We didn’t see the secret when it was still a spreadsheet. We saw it after it had been memorized, memorized by a model that can recite anything it has ever touched. That is the real conflict between Apple and OpenAI, and it is not a copyright dispute wearing a trade secret mask. It is a dispute about whether the law can reach into a matrix of numbers and order it to forget.
Apple is seeking an immediate injunction against OpenAI over trade secrets. That one sentence, reported by Crypto Briefing, dropped into the news like a stone. But anyone who has spent years auditing failed protocols knows that the phrase “immediate injunction” tells you more than the entire complaint. It tells you that Apple believes the damage is already happening, that waiting for a trial would be waiting for the secret to be distributed irreversibly across a global inference network. It tells you that Apple is not asking for money. It is asking for a pause button on reality.
I spent a bear market auditing DeFi protocols that collapsed despite clean code. The pattern was always the same: the incentives were wrong, not the syntax. Trade secret disputes are converging on the same failure mode. The technical infrastructure can be completely lawful — the hiring process, the cloud storage, the model training pipeline — while the underlying information is being absorbed into a system that no human can reverse. That is the insight lawyers are still catching up to. A trade secret in a database can be deleted. A trade secret in a neural network is not “in” the network the way a document is in a file folder. It is woven into the parameters, distributed across millions of micro-adjustments, entangled with other facts that have no business relationship to Apple’s hardware roadmap.
The first thing to understand is the legal frame. If Apple files under the federal Defend Trade Secrets Act, 18 U.S.C. § 1836, it gets a federal cause of action only if the trade secret relates to a product or service used in interstate or foreign commerce. Apple and OpenAI are both California companies, so the state law claim would fall under the California Uniform Trade Secrets Act, Civil Code § 3426. The federal statute gives Apple access to something the state law does not: an ex parte seizure provision. That is the nuclear button. Under DTSA, a court can, in extraordinary circumstances, order the seizure of property needed to prevent the dissemination of a trade secret. But Apple asked for an injunction, not a seizure. That choice is itself a signal.
A preliminary injunction requires the plaintiff to show four things under Winter v. NRDC: a likelihood of success on the merits, irreparable harm absent the injunction, that the balance of equities tips in the plaintiff’s favor, and that the injunction is in the public interest. In trade secret cases, the irreparable harm prong is almost always satisfied by the simple fact that disclosure destroys secrecy. Once the secret is out, no later damages award can put it back. But the first prong — likelihood of success — is where this case gets dangerous for Apple. California courts have refused to embrace the old “inevitable disclosure” doctrine. They do not presume that just because a former employee moves to a competitor, the employee will inevitably disclose what they know. Apple will need to show actual or threatened misappropriation, not merely the opportunity to misappropriate.
This is why the technical details matter more than the legal theories. If Apple only has a hunch that OpenAI hired an engineer who knew something about Apple’s chip design or its private AI infrastructure, a California court will likely say that is not enough. But if Apple can point to a download log, a peculiar communication, or a training run that began suspiciously soon after the engineer joined OpenAI, the court’s calculus shifts. Based on my audit experience, I have learned to look for the transaction that does not fit the pattern. In this case, the pattern is the entire AI industry’s appetite for data. OpenAI is a data-hungry organization. A single engineer does not need to steal a document in order to transfer a secret. They just need to have internalized the secret through years of work and then write natural-sounding prompts that cause a language model to reproduce it. That is the nightmare. There is no file transfer. There is no download. The secret walks out of the building inside a human brain, and the next day it reappears inside a probabilistic machine.
The DTSA contains a fascinating procedural requirement that most casual observers miss. If a plaintiff invokes DTSA, they must file a “privacy statement” identifying the trade secret with enough specificity to put the defendant on notice, and that statement is filed under seal. In other words, Apple must tell the court exactly what the secret is, while simultaneously asking the court to protect it. The judge will read it. The court staff will read it. And if the case proceeds, Apple’s own lawyers will have to argue about the secret in open court, referencing exhibits and depositions that drill into the details. Trade secret litigation is a forced march toward transparency. Winning an injunction may require Apple to reveal more about its internal technologies than it would reveal in three years of product launches. That is one of the hidden costs of “immediate relief.” The government becomes a privileged observer of your crown jewels.
We didn’t design AI to forget. That is a sentence that should terrify every corporate counsel who advises a technology company. Traditional remedies in trade secret law assume that an injunction can order a defendant to stop using and disclosing the secret. But what does “stop using” mean when the secret has been encoded in model weights? OpenAI can stop putting the secret into new prompts. It can try to filter responses that look suspiciously close to Apple’s proprietary information. But the model still contains the information in latent form. It may never output Apple’s exact secret verbatim, yet it might produce a design suggestion that is seventy percent of the way there. Is that “use”? Is that “disclosure”? The statute says misappropriation includes acquiring, disclosing, or using a trade secret without authorization. A machine that has memorized the secret and uses it as a prior probability for generating output is arguably using it in a way that no prior law was written to handle.
This is where the blockchain perspective becomes unexpectedly valuable. I have spent years arguing that decentralized provenance is not just for financial assets. It is for data itself, for models, for the entire chain of custody from raw information to trained inference. Apple and OpenAI are fighting over a secret that has no auditable trail. If OpenAI’s training data pipeline had been built with cryptographically signed receipts, we could ask: did any input to that training run contain a fingerprint matching Apple’s confidential information? We would have an answer. Instead, we have two giant companies and a judge who will have to make a Solomon-like decision about how probability and memorization interact. I spent years in the Web3 world listening to people call on-chain provenance a solution in search of a problem. This case is the problem. The problem is accountability for knowledge itself.
We didn’t need a blockchain to know that OpenAI’s legal team will fight the injunction with procedural speed. The first move is always a request for more time. Discovery needs to happen. The model needs to be inspected. Experts need to be retained. OpenAI will argue that an immediate injunction would be overly broad, that it would harm public interest by interrupting a commercially available service that millions of people rely on. This is a strong card. Courts are hesitant to freeze a popular product based on allegations that do not yet have a full evidentiary record. Apple will respond that every day the model continues to operate, the secret is being further embedded, further distributed, further impossible to extract. And both sides will be right.
The contrarian angle is uncomfortable for Apple. Apple may not actually want the immediate injunction. An injunction, if granted, will force OpenAI to freeze certain systems, but it will also force Apple to post a bond to protect OpenAI against wrongful injury. More importantly, it will force both companies to litigate on an expedited timeline, which means Apple must produce its evidence quickly, perhaps before it has fully investigated its own employee activity. Apple’s lawyers have to decide whether they want speed or certainty. You cannot always have both. If Apple files a polished, detailed motion for a temporary restraining order, it might get a hearing within weeks. But if Apple discovers new evidence after the hearing, it may be locked into a less favorable factual narrative. I have seen this dynamic in DeFi governance disputes. The rush to act is often a trap. The best outcome is often the one you can defer.
There is also a darker theoretical problem. A neural network is not a deterministic repository. It is a lossy compression of all its training data. Some facts are preserved almost exactly, especially if they appear many times across the corpus. Other facts are so deeply abstracted that they no longer resemble the original at all. This is why “deletion” in the AI context is almost meaningless. You cannot surgically remove a single concept from a model without retraining or fine-tuning the entire network, and even then, there is no guarantee the concept is gone. An injunction that says “OpenAI shall not use Apple’s trade secrets” is like telling a river to flow south without changing the landscape. The river will find a way around. Judges understand this at some intuitive level, but they do not yet have a legal vocabulary for it.
That is the information gain that most legal commentary misses. The fight is not about whether Apple can prove OpenAI had access. The fight is about whether the concept of “access” makes sense when the access was mediated by a stochastic process. OpenAI might have trained on a dataset that included a leaked Apple document without any engineer ever reading it. In that scenario, no human at OpenAI has “seen” the trade secret, but the model has. Who is responsible for the model’s knowledge? The corporation that trained it? The dataset compiler? The original leaker? The law has traditionally focused on human actors and their mental states. Trade secret misappropriation requires knowledge, intent, or recklessness. If OpenAI’s training pipeline can acquire information passively, without human awareness, then a court will have to decide whether corporate knowledge includes the model’s latent representations. This is a philosophical question disguised as an evidentiary one.
I remember auditing a smart contract where the vulnerability was not in any single function but in the interaction between two functions that were never supposed to be called in the same transaction. The code looked safe. The protocol failed spectacularly. The same dynamic is playing out here. Apple’s trade secret regime and OpenAI’s training pipeline are two systems that were never designed to interact. When they collide, the failure surfaces in the space between them. A DTSA claim requires Apple to have taken “reasonable measures” to keep the secret secret. Apple has some of the strongest security culture in the world. But “reasonable” now includes not just the physical world of locked servers and NDAs, but the emerging world of data provenance. Did Apple tag its internal documents with metadata that would survive ingestion into a training pipeline? Did it monitor for the statistical fingerprint of its proprietary language? If Apple cannot answer yes to those questions, its own evidence might show that it failed to keep the secret secret in the one way that matters in the age of AI.
OpenAI’s defense will also lean on the idea of independent development. The company will say its model learned general patterns of chip architecture, software engineering, or product strategy from vast public sources, and that any overlap with Apple’s secrets is due to the convergence of best practices, not misappropriation. This is the AI equivalent of the “clean room” defense, except the clean room is more like a public library. OpenAI will argue that you cannot own a concept. Apple will argue that the specific expression of the concept matters, and the model has memorized the specific expression. That argument is stronger than the public might think. Large language models are known to regurgitate training data when prompted in the right way. If Apple can demonstrate that OpenAI’s model can be prompted to produce Apple’s proprietary code or internal design notes nearly verbatim, that is powerful evidence of misappropriation. It is not enough to show the model has the capability; Apple must show that the capability was used, or that the mere possession of the capability itself constitutes a threat of use. The latter argument pushes the law further than most courts have gone.
We didn’t predict how much of the next decade would be about forgetting. Not deleting. Forgetting. Humans forget naturally. We forget because our brains prioritize, because we suppress, because time erodes the intensity of memory. Machines, left alone, do not forget. They only become more confident in their weights. A court order to “forget” a specific fact is a kind of command that has no direct physical implementation. You can fine-tune the model to reduce the probability of reproducing the fact. You can add a filter layer that attempts to detect and block outputs similar to the secret. But none of these mechanisms are true forgetting. They are suppression. And suppression can be bypassed by adversarial prompting, by fine-tuning, or by simply asking the question in a language the filter was not designed to parse. So the immediate injunction, even if granted, may be unenforceable in any meaningful engineering sense. That is the dirty secret of the case.
There is a deeper lesson for the crypto community here. We have spent years talking about decentralized identity, verifiable credentials, and on-chain provenance. This case demonstrates that the legal system desperately needs the kind of tools that blockchains make possible: immutable audit trails, cryptographic hashes, timestamped signatures, decentralized storage that preserves evidence without relying on a single custodian. If Apple had issued a hash of every proprietary training document to a public blockchain at the time of creation, it could prove possession of the secret before the infringement occurred. If OpenAI had required its data pipeline to log every ingested file with a Merkle root, it could prove which files were and were not in the training set. The technology exists. The adoption does not. The result is a courtroom struggle over evidence that could have been objective and automatic. We did not build the trust infrastructure fast enough, and now we are watching two giants fight over the wreckage.
What happens next? The court will hold a hearing, probably sooner rather than later. Apple will present its evidence. OpenAI will present its defenses. The judge will try to balance the irreparable harm to Apple against the public interest in a widely adopted AI product. If the judge sides with Apple, we will see a frantic scramble across the AI industry to implement “data isolation” and “clean team” protocols. Every major AI lab will suddenly care about provenance, because they will understand that a single memorized secret can put a multi-billion-dollar product on ice. If the judge sides with OpenAI, we will see more corporations embrace defensive disclosure — deliberately leaking their own secrets into public datasets so that no one can claim them as trade secrets afterward. One way or another, the case will reshape how we think about intellectual property and neural networks.
But the most likely outcome is a settlement. Both Apple and OpenAI have too much to lose in a judicial opinion. Apple does not want a court to rule that trade secret protection is inadequate for AI because that would weaken its own future enforcement. OpenAI does not want a court to rule that a model’s latent memory constitutes unauthorized use because that would expose every AI company to endless litigation. They will settle, with a confidential agreement, an amount of money, maybe a licensing arrangement, and a carefully worded statement reaffirming both sides’ commitment to innovation. And the underlying doctrinal question — can an AI model be ordered to forget? — will remain unanswered, waiting for the next case, and the next, and the next.
I am an optimist about decentralized systems, but I am a realist about courts. The law is a machine that runs on human concepts. “Knowledge” is a human concept. “Use” is a human concept. “Forgetting” is a human concept. We are asking the law to apply human concepts to non-human intelligence, and the mismatch is not a bug in the code. It is a bug in the ontology. The only way forward is to build the technical infrastructure that makes the concepts legible: provenance for training data, hashes for secrets, identity for models, and audit trails for every parameter that matters. Without that, we will keep seeing cases like Apple versus OpenAI — massive, expensive, and ultimately unresolved in any satisfying way. The future belongs to the organizations that can prove, with cryptographic rigor, what they knew, when they knew it, and where it came from. The rest of us will be left with the uncomfortable question: if a machine can’t forget, should we have let it learn in the first place?

