Guide

Employee Use of AI and Confidential Information

Which AI tools employees may use, what they may put into them, and why the answer affects trade secret protection.

Law checked through

Short Answer

Employees may use AI tools on their own initiative, including tools the company has not approved. When an employee pastes confidential information into such a tool, the information can pass to the provider under terms that allow retention, human review, or training on inputs, and that disclosure is the concrete risk even if nothing further leaks. The legal risk is not the tool itself but what goes into it and on what terms. Customer data brings privacy law, client information brings confidentiality duties, and the company’s own secrets bring trade secret law, which protects information only if the owner takes reasonable measures to keep it secret. A written AI use policy, approved enterprise tools with no-training and access terms, technical controls on what can be uploaded, and training are the measures a court would look for. Routine, unpoliced pasting of confidential information into public tools is evidence an opponent will use to argue those measures failed.

Which Laws Apply

Texas AI-specific: None.

Generally applicable Texas law: Texas Uniform Trade Secrets Act (TUTSA), Civil Practice and Remedies Code § 134A.002(6); contract law (confidentiality agreements); Texas Data Privacy and Security Act (TDPSA) for customer personal data; Texas Disciplinary Rule 1.05 for law firms.

Federal: Defend Trade Secrets Act, 18 U.S.C. § 1839(3); Health Insurance Portability and Accountability Act (HIPAA) where applicable.

What “Reasonable Measures” Means Here

TUTSA protects information that derives independent economic value from not being generally known or readily ascertainable through proper means and that is subject to reasonable measures under the circumstances to keep it secret. Courts look at the whole picture: agreements, access controls, labeling, training and enforcement. AI use adds a new channel to that picture. A company whose employees routinely place customer lists or source code into tools whose terms allow the provider to retain or train on them has weakened its position, even if nothing leaked.

Elements of a Policy

Approved tools, with enterprise terms that bar training on inputs, limit retention and restrict provider access.

Prohibited inputs: trade secrets, client confidential information, personal data outside approved workflows, information held under third-party NDAs.

Personal accounts: barred for company work, or allowed only for non-confidential tasks.

Technical controls: data loss prevention, blocked uploads to unapproved tools, logging.

Review: who checks AI output before it is used externally.

Records: how prompts and outputs are retained and placed on hold.

Departure: return or deletion of AI workspaces and prompt libraries when employees leave.

Departure Records

When an employee leaves, AI chat histories, saved prompts and custom assistants can contain the company’s information. Exit procedures should cover them, and a forensic review of a departing employee’s AI accounts may become as routine as a review of email and cloud storage. See Departing Employees, New Hires, and AI.

Illustrative Example (Hypothetical)

A Texas manufacturer’s engineers use a consumer AI tool to troubleshoot a proprietary process, pasting process parameters into the chat. Two years later the manufacturer sues a former engineer for misappropriation of those parameters. The defendant points to the company’s own engineers’ unrestricted use of a public tool as evidence that the company did not take reasonable measures. A policy, approved tools and training in place before the dispute would answer that argument.

What Is Unsettled

Whether chatbot use defeats reasonable secrecy measures depends on the information, vendor rights, access, controls and actual practice. An upload alone does not supply the complete legal analysis. Document the controls, recipients, permissions and actual disclosure.

Sources