Tools of the Trade (Secrets): Best Practices from Apple v. OpenAI
Protecting trade secrets is harder than you might think. It is not enough to identify a trade secret and have employees sign acknowledgements of the company’s IP policy. Follow-through turns a policy into a program. If employees can leave with company laptops containing confidential information or continue to access project repositories after departure, that failure may become part of the merits in a trade secret case.
In our last post, we used Apple’s complaint against OpenAI to show what a developed trade secret program can make possible: targeted relief for using trade secret information to effectuate an effective non-compete, rather than an actual non-compete. A program that looks strong on paper still has to work at the moment of departure.
Apple’s motion for preliminary injunction against OpenAI in the Northern District of California is a useful case study worth examining. Apple built a trade secret program. Then a departing engineer allegedly walked out with continued access and may have reportedly been working with his own older Apple team and accessing files per their request.
Why It Matters
- Apple has been one of the busiest corporate voices for narrowing injunctive relief and for testing patents rather than respecting them. It is now trying to rely on IP to obtain an injunction.
- Apple’s complaint describes a substantial trade secret program: intellectual property agreements, annual training, code named projects, need to know repositories, badge controls, and supplier chain of custody protocols.
- The preliminary injunction record may test whether that program worked in practice. OpenAI argues that Apple’s offboarding and personal-account practices left former employees with continued access, and that Apple did not adequately test whether deprovisioning worked.
- Any trade secret program is only as good as its execution. Offboarding is not an IT housekeeping item.
Apple Has Argued Injunctions Should Be Hard
It is worth being precise about Apple’s posture. Apple has told Congress that the Supreme Court’s decision in eBay v. MercExchange, 547 U.S. 388 (2006), “strikes a fair balance” and that injunctive relief should issue only where monetary relief is insufficient, after weighing the balance of hardships and the public interest. Responses of Apple Inc. to Questions for the Record, Subcomm. on Antitrust, Commercial and Administrative Law. (July 29, 2020). Apple has also been, by its own account, the single most active petitioner in challenging patents through inter partes review, telling the Supreme Court that by the end of 2020 it had filed 676 IPR petitions, more than any other party at that time. Brief for Apple Inc. as Amicus Curiae in Support of Neither Party, United States v. Arthrex, Inc., No. 19-1434, 19-1452, 19-1458 (U.S. Dec. 2, 2020). Apple’s explanation was that it is sued more than once a week and needs an efficient way to test the patents asserted against it. That is a position that, when taken across an industry, makes exclusive rights harder and slower to enforce.
Apple has pressed the same theme on standard essential patents and at the International Trade Commission, When the ITC issued a limited exclusion order barring importation of Apple Watches over Masimo’s blood oxygen sensor patents in late 2023, Apple stripped the feature from its watches and, as the New York Times reported, gave priority to lobbying Congress to rewrite the ITC’s rules, campaigning for legislation that would make some patent owners ineligible to bring complaints before the agency. Tripp Mickle, Apple Keeps Losing Patent Cases. Its Solution: Rewrite the Rules., N.Y. Times (Mar. 19, 2024). Again, none of this is unlawful or even unusual for Apple’s size and litigation exposure. But it sets up the moment. A company that has spent decades arguing that the right to exclude should be narrow and hard to invoke now needs the right to exclude, urgently, and is asking a federal judge for it.
Apple Tried to Build a Trade Secret Asset Management Program
Apple alleges that its trade secret protection program is substantial. According to the complaint, every employee signs an Intellectual Property Agreement barring use or disclosure of proprietary information during or after employment and barring departing employees from taking any documents or copies containing it. Every employee takes an annual business conduct course reinforcing the obligation to protect Apple confidential information. Projects run under internal code names. File repositories for a project are limited to employees currently working on it, and Apple only discloses individuals onto a project with a demonstrated business need. Apple’s network storage sits behind an Access Manager provisioning system, under terms of use limiting access for work purposes and warning that stored files may contain non-public details about past, present, or future products. And, critically so, Apple pleads that it “disables and prohibits access to its network storage upon an employee’s departure.” Compl. 47.
Was Apple’s Trade Secret Asset Management Program Enough?
Per the complaint, Chang Liu left Apple on January 22, 2026, for OpenAI. Compl. 55. Apple reached out to confirm he had returned his devices, to schedule an exit interview, and to have him sign the confidentiality reminder. Compl. 4, 55. He reportedly did not respond. Id. He allegedly also did not return at least one Apple owned computer. Id. 5, 55. Reportedly, within hours of leaving, he told a still employed Apple colleague, “I still have another computer” he planned to use to access Apple’s confidential information. Id. 56; see also id. 5.
Then, on or around February 9, 2026, Liu purportedly tried to access Apple’s cloud file repository and found he could still get in, the result of a then unknown authentication vulnerability. Compl. 57; see also id. 5. Over the following weeks he allegedly selected, accessed, and downloaded dozens of confidential files, including a compilation running more than a thousand pages, many expressly labeled confidential, and sent his colleague, who was still at Apple, links and pointers to specific project folders. Id. 5, 58, 60. Apple says it discovered the access through its own investigation and cut it off, and that it quickly fixed the bug. Id. 5 n.1, 60. Apple adds that its server logs show the few other users affected by the bug do not appear to have accessed or stolen its confidential information. Id. 5 n.1.
Apple’s complaint suggests that its monitoring and logging worked, because Apple says that is how it discovered Liu’s access. At the same time, it is quite possible that the exit procedures and offboarding process may have failed. It is possible that a laptop authenticated to Apple’s network left the company and remained outside Apple’s control. It is also possible that the control Apple pleads as its backstop, disabling network storage access on departure, failed for a person motivated to test it.
Apple says it has since observed a pattern of departing employees ignoring security outreach and skipping exit processes. Compl. 74, 85. OpenAI may try to substantiate that pattern, the case strategy may quickly stop being about two engineers and starts being about what exactly Apple’s offboarding control is.
The defendants dispute Apple’s characterizations of Liu’s conduct. In opposition to Apple’s preliminary injunction motion, OpenAI argues that Apple’s rushed same-day walkout process left employees without an orderly opportunity to transfer files and responsibilities, and that Apple’s own personal iCloud and residual-access practices created the access problem Apple now characterizes as misconduct. Apple Inc. v. Liu, No. 5:26-cv-07078-EJD, D.I. 97 (N.D. Cal. Aug. 31, 2026). OpenAI also argues that Apple did not test whether his access had actually been removed. and that residual access by former employees was a recurring consequence of Apple’s own practices rather than a scheme by Liu to evade them. D.I. 97.
According to Liu, Apple encouraged employees to use their personal iCloud accounts for work and even offered him free additional iCloud storage so he could keep his work files there, which is where most of them ended up. Apple Inc. v. Liu, No. 5:26-cv-07078-EJD, D.I. 104 5 (N.D. Cal. Aug. 31, 2026). He says he never received any training on removing Apple information from that account after leaving. Id. 6. Because the files lived in his personal account, Liu says he spent the week before giving notice gathering them into folders to hand off, knowing Apple would end his employment that same day. Id. 10. Liu says his own Apple supervisor was part of the effort to organize and download files using Liu’s credentials after he left Apple. Id. 14, 20. Liu agreed not to sign out of his iCloud account on his returned devices, the supervisor texted to ask whether a 64 GB drive would hold the files, and after Liu left, the supervisor stayed logged into Liu’s personal iCloud account to download the Apple materials for the team. Id. 14, 20.
Even further, Liu declares that he accessed certain materials at the request of current Apple colleagues who needed help locating information after his departure, including his former supervisor, and that he shared his credentials with a colleague only because the supervisor had not yet finished downloading the files. Id. 25, 30, 31. Those requests continued for months, at one point through an Apple group chat that Apple employees added him to. Id. 42. Apple’s Reply does not appear to include any declarations from the individuals Liu identified as working with his credentials to download information, including Liu’s own supervisor. See Apple Inc. v. Liu, No. 5:26-cv-07078-EJD, D.I. 150 (N.D. Cal. Aug. 31, 2026).
Was Apple’s Execution of its Offboarding Procedures Sufficient?
The issue is not whether Apple had a trade secret program in the abstract. It did. The issue is whether the program operated effectively when access should have ended. That question is not just on policy but also execution. Under the Defend Trade Secrets Act, information qualifies as a trade secret only if the owner “has taken reasonable measures to keep such information secret.” 18 U.S.C. § 1839(3). The measures are the plaintiff’s burden.
So, the question is not whether Apple was perfect in its protection and security. The DTSA does not require it to be. The question is: did Apple employ measures reasonably consistent with its claim that this information is among the most valuable commercial information in the country? A former employee allegedly not cooperating in exit procedures, was accessing confidential documents, using his own credentials, without Apple taking additional steps, or at worst, upon the request of his old Apple supervisor. Outside the Ninth Circuit, courts have treated comparable failures, including allowing employees to keep company information on personal devices and failing to require its return or deletion at departure, as evidence relevant to trade secret protection or emergency relief. See Yellowfin Yachts, Inc. v. Barker Boatworks, LLC, 898 F.3d 1279, 1300-01 (11th Cir. 2018); DM Trans, LLC v. Scott, 38 F.4th 608, 620 (7th Cir. 2022). At least in the preliminary injunction briefing, neither Apple nor OpenAI appear to identify a post-DTSA Ninth Circuit decision squarely addressing this offboarding fact pattern. Apple’s case may give the court the opportunity.
How Many Protectable Secrets (If Any) Are There?
A preliminary injunction is an extraordinary remedy that issues only on a clear showing that the movant is likely to succeed on the merits, likely to suffer irreparable harm, that the balance of equities tips in its favor, and that an injunction serves the public interest.
Apple’s complaint originally alleged 5 “category[ies] of secrets.” Compl. 40. Apple has since, with its preliminary injunction motion, filed a preliminary trade secret disclosure (unavailable to the public for obvious reasons) identifying 104 trade secrets, “including information contained in over twenty documents identified by file name and related Apple products.” D.I. 150-4 at 2. In less than a month, 5 has become 104 and all from roughly two dozen documents.
How are 104 trade secrets in such a small number of documents sustainable in the litigation, practically speaking? Each one is its own trade secret, with its own burden. For each, Apple has to show independent economic value from secrecy, reasonable measures to protect it, and misappropriation. Apple then must explain to a jury what the misappropriation cost it and do it in a way that identifies demonstrable damages even if some of the 104 trade secrets fall away.
Apple seems to know this. Its reply argues that even if one of its trade secrets turns out not to be secret, that “is not dispositive,” because the motion rests on “multiple discrete trade secrets.” D.I. 150-4 at 3. With the hearing set for October 14, the stage is set to see whether the newest implementation for a preliminary injunction playbook can stand the test this series wrestles with: which of the 104 identified trade secrets were treated as trade secrets and how can Apple show the difference?
Key Takeaways and Best Practices:
Don't make offboarding depend on cooperation. Device return and access revocation should not hinge on whether the departing employee returns your calls. Build the sequence so that access is revoked on the termination date whether or not anyone cooperates.
Escalate unreturned devices. A missing laptop should trigger action, not just a log entry. Treat any device that has not come back as an open security issue, and follow up until it is recovered or disabled.
Know your remote management options before you need them. Remote management of company computers can be part of the control environment, but it does not replace testing access revocation. Confirm in advance which devices can be disabled remotely and what steps will cut off repository access.
Test the cutoff the way an attacker would. Periodically try to authenticate with recently deprovisioned credentials against your crown jewel repositories.
Document the testing. A record of those tests is inexpensive now and very valuable later, because it turns "we had a policy" into "we verified the policy worked."
Differentiate trade secrets from other general and confidential information, and be able to show it. Code names, need to know provisioning and segmented repositories do more than reduce risk. They let you show a court which assets you treated as crown jewels. If a single repository does not distinguish high-level ideas from detailed plans and mechanisms, a court may struggle to tell, without more, whether the company had reasonable measures in place to protect its most sensitive information.
Keep offboarding procedures confidential, but assume they will leak. An internal document describing forensic and security checks is itself a security asset. Design controls that still work even if the person subject to them knows how they work.
Strong evidence does not cure weak process. Apple may win this case. The conduct alleged is serious, and the evidence Apple has gathered is substantial. But Apple now has to defend its own controls while it argues for an injunction.
Policy is not the same as practice. Apple may win this case. The conduct alleged is serious, and the evidence Apple has gathered is substantial. But the preliminary injunction fight teaches the same lesson as the rest of this series: trade secret protection is not a document set, a training module or a repository label. It is operating discipline, and that program has to work when someone leaves.


