Apple v. OpenAI: When an Agent Learns the Secret

Apple’s trade-secret suit against OpenAI, a former Apple electrical engineer, and a former senior Apple hardware executive who is now OpenAI’s chief hardware officer has become the most consequential test yet of how misappropriation doctrine applies when confidential information passes through an AI workflow. The complaint names Chang Liu, who spent eight years at Apple as a Senior System Electrical Engineer, and Tang Yew Tan, formerly Apple’s Vice President of Product Design and an io Products co-founder, now OpenAI’s Chief Hardware Officer. Apple filed in the Northern District of California on July 10, 2026 — Apple Inc. v. Liu, et al., No. 5:26-cv-07078 (N.D. Cal.) — with arguments set for October before Judge Edward J. Davila.

The factual core is unusually concrete. Apple alleges Liu retained an Apple-issued laptop that stayed authenticated to Apple’s network and used residual access to download dozens of confidential files. The central item is a single power-converter circuit schematic among those files. Apple’s forensic review of Liu’s MacBook, submitted in an August 31 filing supporting expedited discovery, alleges he downloaded that schematic in March 2026 — after leaving Apple — and ran it in LTspice for power-conversion work. Apple also alleges Liu coached a still-employed colleague on how to copy confidential files while avoiding the security team, and that OpenAI recruiting probed unreleased Apple hardware.

The AI wrinkle is what elevates the case. Apple says Liu trained an AI agent to operate the simulator — running LTspice, inspecting the results, and tuning a compensation parameter — cutting a day-long workflow to roughly two hours. Importantly, the filing describes an agent learning to drive the tool and tune parameters; it does not establish that OpenAI trained model weights on Apple’s data. Apple nonetheless frames the harm as distinct, arguing secrets absorbed by an agent create “irreversible” effects that are harder to trace or claw back. The court has not adopted that theory; OpenAI seeks dismissal and calls the allegations meritless.

For practitioners, the discovery map is the tell. If an agent’s competence is the injury, then prompt history, simulator sessions, and retrieval-augmented generation stores become the evidence, and Apple’s push for expedited fact-finding aims squarely at them.

There is a defensive mirror image. Feeding a secret into a personal AI account can itself undercut the reasonable-measures element that every trade-secret claim requires. Courts have begun to treat disclosure to a consumer-tier platform as inconsistent with reasonable measures — Trinidad v. OpenAI dismissed a DTSA claim on that basis — though the case law is early and turns heavily on the platform’s terms and configuration. Claimants must also identify secrets with the particularity trade-secret law requires, a standard largely developed by courts. Enterprise tools with no-training and confidentiality terms help, but they complement — not replace — governance over what employees route through AI.

The lesson cuts in both directions: “We deleted the file” is an incomplete answer if the workflow the file taught is still running.

Michael G. Monyok

Meyer, Unkovic & Scott’s Intellectual Property Group represents clients in all aspects of intellectual property protection, acquisition, and enforcement. We represent individuals, universities, small to mid-sized companies, start-ups, and national corporations. The group strives to meet the needs of our clients with quality legal representation in the most cost-efficient manner possible.

How Can We Help You?

Scroll to Top