Uploading a Report to an AI Chatbot Counts as Disclosing a Trade Secret: A Court Ruling Businesses Should Note

On July 13, a Russian court published a ruling, under which an employee's use of a public AI chatbot to process internal business data amounted to disclosure of a trade secret, sufficient on its own to support a lawful dismissal.


The reasoning is consistent with how courts and regulators in the US and EU are beginning to treat AI tools in the confidentiality and data-protection context, and it has direct implications for how companies draft NDAs, confidentiality policies, and AI usage rules.

Key Facts

Remizova v. EnergoProf Group LLC, Babushkinsky District Court of Moscow, Case No. 2-1545/2026:


The claimant, a Sales Director, was dismissed for a single gross breach of duty – disclosure of information constituting a legally protected secret – after the employer's information-security team detected that she had exported confidential information (sales funnel data, deal-level financials, and roughly 30 commercial performance metrics) from the company's internal, access-restricted analytics platform into DeepSeek, a third-party AI chatbot.


The court partially sided with the employee on a procedural point (one reprimand was quashed for disproportionality), but upheld the dismissal itself, and denied both the reclassification and the severance payment for the employee.

Comparable Cases Worldwide


Regulators and courts around the world are converging on the same basic proposition – that feeding confidential business information into a third-party AI tool is a disclosure event with real legal consequences:

 

  • Trinidad v. OpenAI, No. 4:25-cv-06328 (N.D. Cal., January 2026). A plaintiff's Defend Trade Secrets Act claim was dismissed because she had developed the information at issue through ChatGPT – the court held that voluntarily feeding it to OpenAI meant she could no longer show the "reasonable measures to maintain secrecy" the statute requires. The lesson cuts both ways: using AI to generate valuable know-how can itself destroy the secrecy needed to protect it later;
  • West Technology Group v. Sundstrom, No. 3:24-cv-00178 (D. Conn.). A company sued a former salesperson who had used an AI transcription tool to record confidential internal meetings and retained access to the recordings after termination;
  • Samsung's 2023 ChatGPT incident. Engineers pasted proprietary source code into ChatGPT to debug it. The company's response was an outright ban on generative AI tools, which is now a frequently cited cautionary example in US employment and IP practice;
  • EU regulatory action against DeepSeek specifically. Germany's Berlin data protection commissioner found in mid-2025 that DeepSeek's transfer of user data to China was unlawful under the GDPR, pressing Apple and Google to review the app's availability. Belgium, Ireland, France, Italy and the Netherlands have taken parallel steps.

For any EU business, this means uploading company data to DeepSeek (or similar  non-EU AI services) is a live cross-border data-transfer compliance issue under Articles 44–49 GDPR, independent of any trade secret analysis.

What This Means for Business

Traditional confidentiality frameworks were built for a world where secrets left the building through a USB drive or a personal email. Now, with AI tools, an employee trying to be more productive can move sensitive data outside the company's control in a single prompt, often without any subjective intent to harm the business. Courts are responding by treating that transmission itself as the legally operative act of disclosure. That is good news for employers seeking to enforce confidentiality obligations, but only if the underlying compliance architecture exists.


Action List

Businesses that treat AI-tool governance as an extension of their existing trade-secret and data-protection compliance will be far better positioned both to prevent this kind of leak and to enforce their rights if one occurs. The following measures to be taken are recommended in a view of this issue:

  • Update NDAs and trade-secret policies to expressly reference AI tools, chatbots, and third-party data platforms as prohibited disclosure channels.
  • Maintain a defined, written inventory of what qualifies as a trade secret or confidential information, and obtain signed employee acknowledgment.
  • Deploy monitoring and DLP tools capable of detecting uploads to external platforms, and preserve logs in a form usable as evidence.
  • Align termination-related contractual triggers (severance, "golden parachute" clauses) with precisely defined termination grounds, to avoid disputes over reclassification after a disciplinary dismissal.
  • Train managers and staff on safe use of AI tools without breaching the company's internal policies.


REVERA advises businesses on adapting NDAs, confidentiality regimes, and internal policies to cover AI tool usage, on structuring evidence and disciplinary procedures for suspected data leaks, and on assessing cross-border data-transfer exposure when deploying third-party AI platforms.

Contact our lawyer to learn more details

Write to a lawyer