Apple told a federal court on Monday that a former employee's use of its confidential information inside OpenAI's AI systems creates a new category of harm, one that cannot be undone with traditional legal tools. The company filed a supplemental brief supporting expedited discovery in its trade-secret lawsuit against OpenAI, arguing that feeding secrets into a model that "learns" from them produces "irreversible and continually propagating uses" that are "uniquely challenging to undo."

The filing

Apple's attorneys wrote that the former employee's "use of AI agents to learn to run simulations raise concerns extending beyond ordinary document theft." The brief does not name the employee or specify which secrets were involved. It frames the risk as structural: once a model absorbs proprietary data, the influence of that data persists in the system's outputs in ways a court order to delete files cannot reach.

The precedent

A related but distinct claim surfaced in Elon Musk's xAI lawsuit against OpenAI, dismissed in June. That complaint alleged former xAI engineer Xuechen Li stored xAI's entire codebase in a personal cloud account linked to his personal ChatGPT account as a connected "Source," giving OpenAI a pathway to the code. The judge threw out the case. Rutgers law professor Camilla Hrdy said the underlying dynamic is not new, employees have always carried knowledge in their heads, but plugging that knowledge into an AI system represents a "real loss of control" that existing law has not yet calibrated for.

The technical problem

Michigan State computer science professor Sijia Liu, who co-authored a paper on "machine unlearning," said the remedy depends on how the secret entered the system. If a document sits in a retrieval repository, deleting the file may suffice. If the secret was used to train or fine-tune a model, the fix becomes resource-intensive and uncertain. "The influence of something is really difficult to evaluate," Liu said. "You have to precisely define the boundary of unwanted capability."

The remedies

Hrdy said courts already have the standard toolkit: injunctions to stop use and disclosure, orders to protect the secrets, and damages measured by actual losses or reasonable royalties. No novel legal framework has emerged. The open question is whether a technical "detection system" can flag when a model is reproducing protected knowledge, and whether any court will treat that as sufficient compliance.