Skip to main content
Back to News
news/AI Safety

Apple Escalates OpenAI Lawsuit With New Trade Secret Evidence

Apple adds new trade-secret evidence to its OpenAI lawsuit, putting employee offboarding, privileged access, and AI security controls under pressure.

Stefan Trbojevic

Stefan Trbojevic

1 September 20262 min read
LinkedIn
Abstract layered access-control architecture with segmented data routes

The takeaway

AI teams need least-privilege access, automatic offboarding, and tamper-resistant logs before autonomous systems touch proprietary data.

Why it matters for builders

Least privilege, short-lived credentials, verified offboarding, and tamper-resistant logs should be treated as core infrastructure for AI agents.

Apple Escalates OpenAI Lawsuit With New Trade Secret Evidence

Apple has submitted new evidence in its trade-secret lawsuit against OpenAI, raising the stakes around employee access, offboarding, and the security of proprietary engineering data.

What happened

In a filing described by TechCrunch, Apple says a former employee, Chang Liu, used a confidential Apple circuit schematic while working at OpenAI. Apple also alleges that Liu exploited a previously unknown authentication bug to retain access to company information and later enlisted an OpenAI colleague to help destroy evidence after Apple began investigating.

The filing followed the handover of Liu’s former Apple laptop for examination. The public version of the new evidence is redacted, but Apple says the material supports its claim that trade secrets were used and that the case requires accelerated discovery. OpenAI has previously argued that Liu accessed Apple files to help former colleagues and blamed Apple for weak residual-access controls after employees leave.

Apple is seeking a preliminary injunction that would restrict OpenAI from developing hardware based on Apple technology while the case continues. It is also asking the court to fast-track evidence gathering, arguing that additional former employees may be involved. TechCrunch reports that Apple’s initial filing said more than 400 former Apple employees now work at OpenAI.

Why it matters for builders

This is not only a dispute between two large technology companies. It is a reminder that AI teams inherit the same identity and access risks as every other engineering organization, while moving faster and concentrating unusually valuable data in developer environments.

For teams building AI agents, the practical lesson is direct: permissions must expire automatically, device access must be auditable, and agent tooling should not inherit a former employee’s credentials or broad repository access. Human review is still necessary when an agent requests privileged access, exports sensitive artifacts, or touches systems connected to proprietary research.

The case also gives a sharper context to OpenAI’s earlier response: legal safeguards and technical safeguards are now colliding in the same workflow. Builders who treat identity, secrets, and offboarding as core product infrastructure will be better prepared for both litigation and autonomous-system failures.

Builder takeaway: AI security starts with boring controls that work every time: least privilege, short-lived credentials, verified offboarding, and complete logs that cannot be rewritten by the systems being investigated.

Abstract identity and access control architecture

Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

1 September 2026

Updated

1 September 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.