KlarComply
HomeKnowledge › Trade secrets and AI tools

Trade secrets and AI tools: the protection you can lose

A trade secret is not a state of affairs. It is a status you earn through measures. Where the measures are missing, the legal protection falls away entirely. AI tools are currently the most common way of losing that status without noticing.

By , Founder of KlarComply · Reviewed on

Infographic: Trade secrets and AI: the silent loss of status — Trade secret law only protects what is kept secret by reasonable measures — careless AI input eats at exactly that.
The key points of this article as a graphic — feel free to share or download it.

What a trade secret is in law

Directive (EU) 2016/943 defines the term through three requirements that must be met cumulatively. Lose one of them and the information is no longer a trade secret, with everything that follows.

  1. It is secret in the sense that it is not, as a body or in the precise configuration and assembly of its components, generally known among or readily accessible to persons within the circles that normally deal with the kind of information in question.
  2. It has commercial value because it is secret.
  3. It has been subject to reasonable steps under the circumstances, by the person lawfully in control of the information, to keep it secret.

The third requirement is the reason this subject matters for AI. It is not enough to want information kept secret. The directive requires steps, and whoever claims the protection has to show them. The UK regulations implementing the same directive apply the same test, and US trade secret law asks a materially similar question about reasonable measures — so this is not a European peculiarity you can leave behind by relocating.

The consequence that makes the difference

Without the status, the remedies in the directive do not apply — no interim measures, no injunction against use or disclosure, no corrective measures, no damages. If a departed employee deploys your pricing methodology at a competitor, you are left with nothing, even where the facts are not in dispute.

That is the actual point here. This is not about a fine. It is about whether you can defend yourself when it matters.

Where AI tools put the status at risk

Two mechanisms operate, and they are independent of one another.

First: the step is missing

This is the more important one in practice and the clearer one. Allowing staff to enter confidential content into any tool they like means that, for that content, no reasonable step to keep it secret has been taken. The status then falls away not because the information became public, but because requirement three is not met. That is sufficient on its own.

Put the other way round: a company with a clear, known and supervised rule on AI use is in a better position than one without — even where the same data were entered in both.

Second: the information becomes accessible

Whether entering something into an AI tool makes the information “generally known or readily accessible” within the meaning of requirement one is a harder question — and it is contested. There is, so far as we can see, no settled appellate authority on it in any major European jurisdiction.

Arguments run both ways. Where the input is used to improve the model and could therefore surface in outputs to third parties, there is a good deal to be said for accessibility. Where the input stays contractually with the provider, is not used for training and the provider is bound to confidentiality, there is a good deal to be said against — the position then resembles disclosure to a service provider under a duty of confidence.

For practical purposes: do not stake anything on how that argument comes out. The route through requirement three — demonstrable steps — is the safe one, and it lies entirely within your control.

What “reasonable” means

The directive does not require maximum security. It requires steps that are reasonable under the circumstances. Courts across the member states have looked at the value of the information, the size of the company, what is customary in the sector, and how the information is marked and access-controlled. A general confidentiality clause in an employment contract, standing alone, is widely regarded as insufficient.

Graded rather than blanket — this is the decisive idea

Not every piece of information deserves the same level of protection, and trying to protect everything equally results in nothing being protected. Three tiers are enough for most companies:

TierExamplesAI rule
Strictly confidentialcosting bases, formulations, design data, source code of core products, M&A materialno entry into AI tools, without exception
Confidentialdraft proposals, customer lists, supplier terms, project plansonly in approved tools with a contractual confidentiality undertaking and training use disabled
Internalprocess descriptions, internal circulars, training materialentry into approved tools permitted

The classification is itself a step towards secrecy — it shows you identified what is worth protecting.

The measures that count in an AI setting

Ten points, ordered by effect relative to effort. The first four are the core.

  1. A written AI rule with specific prohibitions. Not “confidential information” but “costing bases, formulations, customer lists, draft proposals, source code”. Specificity here is not a matter of style. It is evidence. Structure on writing an internal AI policy.
  2. Approved tools with a confidentiality undertaking. Check the provider terms for whether confidentiality is promised and whether use of inputs for training is excluded. Record the finding with a date in the AI inventory.
  3. Documented briefing. Who received which content, and when. Without a record, the measure does not exist in a dispute.
  4. Classification of the information by the three tiers above, at minimum for the top tier.
  5. Marking of documents — a footer reading “Strictly confidential” on the costing files works in two directions: it reminds people day to day and it evidences the step in litigation.
  6. Access on a need-to-know basis. Someone with no access cannot enter anything.
  7. A contractual clause for staff that expressly covers AI use — more on this below.
  8. A rule for service providers. Agencies, translation bureaux and external developers process your confidential content. Without an AI clause in the contract that flank is open.
  9. An approval process for new tools, so the rule is not undercut by the next subscription — see the approval process for AI tools.
  10. A periodic review with a date. A measure adopted in 2024 that nobody has looked at since is not persuasive in court.

The contract clause

General confidentiality clauses in employment contracts usually do not expressly cover AI use. An addition is quick to draft and works both as a step towards secrecy under the directive and as a basis in employment law.

A drafting block

“Entering trade secrets of the company or of third parties into AI-supported services is permitted only in tools approved by the company and only within the scope of the AI policy in force from time to time. Trade secrets include in particular costing bases, price structures, customer lists, proposal documents, design and process documentation, and source code.”

The second sentence is the important one. A list beats a definition — it is comprehensible and it holds up in a dispute.

Burden of proof: why documentation is the whole point

Whoever asserts a trade secret has to establish that the requirements of the directive are met, including the reasonable steps. That happens in proceedings, usually years after the moment that matters.

So keep a slim file: the classification, the AI policy in the version then in force with its version number, the training records, the contract clauses, and the assessment notes on the approved tools. That is five documents. They come into existence anyway if you implement the AI Act — they simply have to remain findable.

An example from ordinary practice

A salesperson has a proposal drafted and, for that purpose, pastes the complete costing table with purchase prices and margins into a public language model. Three levels are engaged, and they are independent of one another:

The lesson is not to punish the sales team. It is that the permitted route has to be known. Someone who knows they may paste the table without prices, or with placeholders, does exactly that.

What you do not need

The special case of source code

AI-assisted programming is now routine and deserves separate treatment, because two questions coincide here.

For companies with in-house development, a dedicated paragraph in the policy is worth the effort: which repositories never reach external tools, which tools are approved, and how credentials are handled. Three sentences is enough.

Third-party confidential information

One flank is regularly missed. A good deal of what your staff work with is not your secret but somebody else's — a customer's specification, a supplier's pricing, material received under a non-disclosure agreement. Entering that into an AI tool can breach the agreement independently of your own trade secret position, and non-disclosure agreements frequently prohibit disclosure to third parties without prior written consent in terms broad enough to cover an AI provider.

The practical fix is one line in the policy naming third-party material explicitly, and one question in the approval process asking whether the tool will receive it. Both are cheap. The alternative is discovering the position when a customer asks.

Done in two hours

  1. Name five to ten pieces of information that are genuinely strictly confidential. No more — otherwise the list becomes meaningless.
  2. Mark those documents with a footer and check the access rights.
  3. Add the AI paragraph to the policy, with a specific list.
  4. Add the contract clause for new employment contracts; for existing ones, distribute the policy and record acknowledgement.
  5. For the approved tools, check and note whether confidentiality is promised and training use disabled.
  6. Set a date for the next review.

Whether these foundations are in place is shown by the free quick check. And if you are working on your external presentation anyway, labelling AI-generated content takes a few minutes with the free AI labels.

Frequently asked questions

Does a costing lose its protection if it is entered into an AI tool?

Possibly yes — chiefly because the reasonable steps required by Directive (EU) 2016/943 are then missing. Whether the entry additionally makes the information readily accessible is contested and not settled by appellate authority. The safe route is through demonstrable steps, because that route lies entirely within your control.

What are reasonable steps to keep information secret?

The directive requires steps reasonable under the circumstances, measured among other things by the value of the information, the size of the company and what is customary in the sector. A general confidentiality clause standing alone is widely regarded as insufficient. What works is graded classification, specific written rules, documented briefing, access restriction and marking of documents.

What happens if the status falls away?

The remedies in the directive no longer apply — no interim measures, no injunction, no corrective measures, no damages. If a departed employee uses the information at a competitor, you are left without those remedies even where the facts are not in dispute.

Is the confidentiality clause in the employment contract enough?

Usually not on its own. It is one component, but it rarely covers AI use expressly. Add a clause restricting entry into AI services to approved tools and listing the protected information — a list holds up better in a dispute than a definition.

Are we not allowed to put any internal information into AI tools?

You are, in grades. Strictly confidential content such as costing bases, formulations and source code stays out. Confidential content may go into approved tools with a contractual confidentiality undertaking and training use disabled. Internal material is unproblematic. A blanket ban does not work, because it gets worked around.

Who has to prove the steps were taken?

Whoever asserts the trade secret — that is, you. It happens in proceedings, often years later. Keep five documents findable: the classification, the AI policy with its version, the training records, the contract clauses, and the assessment notes on the approved tools.

Does this apply to our customers' information too?

Yes, and there a second level is added. Many customer and framework agreements prohibit disclosure of confidential information to third parties without consent, in terms broad enough to cover an AI provider. Entry into an AI tool can therefore be a breach of contract with a possible penalty, independently of data protection and trade secret law.

We are based outside the EU. Does the directive matter to us?

The directive itself binds the member states, but the test it sets is not unusual. The UK regulations implementing it apply the same reasonable-steps requirement, and US trade secret law asks a materially similar question about reasonable measures. If you litigate in Europe over information handled by an EU entity, the directive's standard is the one that will be applied to you.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Directive (EU) 2016/943 — protection of undisclosed know-how and business information
Article 32 GDPR — security of processing
Article 33 GDPR — notification of a personal data breach
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
European Commission — regulatory framework for AI
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.