Apple–OpenAI Dispute: Protect Your SME’s AI Data

Apple–OpenAI Dispute: Protect Your SME’s AI Data — featured image

by

Why the Apple–OpenAI Dispute Matters to Your Business

A legal dispute between Apple and OpenAI is putting a practical business risk in the spotlight: what happens when a former employee takes confidential information into a new workplace and uses an AI agent to work with it?

Apple says former engineer Chang Liu downloaded a confidential circuit schematic after leaving the company, used it in work conducted at OpenAI, and trained an AI agent to operate LTspice, an electrical engineering simulation tool. These claims remain allegations in an ongoing case, but the underlying lesson is immediately relevant to you: automation can make confidential information easier to use, copy, transform and conceal.

For a Malaysian SME with one to 50 employees, confidential information may include customer lists, supplier terms, product drawings, recipes, quotations, payroll files, source code, marketing plans or internal operating procedures. You may not have a large legal or cybersecurity department. That makes simple controls, clear ownership and careful offboarding especially important.

What Happened

According to Apple’s filing, Liu retained an Apple-issued MacBook after joining OpenAI. Apple said forensic analysis of the returned laptop found evidence that he had downloaded a confidential Apple circuit schematic, accessed third-party cloud storage without authorisation and attempted to hide activity after learning about an internal investigation. MacRumors reported Apple’s allegations and court filing.

Apple further alleged that Liu used the schematic in a simulation on a Mac mini and that the device later synchronised information to the MacBook. The filing also described messages in which Liu said he trained an AI agent to run LTspice, inspect results and adjust a compensation parameter. Apple is asking the court for expedited discovery and restrictions on the alleged use of its trade secrets. OpenAI has disputed the accusations, described them as meritless and said it does not have or want Apple’s trade secrets, according to the same report.

The important issue is not whether every allegation is ultimately proven. The case demonstrates how traditional data-loss risks now overlap with AI workflows. An employee may not simply copy a document into a folder. They may upload it to an AI assistant, connect it to an automation platform, use it to generate code or ask an agent to operate engineering, finance or customer-service software.

Why This Matters for Malaysian SMEs

Many Malaysian SMEs are already using cloud accounting, shared drives, messaging apps, customer relationship systems and AI tools. A small manufacturing company might store technical drawings in Google Drive. A renovation firm may keep quotations, floor plans and supplier rates in WhatsApp and email. A recruitment agency may hold candidate identity documents. A food business may maintain recipes, production instructions and outlet sales reports.

These assets can be commercially sensitive even if they are not labelled “trade secret”. If a former employee downloads them, forwards them to a personal account or submits them to an external AI service, your business may lose control over where the information goes. If an AI agent is allowed to access business software, the risk becomes broader: the agent may read records, create files, send messages or trigger workflows based on instructions that you did not fully review.

You should also consider Malaysian privacy obligations. The Personal Data Protection Act 2010, administered through Malaysia’s Personal Data Protection Department, governs the processing of personal data in commercial transactions. Customer names, telephone numbers, identification details, employee records and other personal information should not be casually pasted into public AI tools or shared without considering your responsibilities.

The case also highlights a common SME weakness: access often remains active after someone resigns. A departing employee may still know passwords, possess a company laptop, have access to cloud folders or remain logged in to a browser session. When your team is small, one person may have broad access across sales, finance and operations. That convenience can create a single point of failure.

Practical Controls You Can Put in Place

You do not need a complex enterprise programme to reduce the risk. Start by identifying important information, limiting access and creating a repeatable leaver process.

Business area Common risk Useful control
Documents Former staff retain downloaded files Use managed storage, folder permissions and download restrictions where available
AI tools Confidential data is pasted into an external service Create an approved-tools list and prohibit sensitive uploads without review
Accounts Old passwords or sessions remain active Disable accounts, revoke sessions and rotate shared credentials immediately
Devices Company information remains on personal or retained devices Maintain an asset register and collect or remotely wipe company devices
Automation An AI agent sends or changes information without approval Use least privilege, approval steps and activity logs

First, create a simple information classification system. For example, mark files as public, internal, confidential or highly confidential. Give employees examples that match their daily work. A public product announcement is different from a customer export, supplier contract or unreleased design.

Second, write an AI usage policy in plain language. State which tools are approved, what information must not be entered, who can connect AI tools to business systems and when human approval is required. Avoid vague wording such as “use AI responsibly”. Tell employees exactly what to do when they are unsure.

Third, require approval before an AI agent can take action. Reading a draft document is lower risk than sending an email, changing accounting records or modifying a production file. Use separate permissions for viewing, editing and executing tasks. Keep logs so you can review what the agent accessed and what it changed.

Fourth, build an offboarding checklist. On the employee’s final working day, disable accounts, remove access to shared drives, revoke application tokens, collect devices, transfer business files and change shared passwords. Confirm that personal devices and cloud accounts no longer contain company information. Keep a dated record of completed steps.

AI does not replace the need for access control. It increases the importance of knowing exactly which information a tool can reach and what actions it is allowed to perform.

The Bigger Picture

The Apple–OpenAI allegations point to a wider shift in how intellectual property can be used. Previously, a person might need significant time to understand a technical document, reproduce a process or operate specialist software. An AI agent can potentially assist with those steps, making sensitive material more actionable. That does not mean every AI system is unsafe, but it does mean your controls must cover both the information and the actions performed with it.

For Malaysian SMEs, the right response is not to ban every new technology. AI can help you draft customer replies, summarise meetings, organise knowledge, identify unusual transactions and automate repetitive administration. The safer approach is controlled adoption: use approved tools, remove personal data where possible, restrict access, review outputs and maintain an audit trail.

You should also make confidentiality part of daily management. Include it in employment agreements, contractor terms and staff training. When employees leave, remind them in writing that confidential information remains protected. If you suspect unauthorised access, preserve device and cloud logs before deleting accounts or resetting equipment, then seek qualified legal and cybersecurity advice.

The most useful question for your business is simple: if one employee left tomorrow, could you identify every system, file and AI connection they used? If the answer is no, start there. A short access register and a consistent offboarding checklist can protect your operations more effectively than a policy that nobody follows.

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →