Apple v. OpenAI: Anatomy of a Defense.

Share
Apple v. OpenAI: Anatomy of a Defense.

Trade Secrets, Labor Mobility, and Litigation as a Competitive Weapon

Gastón Rey

In Brief: Apple's lawsuit aims to freeze OpenAI's hardware ambitions. Yet OpenAI's defense is armed with a formidable arsenal: forcing Apple to define its secrets with surgical precision before discovery, invoking California's categorical rejection of the "inevitable disclosure" doctrine, and diverting the most damaging evidence (the conduct of engineer Chang Liu) into private arbitration. All of this against a backdrop in which trade-secret litigation has become one of the most powerful instruments of industrial competition in the AI era. But the interest of the case is not only legal. It revolves around one question: Can the law separate knowledge from the person who possesses it? That is the philosophical question running through the entire dispute.


Apple v. OpenAI
Use the power of AI for quick summarization and note taking, Gemini Notebook is your powerful virtual research assistant rooted in information you can trust.

I. The Case

On July 10, 2026, Apple Inc. filed suit in the U.S. District Court for the Northern District of California (San Jose Division, Case No. 5:26-cv-07078) against OpenAI Foundation, OpenAI Group PBC, its hardware subsidiary io Products, LLC, and two former Apple employees: Tang Yew Tan (a 24-year Cupertino veteran, former VP of Product Design for iPhone and Apple Watch, now OpenAI's Chief Hardware Officer) and Chang Liu, a senior system electrical engineer who joined OpenAI in January 2026.

The 41-page complaint pleads two causes of action: misappropriation of trade secrets under the Defend Trade Secrets Act (DTSA, 18 U.S.C. § 1836 et seq.) against all defendants, and breach of Apple's Intellectual Property Agreement (IPA) against the two individuals. The factual allegations are severe. Tan allegedly used Apple's internal project code names to extract information from candidates during recruiting interviews, asked them to bring "actual parts" (batteries, logic boards, SiPs) for "show and tell" sessions, and circulated an internal security document ("Need to Know") to teach recruits how to evade Apple's exit controls. Liu allegedly kept a company laptop after resigning and exploited an authentication bug to download dozens of confidential files — celebrating the find by message ("LOL... so funny") — while already working for OpenAI, in addition to receiving a steady stream of information from an employee still inside Apple.

Apple is not merely seeking damages. It petitions for a preliminary and permanent injunction compelling the defendants to stop using its technologies, return all materials, and preserve evidence. Translated: it seeks to freeze, or at least dramatically slow, OpenAI's push into AI hardware, the $6.5 billion business OpenAI acquired when it bought io, the startup co-founded by Jony Ive and Tan himself.

This article does not attempt to adjudicate who is right, but rather to reconstruct, from a doctrinal standpoint, how OpenAI should defend itself — because I believe that is what matters most to lawyers interested in complex defense strategies, and to anyone who supports a free and competitive industry. And also because in the architecture of that defense something larger than the lawsuit comes into view: the structural tension between intellectual property as a fortress and talent mobility as the engine of innovation.

II. The Playing Field: What Apple Must Prove

To prevail under the DTSA, Apple must establish three concurrent elements: (1) that the information at issue constitutes a trade secret — that it derives independent economic value from not being generally known, and that it was the subject of reasonable measures of protection (§ 1839(3)); (2) that there was misappropriation (§ 1839(5)), either acquisition by improper means, or use or disclosure with knowledge of the improper origin; and (3) that the secret relates to a product or service used in, or intended for use in, interstate commerce.

Each element is a battlefront in itself. And a competent defense should not deny wholesale. It should dismantle element by element, defendant by defendant. Because there is a procedural fact here that tends to get overlooked: Apple sued five distinct parties, and what it can prove against Chang Liu is not what it can prove against OpenAI Group PBC. The first rule of the defense, then, is to prevent individual conduct from contaminating the corporation.

III. First Line: The Particularity Requirement

Before reaching the merits, the defense must fight the decisive procedural battle, which is forcing Apple to say, with full precision and exactitude, what was stolen.

The complaint describes the secrets in five categories of enormous breadth: hardware engineering and product design, manufacturing processes, component technologies, testing and validation methodologies, and supply chain operations. Within them fit things like Apple's "business acumen," its "systems-level integration knowledge" conceived "as an integrated whole," and even "aggregated personnel information" about which employees work on which projects. It is fair to say that the complaint betrays its own insecurity with a telling fallback clause: to the extent any item "is determined not to meet the statutory definition of trade secret," it would nonetheless constitute "Apple Confidential Information" protected by contract. That vagueness is not carelessness; it is strategy. A diffuse description lets discovery function as a kind of periscope: Apple would gain access to the internal communications and design documents of its most dangerous competitor in AI hardware, and only then tailor its claims to what it finds.

The tool to block this exists, and it lies in California law, which provides a procedural mechanism designed precisely to prevent this tactic. Section 2019.210 of the California Code of Civil Procedure requires a plaintiff to identify its trade secrets "with reasonable particularity" before commencing discovery related to the secret. Although it is a state rule, courts in the Northern District of California have frequently applied it in federal DTSA cases, either directly or as an exercise of their case-management powers. The defense should therefore file the corresponding motion at the first procedural opportunity, with a crisp argument: a litigant may not use the federal courts as an instrument of industrial intelligence. If Apple cannot define the secret without first rummaging through OpenAI's files, then the "secret" was never a delimited legal object at all, but a mere suspicion shaped like a complaint. In practical terms, this would force Apple to show its cards before it can inspect OpenAI's hand.

There is a further benefit. Forced particularity would expose another weakness: that much of what Apple describes may be general industry knowledge, information disclosed in Apple's own patents, or techniques familiar to the suppliers of the Asian manufacturing ecosystem. A "secret" composed of public elements survives only as a protected compilation if Apple shows that the specific combination is secret and valuable — a burden the current vagueness makes impossible even to assess.

IV. The Structural Defense: California Against Inevitable Disclosure

We now enter the doctrinal heart of the case, and the argument that transcends the parties.

Behind the figure Apple brandishes with alarm (more than 400 of its former employees now work at OpenAI) beats an implicit legal theory: that those professionals will inevitably use what they know. And it is not merely implicit, since the complaint pleads, as an act of misappropriation in itself, the "deploying [of] Apple's institutional knowledge" in OpenAI's hardware development, its supplier operations, and even its "hiring decisions."

When the knowledge an executive carries in his head about how an industry works becomes the object of judicial reproach, and when hiring people is invoked as a form of misappropriation, we have left the law of trade secrets and entered other territory. That territory is the inevitable disclosure doctrine, born in the Seventh Circuit with PepsiCo v. Redmond. And it is precisely the doctrine California has categorically rejected.

In Whyte v. Schlage Lock Co., 101 Cal. App. 4th 1443 (2002), the California courts held that inevitable disclosure is incompatible with the state's public policy, because it converts confidentiality agreements into judicially created ex post non-competes, without the worker's consent and without compensation. The foundation is section 16600 of the Business and Professions Code, which voids any restraint on the practice of a profession — reinforced since 2024 by § 16600.5, which extends that nullity to agreements signed out of state and gives affected workers a cause of action. California does not protect labor mobility for ideological reasons but for pragmatic ones: it protects it because Silicon Valley (Apple included) was built on it.

But the argument has a second part, less cited and more forceful: the DTSA itself codifies the rejection. Section 1836(b)(3)(A)(i)(I) provides that no injunction under the federal statute may prevent a person from entering into an employment relationship, and that any conditions placed on such employment must be based on "evidence of threatened misappropriation and not merely on the information the person knows." This is not merely persuasive state case law: it is express federal text. Apple cannot obtain through an injunction what Congress textually prohibited.

The strategic consequence is twofold. First, everything in the complaint that functions as a reproach to the mass hiring of former Apple talent must be isolated and neutralized: hiring a competitor's engineers is lawful, aggressive, and (in California) constitutionally valid. Second, the defense can reframe the litigation, not as a misappropriation case, but as a plaintiff's attempt to rebuild, through the courts, the mobility restrictions the law denies it by contract.

And here history hands OpenAI forceful narrative material: Apple has already been sued — and paid — for suppressing labor mobility. In In re High-Tech Employee Antitrust Litigation, Apple, alongside Google, Intel, and Adobe, faced claims over secret reciprocal no-poach agreements that depressed engineers' wages across Silicon Valley; the settlement exceeded $400 million. The court does not need this fact to rule, but the public record registers it. It is an unclean hands argument that is hard to articulate as a freestanding technical defense, but powerful in the balance of equities at the injunction stage and in the court of public opinion, which in litigation between giants is never irrelevant.

V. Apple's Weak Link: Individual Acquisition Is Not Corporate Use

I must be very clear on this point. The allegations against Chang Liu are legally "toxic." An unreturned laptop, a bug exploited after resignation, downloads of confidential files, celebratory messages... If those facts are proven, Liu has a serious legal problem, and no doctrinal article should ignore it.

But Apple's case against OpenAI (the corporate entities, which are the real target) requires an additional evidentiary leap that the complaint takes for granted and the defense must contest relentlessly: the distinction between acquisition and use.

Under § 1839(5)(B), misappropriation by use or disclosure requires that the user know, or have reason to know, that the secret was acquired by improper means. That Liu downloaded files does not prove OpenAI received them; that OpenAI received them does not prove it used them; that some team saw them does not prove they informed the design of any product. Apple will have to trace the full chain: from the downloaded file to the OpenAI hardware component. And that chain, today, is conjecture. The complaint itself structurally concedes it: its allegations against the individuals are detailed and documented; its allegations against OpenAI as an institution are only pattern inferences ("a coordinated pattern of misconduct at an institutional level").

At this point, the corporate-dissociation defense operates, and it should be executed in three movements. Let's see them. 1) Exhibit the compliance program: written policies prohibiting new hires from bringing or using prior employers' information, documented trainings, certifications signed at onboarding. 2) Immediate and visible corrective measures: suspension or segregation of the named individuals, an independent forensic audit of their devices and access, quarantine of any suspect material. 3) Perhaps the hard move: accepting that the corporation's best defense may require sacrificing joint defense. For if the facts against Liu are indefensible, separate representation and an eventual individual settlement isolate the infection. In procedural chess, sometimes a pawn can be given up to save the structure.

V.1 The Footnote Defense

The complaint itself hands the defense, in one of its own footnotes, a tool it must not waste: Liu's employment contract with Apple contains an arbitration clause, with a narrow exception that merely allows Apple to go to court for preliminary injunctive relief. Let's see the strategic translation: Liu can compel arbitration of the merits of the claims against him. If the case against the individual migrates to confidential arbitration, the public jury trial against OpenAI loses its most effective material (the laptop, the bug, the celebratory messages) and is reduced to what Apple actually has against the corporate entities: only the pattern inferences. Fragmenting the proceeding would fragment the narrative, and the narrative is half of Apple's case.

The prize of this dissociation is not trivial: the DTSA reserves doubled exemplary damages (§ 1836(b)(3)(C)) for "willful and malicious" misappropriation. If OpenAI shows that the culpable conduct was individual, contrary to its express policies, and corrected upon discovery, the exemplary-damages scenario — the one that truly threatens a company on its way to an IPO — evaporates.

VI. Independent Development: The "Clean Room" as Evidence, Not Slogan

The DTSA expressly recognizes that independent derivation is not an improper means (§ 1839(6)(B)). Independent development is the only absolute defense to misappropriation: if OpenAI's product does not causally descend from Apple's information, there is no case, however grave an individual's conduct may have been.

The so-called "clean room" is not declaimed; it must be documented with technical rigor. The defense needs to reconstruct (or build going forward, if it does not exist) an auditable record: which teams designed which components, with which informational inputs, with which barriers vis-à-vis the former Apple employees named in the complaint. Every specification obtained from public sources, every datum legitimately provided by suppliers, every design decision with a traceable genesis is a brick in the wall that severs the causal nexus.

One should be precise about the cost, because if OpenAI did not implement segregation protocols when it absorbed io and mass-hired Apple's "ex-talent," retrospective reconstruction will be arduous, and discovery will reveal it. The lesson for the entire industry — and this may prove the case's durable contribution — is that the clean room has ceased to be an exotic precaution of 1990s software litigation and has become basic legal infrastructure for any company hiring a competitor's talent. In this sense, IP compliance is, in the AI talent war, what audited accounting is to capital markets.

VII. The Decisive Battle: Neutralizing the Injunction

It is fair to say that Apple can lose the case and win the war if it obtains the preliminary injunction. Freezing OpenAI's hardware development for the two or three years of the litigation is, in technological time, a final judgment without a trial (in economic and market terms). That is why the injunction hearing is the true battlefield — and there, if the strategy is played well, the standard favors the defense.

Let us review the requirements for injunctive relief in a case of this kind. Under Winter v. Natural Resources Defense Council, 555 U.S. 7 (2008), Apple must prove four elements: likelihood of success on the merits, imminent irreparable harm, a favorable balance of equities, and the public interest. And in addition, under the logic of eBay v. MercExchange, 547 U.S. 388 (2006), none of those elements is presumed: not even ownership of an intellectual property right automatically yields injunctive relief.

Keep in mind that Apple's weakest flank is irreparable harm. OpenAI has not launched any commercial hardware product. There is no lost market share, no diverted customer, no eroded price: there is, at most, a contingent future threat that a nonexistent product might incorporate secrets not yet specified. Speculative harm does not sustain injunctions.

The timing factor is delicate. Apple sent its demand letter in February and did not sue until July, and that distance can erode the claimed urgency; but the defense should not overplay the point, because Apple would likely answer that its investigation was ongoing and that the gravest facts (Liu's downloads, Peng's April departure) are recent. The solid argument is not delay but the absence of a product: there can be no urgency to stop the sale of something that does not exist.

Turning to the balance of equities, the asymmetry is brutal and should be exploited by OpenAI: pointing out that for Apple, denial of the injunction merely means waiting for trial while retaining its damages action against a fully solvent company, whereas, at this precise moment, for OpenAI, a grant would mean the paralysis of an entire business line on the basis of unproven allegations. And stressing that, on the public interest, the defense should invoke competition policy: the AI hardware market is being born, and the public interest favors that market being plural — not that Apple, one of the dominant players in consumer hardware, sterilize it in the cradle through injunctive relief.

And finally, there remains in any event an escape valve the defense should keep in mind: the DTSA itself contemplates, in exceptional circumstances, the imposition of a reasonable royalty in lieu of prohibition (§ 1836(b)(3)(A)(iii)) — and, a very telling detail, Apple's own prayer for relief includes a reasonable royalty as an alternative remedy, implicitly conceding that its harm can be monetized. It is the honorable Plan B, or the acceptable defeat: if the court were to find that contamination actually occurred, the proportional remedy is to monetize the use, not amputate the division. In that context, for a company on the eve of an IPO (Initial Public Offering), the difference between a royalty and an injunction is the difference between a cost and, perhaps, a catastrophe.

VIII. The Supplier Front and the Nuance of "Reasonable Measures"

At this point we must address two allegations that deserve separate treatment, because in both the defense should calibrate finely.

The first concerns the supplier: according to the complaint, OpenAI (itself or through io) had a trusted Apple partner perform Apple's secret multi-step metal-finishing technique, "misleading the partner to believe" it had authorization, and knowing (through Tan) that the partner was bound by use restrictions and confidentiality obligations.

Here it becomes relevant to execute a three-layer counter-strategy. First, challenge the claimed novelty of the technique: what exactly is secret about "metal finishing"? Anodizing, polishing, blasting and their combinations are widely diffused techniques in precision manufacturing; Apple will have to isolate the specific step or combination that is genuinely secret, not claim the entire category. Second, expose the subjective elements. Apple's theory requires that OpenAI knew that performance would breach the partner's obligations to Apple. But the party that knows and administers the scope of its own commitments is the partner: if it accepted the engagement, a client's natural inference is that its contractor is acting within its authority. The allegation that OpenAI "misled" the partner rests, for now, on inferences about what Tan remembered of third-party agreements he did not sign on OpenAI's behalf. Third, the architecture of liability: if there was a breach, the primary one is the partner's breach of its contract with Apple — a dispute between them, conspicuously absent from this complaint. Converting that third-party contractual breach into misappropriation by OpenAI requires an evidentiary bridge (in terms of legal logic, knowledge plus inducement) that discovery must build, not presume.

VIII.1 The Argumentative Limit of the Defense

It would be tempting to argue that if Liu exploited an authentication bug Apple never patched and accessed the network with unrevoked credentials, then Apple failed to take "reasonable measures" and the information lost its trade-secret status. The argument has a valid core but also a dangerous excess. Reasonable measures are a constitutive element of the trade secret, and Apple's systemic failures (the unrevoked access, unrecovered devices, known vulnerabilities) are legitimate material for contesting that element, and they also supply ammunition for rhetorical contrast (the company that presents itself as a fortress of confidentiality was not executing basic offboarding for a senior employee); that is the valid core. But at the same time, the danger would lie in forgetting that no court would accept that the victim's negligence validated the hacking. Exploiting a bug is the improper means par excellence, and the doctrine does not demand perfect security, only reasonable security. The defense should deploy this argument to erode the "secrecy" element and Apple's diligence narrative — but never as a justification for Liu's conduct, which must remain, always, isolated.

IX. The Context: The Use of Litigation as Private Regulation of Competition

No complete analysis can ignore the context in which the lawsuit arises. Apple sues while integrating ChatGPT into Apple Intelligence — that is, it litigates against its own partner. While its own AI program accumulates public delays, and at the exact moment OpenAI is preparing a historic IPO and has just survived Elon Musk's trial. The complaint itself reveals the context: a footnote expressly carves the ChatGPT integration agreement out of the case, clarifying that the alleged misappropriations "do not arise from and have no connection to" it — a kind of firewall drafted to keep the commercial partnership from contaminating the litigation, and vice versa.

The irony completes itself looking eleven months back. In August 2025, X Corp. and xAI sued Apple and OpenAI together in federal court in Texas, describing them as "two monopolists joining forces" colluding (through ChatGPT's exclusivity on the iPhone) to block competitors like Grok. In that docket, Apple and OpenAI are partners accused of cartelizing access to AI; while in the California docket, they are adversaries fighting over hardware talent and secrets. The two suits are perfectly compatible in law and perfectly revealing in combination: they describe a de facto duopoly whose cooperation and whose warfare are both instruments of the same competition for the access terminal to AI. And they generate a cross-risk both companies' lawyers know well: whatever each asserts about the other (about its market power, the nature of their relationship, or the value of the integration) in one courtroom can be read aloud in the other.

This lawsuit is best understood not as an anomaly but as part of a broader industry trend. Across the AI and advanced technology sectors, intellectual-property litigation has increasingly become a competitive instrument rather than a mere mechanism for ex post compensation. Waymo's litigation against Uber over autonomous-driving technology, Anthropic's disputes over training data and copyright, Meta's recurrent trade-secret controversies involving former employees, Microsoft's aggressive defense of proprietary technologies, and Tesla's repeated actions concerning confidential engineering information illustrate the same structural pattern. These cases differ in legal theory and factual background, but they converge on a common strategic function: litigation is used not only to vindicate rights, but also to shape rivals' incentives, raise the costs of their expansion, and influence the movement of talent, capital, and technology. Apple's lawsuit therefore belongs to a broader evolution in which intellectual-property law increasingly operates as a form of competitive governance.

The California lawsuit produces effects from the day it is filed, regardless of its merits. It sows doubt among candidates considering leaving Apple, raises OpenAI's recruiting costs, unsettles its suppliers, and adds a risk factor to its offering prospectus.

From an economic perspective, this reveals the dual function of modern trade-secret litigation. At one level, it performs its traditional role of protecting confidential information and preserving incentives to innovate. At another, it inevitably alters the competitive environment by increasing the transaction costs competitors face. Even without a final judgment, litigation forces competitors to divert managerial attention, retain specialized counsel, conduct forensic audits, reassure investors, renegotiate supplier relationships, and slow recruitment. In highly concentrated technology markets, these process costs become economically significant in their own right. The lawsuit is not only an instrument of legal protection but also a mechanism that reshapes the relative costs of market competition.

All these particulars reveal that the lawsuit performs a systemic function in this context. That, today, in concentrated technology markets, trade-secret litigation operates as an instrument of private regulation of competition, where the injunctive remedy is worth more than the judgment and the process is itself the punishment.

X. Conclusion: A Layered Defense, Not a Wholesale Denial

In conclusion, the most likely outcome does not appear to be anyone's total victory, and OpenAI's position is not comfortable — the facts alleged against Chang Liu, if proven, are indefensible, and the unanswered February demand letter was an unforced error — but its defensive architecture, which is the main object of this article, is solid if built in layers. Let us recapitulate: OpenAI must force particularity before discovery; raise California and federal law against inevitable disclosure; sever the link between individual acquisition and corporate use through demonstrable compliance and, if necessary, separate defenses; document independent development; and concentrate the artillery on the injunction hearing, where Apple's speculative harm collides with the standard of the Winter precedent.

This is a litigation that will redefine the rules of the talent war in the AI era: how much knowledge an engineer may carry in his head, how much diligence a new employer owes, and how far a plaintiff may use the courts to do what California law forbids it from doing by contract. If hiring an engineer becomes presumptive evidence of misappropriation — whether one engineer or a hundred — then trade-secret law ceases to protect innovation and begins regulating labor mobility itself. Much of what Apple seeks to protect is not documentary information but tacit engineering knowledge, and that is inseparable from the engineers themselves. In that sense, Apple v. OpenAI is not merely a dispute between two companies: it is a kind of constitutional test pitting personal rights against commercial rights, because the true object of the litigation is no longer just a trade secret, but the knowledge embodied in those who generate it. And in this respect the answer seems to be that the documents, the files, the blueprints do belong to the employer — but professional experience does not, because it is inseparable from the person. This case will judge the validity of controlling the circulation of technical knowledge in the world's most valuable market.


Note: this article analyzes allegations contained in a civil complaint. None of the defendants has been found liable and, as of this writing, none has answered the complaint.

Read more