How to Keep Trade Secrets Safe in AI-Powered Workplaces

How to Keep Trade Secrets Safe in AI-Powered Workplaces — featured image

by

When Your Business Data Becomes an AI Instruction

You may already use AI to summarise documents, analyse spreadsheets, draft emails or support technical work. The convenience is obvious: tasks that once took a full afternoon can sometimes be completed in a much shorter session. The risk is less obvious. A staff member may copy confidential information into an AI tool, connect an automated agent to an internal application, or keep company files on a personal device after leaving.

A recent legal dispute between Apple and OpenAI shows how serious this can become. Apple alleges that a former engineer retained access to company equipment, downloaded a confidential circuit schematic, used it in work at OpenAI and trained an AI agent to operate an engineering simulation tool. These are allegations in an ongoing case, not final court findings. However, the situation highlights a practical issue for every SME: AI can make sensitive information easier to use, reproduce and move without clear visibility.

TL;DR

AI automation does not remove the need for access controls, employee offboarding and confidential-data rules.

Start by identifying sensitive information, restricting who and what can access it, and keeping an audit trail of AI-related activity.

What This Means

Trade secrets are valuable business information that is not publicly known and gives your company an advantage. For an SME, this could include a customer list, supplier terms, product formula, internal workflow, source code, technical drawing, sales script or operational dashboard.

The Apple dispute illustrates several connected risks. First, a former employee allegedly retained company hardware. Second, confidential information was allegedly downloaded after employment ended. Third, the information was allegedly used in another organisation’s work. Fourth, an AI agent was taught to operate a technical tool, potentially allowing repetitive work to happen faster and with less direct supervision.

An AI agent is different from a basic chatbot. A chatbot normally responds to a prompt. An agent may take several actions: open a file, run a program, inspect results, adjust a setting and repeat the process. If the agent has broad permissions, it may interact with systems or files that the user should not be able to access.

The key question is not only “Who can see this file?” It is also “What can an AI tool do with this file after seeing it?”

This does not mean you should avoid AI. It means you need to treat AI tools as part of your business technology environment. They require the same care as email accounts, shared drives, accounting systems and company laptops.

How This Applies to Malaysian SMEs

1. Manufacturing and engineering firms

If you operate a machining, electrical, automation or product-design business, your sensitive information may be stored in drawings, bills of materials, test results and simulation files. A technician could upload a design to an external AI service to ask for troubleshooting help. An engineer could connect an automation agent to a simulation or production application. Without clear rules, you may not know what left your environment or which systems the agent can access.

You should create a simple classification system. Mark files as public, internal, confidential or highly restricted. Require approval before highly restricted files are used with an external AI tool. For technical work, use separate folders and accounts so an AI assistant receives access only to the project it needs, rather than your entire engineering archive.

2. Professional services and agencies

Accounting firms, consultants, recruiters, legal-support businesses and marketing agencies often handle information belonging to clients. A team member might paste a client contract, employee record or campaign plan into an AI assistant for drafting or analysis. Even if the intention is helpful, the action may breach your client agreement or internal confidentiality policy.

Give your team approved examples. Explain what they may use AI for, such as rewriting a generic email or organising non-sensitive notes. Also state what they must not submit, such as identity-card details, bank information, passwords, unpublished client material and confidential commercial terms. This makes the policy practical rather than a document that nobody reads.

3. Retail, distribution and service businesses

Your customer and supplier records may be spread across point-of-sale systems, spreadsheets, messaging apps and cloud storage. An employee who leaves may still have a copy of a customer export on a personal laptop or phone. If that person also used AI tools to organise or analyse the information, the trail may be difficult to reconstruct.

Use company-managed accounts wherever possible. Avoid sending complete customer lists through personal messaging accounts. Limit downloads, review shared-folder permissions and remove access promptly when someone resigns or changes role. If your business has only a few employees, a written offboarding checklist can still prevent major gaps.

4. Small software and digital businesses

Code repositories, product roadmaps, API keys and deployment credentials are especially sensitive. An employee may ask an AI coding assistant to review a private code segment or troubleshoot a configuration file. That request can expose more than the employee intended, particularly if credentials or customer data are included in the same text.

Separate secrets from code, use individual user accounts and enable multi-factor authentication. Review access logs for unusual downloads or activity outside normal working hours. When an employee leaves, revoke repository, cloud, email and device access at the same time instead of handling each item days apart.

Useful Numbers for Your Risk Review

The following checklist gives you a practical starting point. The figures are operating targets for internal planning, not legal requirements.

Area Suggested target Why it matters
Access review Every 90 days Removes permissions that employees no longer need
Offboarding Same working day Reduces the period when former staff can access systems
AI policy training At least once each year Keeps rules visible as tools and work practices change
Multi-factor authentication All business-critical accounts Adds another verification step beyond a password
Backup testing Every 6 months Checks whether important files can actually be restored

Practical Takeaways

  • List your sensitive information. Include customer records, designs, formulas, source code, pricing rules, contracts, credentials and internal reports.
  • Choose approved AI tools. Do not let every employee independently select an application for confidential work.
  • Ban sensitive uploads by default. Allow exceptions only when the tool, purpose and data handling have been reviewed.
  • Use least-privilege access. Give each person and automation tool only the permissions required for the assigned task.
  • Separate personal and company devices. Company work should remain in company-controlled accounts and storage.
  • Keep an offboarding checklist. Collect devices, disable accounts, revoke application access and review downloaded files.
  • Record AI-related activity. Keep basic logs showing who accessed important systems and when.
  • Protect credentials. Never place passwords, API keys or recovery codes in prompts, spreadsheets or shared notes.
  • Train with real examples. Show staff how a harmless-looking request can expose a customer file or technical design.
  • Review supplier agreements. Confirm how external technology providers handle data submitted to their systems.

The Bigger Picture

AI agents will increasingly perform work across business applications. They may prepare quotations, reconcile records, test software, monitor equipment or draft customer responses. The benefit comes from allowing software to take action, but that same ability creates a wider control problem: an automated system can move faster than a person checking every step.

For Malaysian SMEs, the best response is not to create a complicated security department. It is to establish a few clear controls and apply them consistently. Know where important information lives. Know who can access it. Know which AI tools are approved. Know what happens when a staff member leaves.

The Apple allegations also show why device ownership matters. A company laptop, desktop or cloud account may contain synchronised files, browser sessions and access tokens long after the employee stops working for you. Asset registers and proper device recovery are therefore operational necessities, not merely administrative tasks.

Your business does not need to wait for a dispute before improving its controls. Begin with one sensitive workflow, such as customer exports, product designs or accounting records. Map who uses it, where it is stored, which tools touch it and what happens during staff departure. Then apply the same approach to the next workflow.

The practical lesson is straightforward: AI should help your team work with approved information under defined permissions. If an employee can quietly copy, connect or retain sensitive data, the weakness is in the surrounding process—not in the technology alone.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →