In brief

For many organisations, significant trade secret risks arise from individuals who already have legitimate access to confidential information, including employees, former employees, contractors and consultants. While external threats such as cyberattacks and industrial espionage remain important, EU litigation trends indicate that disputes frequently emerge in an employment or post-employment context.

The risk is being amplified by workforce mobility, hybrid working, cloud-based collaboration tools and the growing use of AI solutions, which make it easier than ever to access, copy and share sensitive information, often without malicious intent.

At the same time, EU courts continue to place significant emphasis on whether businesses have taken “reasonable steps” to protect their information. As a result, effective trade secret protection increasingly depends on governance, controls and documentation, rather than legal rights alone.

Key takeaways

  • Treat trade secret protection as a business-wide governance issue involving HR, legal, IT, cybersecurity and compliance functions.
  • Identify and document key trade secrets in advance, as unclear identification can undermine enforcement.
  • Reassess employee lifecycle controls, including onboarding, access rights, monitoring, role changes and offboarding.
  • Update policies on remote working, personal devices and AI tools to reflect current disclosure risks.
  • Ensure that "reasonable measures" are documented, as this is essential to benefit from protection under the EU Trade Secrets Directive

In more detail

Trade secret risk is increasingly shaped by how organisations manage access to confidential information across the workforce. In particular, evolving working practices, expanded use of external resources and the rapid adoption of AI tools are changing how information is accessed, used and potentially exposed

Employees remain central to trade secret disputes

Disputes concerning alleged trade-secret misuse commonly arise in an employment or post-employment context, where individuals have had legitimate access to commercially sensitive information. As workforce mobility increases, so does the potential for such information to be retained, transferred or reused in ways that give rise to disputes.

Changing ways of working are increasing exposure

Hybrid working arrangements, digital collaboration platforms and cloud-based tools have significantly expanded how and where sensitive information can be accessed. At the same time, organisations often rely on consultants, contractors and external specialists who may require access to strategically important information.

This broadens the pool of individuals with access to trade secrets and increases the risk of both intentional and inadvertent disclosures across multiple devices and environments.

AI creates new channels for disclosure

Generative AI tools create additional pathways through which confidential information may be disclosed or otherwise lose its secrecy. Employees may input confidential information, such as source code, business strategies or product specifications, into external systems, potentially exposing it beyond the organisation.

As a result, trade secret protection can no longer be separated from AI governance. Policies governing AI use, alongside rules on personal devices and collaboration tools, are becoming an integral part of managing confidentiality risks. AI governance should therefore address whether particular tools may receive confidential information, how inputs and outputs are retained and used, whether data may be used to train models, and which technical and contractual safeguards apply.

Protection depends on demonstrating reasonable measures

To qualify as a trade secret under the EU Trade Secrets Directive, information must, among other requirements, have been subject to reasonable steps, under the circumstances, to keep it secret. Businesses should therefore be able to demonstrate not only the policies they have adopted, but also how relevant contractual, organisational and technical safeguards operate in practice.

Key elements of an effective framework include:

  • Identifying and classifying trade secrets;
  • Restricting access on a need-to-know basis;
  • Implementing robust confidentiality, IT and AI policies;
  • Maintaining structured onboarding and offboarding procedures; and
  • Documenting the measures in place.

Call to action

Employee-driven trade secret misappropriation is not new. However, the speed, scale and ease with which confidential information can now be accessed and shared have changed significantly.

Organisations should assess whether their trade secret protection framework remains fit for purpose in light of workforce mobility, hybrid working and increasing AI adoption.

For specific guidance on strengthening trade secret governance, reviewing employee-related safeguards, supporting the training of operational teams on the identification and preservation of trade secrets, or responding to a suspected incident, please contact our Trade Secrets team.
Explore More Insight