OpenAI Points to Apple's Internal Security Gaps in Trade Secrets Defense
Court filings reveal how OpenAI is turning Apple's own offboarding practices into a central argument against the iPhone maker's intellectual property claims

A Legal Strategy Built on the Plaintiff's Weaknesses
OpenAI has filed new court exhibits that lay bare its defense strategy in the ongoing trade secrets case brought by Apple: demonstrate that the iPhone maker's own internal security protocols were too lax to merit legal protection under trade secret law. At the heart of the argument is a practice that raises questions about how seriously Apple treated the confidentiality of the information it now claims was misappropriated.
Court documents reveal that an Apple manager was permitted to access the iCloud account of a former engineer after that employee had already departed the company. For OpenAI's legal team, this single fact crystallizes a broader vulnerability in Apple's case. Under U.S. trade secret law, companies must take reasonable measures to maintain secrecy. If the owner of the information fails to protect it adequately, courts may decline to enforce those claims, regardless of whether unauthorized disclosure occurred.
The Reasonable Measures Test
Trade secret litigation hinges on a deceptively simple question: did the company do enough to keep the information secret? The legal standard, codified in the Defend Trade Secrets Act and mirrored in state statutes, requires that owners take steps that are "reasonable under the circumstances" to preserve confidentiality.
What counts as reasonable varies by industry and context. In technology companies, where intellectual property often resides in code repositories, internal wikis, and cloud storage, the bar is high. Companies typically implement role-based access controls, exit interviews that include device return and credential revocation, and strict policies around personal accounts used for work purposes.
OpenAI's filing suggests that Apple's practices fell short of this standard. Allowing a manager to retain or gain access to a departed employee's iCloud account after termination creates a trail of access that undermines any claim that the information was closely held. If multiple individuals, including those no longer bound by employment agreements, could view or retrieve the material, courts may conclude that the trade secret status was forfeited.
Offboarding as a Vulnerability
The specific allegation around iCloud access points to a broader issue in corporate offboarding. At DailyTechWire, we have tracked how Asia-Pacific tech firms, particularly those in Seoul, Shenzhen, and Singapore, have tightened exit protocols in response to high-profile IP disputes. Samsung and Huawei, both veterans of trade secret litigation, now mandate immediate credential revocation and forensic audits of departing employees' activity logs.
Apple's alleged lapse is striking precisely because the company has long positioned itself as a leader in security and privacy. The juxtaposition between external messaging and internal practice is a gift to OpenAI's defense. If Apple cannot secure its own employees' accounts during the sensitive offboarding window, the argument goes, how can it credibly claim that the information those accounts contained was treated as a protectable trade secret?
This line of reasoning also implicates Apple's broader cloud infrastructure. iCloud accounts are consumer-facing products, not enterprise-grade vaults designed for sensitive corporate IP. The decision to allow work-related information to reside in personal iCloud storage, and then to permit managerial access post-employment, suggests a failure to segregate corporate assets from personal data. That failure, OpenAI will argue, is fatal to Apple's case.
Precedent and the Risk to Apple
Trade secret plaintiffs have lost cases on precisely these grounds before. In one notable dispute, a federal court in California ruled that a software company's failure to consistently mark documents as confidential or restrict access to a need-to-know basis undermined its claim. The court found that the company's "haphazard" approach to secrecy meant the information was not entitled to protection, even though the defendant had clearly taken the material.
OpenAI's strategy mirrors that playbook. By spotlighting Apple's inconsistent security practices, the defense shifts the narrative from "did the defendant steal?" to "did the plaintiff adequately protect?" This is not a technical legal maneuver. It reflects a substantive requirement baked into trade secret law: secrecy is not an inherent property of information. It is a status that must be actively maintained through concrete, enforceable measures.
For Apple, the stakes are reputational as well as legal. A ruling that its security practices were insufficient could invite scrutiny from regulators, partners, and customers who have trusted the company's privacy commitments. It also sets a precedent that could embolden other defendants in future IP disputes involving Apple.
Implications for the Tech Sector
This case arrives at a moment when cross-border talent mobility in tech is accelerating. Engineers routinely move between competitors, carrying institutional knowledge, design patterns, and strategic insights. The line between general skills and protectable secrets is often blurry, and courts have grown skeptical of overbroad trade secret claims that effectively prevent employees from working in their field.
OpenAI's defense, if successful, would reinforce that skepticism. It would signal that companies cannot rely on vague confidentiality agreements or post-hoc assertions of secrecy. Instead, they must implement and enforce robust technical controls, document those controls, and apply them consistently across all employees, including senior managers.
The iCloud access issue also highlights a tension between consumer convenience and enterprise security. Many technology workers use personal Apple IDs for work-related tasks, syncing notes, photos of whiteboards, and drafts of code. Companies that tolerate this practice, or fail to enforce strict separation between corporate and personal accounts, expose themselves to the kind of scrutiny Apple now faces.
What Happens Next
The court will likely examine Apple's security policies in granular detail: access logs, offboarding checklists, training materials, and internal communications about trade secret protection. OpenAI will push for discovery that reveals how consistently these policies were applied. Any deviation, any exception granted to a senior employee or overlooked in a manager's exit, becomes ammunition for the defense.
Apple, for its part, will need to argue either that its practices were reasonable given the context, or that the specific information at issue was protected through other means. It may also attempt to distinguish between the general laxity OpenAI alleges and the particular controls applied to the engineer in question. But the iCloud access revelation is a difficult fact to explain away, especially for a company that has built its brand on security.
The outcome will hinge on how the judge interprets the "reasonable measures" standard. If the bar is set high, requiring enterprise-grade controls and zero tolerance for post-employment access, Apple faces an uphill battle. If the court adopts a more forgiving view, one that accounts for the realities of modern cloud-based work, the case may survive this challenge and proceed to the merits.
Either way, the dispute offers a reminder that in trade secret litigation, the plaintiff's own conduct is always on trial. OpenAI has identified a weak point in Apple's armor and is pressing hard. How the court responds will shape not only this case, but the expectations placed on every technology company that seeks to protect its intellectual property through the courts.


