Your employee is not trying to steal anything.
They are trying to finish a task faster. They paste your pricing model into ChatGPT to reformat it as a client proposal. They upload a draft contract and ask the AI to clean up the language. They feed your source code into the prompt to find a bug. They summarize a confidential internal investigation report to save time writing it up.
None of this feels like a security incident. It feels like using a tool.
It is a security incident. And depending on what gets uploaded, it may also be a legal crisis.
Nearly 50 percent of enterprise employees were using generative AI tools like ChatGPT at work as of late 2025. A Harmonic Security study found sensitive information in more than 4 percent of prompts and 20 percent of file uploads sent to AI tools. Cyberhaven’s analysis of enterprise usage found that 4.7 percent of employees had already pasted confidential data into ChatGPT as early as mid-2023, and that number has only grown.
The data that is going in includes internal pricing models, client lists, financial statements, strategy documents, source code, personnel files, legal documents, and trade secrets. It is going in without any policy, any oversight, or any understanding of what happens to it once it leaves your network.
Here is what actually happens. And here is what it means for your business legally.
Where the Data Goes When Your Employee Hits Enter
When an employee types or pastes content into ChatGPT through the standard consumer interface, that content is transmitted to OpenAI’s servers. OpenAI’s terms of service preserve the ability to review inputs provided by users and potentially disclose such inputs to affiliates or third parties. Content entered into ChatGPT may be used to train future versions of the model unless the user has specifically opted out of that training, and those opt-out settings are not the default in every context or account type.
Once your proprietary information leaves your network and lands on OpenAI’s servers, you have lost control of it. You do not know who at OpenAI sees it, how long it is stored, whether it influences the model’s future outputs, or whether a completely unrelated user might receive a response that draws on what your employee submitted.
This is not theoretical. Samsung discovered this in a high-profile 2023 incident when engineers uploaded proprietary source code to ChatGPT to optimize it and check for errors, inadvertently leaking trade secrets. Samsung’s response was to ban employee use of the tool company-wide. But by the time they discovered what had happened, the data was already on OpenAI’s servers.
The Samsung incident was notable because it was publicly reported. Most of these incidents are not. They happen quietly, in the background, during normal workdays, by employees who have no idea they have done anything wrong.
The Court Decision Every Business Owner Needs to Know About
In January 2026, a federal court in the Northern District of California dismissed a trade secret claim in a case that should be on every business owner’s radar.
The plaintiff had developed what she alleged were trade secrets, and she had done so using ChatGPT. The court dismissed her Defend Trade Secrets Act claim for a fundamental reason: she had voluntarily disclosed her alleged trade secrets to OpenAI by entering them into ChatGPT. Because she had made that disclosure, she could not satisfy the legal requirement that a trade secret be maintained in secrecy by its holder.
Read that again. She lost her trade secret protection not because a competitor stole her information, not because of a data breach, not because of any bad act by anyone else. She lost it because she used an AI tool. The very act of entering her proprietary information into ChatGPT to develop it was treated as a voluntary disclosure that destroyed the secrecy her legal claim depended on.
This decision is the clearest demonstration yet of a legal risk most businesses have not thought through. Trade secret protection requires that the holder take reasonable measures to maintain secrecy. Uploading your trade secrets to a third-party AI platform is not a reasonable measure to maintain secrecy. It is the opposite.
What Qualifies as a Trade Secret Under Illinois Law
Illinois adopted the Illinois Trade Secrets Act, which mirrors the federal Defend Trade Secrets Act in most material respects. A trade secret under Illinois law is information, including a formula, pattern, compilation, program, device, method, technique, process, or financial data, that derives economic value from not being generally known or readily ascertainable, and that is the subject of reasonable efforts by its owner to maintain its secrecy.
That second element, reasonable efforts to maintain secrecy, is the one that breaks down when employees are using personal ChatGPT accounts with no company oversight, no policy prohibiting it, and no training about what constitutes confidential information.
The things employees are routinely uploading to AI tools qualify as trade secrets under Illinois law. Customer lists with pricing or relationship data. Proprietary formulas, processes, or methodologies. Source code. Financial models. Strategic plans. Merger or acquisition information. Compensation data. Marketing strategies. All of these are potential trade secrets. None of them should be going into a public AI tool.
When they do go in, and when your company has no AI policy, no confidentiality training that specifically addresses AI tools, and no technical controls to prevent it, you have not taken reasonable measures to maintain secrecy. A court looking at a subsequent trade secret claim would have legitimate grounds to question whether you actually treated the information as a secret.
Your NDA Probably Does Not Cover This
Most employee confidentiality agreements and nondisclosure agreements were drafted before generative AI existed in its current form. They prohibit employees from disclosing confidential information to third parties. They were written with competitors, vendors, journalists, and former employers in mind. They were not written with ChatGPT in mind.
The question of whether entering company information into an AI tool constitutes a prohibited disclosure under a pre-AI confidentiality agreement is not settled law. Some agreements are drafted broadly enough to capture it. Others are not. And even where an agreement does technically prohibit AI disclosure, an employee who has never been told that using ChatGPT violates their NDA is an employee who did not know they were doing anything wrong. That affects the remedies available to you and the enforceability of any discipline.
The gap between what your existing NDA prohibits and what your employees understand it to prohibit is where confidentiality incidents live. Closing that gap requires updating your agreements and your training to specifically address AI tools, not relying on pre-AI language and hoping it applies.
An NDA is not an AI policy. Your business needs both.
The Client Data Problem
Your own trade secrets are not the only thing at risk. If your employees are uploading client information to AI tools, you have a separate set of legal problems that can be even more acute.
Every professional services firm, consulting company, law firm, accounting practice, healthcare business, and financial services operation has confidentiality obligations to its clients that exist independent of internal company policy. Those obligations come from contracts, from professional rules, from regulatory requirements, and in some cases from statutes.
When an employee uploads client data to ChatGPT to draft a proposal, summarize a meeting, or analyze a spreadsheet, that employee has disclosed client information to a third party without authorization. If that disclosure breaches a confidentiality agreement with the client, your company is liable for the breach. If the client data includes information protected by HIPAA, financial regulations, attorney-client privilege, or other legal protections, the disclosure may trigger obligations to notify the client and regulatory consequences on top of the contract breach.
The client whose data was uploaded did not consent to having their information processed by OpenAI. They did not review OpenAI’s terms of service. They did not make the decision that their confidential information could be transmitted to an external server. Your employee made that decision for them, and your company bears the legal responsibility for it.
What the Employee Thought Was Happening
Understanding why this happens is important for building an effective response.
Employees who upload confidential information to AI tools are almost never acting maliciously. They are acting efficiently. The tool is available, it is useful, and nobody told them not to use it for this. The mental model most employees have of AI tools is similar to the mental model they have of search engines, which is that their inputs go somewhere but nobody is actually reading them and the information is not stored in any meaningful way.
That mental model is wrong. But it is the default assumption for most non-technical employees who have not been specifically educated about how generative AI tools actually work.
This is why the absence of an AI policy is not a neutral condition. It is an active risk. Without a policy, employees fill the gap with their own assumptions. And their assumptions are wrong in ways that create legal liability for your business.
The Six Legal Exposures Your Business Faces
When an employee uploads confidential information to a public AI tool, your business faces potential exposure across several distinct legal theories simultaneously.
Trade secret misappropriation. If a competitor or bad actor obtains information that an employee input into an AI tool, and that information qualifies as a trade secret, the disclosure may constitute misappropriation. More significantly, as the January 2026 court decision demonstrates, the disclosure itself may destroy your ability to pursue a trade secret claim against anyone else in the future.
Breach of confidentiality obligations to clients. If client data was included in what the employee uploaded, every confidentiality agreement you have with that client is potentially implicated. Discovery of this breach could trigger notice obligations, damage claims, and termination of the client relationship.
Regulatory violations. If the uploaded data includes health information, financial data, attorney-client communications, or other regulated categories, the upload may violate HIPAA, GLBA, SEC regulations, or other sector-specific requirements that carry their own penalty structures.
Employment law issues. The National Labor Relations Board has taken the position that certain AI policies that are overbroad can violate employees’ rights to engage in protected concerted activity. This creates a tension between restricting AI use broadly and ensuring the restriction does not sweep in protected employee communications. Any AI policy needs to be carefully drafted with this tension in mind.
Contract liability to clients. Even where no specific regulation applies, your contracts with clients almost certainly prohibit disclosure of their confidential information to third parties. An AI tool is a third party. Your contract liability for unauthorized disclosure exists independently of any trade secret or regulatory framework.
Competitive intelligence exposure. Even if no single disclosure crosses a legal threshold, the cumulative effect of employees regularly uploading strategic information to AI tools creates a pathway for that information to influence the AI’s outputs in ways that could benefit competitors who use the same tools and ask related questions.
What Your Business Needs Right Now
The legal and operational response to this problem has three components that need to work together.
A written AI use policy. Your policy needs to specifically define what AI tools employees may and may not use for work purposes, what categories of information may never be input into any external AI tool, and what the consequences are for violations. It needs to be clear that AI tools are third parties for purposes of your confidentiality obligations, and that inputting confidential information into an AI tool is a disclosure. It needs to cover both company-provided AI tools and personal AI accounts employees may be using on their own devices during work hours.
Updated confidentiality agreements and NDAs. Your existing agreements need to be reviewed and updated to specifically address AI disclosure. The update should define AI tools as third parties, explicitly prohibit inputting confidential information into AI tools not approved by the company, and address what happens to information the employee created using AI tools during their employment.
Employee training. Policy and contract language only work if employees understand them and understand why they matter. Training needs to cover what the AI tools actually do with input data, what categories of information are confidential and therefore off-limits for AI input, what the employee should do if they are not sure whether something qualifies, and what the consequences of a violation are for both the company and the employee personally.
None of these three things is complicated. All of them take time and attention to do correctly. And all of them are significantly less expensive than the alternative, which is discovering after the fact that a year of proprietary information has been flowing into OpenAI’s servers because nobody told your employees it was a problem.
The Policy Your Business Should Have Had Yesterday
The businesses that are most exposed to this risk are the ones where AI tool use has outrun policy. Employees are already using these tools. The question is whether they are using them in ways that protect the business or in ways that create liability.
Building the policy now is better than building it after an incident. It is also better than discovering in litigation that your company had no reasonable measures in place to protect its trade secrets, which is the predicate for any successful trade secret claim.
Your employees are not trying to harm your business. They are trying to help it. The job of legal and policy infrastructure is to channel that efficiency in directions that do not create liability in the process.
About George Bellas
George Bellas Partner, Bellas and Wachowski businessattorneychicago.com
George Bellas is a Chicago business attorney with decades of experience helping Illinois businesses navigate commercial disputes, employment law, trade secret protection, and the emerging legal landscape around technology and AI. The intersection of employee AI use and trade secret law is one of the fastest-moving areas in business law right now, and the legal exposure it creates is real, compounding, and almost entirely preventable with the right documentation in place.
If your business does not have an AI use policy, has not updated its confidentiality agreements since generative AI became a workplace tool, or wants to understand its current exposure, contact George Bellas for a consultation.
Call 800.825.9260 or visit bellas-wachowski.com.
Chicago Business Attorney Blog

