The legal battle between Apple and OpenAI over alleged trade secret misappropriation offers a cautionary lesson for HR leaders. Protecting sensitive information is not just an IT or legal function. It is an employee lifecycle issue that begins during recruiting and continues through offboarding, according to experts.
Apple sued OpenAI and two former Apple employees in July, alleging a coordinated campaign of corporate espionage and trade secret theft. Apple alleges that one former employee downloaded confidential files and that another, OpenAI’s chief hardware officer, directed candidates to bring Apple hardware parts to interviews. OpenAI has denied the allegations, saying it has no interest in other companies’ trade secrets.
Neither Apple nor OpenAI responded to requests for comment.
For HR, the case highlights two sides of the same risk: ensuring new hires are not asked about protected information from their former employers and making sure departing employees do not take an organization’s confidential information with them.
“There is a lifecycle to trade secrets, and it starts in the onboarding process,” said Justin Beyer, an attorney in the Chicago office of Saul Ewing. “I tell clients that trade secret protection is as much about knowledge and communication as it is any back-end technical software.”
Establish Expectations at the Start
Organizations often think about confidentiality agreements as something employees sign when they accept a job. But Beyer recommends addressing the issue even earlier, particularly when candidates are finalists.
“With onboarding, employers could consider having finalist candidates sign simple NDAs where it is made clear that you are not seeking confidential information in the interview process,” he said. “Having that signed at the outset will notify candidates that the employer is looking to hire them for general skills and knowledge and not anything specific that they may be bringing from a former employer.”
That communication serves a broader purpose than legal protection.
“That’s important to do because it presents a culture of confidentiality,” Beyer said. “It sets the tone at the outset that protecting information, whether it’s someone else’s information or our own, is important.”
For HR, that means recruiters and hiring managers should be trained on the boundaries of appropriate interviewing. Candidates can discuss their experience, capabilities, and accomplishments, but interviews should not become opportunities to solicit proprietary information about a competitor.
“The guidepost I would use: if you are an employer with a strong intellectual property protection program, I would not ask for information that you would not want your competitors having access to,” Beyer said. “Don’t ask about specific customers, contact information, vendor terms, or products.”
Stacy Thomsen, an attorney in DarrowEverett’s Providence, R.I., office, similarly cautioned employers against probing candidates for information they know could be protected.
“You can poke and prod into a candidate’s work history, and there is nothing wrong in asking if they are subject to an NDA,” Thomsen said. “But to the extent that you are directly asking somebody about things that you know are trade secrets or confidential information, that is clearly not allowed.”
Treat Real Trade Secrets Like Secrets
Having a confidentiality policy is not enough. Employers also need to demonstrate that they actually treat sensitive information as confidential.
“This is very important. The court will ask whether or not you treated the information in question like it was a trade secret while you had possession of it,” Thomsen said.
That can become difficult when organizations broadly label documents as confidential without limiting who can access them.
“Many employers over-label things as confidential or trade secrets, but that tactic can bite you later,” she said. “If you treat everything that way, then those aren’t really trade secrets.”
Instead, employers should identify genuinely sensitive information and limit access based on business need.
“The key is making sure that true confidential information is only shared with people who have a need to know about it,” Thomsen said. “If someone doesn’t need access to it they shouldn’t have access to it.”
That principle should be reflected in HR information systems as well as broader enterprise technology. HR systems contain compensation information, benefits data, performance evaluations, and employee records, making access management an important component of HR governance. Role-based permissions should be reviewed when employees change jobs or responsibilities, and access should be removed promptly when employment ends.
Make Offboarding a Coordinated Process
The Apple allegations underscore why offboarding cannot be treated as an administrative checklist that HR completes after an employee’s last day.
“Offboarding is crucial,” Thomsen said. “You must have standard offboarding checklists for all employees, rigorously maintained.”
She recommended an immediate and coordinated cutoff of access. “If somebody is terminated and maintains access, there is potential to take things. Access to email, VPN, and cloud credentials should be shut off, and hardware collection should happen before or at the exit meeting,” she said.
Organizations should also consider reviewing activity before departure. “On the back end, employers can do a forensic review of any activity leading up to the employee’s departure,” Thomsen said. “Check to see that there are no massive downloads or data transfer.”
Beyer likewise recommended making device and access management part of the formal offboarding process.
“During offboarding, employers need to be particularly diligent in collecting devices, and cutting off access to devices as quickly as possible,” he said. “What is your policy around device access management? Do you keep track of when a device is issued? And when it is returned?”
This requires close coordination between HR, IT and security. HR may initiate the departure process, but other functions are responsible for executing critical controls.
“HR may need to reach out to IT to make sure access is cut off and devices collected. And IT needs to let HR know when that has been done,” Beyer said.
Don’t Overlook BYOD and Remote Work
The proliferation of cloud applications, personal devices, and remote work has made traditional offboarding more complicated. An employee may have accessed sensitive information through a personal smartphone, cloud storage account, or other platform that is not physically controlled by the employer.
“Many employers have BYOD [bring your own device] policies in place,” Beyer said. “Employees are using their personal smartphones to tap into company sensitive information through off-the-shelf platforms like Google Drives or Google Docs. Make sure that access is cut off and that employees are not able to migrate that information to another source.”
Exit interviews can provide another opportunity to close gaps. “During exit interviews, HR could ask departing employees about any devices they may still have, other than the ones they are currently using,” Beyer said. “Make the device return process for remote workers as seamless as possible.”
Thomsen also noted that employers may take different approaches when an employee gives notice, particularly when the person is moving to a direct competitor.
“In the case of someone who gives notice, you could monitor their activity to make sure there is nothing suspicious going on,” she said. “I know some clients who don’t want that risk, so if someone gives their notice, they will release that person early with pay. It’s also helpful to know where an employee is moving to, and if it is a direct competitor, that would be useful information as well.”
Build a Culture of Confidentiality
Ultimately, trade secret protection cannot rest on technology alone. Access controls, monitoring tools, and automated offboarding are important safeguards, but employees also need to understand what information is protected and what the organization expects of them.
“Ensure that you are educating employees how to treat confidential and trade secret information in their day-to-day work,” Beyer said.
That education should be ongoing. He recommended annual or semiannual training so employees understand their responsibilities.
“When employees leave the organization, they should leave with the knowledge of what the company considers to be trade secrets, and what it means to protect that information,” Beyer said.
Was this resource helpful?