17.08.2026

Firing Over ChatGPT: What Counts as a Leak When Staff Feed Work Data to AI

Feeding work data into a model can destroy trade secret status, and a court has already ruled on it. What counts as reasonable measures and when a dismissal holds.

Firing Over ChatGPT: What Counts as a Leak When Staff Feed Work Data to AIFiring Over ChatGPT: What Counts as a Leak When Staff Feed Work Data to AI

Data counts as disclosed the moment it reaches a recipient under no duty of confidentiality, and whether an outsider actually read it makes no difference. Pasting a work document into a chat with a model is a transfer of information to a third-party provider's servers. Two independent mechanisms then start running: the information loses its status as a protected secret, and the employer gains grounds for a disciplinary response.

The first mechanism has already played out in court; the second is written into statute.

Feeding a model can destroy trade secret status

The most uncomfortable consequence surfaced in a US court. In Trinidad v. OpenAI, the plaintiff claimed rights in methodologies and protocols she had developed through her conversations with ChatGPT. The Northern District of California dismissed her claim under the Defend Trade Secrets Act, and dismissed it for good.

The reasoning is short. The statute protects information on condition that its holder took reasonable measures to keep it secret. By entering the information into a third-party service, she disclosed it voluntarily, and the condition stopped being met.

What reasonable measures are

Reasonable measures are what a company actually did to keep the information secret. A secret does not arise from wishing to have one: with no measures there is nothing to protect, and the dispute ends before it starts. Courts look at the whole picture and at whether the effort was proportionate to the value being protected. In practice the measures fall into four groups.

Table: what an AI usage policy should prohibit

No single group carries the case. An NDA without access control reads as a formality, and access control without marking fails to show that the person knew what the material was worth. The reverse fails too: rules that sit in a folder and were never applied are read as no rules at all.

Entering information into a public service hits all four groups at once: the recipient is under no duty of confidentiality, movement across the perimeter went uncontrolled, marking means nothing outside the company, and the record of practice shows the opposite of what it should.

The plaintiff acted without counsel, and she created the methodologies in dispute inside those conversations, so the court was looking at an extreme case with no protective measures at all. A developer who pastes a block of closed source into a chat to have it refactored weakens the reasonable-measures argument, at least where the service is used on consumer terms with no enterprise confidentiality agreement in place. Suing a competitor who later reproduces the same logic becomes materially harder. Samsung restricted external models on work devices in 2023, after a series of incidents in which engineers uploaded source code to ChatGPT.

Service terms differ here, and the difference matters. On consumer tiers, training on conversations is on by default and the switch that turns it off sits buried in the interface. On enterprise tiers and through the API, providers do not train on customer data by default.

In the EU this is personal data processing

The moment a client's name, address, phone number or payment details lands in a prompt, the company acts as a controller sending personal data to a third party. On consumer terms, with no processing agreement in place, that recipient is not a processor at all: it handles the data for its own purposes, which leaves the company worse off. That calls for a lawful basis, a processing agreement, and a view on where the data physically travels.

For example, the Garante fined OpenAI 15 million euros, and the Court of Rome annulled the fine. It annulled on competence: once OpenAI's Irish establishment was recognised, supervision passed to the Irish authority. The court did not rule on the substance of the allegations, and controller obligations survive the annulment untouched.

The UAE applies two laws at once

One governs the data, the other governs the dismissal.

Data. Federal Decree-Law No. 45 of 2021 requires the controller to maintain technical and organisational safeguards, to notify the regulator and the data subject of a breach, and it restricts transfers outside the country to jurisdictions without an adequate level of protection.

Dismissal. Federal Decree-Law No. 33 of 2021 sets out, in Article 44, a closed list of ten grounds for dismissal without notice. Disclosure of work secrets related to industrial or intellectual property is on that list, with the qualifier that usually decides the case: the disclosure has to cause loss to the employer, a lost opportunity, or personal gain for the employee. A leak of client personal data does not squarely fall under that wording; the data protection statute governs there.

Table: the four groups of reasonable measures protecting a trade secret

The Article 44 list is exhaustive, and no order or internal regulation can extend it. An employer who invokes Article 44 and fails to prove the ground loses the right to dismiss without notice: the employee keeps the notice allowance and the end-of-service gratuity. The separate Article 47 compensation of up to three months' wage, calculated on the last wage received applies in a narrower case — where the dismissal answered the employee's complaint to the Ministry or a lawsuit the employee won.

Effort at some companies goes into banning models, which staff route around from a personal phone in under a minute, while the documents stay as they were. The construction that works is different: write into the employment contract a list of data that may never be sent out, name the permitted services, keep technical logging of data leaving the perimeter. Dismissals are won on documents assembled in advance.
— Futura Digital's assessment

What never goes into a model

  • Passwords, access keys and tokens.
  • Personal data of clients and staff.
  • Closed company code and internal technical documentation.
  • Information on upcoming releases, deals and negotiations.
  • Anything covered by a non-disclosure agreement with a counterparty.

An instruction inside the prompt along the lines of "do not remember this" offers no protection: the data has already been sent by that point, and the wording itself shows the sender knew about the risk.

The first day after an incident

STEP 1 — Close the source

Cut access to the service and to the account the data went through. Until this step, the volume of the leak keeps growing.

STEP 2 — Record the facts

Write down the time, the specific service, the account and the categories of data. The same records later become your evidence in an employment dispute.

STEP 3 — Assess the regulatory footprint

If personal data is in the set, notification duties switch on. UAE law requires the controller to notify the regulator as soon as it becomes aware of the breach, and the data subject where the breach affects the confidentiality of their data. The timings and the procedure are left to executive regulations that have still not been issued, so what you can rely on is the duty itself.

STEP 4 — Handle the employee separately

The disciplinary track runs its own course: written investigation, the employee's explanation, a reasoned decision. Skipping the procedure costs the employer the right to rely on Article 44, and the separation then runs on ordinary terms, with notice and payments.

What to fix in your documents

A company-wide AI policy is a conversation of its own, and the minimum for this situation fits into three documents. The employment contract needs a definition of confidential information that expressly covers transfers to third-party services, plus a reference to the list of permitted tools. The internal handbook carries that list and the investigation procedure. On the data side, you need an assessment of the personal data regime across your jurisdictions.

All of it ties back into the company's broader employment law framework: grounds for dismissal only work together with procedure.

The short version

A leak through a model is an event with two consequences, and both land before anyone has read your data. The company loses the ability to defend the information as a secret, and a dismissal only holds up with proven damage and a procedure that was followed. Both risks are closed by documents written in advance.

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.