FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Governance ¡ 5 minute read

AI and Trade Secrets: Protecting What Leaves in a Prompt

Trade secret protection depends on taking reasonable measures to keep information secret, and sending it to an external model service tests that directly. The practical questions are what leaves in prompts, whether the provider retains it, and whether employees can send confidential material without controls. Record the decisions you take so the position can be revisited if the requirements change.

By FISTA Solutions¡ AI-Native Engineering Team¡
AI and Trade Secrets: Protecting What Leaves in a Prompt article cover

Trade secret protection depends on taking reasonable measures to keep information secret, and AI use tests that directly. The exposure is rarely a deliberate disclosure; it is an employee pasting a document into a consumer tool. This guide covers the controls that work, drawing on FISTA Solutions' AI enablement work. This article is general guidance, not legal advice.

Where does the exposure sit?

Mostly in paths nobody sanctioned rather than in the sanctioned ones.

PathExposure
Consumer AI tools on personal accountsHighest; no terms, no control
Browser extensions with page accessHigh; frequently unnoticed
Sanctioned service, default termsModerate; retention may apply
Sanctioned service, enterprise termsLower; confirm retention and training use
Self-hosted modelLowest; operational burden instead
Code assistants on proprietary codeDepends entirely on terms

What should you check in provider terms?

Retention period, whether inputs are used to train models, sub-processing arrangements, and the confidentiality commitments offered.

Arrangements with zero retention and no training use are materially better for confidential material than default consumer terms. The difference is usually available and usually not the default, which means someone has to configure it deliberately. See what is a data protection impact assessment.

What is the largest practical exposure?

Employees using consumer AI tools with confidential material, on personal accounts, outside any control.

That is where most organisations lose information, and it happens because the sanctioned path is worse or does not exist. A policy prohibiting it does not stop it; a good sanctioned alternative plus technical controls does. See what is shadow ai.

What controls actually work?

A sanctioned tool with appropriate terms that people actually prefer, network controls limiting access to unsanctioned services, data loss prevention on the paths people use, and training that explains the reasoning.

The order matters. Blocking without providing an alternative drives usage to personal devices, which removes what visibility you had. Provide first, then control.

What evidence do you need?

Records of which services are sanctioned and on what terms, evidence of technical controls limiting unsanctioned use, training records, and documentation of what categories of information may be sent where.

If that evidence exists as a by-product of how systems are built and operated, you are in good shape. If it exists only as documents written for a review, you are not, and the difference is visible to anyone who looks carefully.

How does this change engineering practice?

It pushes classification-aware routing into internal tooling. A system that knows a document is confidential can route it to a self-hosted or zero-retention path while sending ordinary material to the cheapest option.

That is better than a blanket rule in both directions: it protects what matters without making the tool useless for everything else, which is what drives people to unsanctioned alternatives.

How does it interact with other regimes?

Usually more than expected. The same system can attract questions from a data protection authority, a sector supervisor, and a general AI regulator, each starting from a different premise and arriving at overlapping requirements.

One evidence base mapped to several requirements answers all of them. Separate programmes produce separate documents describing the same systems, and inconsistencies between them are themselves a finding.

What does compliance cost?

Mostly the cost of good engineering practice: evaluation, documentation, logging, and oversight design. Built into a project, the incremental cost is modest and much of it is work the system needed anyway.

Retrofitted onto a live system it becomes a project, performed under a deadline you did not choose, on something people already depend on. See AI compliance audit cost.

What are the common mistakes?

Blocking tools without providing an alternative. Using default consumer terms for confidential material. Assuming a policy is a reasonable measure on its own. And overlooking browser extensions with page access.

Who owns this internally?

The function that owns the systems, with legal and compliance support. Ownership by compliance alone produces documents describing systems nobody changed; ownership by engineering alone produces good practice with no one accountable for the interpretation.

Name a person per system rather than a committee. Committees review; people decide.

What should you ask a supplier?

What documentation they provide about capabilities and limitations, what evaluation evidence they share, how they handle personal data, where processing happens, and what happens to your prompts and outputs.

Suppliers who have prepared answer those quickly. Suppliers who have not take weeks, and that delay is itself information about how the relationship will run.

How do you keep this current?

Assign someone to watch the sources that actually bind you rather than general commentary. Record what was checked and when, so the next review starts from a known point.

Rules in this area change, and a position taken eighteen months ago and never revisited is a risk in itself.

What about code and technical material?

Code assistants raise the same question with higher volume. Proprietary source code sent to a service that retains or trains on it is a disclosure worth assessing deliberately.

Enterprise arrangements generally address this, and the default consumer ones frequently do not. Check the terms actually in force for your organisation rather than the ones on the marketing page.

What should you do first?

Find out which AI services your staff actually use. Network logs usually answer this quickly, and the answer is usually broader than the sanctioned list.

How FISTA Solutions helps

FISTA Solutions builds AI systems so the evidence exists when it is needed: classification-aware routing so confidential material reaches only sanctioned paths, provider terms confirmed for retention and training use, evaluation results dated and versioned, oversight designed structurally rather than asserted in policy, and documentation produced during the build rather than reconstructed afterwards. Delivery runs through AI enablement, AI agents, and forward deployed engineers. The record is 150+ projects for 50+ companies across 12+ countries.

To align a system with these requirements, message FISTA on WhatsApp, or read what is shadow AI.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Can using AI undermine trade secret protection?

It can, where sending information to an external service is inconsistent with taking reasonable measures to keep it secret. The analysis depends on the terms, the controls in place, and whether disclosure was limited. This is general guidance, not legal advice.

02What should you check in provider terms?

Retention, whether inputs are used for training, sub-processing, and the confidentiality commitments offered. Arrangements with zero retention and no training use are materially better for confidential material than default consumer terms.

03What is the largest practical exposure?

Employees using consumer AI tools with confidential material. That is where most organisations lose control, and a policy alone does not stop it — technical controls and a sanctioned alternative do.

04What controls actually work?

A sanctioned tool with appropriate terms, network controls limiting access to unsanctioned ones, data loss prevention on the paths people actually use, and training that explains why rather than only prohibiting.

05What evidence should you keep?

Records of which services are sanctioned and on what terms, evidence of technical controls limiting unsanctioned use, training records, and documentation of what categories of information may be sent where.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project