Trade secrets and AI: if you cannot prove the measures, there is no protection
6 min read
A typical scenario, not the case of a real company. An engineer pastes a bill of materials and a dimensioned drawing into a public AI service to compare two variants: the table is ready in thirty seconds, nobody notices. Eighteen months later a competitor launches a suspiciously similar component and the company sues. The case turns not on what happened to its know-how, but on what it can prove it did to protect it.
A secret is not a property of the information
It is a property of the measures. Article 98 of the Italian Industrial Property Code (Legislative Decree 30/2005), in force since 22 June 2018, protects business information and technical-industrial experience only where three cumulative conditions are met: (a) it is secret, not “generally known or readily accessible to experts and operators in the sector”; (b) it has “economic value because it is secret”; (c) it is “subject, by the persons lawfully in control of it, to measures that can be regarded as reasonably adequate to keep it secret”.
The first two depend on the market. The third depends on you alone. Legislative Decree 63/2018 — implementing Directive (EU) 2016/943 — replaced “confidential business information” with “trade secrets” throughout the Code, rewrote article 99 (unlawful conduct now covers whoever acquires or resells knowing, or having reason to know; five-year limitation period) and replaced article 623 of the Criminal Code: disclosing or exploiting trade secrets carries up to two years’ imprisonment, with an increased penalty where the act is committed “by means of any IT instrument”.
There is no title to produce: there is a file
A patent has a certificate, a trade mark a registration. A trade secret has neither: article 2(4) of the Code protects it “where the conditions laid down by law are met”. There is nothing to file in court but proof of those conditions — and one of the three you write yourself, every day.
Directive (EU) 2016/943 confirms it. Article 11(1) gives the court authority “to require the applicant to provide evidence that may reasonably be considered available in order to satisfy themselves with a sufficient degree of certainty” that a trade secret exists, that the applicant holds it and that it was infringed; article 11(2)(b) lists, among the circumstances to consider, “the measures taken to protect the trade secret”.
First-order consequence: when an employee pastes a drawing, a bill of materials, a formula or a price list into a public AI service, the problem is not only the data leaving: the third statutory condition falls away, and protection with it.
Second-order consequence, the one almost nobody writes down: the burden of proving the measures lies with whoever claims the secret. If you cannot produce policies, access logs, training delivered and technical controls, the court has nothing on which to found protection, and the competitor who benefited answers for nothing. The value of the asset remains. Its defensibility does not.
Why generative AI raises the bar
“Reasonably adequate” is not a fixed level: the directive speaks of steps that are “reasonable under the circumstances” (article 2(1)(c)). A locked cabinet, a confidentiality agreement and a VPN were proportionate when getting a drawing out required a photocopier. Today every desk has an exit channel that takes whole attachments and leaves no trace. A company that in 2026 has written nothing about AI use does not have unchanged measures: it has inadequate ones.
The 27 July paradox
Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force from 27 July, replaces article 4 of the AI Act. Where the 2024 text required providers and deployers “to take measures to ensure, to their best extent, a sufficient level of AI literacy”, the new paragraph 1 requires “measures to support the development of AI literacy” and adds: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The high-risk calendar is unchanged — 2 December 2027 for Annex III, 2 August 2028 for Annex I (map here).
Many will read this as: we can stop documenting training. That is the mistake you pay for in court. The civil judge assessing article 98(c) does not apply the AI Act: they assess the measures, and the training register — dates, attendees, materials — is one of the very few pieces of hard evidence. Brussels has lightened an administrative duty; the Industrial Property Code has not. Same document, two functions: one optional, the other decisive.
When there are people inside the secret
Bills of materials, tender specifications and price lists almost always carry names, and a second front opens. Article 32(4) of the GDPR requires the controller to ensure that anyone acting under its authority “does not process them except on instructions from the controller” — the instruction is itself a measure. Article 32(1)(d) requires “a process for regularly testing, assessing and evaluating the effectiveness” of the measures; article 5(2) requires the controller to “be able to demonstrate compliance” with the principles, lawfulness under article 6 included; article 88 defers to national rules on “monitoring systems at the work place”, ground on which the Italian data protection authority has already acted. Two regimes, one demand: measures that exist and can be shown.
The evidence to put in the binder
Not good intentions: documents a court-appointed expert can open.
- A written, dated perimeter: information classified as a trade secret — drawings, bills of materials, formulas, price lists, source code, supplier records — with the classification criterion. Without the “what”, nothing is assessable.
- An AI use policy signed as read, with communication date and version history: already an obligation in itself, here it counts as evidence.
- A training register: dates, attendees, materials, topics covered.
- Access tracking: who opened what and when, with logs retained, not merely enabled.
- Documented technical controls: segmentation, encryption, restrictions on transfers to external services, with proof they were active on the day.
- Contractual constraints: confidentiality with employees, suppliers, consultants and interns; clauses in IT contracts.
- Periodic review minutes: measures verified, not only adopted.
- Traceability of the AI environment: which system, where the data resides, who administers it, what it keeps.
How we solve it
The first seven entries are paper. The eighth is architecture, and it makes the others credible: if prompts and attachments end up on a public service, no document will show where the data went. That is why we build dedicated, closed AI, detached from the open web, in two modes: on-premise in the client’s own environment, or on our dedicated cloud — reserved for the single client, accessed over a dedicated VPN, with the data centre resident in Italy and premises we staff ourselves. In both cases the data never leaves the perimeter and the log stays yours: producible in court. That is the principle behind our platform: not a commercial promise, an architectural choice.
Could you demonstrate today, before a judge, the “reasonably adequate measures” protecting your trade secrets? Half an hour with one of our experts is enough for a first map of the evidence.
Sources
- Italian Industrial Property Code, article 98 — consolidated text (Normattiva)
- Legislative Decree 63 of 11 May 2018 — implementing Directive (EU) 2016/943, amending articles 98-99 of the IP Code and article 623 of the Criminal Code (Normattiva)
- Directive (EU) 2016/943 — trade secrets, articles 2 and 11 (EUR-Lex)
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, new article 4 of the AI Act (EUR-Lex)
- Regulation (EU) 2016/679 (GDPR), articles 5, 6, 32 and 88 (EUR-Lex)