Skip to Main Content
  • About Us
  • People
  • Capabilities
  • News & Insights
  • Events
  1. Insights
  2. Publications

Dan Schwartz Co- Authors The Legal Intelligencer Article Entitled “When the Stolen Trade Secret Was Never Copied: AI-Accumulated Context and the Employer’s Vanishing Evidence Trail"

Articles

September 17, 2026

Lawyers

Biography Photo of Daniel Schwartz
Daniel A. Schwartz

Partner

860.251.5038

dschwartz@goodwin.com
  • -

A forensic examination revealed months of employee activity on a personal Al account containing sensitive company information-not through uploaded files, but through accumulated conversational context that could reconstruct trade secrets via prompts, exposing a critical gap in traditional data loss prevention systems that employers must address before departures occur rather than after.

The forensic examination came back too clean, and that was the first red flag.

A company did the usual things after a senior employee resigned. It preserved the laptop, pulled the logs, and asked an examiner to look for the familiar signs of trade secret theft on the way out. No bulk file movements. Nothing to removable media, a personal cloud account, or a personal email address at eleven at night. What it found instead was months of activity running through a personal Al account on the company laptop, concentrated around the company's most important development initiatives.

The company was not hostile to Al. It had licensed Copilot for everyone, and the productivity gains were real. Its written policy prohibited other platforms, but nothing enforced it no blocking, no monitoring, nothing that would have noticed. The employee preferred a different tool, because it was familiar and it worked.

That employee had never uploaded the project plans. No attachments, no pasted documents, nothing a data loss prevention system would have flagged. But across months of ordinary working conversation, the thread accumulated enough context that a few well-chosen prompts could reconstruct the plan and the designs, in an account the employee still owned after leaving.

Not Memory, and Not a Document

Every lawyer who handles departures knows the line: general knowledge, skill, and experience leave with the employee, lawfully. The stolen document does not. An accumulated Al thread fits neither category, and in practical terms it is worse than both.

Memory does not sit on a server and cannot be searched. A document requires someone to decide to create it. An Al thread does neither. The closest analogy is a notebook on the corner of a desk, and even that undersells it a notebook requires someone to write in it. The Al thread accumulated passively, one session at a time, and can be queried by someone who has long since forgotten what they disclosed. The former employee does not need to remember the secret. They only need to ask for it.

Under both the federal Defend Trade Secrets Act (DTSA) and the Uniform Trade Secrets Act (UTSA), a trade secret is information that derives independent economic value from not being generally known, provided the owner has taken "reasonable measures" to keep it secret. See 18 U.S.C Section 1839(3). The definition easily reaches the accumulated context in an Al thread. The harder question is whether the employer can prove reasonable measures when its own policies failed to prevent the accumulation.

What the Company Can Actually See

Consider what an examination reaches once the resignation letter is in. Browser history, cache, and local application databases are the obvious places to look, and a user can wipe most of them in a minute. What survives is less convenient: registry entries and activity artifacts are harder to erase.

None of that produces content. The conversations live in an account the company does not own, and reaching them takes the former employee's cooperation, a subpoena, or a court order. In one matter, the review produced no file names at all; usage had to be confirmed from a billing record. The absence of an audit record is not evidence that nothing happened.

The Controlled Environment Is Not as Controlled as It Looks

The obvious response is to block the unsanctioned tools and route everyone into the platform you govern. For most organizations that is the right direction, but not the finish line. Blocking is leaky: providers change URLs and block lists fall behind. Monitoring consumer Al depends on which browser the employee opened and which network path they took.

Then there is the failure mode nobody plans for. In one matter, the sanctioned corporate Al summarized proprietary material, and because what left was a summary rather than the source document, it matched nothing the data loss prevention system was watching for. The approved tool became the step that defeated the control.

The sharpest version of the problem sits inside the governed platform itself. Assistant memory, the running profile a tool builds about its user, is not always stored or governed the way the conversations are. A retention policy or litigation hold can reach the chat and miss the memory; deleting a prompt does not delete what the system inferred from it. If broad access to an approved assistant produces the same accumulation, held in a layer your own hold does not reach, have you taken reasonable measures?

Courts have long held that "reasonable measures" need not be perfect, only reasonable under the circumstances. Confidentiality agreements, handbooks, password protections, need-to-know access, and secure storage have all been recognized as adequate safeguards. See, e.g., Fujikura Composite America v. Dee, 2024 WL 3261214, at *11 (S.D. Cal. 2024). But a company cannot claim protection for information it failed to treat as secret, and courts have discounted claims where nondisclosure agreements were absent or contractors were never told of their obligations. See Cashman Dredging & Marine Contracting v. Belesimo, 759 F. Supp. 3d 120 (D. Mass. 2024); Freedom Capital Group v. Blue Metric Group, 2024 WL 3331641 (M.D. Tenn. 2024). Al accumulation poses a different question: the employer may have had all the right policies, and those policies still did not reach the mechanism by which the information left.

The Intervention Point Is Now, Not the Exit Interview

Most companies treat this as a separation issue, and the instinct is expensive. By then the accumulation already exists, in an account you cannot reach, belonging to someone whose interests have just diverged from yours. Your leverage is reduced to asking politely or asking a judge.

The first move is not a control; it is an inventory. Which tools do your people actually use, on whose accounts, and is memory switched on? Most cannot answer, and the ones who think they can are reading a policy rather than a log. You cannot preserve, monitor, or credibly claim reasonable measures over an environment you have never mapped. For counsel, that map is the fastest route to knowing what can still be preserved and what is already gone.

Preserving what the company does not control is harder still. A personal Al account sits outside the employer's legal authority, so preservation depends on the departing employee's cooperation. A hold letter cannot compel production or prevent deletion, and subpoenas to providers may run into short retention windows or privacy objections. The window can close before the employer knows there is something to preserve.

The Wrong Question at the Door

Trade secret programs are built around documents, on the assumption that a secret sits somewhere, gets copied, and walks out the door. That architecture still catches the employee who leaves with the file.

Context does not behave that way. It accumulates without anyone deciding to create it and can be retrieved by someone who no longer remembers it exists. The question at the door is no longer whether the departing employee took anything. It is whether, somewhere they still have access to, enough of it survives to be asked for.

The side that asks that question first tends to control the story that follows.

Proactive Risk Reduction: What Employers Can Do Now

Start with the policy. An effective one names the approved tools, prohibits the rest for work purposes, addresses what may be entered into an Al system, and requires that memory and conversation-saving features be off when the material is sensitive. A policy in a handbook is not a control. It has to be trained, acknowledged, and refreshed.

Then move it into the employment lifecycle. Onboarding should capture acknowledgment of the policy and confidentiality terms that expressly reach information entered or generated by Al systems and prohibit keeping it in personal accounts after employment ends. Offboarding should ask directly which tools were used and, on whose accounts, and require certification that company information has been deleted. Any agreement governing trade secrets also needs the DTSA whistleblower notice; omitting it forfeits exemplary damages and fees. See 18 U.S.C. Section 1833(b)(3).

Policy without enforcement is aspiration. Where feasible, block unapproved platforms from corporate devices, monitor traffic to known consumer services, and restrict memory features in the tools you do approve. No control is perfect, and determined employees will get around most of them. That is not the point. The record of having tried is what reasonable measures are made of.

Then audit annually: what tools people actually use, which accounts hold work product, whether memory is on. Write down what you examined, what you found, and what you changed.

The Path Forward

The law of trade secrets is well established. What remains unsettled is how it applies when the mechanism of misappropriation is not a copied file but an accumulated context that lives in an account the employer cannot reach. The employers who fare best will treat Al governance as a trade secret issue rather than an IT issue, and will build the record of reasonable measures before the separation, not after.

Hunter McMahon is president of iDiscovery Solutions, an expert-led consulting firm specializing in digital forensics, e-discovery, structured data analytics, and Al-related evidence. He is the author of ''The 5-Year-Old CEO" and writes and speaks on the intersection of legal technology, artificial intelligence, and human judgment. He can be reached at hmcmahon@idsinc.com

Daniel A. Schwartz is chair of the employer defense and labor relations practice group at Shipman & Goodwin in Hartford, Connecticut. He counsels employers on trade secrets, restrictive covenants, and workforce protection strategies. He is the creator of the Connecticut Employment Law Blog and a Fellow of the College of Labor and Employment Lawyers. He can be reached at dschwartz@goodwin.com

Reprinted with permission from the [September 17, 2026 edition of the The Legal Intelligencer © 2026 ALM Global Properties, LLC, trading as Centellic. All rights reserved. Further duplication without permission is prohibited, contact 877-256-2472 or asset-and-logo-licensing@alm.com. 

Related Practices

  • Employment and Labor
  • Privacy, Cybersecurity and Data Innovation
Pay Bill Online

Keep in Touch

Stay current with our latest insights

Manage Subscriptions
  • Lawyers
  • Capabilities
  • Events
  • Diversity, Equity and Inclusion
  • Pro Bono and Community
  • Blogs and Resource Centers
  • Insights
  • Podcasts
  • Dobbs Decision Resource Center
  • About Us
  • Careers
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • Accessibility Statement

© Shipman & Goodwin LLP 2026. All Rights Reserved