access to the stolen information.

We will continue to monitor developments in this area and will report on any significant rulings as they emerge.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.


¹ The academic literature on this intersection is still developing, but scholars have begun to identify the structural problem. As Professor Tabrez Ebrahim has noted, AI-based inventions are “even more difficult to reverse engineer” than traditional software “because they are neither explainable nor scrutable”—an observation that applies with equal force to plaintiffs trying to trace stolen information through a training pipeline. See Tabrez Y. Ebrahim, Artificial Intelligence Inventions and Patent Disclosure, 125 Pa. St. L. Rev. 147, 184 (2020), as discussed in Camilla A. Hrdy, Trade Secrecy Meets Generative AI, 100 Chi.-Kent L. Rev. 317, 342 (2025).

² As Professor John Villasenor has discussed, a growing number of courts are requiring that misappropriation complaints identify the alleged trade secret with “sufficient particularity,” a standard that could pose real difficulty when the trade secret at issue is an AI system whose operation may be opaque even to its own designers. See John Villasenor, Artificial Intelligence, Trade Secrecy, and the Challenge of Transparency, 25 N.C. J.L. & Tech. 495, 514–16 (2024).

³ As Profs. Hrdy and Villasenor have each discussed, not every category of information related to a frontier AI system qualifies for trade secret protection (even when kept confidential) and there is a tendency toward overinclusion in the AI context. See Hrdy, supra note 1, at 337–40; Villasenor, supra note 2, at 508.

⁴ As Professor Villasenor has put it, it is not sufficient for a plaintiff to allege, in effect, that “we are not sure how the AI algorithm works, but whatever it is doing, it is our trade secret, and the defendant has misappropriated it.” See Villasenor, supra note 2, at 512.

xAI v. OpenAI: Motion to Dismiss Granted (But the Story Might Not Be Over)

 

The high-profile litigation between xAI and OpenAI has reached a significant turning point, with Judge Rita Lin of the Northern District of California granting OpenAI’s motion to dismiss xAI’s First Amended Complaint on February 24, 2026. The dismissal was granted with leave to amend, giving xAI until March 17, 2026 to try again. But the court’s reasoning makes clear that xAI has to do more if it intends to pursue its claims against OpenAI.

The ruling is a reminder of something California trade secret practitioners already know but that bears repeating, especially as AI companies raid each other’s top talent: California is one of the most employee-friendly jurisdictions in the country, and it does not recognize the inevitable disclosure doctrine. To hold a company liable for trade secret misappropriation, you have to show what the company did, not just what its new employees did before they arrived.

or those coming to this case fresh: the lawsuit arises from a wave of departures from xAI to OpenAI in the summer of 2025, during which eight xAI engineers and executives allegedly left for OpenAI in quick succession. Two of those former employees, Xuechen Li and Jimmy Fraiture, allegedly exfiltrated xAI source code and other confidential materials around the time they accepted OpenAI offers. xAI sued OpenAI, arguing it orchestrated or at least benefited from those departures as part of a scheme to acquire xAI’s trade secrets. (For more background on the case, including OpenAI’s motion to dismiss and answer, see my prior post here.)

California Does Not Do Inevitable Disclosure

Before getting to the court’s analysis, it is worth situating this ruling in the broader legal landscape, because the outcome will not be surprising to anyone who litigates trade secret cases in California.

In many jurisdictions, a trade secret plaintiff can make a case based on the inevitable disclosure doctrine, and argue that a former employee will inevitably use the former employer’s confidential information in a sufficiently similar new role. Under this theory, the likelihood of future use is itself actionable. California rejects that theory entirely. Under California law, and in federal courts applying California law, mere possession of a trade secret is not misappropriation. Neither is the prospect of future use, however likely it may seem given the employee’s new responsibilities. A plaintiff must plead and ultimately prove actual acquisition, disclosure, or use by the defendant.

This principle has deep roots in California case law. In Whyte v. Schlage Lock Co., 101 Cal. App. 4th 1443 (2002), the court explicitly declined to adopt the inevitable disclosure doctrine, reasoning that it would effectively convert employment agreements into covenants not to compete, which California’s strong public policy against noncompetes does not permit. And in Silvaco Data Systems v. Intel Corp., 184 Cal. App. 4th 210 (2010), the court held that mere possession of a trade secret, without use, does not constitute misappropriation. Federal courts in the Ninth Circuit have consistently applied the same principle at the pleading stage, requiring specific factual allegations of use rather than allowing inference based solely on employee mobility or role similarity.

This order fits squarely in that tradition. xAI essentially asked the court to infer that because its former employees took confidential materials and then went to work for a direct competitor in similar roles, OpenAI must have benefited. The court declined.

The Core Holding

The dismissal turns on whether xAI plausibly alleged that OpenAI itself, rather than one of its employees, misappropriated xAI’s trade secrets.

Under the Defend Trade Secrets Act, misappropriation requires that the defendant acquired, disclosed, or used a trade secret through improper means. Even accepting xAI’s allegations as true, Judge Lin found that the First Amended Complaint failed to plausibly allege that OpenAI acquired or used any xAI trade secrets, or that it directed or induced employees to steal them. As the court put it, the complaint alleges what employees did before joining OpenAI, but not what OpenAI did.

Direct Misappropriation and Inducement

xAI’s primary theory was that OpenAI induced its former employees to misappropriate trade secrets. The court rejected that theory.

The amended complaint pointed to the fact that multiple employees departed around the same time, communicated with the same OpenAI recruiter (Tifa Chen) via the encrypted Signal app, and downloaded xAI materials during the period they were negotiating job offers. Critically, xAI did not allege that OpenAI received any of the alleged trade secrets, incorporated them into its systems, or conditioned Li’s or Fraiture’s employment on their disclosure. Taken together, and with all reasonable inferences drawn in xAI’s favor, the court found those facts insufficient to support a plausible inference that OpenAI encouraged or directed the alleged theft. 

Vicarious Liability and the TRO That Cut Both Ways

The court also rejected xAI’s respondeat superior theory, and its employee-by-employee analysis illustrates precisely where the complaint fell short. It also reveals a strategic tension that practitioners in this space should note.

Early in the litigation against Li, xAI obtained a temporary restraining order, prohibiting him from taking any role at OpenAI until xAI confirmed that all of its confidential information in his possession had been deleted. OpenAI then revoked Li’s job offer. That was unquestionably a short-term win for xAI (and likely necessary for xAI to protect itself). But it created a wrinkle for the corporate liability theory: because Li never actually started working at OpenAI, there was no basis to infer that OpenAI ever used anything he allegedly took. The TRO that kept Li out of OpenAI also kept xAI from being able to argue that OpenAI put his alleged misappropriation to use. This is a dynamic worth keeping in mind when sequencing relief in trade secret cases. Early injunctive success against an individual employee can, in some circumstances, undermine a subsequent corporate liability claim.

A Particular Challenge in AI Cases

That gap in xAI’s complaint reflects a structural challenge that will recur in AI trade secret litigation and that plaintiffs’ counsel need to think carefully about.

In a traditional trade secret case involving a customer list or a manufacturing process, it is often possible to observe relatively directly whether the defendant is using the misappropriated information. A competitor that suddenly targets your customers, or that produces a product using a process it did not previously know, provides visible evidence of use. AI systems are different. Whether a large language model, a training pipeline, or a proprietary architecture incorporates a specific piece of stolen source code or methodology is genuinely difficult to determine from the outside, particularly before discovery. The systems are complex, the relevant details are internal, and the causal connection between a specific stolen file and a specific capability in a deployed model may be nearly impossible to trace without access to the defendant’s systems.

Courts have so far declined to lower the pleading bar to account for this asymmetry, as this order confirms. That means plaintiffs in AI trade secret cases need to invest heavily in pre-filing investigation, including technical forensic analysis, product comparison, and patent review, looking for the kinds of external signals that courts have found sufficient in analogous cases: unexpected capability jumps, suspiciously similar product features, or patent filings that could only reflect the plaintiff’s proprietary work. xAI may face exactly this challenge if it files a Second Amended Complaint.

What Comes Next

The dismissal was granted with leave to amend. xAI has until March 17, 2026 to file a Second Amended Complaint, limited to curing the deficiencies the court identified. No new claims or parties may be added without further leave of court.

The court’s guidance on what is missing is clear. To survive another motion to dismiss, xAI will need to plead facts that connect OpenAI itself to the acquisition or use of its trade secrets. That means allegations along the lines of explicit recruiter instructions to bring confidential materials, employment conditions tied to the delivery of trade secrets, or evidence that OpenAI’s products or internal systems reflect xAI’s misappropriated information. Whether xAI can make those allegations on the basis of publicly available information alone, without the benefit of discovery, is the central question.

All eyes will now turn to whether xAI files a Second Amended Complaint by the March 17 deadline, and if so, whether it can plead the kind of concrete, defendant-focused allegations that Judge Lin’s order requires. We will keep this page updated accordingly.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

xAI Files Amended Complaint Against OpenAI: New Allegations and a Sharpened DTSA Strategy

The xAI v. OpenAI litigation has taken another significant turn. Two weeks after OpenAI filed its motion to dismiss (see my previous post that motion here), xAI has filed an amended complaint, introducing new details that substantially expand its allegations and strengthen the foundation of its trade secret claim under the Defend Trade Secrets Act (DTSA).

The new complaint, spanning 34 pages and supported by multiple exhibits, adds new factual allegations about the nature of xAI’s alleged trade secrets, how OpenAI and its employees obtained them, and how those secrets were protected. It also broadens the cast of alleged actors and reasserts that OpenAI’s conduct was part of a “coordinated pattern” of misappropriation aimed at undermining a direct competitor in the race to build next-generation AI systems.

Strengthening the DTSA Elements

Under the DTSA, a plaintiff must show (1) the existence of trade secrets, (2) reasonable measures to maintain secrecy, and (3) acquisition, disclosure, or use through improper means. The amended complaint adds specificity on all three fronts.

1. Identification of the Alleged Trade Secrets

The new filing adds concrete examples of the information xAI claims qualifies as trade secrets, a key improvement over the original complaint. xAI now identifies:

  • The full source code and architecture of the Grok model, including training and fine-tuning processes, tokenization methods, and proprietary safety tuning protocols.

  • Infrastructure and inference cluster designs, describing xAI’s approach to scaling and GPU allocation for high-throughput deployment, allegedly more efficient than competitors’ systems.

  • Data center buildout and deployment methodologies, including details of xAI’s proprietary approach to cabling, power distribution, and cooling optimization for GPU clusters.

  • Operational and business information, including internal product roadmaps, confidential performance metrics, vendor pricing and supplier relationships, and future R&D directions.

These categories replace the more general references to “code and infrastructure” in the original complaint with a clearer delineation of the specific areas of alleged secrecy.[1] 

2. Reasonable Measures to Maintain Secrecy

xAI also bolsters its showing of reasonable measures, another crucial DTSA element. The amended complaint attaches as exhibits several employee confidentiality, non-disclosure, and invention assignment agreements, which explicitly prohibit retention or disclosure of company materials after employment ends.

The complaint further describes internal access controls on xAI’s systems, including:

  • Restricting access to Grok model code and data center specifications to a small group of engineers and executives.

  • Requiring employees to use multi-factor authentication for cloud storage access.

  • Limiting permissions for external data transfers and monitoring unusual download activity.

It also references termination certifications, which departing employees (including Li and Fraiture) were required to sign to confirm the return or deletion of all confidential materials. In Li’s case, xAI alleges that he signed such a certification and then violated it almost immediately.

3. Acquisition and Use of the Alleged Trade Secrets

The new allegations under DTSA focus squarely on OpenAI’s knowledge and intent, addressing the “improper means” element.

xAI now alleges that OpenAI:

  • Targeted specific employees with access to its core systems, including Grok’s source code and data center infrastructure.

  • Knew or should have known that these employees retained xAI data when they joined OpenAI.

  • Directed or encouraged employees to disclose or re-create xAI’s trade secrets in their new roles.

For example:

  • Li allegedly uploaded the entirety of xAI’s Grok source code to his personal iCloud and GitHub accounts before leaving xAI, then accessed those same accounts from OpenAI’s network. xAI alleges that OpenAI became aware of this during Li’s onboarding and failed to take any steps to prevent use or disclosure.

  • Fraiture, who allegedly copied xAI’s infrastructure and inference cluster code via AirDrop, is now alleged to have joined an OpenAI team working on similar deployment technology within weeks of leaving xAI.

  • The senior finance executive allegedly carried xAI’s confidential data center expansion plan to OpenAI, where he took on a role managing GPU procurement and facility buildouts, the same area in which xAI claims to have developed unique know-how.

The amended complaint adds a key factual allegation missing from the first version: that OpenAI gained an unfair competitive advantage by incorporating xAI’s proprietary methods into its own model-training infrastructure, allegedly improving performance efficiency and cost metrics.

xAI also alleges that OpenAI knowingly benefited from the misappropriated information by using it to accelerate development of its large language models and reinforce its market position.

4. Exhibits Supporting the Narrative

The attached exhibits—which include employment agreements, correspondence, and the Temporary Restraining Order (TRO) issued in xAI v. Li—serve to corroborate the claim that these trade secrets were both valuable and adequately protected. Exhibit 6, the TRO, is particularly significant because it confirms that the court already found a likelihood of success on the merits of xAI’s trade secret claim against Li. That prior finding strengthens xAI’s argument that the same conduct, extended to OpenAI, also violates the DTSA.

Procedural Strategy and October 28 Court Order

xAI’s amended complaint mooted OpenAI’s pending motion to dismiss, and the court confirmed that in an order entered on October 28, 2025.

That procedural order resets the playing field. OpenAI must now decide whether to file a renewed motion to dismiss directed at the new complaint or move straight to an answer. Either way, xAI’s amended filing succeeded in halting OpenAI’s effort to dismiss the case on the prior record.

What Comes Next

xAI’s amended complaint represents both a procedural and substantive escalation. Procedurally, it mooted OpenAI’s motion to dismiss and forced the company to start over. Substantively, it shores up the weakest parts of the original complaint by supplying detail where the DTSA requires it most—what the trade secrets are, how they were protected, and how OpenAI allegedly acquired and used them.

The amended filing also raises the stakes for OpenAI’s previously asserted bad faith defense under Section 1836(b)(3)(D). With xAI now presenting a more detailed and documentary record, OpenAI’s claim that the lawsuit was filed “for publicity or competitive reasons” may face a steeper climb.

Now all eyes will be on how OpenAI chooses to respond. We will be monitoring the docket closely, as this case is shaping up to be one of the most high-profile trade secrets battles in the AI industry.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.


[1] If you are interested in learning more about the nuts and bolts of how large language models like Grok and ChatGPT work, I highly recommend Duke Law Professor Nita Farahany’s Substack, where she opens up her AI Law and Policy course to the general public, and makes the technical concepts extremely accessible. I did not have the pleasure of having a class with Professor Farahany while I was at Duke, so I’m pleased to be learning from her now!

OpenAI Fires Back: The Latest in xAI’s Trade Secret Lawsuit

The high-profile litigation between xAI and OpenAI continues to escalate, with new filings that lay bare the deepening legal and reputational battle between Elon Musk’s AI startup and the industry leader he helped found.

In early October, OpenAI filed both a motion to dismiss xAI’s complaint and an answer and affirmative defenses. Together, the filings portray xAI’s trade secret suit as a vindictive effort to generate bad publicity, rather than to vindicate any legitimate intellectual property rights.

OpenAI’s Motion to Dismiss

OpenAI’s motion to dismiss, filed October 2, 2025, argues that xAI’s trade secret claims fail as a matter of law because xAI does not plausibly allege that OpenAI ever acquired, used, or even knew about xAI’s alleged trade secrets.

The motion methodically walks through xAI’s allegations about its former engineers, Xuechen Li and Jimmy Fraiture, but argues that the complaint “stops short of claiming that OpenAI sought xAI trade secrets through them, that they ever transferred trade secrets to OpenAI, or that they used those secrets at OpenAI.” The filing stresses that Li allegedly uploaded xAI code to a personal cloud account, not to any OpenAI system, and that Fraiture deleted any downloaded materials before joining OpenAI.

OpenAI also urges the court to strike portions of the complaint that name other former xAI employees who later joined OpenAI but are not alleged to have misappropriated anything. It argues those allegations are “immaterial” and “scandalous” under Rule 12(f), intended only to publicly smear current OpenAI employees.

The filing closes with a request for full dismissal of the complaint, or, in the alternative, an order striking paragraphs 114–115 of xAI’s pleading. The hearing is scheduled before Judge Rita Lin on November 18, 2025.

The Answer and Affirmative Defenses

OpenAI filed its answer and affirmative defenses on the same day, offering a direct and sharply worded response to Musk’s accusations. The document opens with a statement that “xAI has filed this groundless trade secret lawsuit” and personally accuses Elon Musk of using litigation “to distract from the failures of his own competitive AI effort.”

Among its key factual rebuttals, OpenAI emphasizes that:

  • Li never joined OpenAI. OpenAI admits it extended Li an offer on July 28, 2025, which he accepted by August 1, but confirms that it revoked the offer shortly thereafter. The revocation, though not explained in detail, appears consistent with OpenAI’s claim that it “had no role in Li’s alleged actions” and did not want any involvement once the allegations against him surfaced.

  • Recruiting communications were routine. OpenAI includes screenshots of its recruiter’s emails and a DocSend link to a benefits packet to refute xAI’s claim that a “cloud storage link” was used to solicit stolen code.

  • Fraiture’s conduct predated his employment. OpenAI notes that Fraiture allegedly downloaded code while still at xAI and deleted it before joining OpenAI.

The answer also sets out fourteen affirmative defenses, ranging from failure to state a claim, waiver, and estoppel, to a notable fourteenth defense: that xAI’s claims are “frivolous, unreasonable, and brought in bad faith.” OpenAI specifically invokes 18 U.S.C. § 1836(b)(3)(D), which allows defendants in DTSA cases to recover attorneys’ fees where a trade secret claim is brought in bad faith.

Bad Faith Under the DTSA

One of the most strategically significant aspects of OpenAI’s filing is its reliance on the DTSA’s bad faith fee-shifting provision, § 1836(b)(3)(D), which authorizes courts to award reasonable attorneys’ fees to the prevailing party when a misappropriation claim is made “in bad faith,” when an injunction is sought or opposed in bad faith, or when misappropriation is willful and malicious.

What Does “Bad Faith” Mean Under the DTSA? 

The definition of “bad faith” under the DTSA is unsettled, and different circuits apply slightly different standards. In the Southern District of New York, Judge Liman’s recent opinion in Recoop LLC v. Outliers Inc., No. 22-cv-4535, 2025 WL 1725024 (S.D.N.Y. June 20, 2025), provides a very comprehensive overview. There, the court reviewed competing formulations across jurisdictions:

  • The Second Circuit has not adopted a uniform rule but generally follows the two-part meritlessness and improper purpose test, tracking the common law fee-shifting standard. See Insurent Agency Corp. v. Hanover Ins. Co., 2020 WL 86813 (S.D.N.Y. Jan. 9, 2020).

  • The Third Circuit requires proof that the plaintiff completely lacked evidence and knew, or was reckless in not knowing, that its claims lacked merit. See Elmagin Cap., LLC v. Chen, No. 22-2739, 2024 WL 2845535, at *5 n. 14 (3d Cir. Mar. 21, 2024).

  • The Seventh Circuit takes a broader approach, finding bad faith where claims are frivolous or maintained for improper purposes such as harassment or delay, or needless increase in the cost of litigation. See LQD Bus. Fin., LLC v. AKF, Inc., 2025 WL 830444, at *4 (7th Cir. Mar. 17, 2025).

  • The Sixth Circuit demands evidence that “that a party’s claim was meritless, that the party knew at a certain point that it was meritless and nonetheless maintained it, and that the party brought or maintained the claim for some improper purpose.” Shepard & Assocs., Inc. v. Lokring Tech., LLC, 2025 WL 1420931, at *4 (6th Cir. May 16, 2025).

  • The Fourth Circuit, by contrast, holds that a DTSA claim is not made in bad faith if it had “at least some chance of success,” and that a finding of bad faith “requires, at a minimum, that the plaintiff’s ‘claim had no chance of success under existing law.’ ” Akira Techs., Inc. v. Conceptant, Inc., 773 F. App’x 122, 125 (4th Cir. 2019) (quoting Tullidge v. Bd. of Supervisors of Augusta Cty., 391 S.E.2d 288, 290 (Va. 1990)).

In Recoop, Judge Liman concluded that most courts require both (1) objective speciousness (the absence of a reasonable factual or legal basis) and (2) subjective bad faith (an improper motive). Applying that framework, the court denied the defendant’s motion for fees, finding that the plaintiff’s weak but colorable claims did not satisfy that dual showing (“a failure of proof does not alone establish that the claim was brought in bad faith.”).

Illustrative DTSA Cases

The cases below further illustrate how courts apply (and often reject) bad faith fee requests:

  • TransPerfect Global, Inc. v. Lionbridge Technologies, Inc., No. 19-cv-3283 (DLC), 2022 WL 2119344 (S.D.N.Y. May 31, 2022): After granting summary judgment for defendants, the court denied fees, holding that although TransPerfect’s claims lacked evidentiary support, defendants failed to show the “high degree of bad faith” required under the DTSA.

  • Design Gaps, Inc. v. Hall, No. 3:23-cv-186-MOC, 2024 WL 203244 (W.D.N.C. Jan. 18, 2024): The court dismissed the DTSA claim for failure to identify any cognizable trade secret but declined to award fees, emphasizing that “transparently flawed” pleadings alone do not prove dishonest intent.

  • RJB Wholesale, Inc. v. Castleberry, 788 F. App’x 565 (9th Cir. 2019): The Ninth Circuit reversed a fee award, holding that even meritless trade secret claims do not justify fee shifting without evidence of improper motive or intentional abuse of process.

OpenAI’s Litigation Strategy

Bad faith fee awards under the DTSA remain rare and demand a high evidentiary showing. But OpenAI’s invocation of this defense is telling. It signals that OpenAI is preparing not only to defend the lawsuit but also to argue that xAI filed it to inflict reputational harm and deter employee movement. If successful, OpenAI could recover attorneys’ fees and set an influential precedent discouraging companies from using trade secret litigation as a competitive weapon in Silicon Valley’s AI arms race.

Why It Matters

If OpenAI succeeds in persuading the court that xAI’s claims were brought in bad faith, it could do more than win the lawsuit against it. A favorable ruling under the DTSA’s bad faith provision would help define how courts interpret and apply the DTSA’s fee-shifting provision and, in doing so, bolster the strategy for defendants to go on offense in trade secret litigation. Rather than simply defending against misappropriation allegations, OpenAI is using the DTSA to challenge the motives and methods behind the claim.

All eyes will now turn to the November 18 hearing before Judge Rita Lin, and we will keep this page updated accordingly.


Sarah Tishler is the author of this article. Sarah is a partner at Beck Reed Riden LLP. She is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.

xAI v. Li Trade Secret Litigation Heats Up: Criminal Exposure and Fifth Amendment Battles

The litigation storm surrounding xAI is no longer just a civil employment dispute. In the case against its former engineer, Xuechen Li, there are now high-stakes battles implicating both the civil trade secret misappropriation claim, and the federal criminal investigation that is also taking place. 

The Fifth Amendment and the Li Case

xAI’s case against its former engineer, Xuechen Li, took a dramatic turn when it emerged that federal prosecutors were investigating him for trade secret theft. According to Li’s filings, the day before xAI filed its civil complaint, the FBI executed coordinated search warrants on his residence, his vehicle, his person, and his hotel room. Agents seized three cell phones, multiple computers, notepads, notebooks, books, bank receipts, keys, and a flash drive. Li has been formally informed that he is the subject of a federal criminal investigation.

This backdrop has shaped the discovery fight. xAI obtained a temporary restraining order on September 2 requiring Li to turn over devices, accounts, and identify all storage locations where xAI’s confidential information might be found. But Li’s lawyers argue that compliance would effectively force him to admit the possession and movement of stolen data—admissions that could be used against him in a criminal case. In their briefs, they describe xAI’s requests as “wide-ranging, broad-sweeping discovery specifically designed to provide a ‘link in the chain’ to be used by law enforcement.”

Li has therefore invoked the Fifth Amendment against many of xAI’s interrogatories and production requests, particularly those requiring him to identify devices, accounts, or people to whom xAI data may have been disclosed. He argues that responding would not just be embarrassing or inconvenient but would directly map onto the factual questions prosecutors are pursuing.

Judge Rita Lin’s September 9 order struck a middle ground: Li must appear for deposition and respond to discovery, but he may assert the Fifth Amendment on a question-by-question basis. The court also authorized xAI to begin third-party discovery “without further delay.” The preliminary injunction hearing is scheduled for December 2, 2025.

The practical reality is stark: Li faces a choice between protecting himself in the criminal action with his silence, and the civil consequences of doing so. Refuse to answer, and xAI could argue adverse inferences; answer, and the responses could feed the criminal case. For xAI, leveraging that tension is now surely part of its litigation strategy, not just against Li, but against his new employer, OpenAI.

Why the FBI Is Involved: Theft of Trade Secrets Under 18 U.S.C. § 1832

To understand the gravity of the situation, it is instructive to look at how aggressively the U.S. government prosecutes trade secret theft. These aren’t run-of-the-mill civil cases — in many instances, they are high-stakes criminal prosecutions.

  • In May 2022, Dr. Xiaorong You (aka Shannon You) was sentenced to 168 months (14 years) in prison plus three years of supervised release and a $200,000 fine after a jury convicted her of conspiracy to commit trade secret theft, economic espionage, and wire fraud. Her offenses involved stealing proprietary formulations for BPA-free coatings during her work at major chemical companies.

  • On December 16, 2024, Klaus Pflugbeil was sentenced to 24 months in prison after pleading guilty to conspiring to send trade secrets belonging to a U.S.–based electric vehicle company.

  • In January 2022, Xiang Haitao, a Chinese national, pleaded guilty to conspiracy to commit economic espionage. His scheme involved the theft of proprietary software developed by Monsanto’s subsidiary to improve crop yields, with the intent of benefiting a foreign entity.

These prosecutions underscore how seriously federal authorities treat trade secret failures. Under § 1832, to obtain a conviction the government must prove that:

  1. The defendant improperly obtained or stole the information. 
  2. The defendant knew it was proprietary. 
  3. The information qualified as a trade secret. 
  4. The defendant intended to use it for someone other than the owner. 
  5. The defendant knew the owner would be harmed. 
  6. The trade secret related to a product or service in interstate or international commerce. 

Under § 1832, the sentence has the potential to be steep. Each count under § 1832 carries a maximum of 10 years in prison, along with substantial fines. That context makes it clearer why Li is fighting so hard to avoid admitting where he stored data, which devices he used, or whether information was transmitted internationally. Doing so could provide prosecutors the missing link in a criminal case against him.

The Broader xAI v. OpenAI Case

The developments in the Li case also implicate xAI’s broader lawsuit against OpenAI, which I wrote about in a previous post. That complaint alleges that OpenAI recruited Li and other employees to bring over Grok’s source code, inference systems, business strategies, and confidential data center deployment methods. If the civil case establishes that OpenAI knowingly benefited from misappropriated information, remedies could even include injunctions that affect OpenAI’s flagship products.

The Fifth Amendment issues in xAI v. Li may reverberate in the OpenAI case. If key witnesses refuse to answer discovery on criminal grounds, xAI will need to rely heavily on forensic evidence, third-party records, and circumstantial proof to connect the dots back to OpenAI. And if prosecutors bring a criminal case against Li, the effects could be dramatic: a conviction or guilty plea would essentially establish that xAI’s trade secrets were stolen, easing xAI’s burden in the civil action. It could also create reputational and regulatory pressure on OpenAI, even if the company is not a criminal defendant, by reinforcing xAI’s narrative of systematic misappropriation. Finally, evidence generated in a criminal prosecution (such as transcripts, forensic reports, or plea admissions) could provide xAI with powerful new material to use in its case against OpenAI.

In short, a criminal prosecution against Li could transform the OpenAI case. Today, xAI has to overcome Li’s Fifth Amendment silence with circumstantial evidence. If prosecutors secure a conviction or guilty plea, xAI would suddenly have a government-backed record that its trade secrets were stolen. That shifts the battleground in xAI v. OpenAI from “was there a theft?” to “what did OpenAI know, and when did it know it?”

Why It Matters

The FBI investigation into Li highlights the grim reality that in any high-stakes AI disputes, like high-stakes trade secret disputes more generally, the exposure may not just be civil liability; individuals may face criminal exposure. For xAI, the Fifth Amendment fights may delay discovery but also amplify the gravity of the underlying claims. For Li, silence may be the safest legal posture, but it comes with significant risk in the civil litigation.

And for OpenAI, the outcome of a potential prosecution against Li could be pivotal. A conviction would validate xAI’s claims of theft and shift the focus of the civil litigation away from whether xAI’s trade secrets were taken, and onto what OpenAI did with them. That reframing would dramatically strengthen xAI’s position, leaving OpenAI to defend not the existence of a theft, but its own knowledge and conduct.

As xAI presses forward against both Li and OpenAI, the fight over AI’s next frontier is playing out not just in labs and markets, but in courtrooms where the stakes include market dominance, criminal exposure, and the integrity of some of the most valuable trade secrets in the world.

 


Sarah Tishler is the author of this article. Sarah is a commercial litigator whose practice focuses on complex business disputes in state and federal courts, including intellectual property, breach of contract, and fraud claims. Her experience also includes regulatory investigations, international arbitration, securities litigation, shareholder litigation, class-action litigation, and pre-transactional advising.

 


eck Reed Riden LLP is among the leading authorities in trade secret, noncompete, and unfair competition law, and our experience handling these matters is backed by our extensive employment law and business litigation experience. Our hand-picked team combines attorneys with complementary expertise and practical experience.

Beck Reed Riden LLP is Boston’s innovative litigation boutique. Our lawyers have years of experience working with clients ranging from Fortune 500 companies to start-ups and individuals. We focus on business litigation and employment.

We are experienced litigators and counselors, helping our clients as business partners to resolve issues and develop strategies that best meet our clients’ legal and business needs – before, during, and after litigation. We’re ready to roll up our sleeves and help you. Read more about us, the types of matters we handle, and what we can do for you here.