Apple–OpenAI Trade Secrets Fight: Lessons for SMEs

Apple–OpenAI Trade Secrets Fight: Lessons for SMEs — featured image

by

Why This AI Lawsuit Should Matter to Your Business

A trade secrets dispute between Apple and OpenAI may sound like a battle reserved for global technology companies. However, the underlying issue is familiar to Malaysian SME owners: what happens when an employee, contractor or new hire has access to confidential information and later moves to another business?

The dispute highlights a practical business risk that is becoming more important as companies adopt artificial intelligence, cloud systems and digital collaboration tools. Your customer lists, supplier terms, product designs, operating procedures, software prompts, sales scripts and internal reports may not look as valuable as a global technology company’s engineering files, but they can still give a competitor an advantage.

For a Malaysian SME with between one and 50 employees, the lesson is straightforward. Confidential information needs to be identified, controlled and handled consistently. A clause in an employment contract is useful, but it is not a complete information-security strategy.

What Happened

According to MacRumors, Apple asked a federal judge to reject OpenAI’s request to dismiss a trade secrets lawsuit. Apple filed the lawsuit in July and alleged that confidential product information was obtained through former Apple employees who became job candidates or employees at OpenAI. The report says Apple claimed that more than 400 former Apple employees now work at OpenAI.

OpenAI argued that Apple had not properly identified the information it considered a legally protectable trade secret. It also said it was building something entirely new and different from Apple’s products. Apple responded that OpenAI’s arguments involved disputed facts that should be examined during evidence-gathering and a later stage of the case, rather than being used to end the lawsuit immediately.

Apple’s filing reportedly repeated allegations involving former engineer Chang Liu and OpenAI hardware chief Tan Yew Tan. Apple said Liu exploited an authentication bug to access Apple’s network storage after joining OpenAI and downloaded confidential engineering files, including material about manufacturing and testing main logic boards. Apple also alleged that Tan used internal project codenames when questioning interview candidates about unreleased products and asked an employee to bring components to an OpenAI “show and tell” session.

The allegations have not been finally determined by the court. OpenAI is contesting Apple’s position, and the judge is scheduled to hear arguments on October 1, according to MacRumors.

Why This Matters for Malaysian SMEs

Your business probably does not have hundreds of engineers or a large legal department. That makes information controls more important, not less. In a small team, one person may handle customer records, pricing, supplier negotiations, marketing plans and access to several cloud applications. If that person leaves, the business may struggle to know exactly what information was viewed, copied or downloaded.

Consider a Malaysian food manufacturer preparing a new private-label product. Its confidential information may include the formulation, supplier contacts, production schedule, packaging artwork and target customer list. A logistics company may need to protect route plans, delivery rates and customer addresses. A software agency may need to secure source code, client credentials, technical documentation and project proposals. These materials can be commercially sensitive even if they are not formally labelled “trade secret”.

The Apple–OpenAI dispute also raises questions about recruitment. When you hire someone from a competitor, you should not encourage the person to bring documents, files, screenshots, customer lists or product samples from the previous employer. Instead, ask candidates to describe their skills and experience without revealing confidential information belonging to another organisation.

This is particularly relevant when you use AI tools. An employee might paste a customer complaint, contract, product specification or internal report into an AI assistant to obtain a summary or draft response. If your team has no policy, you may not know where sensitive information has gone or whether it has been retained, shared or exposed through an account with weak access controls.

Business area Information to control Practical action
People and hiring Previous employer information and interview materials Tell candidates not to disclose or bring confidential documents
Cloud storage Product files, customer records and financial documents Use individual accounts, multi-factor authentication and access reviews
AI tools Contracts, personal data, source code and internal plans Create a written list of information staff must not upload
Employee departures Files, passwords, devices and shared links Use a documented offboarding checklist on the final working day

What You Should Do Now

Start by making a simple information register. You do not need a complicated software system. List the information that could harm your business if exposed, such as customer databases, supplier pricing, product plans, passwords, source code, payroll records and unreleased marketing campaigns. Assign an owner to each category and decide which employees genuinely need access.

Next, separate access by role. Your sales team may need customer and quotation records, but not payroll files. Your operations team may need production information, but not every marketing document. Avoid shared passwords wherever possible. When each person has an individual account, you have a clearer record of who accessed a file and can remove access when someone leaves.

Review employment contracts and confidentiality agreements with a qualified Malaysian lawyer. Your documents should explain what information is confidential, how it may be used, what happens when employment ends and how company devices and accounts must be returned. Do not rely on broad wording alone. Your daily practices should show that the business actually treats the information as confidential.

Confidentiality is not created by a label alone. It is demonstrated through sensible access controls, staff instructions, secure systems and consistent offboarding.

Introduce a short onboarding briefing for every new employee. Explain that they must not bring confidential information from a former employer and must not share your business information outside approved channels. Repeat the message when employees receive access to new systems or handle a new category of data.

The Bigger Picture

The dispute shows how AI competition is increasing the value of people, information and technical know-how. Businesses are no longer protecting only physical documents. They must also consider cloud folders, collaboration platforms, messaging applications, code repositories, AI prompts and exported reports.

For Malaysian SMEs, the strongest response is not to stop using AI or avoid hiring experienced staff. It is to build clear boundaries around information. You can benefit from automation while limiting exposure by using approved tools, restricting access, maintaining activity logs and training employees on acceptable use.

AutoRunBiz can help you turn these principles into repeatable workflows, including onboarding, access requests, document approvals, staff offboarding and AI-use acknowledgements. The objective is to make good information handling part of everyday operations, rather than something you consider only after a dispute begins.

Global lawsuits often reveal risks that smaller companies encounter on a smaller scale. By identifying your valuable information and controlling how it moves, you give your business a stronger foundation for growth, hiring and responsible AI adoption.

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →