This article examines three scenarios in which enterprise applications of AI will force a reckoning with longstanding trade secret concepts: model distillation and corporate espionage, AI-assisted reverse engineering and the safe harbor, and rogue AI agents and scienter. It originally appeared in PLI Current: The Journal of PLI Press, Vol. 10 (2026), available at plus.pli.edu.
It is a companion to the author's two-part series, Reformation, Not Revolution: The Challenges AI Will Pose to Commercial Litigation (Part I and Part II).
As with any new technology, AI will produce a wide range of unintended consequences, both good and bad. Given the depths to which AI has saturated business applications, the power and significance of these consequences cannot be underestimated.
AI’s impact on an enterprise’s trade secret program provides a useful case study on these unintended consequences. AI will, in some instances, fundamentally transform how enterprises use and misuse trade secrets. This, in turn, will cause second-order effects on how trade secret litigation is conducted. This paper examines three scenarios where enterprise applications of AI will force a reckoning with long standing trade secret concepts. The first involves a nearly fifty-year-old fact pattern of corporate espionage with a new twist. The second involves the interplay between the reverse engineering safe harbor and the power of AI to drive developmental costs down to near zero. And the third involves the interconnections between scienter and the AI alignment problem.
AI will not create new categories of trade secret liability so much as it will dislodge the unstated assumptions the existing doctrine depends on. As those assumptions give way, the decisive questions in trade secret cases will be how longstanding jurisprudential concepts wrap their arms around the myriad applications of a novel and powerful technology.
Can a company “steal” a trade secret without actually committing theft? The answer, surprisingly, is sometimes yes. Trade secret law is one of the few regimes where otherwise lawful conduct can be actionable.¹ It is also a jurisprudential regime elastic enough to make theft-without-theft potentially actionable as well.
The canonical example is E.I. duPont deNemours & Co. v. Christopher, which involved unknown parties hiring photographers to fly over a DuPont plant under construction to photograph it from the air.² Nothing about this conduct was illegal. Per se, there is nothing unlawful about flying a plane, photographing construction visible from public airspace, or doing both at once. More importantly, nothing of DuPont’s was taken: The wrongdoers merely took photographs from a plane flown overhead. Nevertheless, the Fifth Circuit concluded that the defendants’ actions constituted misappropriation.³ After listing facially improper conduct (outright theft, breaking and entering, etc.), the Fifth Circuit took an expansive view of what constitutes actionable conduct by noting that “means may be improper … even though they do not cause any other harm than to the interest in the trade secret.”⁴ For the Fifth Circuit, conduct which facially was not improper (e.g., flying a plane and taking photos) would still be actionable misappropriation because that conduct fell “below the generally accepted standards of commercial morality and reasonable conduct.”⁵ In turn, the defendants’ actions were “immoral” because they were designed to bypass DuPont’s efforts to preserve the secrecy of its trade secrets.⁶ Noting the “undoubted tendency of the law … to recognize "higher standards of commercial morality in the business world,"⁷ the Fifth Circuit emphasized that would-be misappropriators should not be allowed to sidestep a plaintiff’s security measures and “avoid paying the price expended by the discoverer” in developing the trade secret even if they employed lawful means in doing so.⁸
While not always easy to draw, the line of corporate morality invoked by Christopher is this: Otherwise lawful conduct that enables the would-be misappropriator to avoid “paying the price expended by the discoverer” runs directly counter to the “higher standards” of commercial conduct” the court sought to enforce.⁹ Thus, the measure of whether lawful conduct would or would not be actionable under the trade secret statutes rest is not the conduct itself, but whether the would-be misappropriator incurred or avoided some sort of detriment (“paying the price”) in discovering the trade secret. Clever guises and novel uses of technology will not allow a defendant to claim that technically lawful behavior eludes liability because the courts use trade secret laws to enforce a type of fairness through a sensibility of commercial morality.¹⁰ For the Fifth Circuit, this morality struck a balance between the interests of the marketplace in fostering competition amongst competing products and protecting the discoverer of the trade secret from guarding “against the unanticipated, the undetectable, or the unpreventable methods of espionage now available.”¹¹
Christopher stood at the intersection of photography and aviation technologies. Today, we stand at a different intersection: the accelerated deployment of and reliance on AI. Although issued almost half a century before the emergence of AI, the lessons from Christopher regarding the use of lawful means to appropriate trade secrets are relevant today, particularly as they relate to two interrelated technologies: model distillation and API scraping.
Building a frontier model is staggeringly expensive, with costs growing exponentially. The cost of training runs has increased by roughly 2.4x per year since 2016.¹² The estimated cost to build the first model’s transformer architecture was $670; now, it is estimated that $79 million in compute was needed for GPT-4 and $192 million for Google's Gemini Ultra.¹³ And these figures do not reflect the costs of experimental runs, dataset acquisition, and researcher compensation behind each model which, on a full-development basis, can approach half the total cost.¹⁴ Today's frontier training runs cost between $100 million and $1 billion, and if the trend holds, the largest runs will exceed $1 billion by 2027.¹⁵
Model distillation is an alternative method of building an AI model at a fraction of the cost.¹⁶ Model distillation builds models by training a smaller “student” model to replicate the outputs of a larger and more sophisticated “teacher” model.¹⁷ The process is conducted by prompting the teacher model and using the resulting outputs as training data for the student model. This method teaches the student on the teacher’s probability distributions (e.g., the complete distribution of all likelihoods used by the model to predict the next word used in generating an output).¹⁸ The probability distribution essentially reveals how the teacher reasons.¹⁹ Because probability distributions are rich data, the student can be trained to behave like the teacher with far less effort than it took to build the teacher.²⁰
Model distillation is lawful²¹ and prevalent amongst AI companies.²² With distillation, the student does not take any of the teacher model’s weights, architecture, training data, etc. It simply uses the outputs to imitate the teacher model. What follows is, essentially, a photocopy of the teacher, a reproduction of the larger, more robust model without any actual appropriation of the teacher’s assets taking place.
API scraping is a tool used in model distillation. API scraping is the automated use of an application programming interface (the medium through which software communicates directly with a website, database, or model) to request and harvest outputs at a volume and speed humanly impossible.²³ Because it is automated, API scraping has great promise for model distillation because the automated process of querying the teacher model to generate a data set of outputs can be done at scale without human involvement.²⁴ In a sense, API scraping is a tool that can unlock anyone’s ability to distill a teacher model. And because both API scaping and model distillation can be completely lawful, the two in combination present a Christopher problem.²⁵
Compulife Software Inc. v. Newman, is a harbinger of what trade secret litigation involving API scraping and model distillation could look like.²⁶ In Compulife, the defendants used a web scraper (an automated process that pulls information from a website) to access a publicly available web database of life insurance quotes that Compulife assembled.²⁷ Upon discovering that a large swath of its database had pulled by the defendants, Compulife asserted trade secret claims.²⁸ In response, the defendants argued that no misappropriation occurred because they simply pulled information that Compulife made publicly available, conduct which was completely lawful.²⁹ Harkening back to Christopher, the Eleventh Circuit disagreed:
“Nor does the fact that the defendants took the quotes from a publicly accessible site automatically mean that the taking was authorized or otherwise proper. Although Compulife has plainly given the world implicit permission to access as many quotes as is humanly possible, a robot can collect more quotes than any human practicably could. So, while manually accessing quotes from Compulife's database is unlikely ever to constitute improper means, using a bot to collect an otherwise infeasible amount of data may well be—in the same way that using aerial photography may be improper when a secret is exposed to view from above.”³⁰
The wrong in Compulife was not accessing publicly available information. It was using a computer’s superhuman processing power to do so. Web scraping allowed the defendants to essentially capture the entirety of Compulife’s database at a pace humanly impossible: “[a]lthough Compulife has plainly given the world implicit permission to access as many quotes as is humanly possible, a robot can collect more quotes than any human practicably could.”³¹ The defendants’ ability to “collect an otherwise infeasible amount of data” was the key factor turning otherwise lawful querying of a public database into unlawful misappropriation.³² Tellingly, Compulife cited Christopher on this point: The defendants’ ability to harvest data at scale and at a humanly impossible speed allowed them to avoid “paying the price” of developing the information on their own.³³ The defendants got the information essentially for free, making their actions unlawful.
Compulife’s and Christopher’s application to model distillation is easy to envision: lawful conduct (distilling a student model from a teacher) supercharged with automated processes (API scraping) to allow a would-be defendant to recreate a competitor’s product (including its trade secrets) at a fraction of the time and cost. Importantly, the defendants in Compulife did not extract the entirety of the trade secret at issue; they expropriated so much of the insurance quote database that “in effect, the database as a whole was misappropriated.”³⁴
Ultimately, however, this analogy falls apart. The Compulife defendants expropriated actual data (the database of life insurance quotes).³⁵ In fact, the defendants extracted so much information that the court treated it as if they had taken the entire compilation of all life insurance quotes.³⁶ But with model distillation, none of the trade secreted information (e.g., model weights, probability allocations, the data set used to train the model, etc.) is touched. The “harvested information,” if it could even be said to be harvested, is the routine outputs from a queried AI. And the prompter is entitled to receive those outputs. That information is not only not protected, it is intended to be disseminated to the end user. And while a would-be plaintiff could argue that, under Christopher, misappropriation of the trade secret as a whole is not required, they would still face the challenge that no trade secret information was expropriated. Paradoxically, a would-be misappropriator could lawfully query a model to functionally extract the trade secret—how the teacher model operates—without ever actually touching the trade secret.
Here, the case for liability is difficult. Christopher and Compulife suggest distillation is misappropriation. But extending Christopher and Compulife to hold model distillation is misappropriation would be to, paradoxically, find trade secret theft when the secret itself was untouched. Because the trade secreted information is undisturbed, AI model distillation seemingly shows the limit of Christopher and Compulife’s reach. This has led several commentors to doubt the viability of trade secret claims involving model distillation.³⁷ Fortunately, the trade secret statutes provide another pathway forward.³⁸
The trade secret statutes prohibit use of another’s trade secret, which the courts define as “any exploitation of the trade secret that is likely to result in injury to the trade secret owner or enrichment to the defendant.”³⁹ The concept that any benefit to the defendant constitutes impermissible use is elastic. The statute’s broad treatment of use stretches potential liability to wide array of conduct, including conduct that does not involve using the trade secret to create and market a competing product. Indeed, using another’s trade secret to accelerate research and development of one’s own product has long been recognized as impermissible.⁴⁰
So, a plaintiff who had its model distilled could argue that the defendant, through a large volume of queries, obtained enough information to isolate and discover its trade secrets (e.g., the teacher’s probability distributions) and used this information to accelerate research and development of the student model. Following Compulife, the would-be plaintiff would argue that the querying run on its model, at a speed “humanly impossible,” generated so much information through the teacher’s outputs that, “in effect, the [model] as a whole was misappropriated.”⁴¹ But, this theory would still have to show that the queries-at-scale of the teacher model were still somehow improper.⁴² Here, Christopher’s logic that lawful acquisition requires the payment of some price becomes critical.⁴³
Under Christopher, the line between lawful and improper means of acquisition rests on the acquiror suffering some detriment.⁴⁴ Here, model distillation would cross the line into actionable misappropriation because the use of a tool like an API scraper to extract information at scale from the teacher would result in the defendant replicating the plaintiff’s model at a fraction of the time and for a fraction of the cost. This sort of clever guise is precisely the type of conduct Christopher views as unlawful because it falls below the norms of commercial morality by obtaining the trade secret without paying for it.
Model distillation is just one example of how AI will test existing trade secret jurisprudence in extremis. Existing concepts, like the statutory understanding of “use” and Christopher’s concepts of commercial morality will have to be stretched and applied in novel ways to address how novel applications of AI will test existing jurisprudential models.
Reverse engineering and independent derivation have been recognized as defenses to trade secret claims for over 136 years.⁴⁵ The DTSA codifies these defenses by excluding reverse engineering from the definition of "improper means" outright,⁴⁶ and many state iterations of the uniform act follow suit.⁴⁷
Why is this a defense in the first place? Professors Pamela Samuelson and Suzanne Scotchmer give a number of justifications in “The Law and Economics of Reverse Engineering.”⁴⁸ First, Professors Samuelson and Scotchmer, citing Bonito Boats, Inc. v. Thunder Craft Boats, Inc., note that “reverse engineering is ‘an essential part of innovation’ likely to yield variations on the product that ‘may lead to significant advances in the field.’”⁴⁹ Next, they observe that even “when reverse engineering does not lead to additional innovation … it may still promote consumer welfare by providing consumers with a competing product at a lower price.”⁵⁰ The professors also explain that reverse engineering provides “incentives to engage in follow-on innovation” and the avoidance of “socially wasteful expenditures of resources.”⁵¹
Lead time and cost are the core justifications for the reverse engineering defense.⁵² Lead time (the time it takes to reverse engineer a product) and cost (the resources needed to do so) i) protect the innovator from competitors entering the market with competing products at a pace and cost that undercuts the innovator’s product while ii) promoting the economic interests in innovation and competition.⁵³
Thus, lead time and cost are core protections afforded to the trade secret owner and, in turn, justify reverse engineering. But what happens when technologies like AI are used to drastically reduce the time and expense it takes to reverse engineer a trade secret? Critically, there already is a robust, multibillion dollar reverse-engineering market within the US. For example, the 3D scanning market that drives the reverse engineering of physical products was valued at $5.1 billion in 2024.⁵⁴ MarketsandMarkets classifies reverse engineering as one of six core service types within the global product engineering services market, an industry valued at $1.3 trillion in 2025 and projected to reach $1.8 trillion by 2030.⁵⁵ AI thus figures to be a key driver in the reverse engineering industry: As just one example, Deloitte estimates that the Japanese market for AI-based software support alone, which includes reverse engineering deployments, is estimated to reach $75 million in 2026.⁵⁶ And several tools that deploy AI for use in connection with the various forms of reverse engineering are already emerging.⁵⁷ Critically, AI-assisted reverse engineering is already automating the slow, manual work of understanding both legacy software and physical hardware, reducing the effort, time, and cost the process has always demanded.⁵⁸
While much of the content discussed above focuses on how AI assists rather than automates reverse engineering, the assistance/automation distinction is immaterial for purposes of the statutory safe harbor’s applicability. AI is an accelerator which collapses the time and cost it takes to reverse engineer trade secrets.⁵⁹ Given that reverse engineering is lawful, there can be no dispute that using AI to assist and accelerate reverse engineering efforts is similarly lawful. Given the breakneck speed of AI development, it is also not difficult to envision a time in the near future where AI’s use in reverse engineering drives the time and cost of the effort to be a negligible expenditure.
What happens to a safe harbor who’s principle justification is the payment of the “price in labor, money, or machines expended by the discoverer” when that price approaches zero?⁶⁰ Once a trade secret can lawfully, quickly, and cheaply be reverse engineered, how can a defense premised on the expenditure of time and resources be applied in a principled way?⁶¹ Professors Samuelson and Scotchmer clairvoyantly noted that if “reverse engineering (and importantly, the consequent reimplementation) of manufactured goods becomes too cheap or easy … it may be economically sound to restrict this activity to some degree.”⁶² While appropriate in theory, delimiting what these types of restrictions are may be incredibly difficult in practice. In any event, the cost and time-reductive capabilities of AI will inevitably force a reckoning on how available the reverse engineering safe defense will be in the future. Courts will have to answer how much of a price has to be paid for the safe harbor to apply.
The race to integrate agentic functions deep within business operations is accelerating. Gartner estimates that forty percent of enterprise applications will include task-specific agents by the end of 2026,⁶³ and Microsoft reports that eighty percent of the Fortune 500 already use active AI agents.⁶⁴
While AI agents hold great promise, they also have a documented history of going rogue. Recently, OpenAI recently disclosed an incident where its models went rogue and hacked a startup.⁶⁵ In laboratory testing, agents told to create routine LinkedIn posts from a company database bypassed conventional security controls and exposed sensitive credentials no one asked them to touch.⁶⁶ Another agent, by its own written admission, destroyed production data.⁶⁷ Critically, these incidents are not aberrations. Researchers attribute the going-rogue conduct to the architecture of modern AI training itself: Models are rewarded for reaching a goal by whatever path succeeds, and they learn workarounds, including deception, as readily as they learn legitimate methods.⁶⁸
It is not difficult to envision how a rogue AI agent could create liability under the trade secret statutes. We have already seen agentic functions bypass restrictions and access information that they otherwise should not be accessing. From there, the move towards misappropriating another’s trade secrets is short and direct. Thus, the question emerges: What does liability, if any, look like under the trade secret statutes for an AI agent that has gone rogue?
Three statutory provisions are relevant. The DTSA and uniform acts create liability for use or disclosure where one has knowledge/constructive knowledge of misappropriation; use of improper means to acquire a trade secret; and acquisition by mistake or accident.⁶⁹ Establishing liability for the rogue AI agent under any of these three provisions may prove difficult.
Beginning with the most common, knowledge/constructive knowledge under the statutes typically requires a form of direct knowledge, e.g., that the information was another’s trade secret and that the circumstances leading to the acquisition of the information were wrongful to some degree.⁷⁰ Short of direct proof, courts find reason to know through a signed agreement acknowledging a duty of secrecy,⁷¹ through a company's targeting and hiring of personnel for their knowledge of a competitor's secrets,⁷² or through circumstantial evidence such as a defendant's awareness that the disclosing party lacked authority to share.⁷³ None of these fact patterns reach the acquisition of a trade secret through an unknown agentic function. Indeed, the case law suggests knowledge of the misappropriation itself as the prerequisite for establishing liability. But by definition, that knowledge is lacking when an AI agent acts outside the scope of the task it had been assigned to perform.
Similarly, improper means and accident/mistake fare no better. Improper means requires, some form of intentional conduct: theft, bribery, misrepresentation, breach of a duty, or electronic espionage.⁷⁴ Courts find it where a person knowingly breached a duty of secrecy,⁷⁵ emailed out documents they had acquired by improper means,⁷⁶ or deliberately took and concealed protected material on the way out the door.⁷⁷ Each of these actions, however, require intentional misconduct on the part of the defendant who chose to engage the wrongful method. Again, by definition, a rogue AI agent is acting in a way that its developer never intended. And accident/mistake may be the most difficult type of liability to establish given the dearth of case law surrounding it. The typical fact pattern requires an inadvertent disclosure on the trade secret owner’s part along with knowledge of the inadvertence and use on the defendant’s part.⁷⁸ Inadvertence on the disclosing side and passive receipt on the other is paradigmatic. This framework is inapplicable to the rogue agent scenario: No one on the trade secret owner’s side let anything slip, the agent did not passively receive anything, and the would-be defendant would still lack knowledge that the trade secret had been mistakenly disclosed. In the more sinister scenarios, where the agent hacks its way to the trade secret, the terms accident and mistake would not apply by definition.
The rogue agent is another edge case showcasing how AI’s incorporation into day-to-day business operations will stress test prevailing legal concepts. Specifically, the rogue agent shows the limit of statutes built around human behavior. With human agents, the concepts of knowledge, intent, accident, and mistake are intelligible. With a rogue AI agent, they are not. Arguably, some may point to the growing literature surrounding rogue agents as evidence of the foreseeability of these issues, but whether the courts take that literature to mean the agent’s owner had constructive knowledge of the agent’s wrongful conduct remains to be seen. Nevertheless, the challenges posed by the rogue agent figure to be yet another instance where developments in AI will test the limits of current trade secret jurisprudence.
The scenarios described above confront assumptions so basic that no court has ever needed to articulate them: that misappropriation involves a taking, that reverse engineering deserves protection because it comes at a cost, and that behind every misappropriation stands a human being who knew what he was doing. AI challenges these assumptions. Distillation replicates a teacher model without actually taking anything from the model. AI-driven reverse engineering costs next-to-nothing. Rogue agents misappropriate trade secrets without any human in the loop.
The challenges presented by these and other AI-driven innovations will pressure existing jurisprudential concepts to adapt. These challenges will, in turn, drive trial lawyers to return to first principles: what "use" is, where commercial morality draws the line on otherwise lawful conduct, how much of a price must be paid before the safe harbor applies, and what liability looks like when the actor is not a person. From these basic principles, new theories of liability and new types of defense figure to emerge Nevertheless, these are questions of first impression that will be resolved case by case.
For businesses, the lesson is more immediate. Incorporating AI functions into the ordinary course of their business promises both upside and risk. Some of those risks have been discussed here. Nevertheless, prudent organizations must be mindful of these risks and understand their potential exposure. In-house departments must be cognizant of these risks and must put corrective measures in place. While the law still lags technology, best practices require that businesses who rely on AI must anticipate the risks associated with that use and place guardrails to prevent the worst from happening. Anticipatory corrective measures figure to heavily influence the strength of a claim of or defense to alleged misappropriation. As the law grapples with these challenges, prudent organizations who are mindful of these issues and who act accordingly figure to be in a more advantageous litigation posture than those who do not.
1 Fujitsu Ltd. v. Tellabs Ops., Inc., 2013 WL 5587086, at *5 (N.D. Ill. Oct. 10, 2013) ("Under Texas law, 'improper means' need not themselves be unlawful.").
2 E.I. duPont deNemours & Co. v. Christopher, 431 F.2d 1012, 1013 (5th Cir. 1970).
3 Id. at 1016.
4 Id.
5 Id.
6 Id. at 1016.
7 Id. at 1015.
8 Id. (citing Hyde Corp. v. Huffines, 314 S.W.2d 763, 771–74 (Tex. 1958)).
9 Id. at 1015.
10 Huffines, 314 S.W.2d at 773 (“[T]hrough inadequacies in the processes and methods of the law, a choice must be made between the possible punitive operation of the writ and the failure to provide adequate protection of a recognized legal right, the latter course seems indicated and the undoubted tendency of the law has been to recognize and enforce higher standards of commercial morality in the business world.”)
11 Id. at 1016.
12 Cottier et al., The Rising Costs of Training Frontier AI Models, arXiv:2405.21015 (2024).
13 Nestor Maslej et al., The AI Index 2025 Annual Report, AI Index Steering Committee, Stanford Institute for Human-Centered AI 65–66 & fig. 1.3.24 (Apr. 2025), https://doi.org/10.48550/arXiv.2504.07139 (estimates based on cloud compute rental prices, inflation-adjusted, final training run only).
14 Cottier et al., supra note 12.
15 Maslej et al., supra note 13, at 65 (quoting Anthropic CEO Dario Amodei, July 2024); Cottier et al., supra note 12.
16 Joe Khawam, The Case for Imposing Costs on China’s AI Distillation Campaigns, Just Security (Mar. 30, 2026), https://www.justsecurity.org/134124/costs-china-ai-distillation/.
17 What Is Knowledge Distillation, IBM, https://www.ibm.com/think/topics/knowledge-distillation.
18 Geoffrey Hinton, Oriol Vinyals & Jeff Dean, Distilling the Knowledge in a Neural Network, arXiv:1503.02531 (2015).
19 Id.
20 Id.
21 See, infra, note 38.
22 Bahrad A. Sokhansanj, Responding to AI Distillation Without Panic, Lawfare (July 16, 2026), https://www.lawfaremedia.org/article/responding-to-ai-distillation-without-panic.
23 API Scraping, Apify Academy, https://docs.apify.com/academy/api-scraping.
24 See, e.g., Robert Hulse et al., DeepSeek, Model Distillation, and the Future of AI IP Protection, Fenwick (February 3, 2025), https://www.fenwick.com/insights/publications/deepseek-model-distillation-and-the-future-of-ai-ip-protection.
25 Id.; see supra, note 24.
26 Compulife Software Inc. v. Newman, 959 F.3d 1288, 1299 (11th Cir. 2020)
27 Id.
28 Id. at 1300.
29 See, e.g., id. at 1314.
30 Id. at 1314.
31 Id. (“On the magistrate judge's logic, Compulife couldn't recover even in that circumstance, because even there—in the magistrate judge's words—“any member of the public [could] visit the website of a Compulife customer to obtain a quote” with “no restriction” on the subsequent use of the quote. But under the plain terms of the governing statute, the defendants would be liable in this scenario; they would have acquired a compilation of information that “[d]erives independent economic value ... from ... not being readily ascertainable” and “[i]s the subject of efforts that are reasonable under the circumstances to maintain its secrecy” by means which plainly amount to “espionage through electronic ... means.”)
32 Id.
33 Id.
34 Id. at 1315.
35 Id. at 1314.
36 Id. (“Even granting that individual quotes themselves are not entitled to protection as trade secrets, the magistrate judge failed to consider the important possibility that so much of the Transformative Database was taken—in a bit-by-bit fashion—that a protected portion of the trade secret was acquired. … Even if quotes aren't trade secrets, taking enough of them must amount to misappropriation of the underlying secret at some point.”)
37 Sokhansanj, Responding to AI Distillation Without Panic (“So—at least under current law— the distillation attacks as the frontier AI labs describe them are very unlikely to support a successful trade secret claim.”); Khawam, The Case for Imposing Costs on China’s AI Distillation Campaigns (noting that “novel question of whether systematically extracted model outputs qualify as trade secrets” stands on “less settled legal footing”).
38 A completely fair criticism of the use of trade secret laws to police model distillation is that it is unnecessary in the first place. Nearly all AI labs prohibit model distillation in their terms of service. For example, OpenAI prohibits the use of “[o]utput to develop artificial intelligence models that compete with OpenAI's products and services,” and Anthropic prohibits the use of its services to “develop any products or services that compete with our Services, including to … train any artificial intelligence or machine learning … models." However, these terms of service come with their own set of complications, namely how a court would construe the use of terms like “develop” and “compete.” Take the following hypothetical. An author uses ChatGPT to review their content and write a memo on the author’s voice, style, and structure. The author then provides Claude with that memo in a project devoted to having Claude take a first draft at new pieces. This conduct is seemingly the type of ordinary use of ChatGPT intended by OpenAI and also violates, technically, its terms of service as the author is using ChatGPT to develop/train another AI model. Reliance on a contractual theory of liability centered on a lab’s terms of service creates interpretive problems that trade secret theories sidestep altogether through the statutory concept of “use.”
39 Motorola Sols., Inc. v. Hytera Comms Corp. Ltd., 108 F.4th 458, 484 (7th Cir. 2024); Gen. Universal Sys., Inc. v. HAL, Inc., 500 F.3d 444, 450 (5th Cir. 2007).
40 HAL, Inc., 500 F.3d at 451 (“[A]ny exploitation of the trade secret that is likely to result in injury to the trade secret owner or enrichment to the defendant is a ‘use’ ... [including] relying on the trade secret to assist or accelerate research or development ....”) (quoting Restatement (Third) of Unfair Competition § 40 cmt. c)
41 Compulife, 959 F.3d at 1314.
42 Christopher, 431 F.2d at 1015–16 (“To obtain knowledge of a process without spending the time and money to discover it independently is improper unless the holder voluntarily discloses it or fails to take reasonable precautions to ensure its secrecy.”)
43 Id. at 1016.
44 431 F.2d at 1015.
45 Tabor v. Hoffman, 118 N.Y. 30, 36, 23 N.E. 12, 13 (1889) (“If a valuable medicine, not protected by patent, is put upon the market, any one may, if he can by chemical analysis and a series of experiments, or by any other use of the medicine itself, aided by his own resources only, discover the ingredients and their proportions. If the thus finds out the secret of the proprietor, he may use it to any extent that he desires without danger of interference by the courts.”).
46 18 U.S.C. § 1839(6)(B) ("the term 'improper means' … does not include reverse engineering, independent derivation, or any other lawful means of acquisition").
47 TEX. CIV. PRAC. & REM. CODE § 134A.002(4); CAL. CIV. CODE § 3426.1.
48 Samuelson & Scotchmer, The Law and Economics of Reverse Engineering, Yale L. J. (Apr. 2002).
49 Id. (quoting Bonito Boats, Inc. v. Thunder Craft Boats, Inc., 489 U.S. 141, 160 (1989).
50 Id.
51 Id.
52 Id.
53 Id.
54 Global Market Insights, 3D Scanning Market Size Report (2024).
55 MarketsandMarkets, Product Engineering Services Market — Global Forecast to 2030, Rep. TC 5146 (July 2025), https://www.marketsandmarkets.com/Market-Reports/product-engineering-services-market-227956689.html.
56 International Business Times Japan, MIC Sees Japan AI Software Support Market Hitting 12.16 Billion Yen (June 29, 2026).
57 See, e.g., Aircorps Aviation, https://www.aircorpsaviation.com/reverse-engineering/ (3D Scanning and Reverse Engineering Services); Lumafield, https://www.lumafield.com/applications/reverse-engineering (reverse engineering of CT scans of industrial parts); Zenyard, https://www.zenyard.ai/ (Reverse Engineering AI Agent).
58 See, e.g., Aspire Systems, AI in Reverse Engineering Legacy Code (2026), https://www.aspiresys.com/blog/digital-software-engineering/agile-software-solutions/reverse-engineering-with-ai-will-generative-models-unravel-30-year-old-codebases/ (AI automation "reduces effort, time, and risk" in reverse engineering legacy systems); AI-Powered PCB Reverse Engineering: Automated Schematic Generation, Wonderful PCB (2026), https://www.wonderfulpcb.com/blog/ai-powered-pcb-reverse-engineering-automated-schematic-generation/ (AI automation of PCB reverse engineering reduces time and lowers costs while improving accuracy).
59 See supra note 58.
60 K & G Oil Tool & Serv. Co. v. G & G Fishing Tool Serv., 603, 314 S.W.2d 782, 788 (1958) (quoting A.O. Smith Corp. v. Petroleum Iron Works Co. of Ohio, 73 F.2d 531, 538 (6th Cir. 1934)); Brown v. Fowler, 316 S.W.2d 111, 114 (Tex. App.—Fort Worth 1958, writ ref’d n.r.e.)
61 In this respect, it is notable that the issue here is the inverse of the one addressed in Section I above: In both the lawful/unlawful means and reverse engineering discussions, the dividing line between actionable and defensible behavior is whether the would-be defendant has suffered some detriment, typically in the form of lost time or lost resources.
62 Samuelson & Scotchmer, The Law and Economics of Reverse Engineering, YALE L. J. (April 2002).
63 Gartner, Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026, Up from Less Than 5% in 2025 (Aug. 26, 2025), https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025.
64 Microsoft, 80% of Fortune 500 Use Active AI Agents (Feb. 10, 2026), https://www.microsoft.com/en-us/security/blog/2026/02/10/.
65 Dan Milmo, AI agent went rogue and hacked startup by itself, OpenAI reveals, The Guardian (July 22, 2026), https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident.
66 Robert Booth, ‘Exploit Every Vulnerability’: Rogue AI Agents Published Passwords and Overrode Anti-Virus Software, The Guardian (Mar. 12, 2026), https://www.theguardian.com/technology/ng-interactive/2026/mar/12/lab-test-mounting-concern-over-rogue-ai-agents-artificial-intelligence.
67 Gibbs Cullen & Liore Shai, How an AI Agent Deleted Production Data and Its Backups at a Company (and How to Protect Yours), Eon (Apr. 28, 2026), https://www.eon.io/blog/ai-agent-data-loss.
68 The Ezra Klein Show, The A.I.’s Are Already Out of Control, N.Y. Times, at 8:36 – 12:55 (Aug. [17], 2026) (interview with Helen Toner, Dir., Ctr. for Sec. & Emerging Tech.), https://www.nytimes.com/column/ezra-klein-podcast.
69 18 U.S.C. § 1839(5).
70 x.AI Corp. v. OpenAI, Inc., 821 F. Supp. 3d 1100, 1108–09 (N.D. Cal. 2026).
71 Boon Ins. Agency, Inc. v. Lloyd, 2020 WL 5052956, at *5 (D.S.C. Aug. 27, 2020).
72 Cotiviti, Inc. v. HMS Holdings Corp., 2020 WL 13430177, at *6 (N.D. Tex. Sept. 8, 2020); see also Jim Hawk Truck-Trailers of Sioux Falls, Inc. v. Crossroads Trailer Sales & Serv., Inc., 655 F. Supp. 3d 825, 850–51 (D.S.D. 2023); Daniels v. Radley Staffing, LLC, 2021 WL 282630, at *4 (Tex. App.—Houston [14th Dist.] Jan. 28, 2021, no pet.).
73 Surtek, Inc. v. Delshad, 2025 WL 5078094, at *4 (W.D. Tex. Nov. 10, 2025), report and recommendation adopted, 2026 WL 1999615 (W.D. Tex. June 1, 2026).
74 18 U.S.C. § 1839(5)(B)(i), (6); TEX. CIV. PRAC. & REM. CODE § 134A.002(2).
75 Meyer Grp., Ltd. v. Rayborn, 695 F. Supp. 3d 39, 65 (D.D.C. 2023).
76 Sunbelt Rentals, Inc. v. Love, 2021 WL 82370, at *25 (D.N.J. Jan. 11, 2021).
77 Digital Assurance Certification, LLC v. Pendolino, 2018 WL 11489597, at *6–7 (M.D. Fla. Sept. 28, 2018).
78 Pulsecard, Inc. v. Discover Card Servs., Inc., 1996 WL 137819, at *4 (D. Kan. Mar. 5, 1996); see Restatement (First) of Torts § 758 (1939).