Introduction: AI’s Impact on Trade Secrets
In the early months of 2023, Samsung faced a significant data breach when its engineers used ChatGPT to share proprietary data, including source codes and other confidential information. This incident led the company to ban the usage of the tool, raising critical questions about the confidentiality of data once it enters a public AI model. As these AI systems become increasingly integrated into daily operations—such as document summarization or code debugging—the preservation of confidentiality warrants more profound scrutiny.
Understanding Confidential Information
In India, the protection of confidential information is not governed by a dedicated statute but through equitable actions for breach of confidence. This requires the information to possess a “necessary quality of confidence,” be disclosed under “obligations of confidence,” and demonstrates unauthorized use to the detriment of the discloser, as established in Coco v. AN Clark (Engineers) Ltd and upheld by the Supreme Court in Central Public Information Officer, Supreme Court of India v. Subhash Chandra Agarwal (2020).
Section 27 of the Indian Contract Act, 1872, allows confidentiality agreements during employment, provided they are not unconscionable, as seen in Niranjan Shankar Golikari v. Century Spinning (1967) and VFS Global Services Pvt Ltd v. Suprit Roy (2007). The Information Technology Act, 2000, further provides remedies under Sections 43A, 72, and 72A for breaches of data confidentiality.
The Challenges of AI in Data Confidentiality
The traditional framework for breach of confidence presumes a human misappropriator. However, when confidential information is entered into a public AI model, like a chatbot, the information often loses its confidential status upon entry. The AI system can retain and utilize the data for training, leading to an unpredictable and irreversible information trajectory, as illustrated by the Samsung incident.
Courts can issue injunctions to prevent disclosures but cannot restore confidentiality once a secret is exposed. This challenge is further complicated by the fact that AI systems are not considered recipients in the traditional legal sense, thus positioning foreign AI providers beyond local jurisdiction, complicating legal recourse.
Legal and Practical Implications
The Digital Personal Data Protection Act, 2023, introduces penalties for data breaches, potentially placing companies in the dual role of victim and wrongdoer if confidential data is leaked through AI tools. Recent cases from the US and UK courts, such as Trinidad v. OpenAI Inc (2026) and United States v. Heppner (2026), highlight the loss of legal protection for information disclosed to AI systems.
Preventive Measures and Strategic Recommendations
Given the limitations of existing legal frameworks, companies must adopt preventive measures to protect their trade secrets. These include crafting robust AI usage policies, revising confidentiality agreements to address AI misuse, and implementing enterprise solutions that prevent data from being used in AI model training. Furthermore, deploying technical controls and monitoring systems can aid in safeguarding sensitive information.
Conclusion: A Call for Proactive Measures
The integration of generative AI into business practices necessitates a reevaluation of traditional trade secret protections. As seen in recent legal decisions, data shared with AI tools loses its protected status, leaving organizations with limited legal remedies. Proactive measures, such as clear policies and technological safeguards, are essential to protect valuable information in the AI era.
