On 10 July, Apple filed suit against OpenAI in federal court in Northern California, alleging trade secret theft that its lawyers describe as happening "at every level, from members of its Technical Staff to its Chief Hardware Officer, and in coordination with business partners." That Chief Hardware Officer is Tang Tan, a former Apple vice president who now leads hardware at OpenAI. Apple's filing, reported by CNBC and TechCrunch, alleges Tan directed Apple employees interviewing at OpenAI to bring "actual parts" from Apple's campus for show-and-tell sessions, and coached departing staff on how to leave without tripping Apple's exit security checks. Separately, the suit claims a former Apple engineer, Chang Liu, kept an Apple-issued laptop after joining OpenAI and used it to access and download dozens of files marked confidential while working on OpenAI's hardware programme.
The backdrop makes this stranger than a routine poaching dispute. Apple and OpenAI have been commercial partners since 2024, when ChatGPT was built into iOS. The relationship cooled once OpenAI moved into consumer hardware itself, paying a reported $6.4 billion for former Apple design chief Jony Ive's startup, io Products. Fortune's coverage counts more than 400 former Apple employees now on OpenAI's payroll, across silicon, on-device AI and hardware design specifically. OpenAI has not yet filed a public response.
This isn't really a story about two companies
It's tempting to file this under "tech industry drama" and move on, but the pattern Apple describes is generic, not Apple-specific: a fast-growing AI lab hiring aggressively from an incumbent, and an incumbent alleging that the hiring crossed from talent acquisition into something closer to industrial espionage. Every enterprise that has signed a partnership, data-sharing or co-development agreement with a frontier AI lab in the last two years has effectively made the same bet Apple made in 2024 - that the relationship will stay commercial, and that confidential material shared under NDA will stay inside the fence it was meant to stay inside. Apple's lawsuit is a live test of what happens when that bet goes wrong, and it is playing out with more legal resources and more visibility than almost any dispute your organisation is likely to have with a vendor.
The two specific failure modes worth borrowing
Strip away the celebrity names and the filing describes two mechanisms, both mundane and both familiar to anyone who has run a security review of joiner-mover-leaver processes. First, an offboarding gap: an employee leaves with a company device and continues to have effective access to confidential systems and files after their employment ends, because device retrieval and access revocation were not enforced tightly enough at the moment of departure. Second, a hiring-process gap: interviews and technical discussions with a departing or potential hire become a channel for information to move that was never intended to move, because nobody drew a hard line around what a candidate can bring, show or describe from their current employer.
Neither of these requires a sophisticated attacker or a technical exploit. They require only that a determined person, or a manager willing to look the other way, treats normal hiring and offboarding friction as an obstacle rather than a control. That is precisely why they are common, and precisely why "we have an NDA" is not the same as having a process that would survive the scrutiny Apple's lawyers are now applying to OpenAI's hiring practices.
What this means if your organisation has an AI vendor relationship
Most enterprises now share something sensitive with at least one AI vendor: proprietary data for fine-tuning, internal workflows described in detail during implementation, or simply the institutional knowledge that flows through a deeply embedded delivery team. The Apple filing is a useful prompt to check whether your own contractual and operational protections would actually hold up if that vendor's staff turnover, or your own, created the same exposure. Two things are worth separating here: what your contract says on paper, and what your access and offboarding controls actually enforce day to day. Litigation like this tends to surface the gap between the two.
- Confirm your AI vendor contracts include explicit trade secret and confidential information clauses, not just generic NDA boilerplate, with defined remedies if breached.
- Review how quickly your own device retrieval and access revocation actually happens when an employee with vendor-facing or IP-sensitive access leaves, not how quickly the policy says it should happen.
- Set clear rules for what your staff can discuss with recruiters or interviewers from partner or competitor AI labs, and make the rule visible, not just written into a handbook nobody reads.
- Ask any AI vendor with deep access to your systems or data what their own insider-risk controls look like, in the same way you'd ask about their encryption or their SOC 2 report.
- Track which vendor employees hold institutional knowledge of your environment, and build a plan for what happens to that exposure when they move on, before it becomes someone else's leverage.
Courts will eventually decide whether OpenAI's hiring crossed a legal line. For everyone watching from outside, the more useful exercise is quieter: pull up your own AI vendor contracts and your own offboarding checklist, and ask honestly whether they would survive the kind of discovery process Apple has just started. Want a practical review of the IP and access exposure in your AI vendor relationships? Email sales@halfteck.com.