

In early 2023, Samsung discovered that its engineers had been pasting proprietary source code, internal meeting transcripts and semiconductor yield data into ChatGPT. The company promptly banned the tool. However, a pertinent question arises: what is the sanctity of sensitive data once entered into a public AI model?
With public AI models increasingly accessible for everyday tasks (summarising documents, debugging code, or drafting memos), the extent to which confidentiality is preserved once information is entered into an AI system requires deeper consideration.
India has no dedicated trade-secrets statute. It protects confidential information through the equitable action for breach of confidence, requiring (i) information with "the necessary quality of confidence," (ii) disclosure "in circumstances importing an obligation of confidence" and (iii) unauthorised use to the discloser's detriment. That test, from Megarry J in Coco v. AN Clark (Engineers) Ltd, was adopted by the Supreme Court in Central Public Information Officer, Supreme Court of India v. Subhash Chandra Agarwal (2020).
Where a contract exists, Section 27 of the Indian Contract Act, 1872 (which renders void agreements in restraint of trade) permits enforcement of confidentiality covenants during employment. Niranjan Shankar Golikari v. Century Spinning (1967) held that a negative covenant during employment is enforceable if not unconscionable. In VFS Global Services Pvt Ltd v. Suprit Roy (2007), the Bombay High Court confirmed that restraints on trade secret use do not offend Section 27. Sections 43A (compensation for failure to protect data), 72 (breach of confidentiality and privacy) and 72A (disclosure of information in breach of lawful contract) of the Information Technology Act, 2000 provide remedies for breach of data confidentiality.
This entire framework assumes a human wrongdoer who can be identified and restrained. When an employee pastes confidential information into a public chatbot, the disclosure has no human recipient, no locatable misuse and no practical way to restore the secret.
The action for breach of confidence rests on a precondition: the information must still be confidential. Once information reaches the public domain or passes to a third party who owes no duty of confidence, it is no longer protectable. An injunction can stop a threatened disclosure; it cannot reverse one already made.
Generative AI severs the link between data and point of input: data entered into a public model may be retained, used for training and resurface in outputs to other users. That is precisely what the Samsung episode illustrated. Once information enters the model, its trajectory becomes unpredictable and largely irreversible.
Such a leak extinguishes the quality of confidence on which protection depends. Courts can restrain a person from disclosing a secret; they cannot restore secrecy to information already absorbed into an external system’s training data. The harm is complete the moment the enter key is pressed.
The action for breach of confidence presupposes a person. In John Richard Brady v. Chemical Process Equipments (1987), the Delhi High Court restrained defendants who had used technical information "entrusted to them under express condition of strict confidentiality" as a "spring-board,” reaffirming that equity restrains abuse of confidential relationships.
An AI system is not such a recipient. It owes no obligation of confidence, stands in no fiduciary relationship and cannot "misuse" information in the sense the cases contemplate. The provider behind it is usually a foreign company that can challenge jurisdiction on grounds of no physical presence in India. Even where jurisdiction can be established, practical obstacles obtaining foreign discovery. Proving what data entered the training corpus and quantifying harm from probabilistic outputs make litigation uncertain.
Under the Digital Personal Data Protection Act, 2023, if the information an employee feeds into an AI tool contains personal data and the employer is a data fiduciary, Section 8(5) (requiring reasonable security safeguards to prevent personal data breach) obliges it to take such safeguards. Section 8(6) (requiring intimation of breach to the Board and affected data principals) requires notice upon breach. Failure carries a penalty of up to ₹250 crore under the Schedule read with Section 33. The leak that makes the company a victim under confidentiality law can simultaneously make it a wrongdoer under data protection law.
Over the past two years, courts in the United States and United Kingdom have begun to confront whether information disclosed to a public AI tool remains legally protected.
In Trinidad v. OpenAI Inc (2026), the Court dismissed a trade secret claim because the plaintiff had developed her claimed "protocols and frameworks" using ChatGPT, thereby disclosing them to a company under no confidentiality obligation. Drawing on Ruckelshaus v. Monsanto Co (1984), the Court explained that where a party discloses a trade secret to others under no obligation to protect it, the property right is extinguished and accepting a platform's terms of service was not a reasonable measure to preserve secrecy.
In United States v. Heppner (2026), Judge Rakoff held that material generated using Anthropic's Claude was not protected, because "Claude is not an attorney" and all "recognised privileges" require "a trusting human relationship" with "a licensed professional who owes fiduciary duties.” Because the consumer terms allowed the platform to train on and disclose user inputs, the defendant "could have had no reasonable expectation of confidentiality.”
In UK and R (on the application of Munir) v Secretary of State for the Home Department (2026), the UK Upper Tribunal held that "uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information" in the public domain, breaching confidentiality and waiving legal professional privilege. The Tribunal noted that closed-source enterprise tools such as Microsoft Copilot “can be used without these risks.”
A company can sue the employee for breach of contract or confidence, but damages are hard to quantify and an injunction cannot reverse absorption into the training corpus. The Information Technology Act, 2000 offers limited remedies through Sections 43A, 72, and 72A. The Bharatiya Nyaya Sanhita, 2023 contains provisions on dishonest misappropriation (Section 314, covering dishonest misappropriation of property), criminal breach of trust (Section 316) and cheating (Section 318), though whether prosecution could be sustained for uploading confidential data into AI remains untested. The law provides avenues for redress, but none that can undo the disclosure.
Companies must draft acceptable use policies that draw a line around confidential, client and personal data; confidentiality and IP assignment clauses that expressly name AI misuse; vendor agreements that address training and retention; and, where employees need these tools, enterprise deployments that contractually exclude inputs from training. Technical controls disabling copy-paste for sensitive systems, data loss prevention tools and network monitoring should complement policy measures.
The settled principles of Indian trade secret law were not designed for generative AI. The doctrine presupposes a human recipient, a locatable misuse and a containable secret, none of which generative AI presents. Early decisions from US and UK courts confirm this gap: information disclosed to a public AI tool loses protected status and the organisation may find itself without meaningful remedy.
Accordingly, protecting an organisation’s most valuable information now depends on preventive action: (i) publishing an AI acceptable-use policy that draws a clear line around confidential, client and personal data; (ii) amending confidentiality and intellectual property clauses to expressly address AI misuse; and (iii) where employees require such tools for legitimate business purposes, deploying enterprise versions that contractually prohibit the use of inputs for model training.
Priyam Sharma is an advocate practicing before the Bombay High Court.