The legal dispute involving Apple and OpenAI over alleged trade secret misappropriation highlights an issue that extends beyond cybersecurity and legal teams: protecting confidential information throughout the employee lifecycle.
Apple filed a lawsuit in July against OpenAI and two former employees, alleging that confidential information was improperly obtained and that one former employee downloaded sensitive files. Apple also alleged that another former employee, now an OpenAI executive, directed candidates to bring Apple hardware components to interviews. OpenAI has denied the allegations.
Regardless of how the case develops, it offers HR teams an opportunity to examine how their organizations protect confidential information during recruitment, employment, and offboarding.
Set Confidentiality Expectations During Recruitment
Trade secret protection should begin before an employee joins the company.
Justin Beyer, an attorney with Saul Ewing, recommends that employers consider using simple confidentiality agreements with finalist candidates. Such agreements can make it clear that candidates are being evaluated for their skills and experience, not for confidential information belonging to a previous employer.
Recruiters and hiring managers should also understand what questions are appropriate during interviews.
Candidates can discuss their professional experience, responsibilities, and accomplishments. However, interviews should not become an opportunity to obtain proprietary information about a competitor.
Employers should avoid requesting details such as confidential customer information, vendor agreements, product plans, or other proprietary material.
Identify and Protect Genuine Trade Secrets
A confidentiality policy alone does not necessarily establish that information qualifies as a trade secret.
Stacy Thomsen, an attorney with DarrowEverett, notes that courts may consider whether an organization actually treated the information as confidential.
That means companies should identify genuinely sensitive information and restrict access based on business need.
If every document is marked as a trade secret, the designation can lose meaning.
A stronger approach is to determine what information truly requires protection and ensure that only employees with a legitimate need can access it.
This principle also applies to HR systems, which may contain compensation details, performance records, benefits information, and other sensitive employee data.
Make Offboarding a Cross-Functional Process
Employee departures should not be treated as an HR-only administrative task.
HR, IT, security, and management may all have responsibilities during the offboarding process.
Organizations should maintain clear procedures for:
Disabling email and application access
Revoking VPN and cloud credentials
Collecting company devices
Recovering physical equipment
Reviewing access permissions
Checking for unusual downloads or transfers
Documenting returned assets
Thomsen recommends reviewing employee activity leading up to departure when circumstances warrant it, particularly for unusual downloads or large data transfers.
Beyer similarly emphasizes the importance of quickly recovering devices and removing access.
BYOD and Remote Work Add Complexity
Remote work and bring-your-own-device programs can make information protection more complicated.
Employees may access company information through personal smartphones, cloud applications, or other systems outside the company's physical environment.
Organizations should understand where corporate information can be accessed and ensure that permissions can be revoked when employment ends.
Exit interviews can also be used to confirm whether employees still possess company devices or have access to organizational accounts.
Build a Culture of Confidentiality
Technology can restrict access, but employees still need to understand why information protection matters.
Beyer recommends regular training so employees understand how confidential information should be handled during their employment and what responsibilities continue after they leave.
For HR leaders, the broader lesson is that trade secret protection is not a single event.
It begins during recruitment, continues through employment, and becomes particularly important during offboarding.
A strong confidentiality program therefore requires more than an NDA or security tool. It requires clear expectations, controlled access, coordinated processes, employee education, and cooperation between HR, IT, security, and legal teams.
