AI Tools and Trade Secret Waiver: A Patent Attorney Guide

For IP and patent attorneys, the value of a client's invention often depends on two fragile things: a filing date and a chain of secrecy. Both are easy to lose. A single voluntary disclosure to a third party — even one made through a tool the lawyer never thought of as a "third party" — can convert a protectable trade secret into public information, undermine a later patent application, or hand a defendant a ready-made defense.

The rise of cloud AI meeting notetakers, drafting copilots, and general-purpose chat assistants has quietly multiplied the number of places where invention disclosures, prior art discussions, and inventor interviews leave the lawyer's control. This article walks through where the trade-secret exposure actually lives, what recent authority says about AI and confidentiality, and what a defensible workflow looks like for a modern IP practice.

This article is for information only and is not legal advice.

Why Trade-Secret Status Is Structurally Fragile

Trade-secret protection under the Defend Trade Secrets Act and the Uniform Trade Secrets Act requires that the owner take "reasonable measures" to keep the information secret and that the information derive independent economic value from not being generally known. Unlike patent or copyright, there is no registration that fixes the right in place. The protection exists only so long as the secrecy discipline holds.

That structure creates two failure modes patent attorneys already know well:

The typical IP practice already has NDAs, invention disclosure forms, engineering notebooks, and access controls. What has changed is that inventor interviews, brainstorming sessions, and internal strategy calls now often pass through cloud AI systems that inject a new third party into the chain — one that most trade-secret programs were not designed for.

The Third-Party Doctrine Meets Cloud AI

The clearest recent signal on this issue came in US v. Heppner (S.D.N.Y. Feb. 2026), where Judge Rakoff addressed whether a litigant's conversations with a public AI platform were privileged. The court held they were not, drawing an analogy to the third-party doctrine: voluntarily handing content to an outside platform is, for confidentiality purposes, disclosure to a third party. The holding is about privilege rather than trade-secret status, but the reasoning matters here, because trade-secret law asks the same underlying question — whether the owner meaningfully controlled disclosure.

If a patent attorney records an inventor interview through a cloud-based meeting assistant, the audio and transcript typically move to the vendor's servers, are processed there, and may be retained under the vendor's default terms. That is a voluntary transmission of the substantive content of the invention to a corporate third party. Whether it defeats trade-secret status in any particular case depends on the vendor's contract, the security posture, and what the client authorized. But the analytic problem is real, and it is the same problem Heppner flagged.

The ABA reached a compatible conclusion on the ethics side in Formal Opinion 512 (July 2024), advising that lawyers using generative AI tools must understand how client information is handled, obtain informed consent where appropriate, and evaluate the tool's confidentiality posture under Model Rule 1.6. The NYC Bar Formal Opinion 2025-6 (Dec. 2025) developed the point further for New York practitioners, focusing on the specific confidentiality analysis for cloud AI features.

Where AI Actually Touches Invention Disclosures

The exposure is not limited to obvious "AI products." Common touchpoints in an IP practice include:

Each of these represents a moment where the substantive technical content of a client's invention leaves the firm's controlled environment. The trade-secret question is not whether the vendor is trustworthy in the colloquial sense. It is whether the client's disclosure discipline can survive a hostile examination about who touched the invention before filing.

The Litigation Backdrop: What Vendors Actually Do

Brewer v. Otter.ai (2025) is a useful reference point. The case put the internal workings of a widely used AI transcription vendor in front of the court and highlighted how meeting content is captured, stored, and processed on vendor infrastructure. Whatever one thinks of the specific allegations, the case surfaced the general fact that cloud transcription is not a passive pipe: it is a data-processing operation on someone else's servers, typically involving retention, indexing, and — depending on the product — model interaction.

On the enterprise-contracting side, West Technology Group v. Sundstrom (D. Conn. 2024) reinforced that trade-secret protection depends heavily on the concrete measures the owner took, not on abstract intent. A firm that funnels invention disclosures through a cloud tool whose terms permit broad processing rights is going to have a harder time arguing "reasonable measures" than one that keeps that content inside a controlled boundary.

Statutory Bar and On-Sale Concerns

Patent attorneys have an additional worry that pure trade-secret counsel do not. Under 35 U.S.C. § 102, a public disclosure of the claimed invention more than one year before filing triggers a statutory bar. "Public disclosure" in the § 102 sense is not identical to the trade-secret analysis, and a confidential disclosure to a vendor under a strong NDA is generally not treated as public. But there are gradations.

Consider a tool whose terms allow the vendor to use content for model improvement, or a free consumer product where the user is effectively the product. The gap between "disclosed under an enforceable obligation of confidence" and "disclosed to a general-purpose service with permissive terms" is exactly the gap where trade-secret protection and § 102 safety both start to fray. The USPTO's guidance on AI use in patent practice acknowledges the confidentiality dimension and pushes practitioners toward tools with defensible data handling.

A Comparative Look at Tool Architectures

The single most useful move for an IP attorney evaluating an AI tool is to ignore the marketing and look at the data path. Where does the audio go? Where does the transcript live? Who can subpoena the vendor? The table below sketches the general categories.

Architecture Where invention content lives Third-party disclosure? Trade-secret risk profile
Public consumer chatbot Vendor cloud, often used for training absent opt-out Yes, by default High — see Heppner reasoning
Cloud meeting bot (joins the call) Vendor cloud, with retention and indexing Yes High unless bound by DPA and confidentiality terms
Enterprise cloud AI with DPA and no-training terms Vendor cloud, contractually restricted Yes, but under obligation of confidence Moderate — depends on contract enforcement and breach exposure
On-device AI (processing on the lawyer's machine) Local device only No vendor recipient of content Lower — no server to subpoena, fewer third-party touchpoints

None of these categories eliminates risk on its own. On-device tools still require good device hygiene, access controls, and clear records of what was captured. But the architectural gap between a public chatbot and a local-only tool is not marketing spin — it is a difference in who can be served with process and who can be breached.

Practical Steps for an IP Practice

A defensible AI posture for a trade-secret-heavy practice tends to share a few elements:

  1. Map every tool that touches invention content. Include meeting notetakers, drafting assistants, search tools, and anything integrated with the firm's document system. If you cannot list them, you cannot defend the chain of secrecy.
  2. Read the data-processing terms, not just the privacy page. Look for training opt-outs, retention periods, subprocessor lists, and audit rights. A vendor that will sign a DPA and an NDA is meaningfully different from one that will not.
  3. Distinguish inventor-facing tools from internal-only tools. A cloud tool used only by lawyers for their own note-taking is a different risk than a cloud tool that ingests raw inventor interviews.
  4. Get informed consent where appropriate. ABA Formal Opinion 512 and NYC Bar 2025-6 both push toward client awareness of AI use in specific matters, particularly where sensitive content is involved.
  5. Prefer on-device processing for the highest-value content. For inventor interviews on unfiled inventions, the safest architecture is one where the audio never leaves the lawyer's device.
  6. Keep a matter-level record of what tool captured what. If trade-secret status is ever challenged, the ability to show a specific, contemporaneous confidentiality chain is worth more than any general policy.

Documenting Reasonable Measures

Trade-secret cases turn on evidence of reasonable measures. That evidence tends to be boring: access logs, NDAs, training records, labels, and matter organization. AI tooling should slot into that evidentiary story, not disrupt it. Two documentation habits are worth building:

For a broader treatment of privilege-and-AI risk beyond trade secrets, see our overview at Basil for Law, which covers the architectural reasoning in more depth.

How Basil approaches this

Basil is a meeting notetaker built for lawyers by a practicing lawyer. Audio capture, transcription, and summarization run entirely on the attorney's Mac using the Apple Neural Engine. There is no server component, no upload step, and no subprocessor chain — Basil itself never receives user data. For an IP practice, that means inventor interviews and internal strategy calls can be captured without introducing a new cloud third party into the trade-secret chain. There is no vendor server to subpoena and no vendor breach surface that touches invention content.

Basil captures both in-person meetings and virtual calls (Zoom, Teams, Google Meet) through on-device "Computer mode" capture, so no bot joins the call. The general Basil app is available today with a 60-minute monthly free tier. The Basil for Law edition — adding privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling for solo practitioners at $19.99/month or $199.99/year, with a 3-day monthly trial and a 7-day annual trial — launches in August 2026. Basil signs DPAs and NDAs on request.

None of this eliminates the underlying legal analysis. Trade-secret status still depends on the client's own secrecy discipline, the completeness of the firm's reasonable measures, and the specific facts of any later dispute. But architecture matters, and choosing tools that keep invention content on the lawyer's device is a straightforward way to reduce the surface area of the problem.

This article is for information only and is not legal advice.

Frequently asked questions

Can using a cloud AI notetaker actually waive trade-secret status?

It depends on the specific facts, but the risk is real. Trade-secret law requires reasonable measures to maintain secrecy and treats voluntary disclosure to a third party without an obligation of confidence as fatal. Routing inventor interviews through a cloud vendor without a DPA, NDA, or comparable protections weakens the secrecy chain and gives an adversary a story to tell. The stronger the contractual and architectural protections, the lower the risk.

What did US v. Heppner say about AI and confidentiality?

In US v. Heppner (S.D.N.Y. Feb. 2026), Judge Rakoff held that a litigant's conversations with a public AI platform were not privileged, reasoning by analogy to the third-party doctrine: voluntarily handing content to an outside platform is, for confidentiality purposes, disclosure to a third party. The case is about privilege, but the same logic informs trade-secret analysis, which also asks whether the owner controlled disclosure.

Does an enterprise DPA solve the trade-secret problem?

It helps, but it does not eliminate the problem. A DPA with no-training terms and clear retention limits converts the vendor into a party bound by an obligation of confidence, which is meaningfully better than a public consumer tool. But there is still a third party holding the content, still a server that can be subpoenaed, and still a breach exposure. On-device processing avoids most of those touchpoints.

How does this interact with the § 102 statutory bar?

35 U.S.C. § 102 bars a patent when the invention was in public use, on sale, or otherwise available to the public more than one year before filing. A disclosure to a vendor under a strong confidentiality obligation is generally not treated as public, but permissive vendor terms or consumer-grade tools narrow that safe harbor. Patent attorneys should treat AI tool selection as part of the pre-filing confidentiality analysis.

What does ABA Formal Opinion 512 require for AI use?

ABA Formal Opinion 512 (July 2024) advises lawyers using generative AI to understand how the tool handles client information, evaluate confidentiality under Model Rule 1.6, obtain informed consent where appropriate, and maintain competence in the technology. It does not ban cloud AI, but it puts the burden on the lawyer to know what the tool does with client content.

Is an on-device AI tool automatically safe?

No. On-device processing removes the vendor as a recipient of content and eliminates a server-side subpoena target, which is a significant architectural advantage. But the lawyer still needs device security, access controls, matter-level documentation, and the same reasonable-measures discipline that trade-secret law has always required. Architecture reduces risk; it does not replace practice management.

Keep client conversations on your device

Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →

This article is for information only and is not legal advice.