A trade secret is not a state of affairs. It is a status you earn through measures. Where the measures are missing, the legal protection falls away entirely. AI tools are currently the most common way of losing that status without noticing.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Directive (EU) 2016/943 defines the term through three requirements that must be met cumulatively. Lose one of them and the information is no longer a trade secret, with everything that follows.
The third requirement is the reason this subject matters for AI. It is not enough to want information kept secret. The directive requires steps, and whoever claims the protection has to show them. The UK regulations implementing the same directive apply the same test, and US trade secret law asks a materially similar question about reasonable measures — so this is not a European peculiarity you can leave behind by relocating.
Without the status, the remedies in the directive do not apply — no interim measures, no injunction against use or disclosure, no corrective measures, no damages. If a departed employee deploys your pricing methodology at a competitor, you are left with nothing, even where the facts are not in dispute.
That is the actual point here. This is not about a fine. It is about whether you can defend yourself when it matters.
Two mechanisms operate, and they are independent of one another.
This is the more important one in practice and the clearer one. Allowing staff to enter confidential content into any tool they like means that, for that content, no reasonable step to keep it secret has been taken. The status then falls away not because the information became public, but because requirement three is not met. That is sufficient on its own.
Put the other way round: a company with a clear, known and supervised rule on AI use is in a better position than one without — even where the same data were entered in both.
Whether entering something into an AI tool makes the information “generally known or readily accessible” within the meaning of requirement one is a harder question — and it is contested. There is, so far as we can see, no settled appellate authority on it in any major European jurisdiction.
Arguments run both ways. Where the input is used to improve the model and could therefore surface in outputs to third parties, there is a good deal to be said for accessibility. Where the input stays contractually with the provider, is not used for training and the provider is bound to confidentiality, there is a good deal to be said against — the position then resembles disclosure to a service provider under a duty of confidence.
For practical purposes: do not stake anything on how that argument comes out. The route through requirement three — demonstrable steps — is the safe one, and it lies entirely within your control.
The directive does not require maximum security. It requires steps that are reasonable under the circumstances. Courts across the member states have looked at the value of the information, the size of the company, what is customary in the sector, and how the information is marked and access-controlled. A general confidentiality clause in an employment contract, standing alone, is widely regarded as insufficient.
Not every piece of information deserves the same level of protection, and trying to protect everything equally results in nothing being protected. Three tiers are enough for most companies:
| Tier | Examples | AI rule |
|---|---|---|
| Strictly confidential | costing bases, formulations, design data, source code of core products, M&A material | no entry into AI tools, without exception |
| Confidential | draft proposals, customer lists, supplier terms, project plans | only in approved tools with a contractual confidentiality undertaking and training use disabled |
| Internal | process descriptions, internal circulars, training material | entry into approved tools permitted |
The classification is itself a step towards secrecy — it shows you identified what is worth protecting.
Ten points, ordered by effect relative to effort. The first four are the core.
General confidentiality clauses in employment contracts usually do not expressly cover AI use. An addition is quick to draft and works both as a step towards secrecy under the directive and as a basis in employment law.
“Entering trade secrets of the company or of third parties into AI-supported services is permitted only in tools approved by the company and only within the scope of the AI policy in force from time to time. Trade secrets include in particular costing bases, price structures, customer lists, proposal documents, design and process documentation, and source code.”
The second sentence is the important one. A list beats a definition — it is comprehensible and it holds up in a dispute.
Whoever asserts a trade secret has to establish that the requirements of the directive are met, including the reasonable steps. That happens in proceedings, usually years after the moment that matters.
So keep a slim file: the classification, the AI policy in the version then in force with its version number, the training records, the contract clauses, and the assessment notes on the approved tools. That is five documents. They come into existence anyway if you implement the AI Act — they simply have to remain findable.
A salesperson has a proposal drafted and, for that purpose, pastes the complete costing table with purchase prices and margins into a public language model. Three levels are engaged, and they are independent of one another:
The lesson is not to punish the sales team. It is that the permitted route has to be known. Someone who knows they may paste the table without prices, or with placeholders, does exactly that.
AI-assisted programming is now routine and deserves separate treatment, because two questions coincide here.
For companies with in-house development, a dedicated paragraph in the policy is worth the effort: which repositories never reach external tools, which tools are approved, and how credentials are handled. Three sentences is enough.
One flank is regularly missed. A good deal of what your staff work with is not your secret but somebody else's — a customer's specification, a supplier's pricing, material received under a non-disclosure agreement. Entering that into an AI tool can breach the agreement independently of your own trade secret position, and non-disclosure agreements frequently prohibit disclosure to third parties without prior written consent in terms broad enough to cover an AI provider.
The practical fix is one line in the policy naming third-party material explicitly, and one question in the approval process asking whether the tool will receive it. Both are cheap. The alternative is discovering the position when a customer asks.
Whether these foundations are in place is shown by the free quick check. And if you are working on your external presentation anyway, labelling AI-generated content takes a few minutes with the free AI labels.
Possibly yes — chiefly because the reasonable steps required by Directive (EU) 2016/943 are then missing. Whether the entry additionally makes the information readily accessible is contested and not settled by appellate authority. The safe route is through demonstrable steps, because that route lies entirely within your control.
The directive requires steps reasonable under the circumstances, measured among other things by the value of the information, the size of the company and what is customary in the sector. A general confidentiality clause standing alone is widely regarded as insufficient. What works is graded classification, specific written rules, documented briefing, access restriction and marking of documents.
The remedies in the directive no longer apply — no interim measures, no injunction, no corrective measures, no damages. If a departed employee uses the information at a competitor, you are left without those remedies even where the facts are not in dispute.
Usually not on its own. It is one component, but it rarely covers AI use expressly. Add a clause restricting entry into AI services to approved tools and listing the protected information — a list holds up better in a dispute than a definition.
You are, in grades. Strictly confidential content such as costing bases, formulations and source code stays out. Confidential content may go into approved tools with a contractual confidentiality undertaking and training use disabled. Internal material is unproblematic. A blanket ban does not work, because it gets worked around.
Whoever asserts the trade secret — that is, you. It happens in proceedings, often years later. Keep five documents findable: the classification, the AI policy with its version, the training records, the contract clauses, and the assessment notes on the approved tools.
Yes, and there a second level is added. Many customer and framework agreements prohibit disclosure of confidential information to third parties without consent, in terms broad enough to cover an AI provider. Entry into an AI tool can therefore be a breach of contract with a possible penalty, independently of data protection and trade secret law.
The directive itself binds the member states, but the test it sets is not unusual. The UK regulations implementing it apply the same reasonable-steps requirement, and US trade secret law asks a materially similar question about reasonable measures. If you litigate in Europe over information handled by an EU entity, the directive's standard is the one that will be applied to you.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free