In January 2026, a federal court in the Northern District of California dismissed a Defend Trade Secrets Act claim for a specific reason: the plaintiff had developed her alleged trade secrets inside ChatGPT, and the DTSA requires secret owners to take reasonable measures to keep their information secret. Typing it into a consumer AI tool defeated that requirement before the case reached its merits. (Trinidad v. OpenAI)
Two years earlier, a Connecticut company learned it had a shadow AI problem the way most companies do: by accident. Four days after terminating a salesperson, an AI transcription bot the company had never approved attempted to join a confidential sales call under his name. Only then did the company discover the tool had been recording and transcribing meetings for months. (West Technology Group v. Sundstrom)
In June 2026, Samsung ended a ban that had run the opposite direction for three years. After a 2023 leak sent proprietary source code to ChatGPT, Samsung banned generative AI company-wide. This June, it reversed course and rolled out ChatGPT Enterprise to roughly 125,000 employees, not as an open door but as a governed one, with content policy enforcement and a durable audit trail attached to every call. (Samsung's reversal)
Three companies, three different failure points. A legal claim that failed because there was no record of reasonable protective measures. A shadow tool that stayed invisible until it accidentally announced itself. A three-year ban that ended not because the risk went away, but because prohibition stopped working as a strategy at scale.
This guide covers what shadow AI governance requires under the current trade secret standard, why blocking or redacting alone will not satisfy it, and what a credible governance framework looks like in practice.
Why Shadow AI Is Now a Legal Exposure, Not Just a Security One
Most enterprise narratives around shadow AI focus on the breach: the leaked source code, the pricing sheet pasted into a personal ChatGPT account, the customer list that left through a channel nobody was watching. IBM's most recent Cost of a Data Breach research puts a number on that: organizations with a shadow AI related breach pay roughly $670,000 more on average than the baseline, largely in the cost of reconstructing what happened after the fact.
That number describes a forensics problem. It is not the whole exposure.
The trade secret exposure is structural, not incremental. Under the DTSA, information only qualifies for protection if the owner has taken reasonable measures to keep it secret. Trinidad v. OpenAI tested what happens when the alleged secret was developed inside a consumer AI tool with no protective measures around it: the claim was dismissed with prejudice, not because a competitor stole anything, but because the disclosure itself, to OpenAI, defeated the secrecy requirement. Legal commentary following the ruling has been direct about the implication for employers: a company with no AI usage policy, no employee training that specifically addresses AI tools, and no technical controls has not taken reasonable measures, and a court evaluating a later claim has grounds to say so.
This did not require a data breach. It required an absence of governance.
This is legal commentary on a developing area of law, not legal advice. Organizations should evaluate their own exposure with counsel.
Verizon's 2026 Data Breach Investigations Report found that regular AI use on corporate devices jumped from 15% to 45% in a single year, with source code and other intellectual property the most common category of data entered into unauthorized tools. Cyberhaven's most recent AI adoption research found the sensitive share of corporate data entering AI tools rose from 10.7% to 34.8% over two years. The volume of exposure is rising at the same time the legal standard for adequate protection is being tested in court for the first time.
The Structural Gap: Disclosure Without Attribution
The term "shadow AI governance" gets used loosely across security vendor content, but most of what is marketed under that label is detection: flagging that an employee used an unsanctioned tool, after the fact.
Detection is necessary. It is not sufficient.
What's missing is attribution: a durable, cross-platform record of what was shared, with which AI platform, by whom, and when. Most organizations cannot answer that question today. Anthropic's Console, OpenAI's admin dashboard, and Google's admin tools show usage within their own platform. None of them show what happened on a competitor's platform, on a personal account, or through a browser extension IT never approved. An employee who moves between ChatGPT, Claude, Gemini, and a personal account on any of them leaves several disconnected, partial records, or none at all if the account is personal.
Shadow AI attribution is the practice of maintaining a single, cross-platform record of AI interactions regardless of which tool or account produced them. Without it, an organization cannot answer the questions that matter most when a trade secret claim, a regulatory inquiry, or a board question arrives:
- What data was shared with which AI platform, and when?
- Was the interaction on a sanctioned account or a personal one?
- Can we demonstrate, with a verifiable record, that our AI usage policy was actually enforced, not just published?
- If challenged in litigation, can we produce a record of what was and was not disclosed?
Without that record, a company's AI usage policy and its actual AI usage are two separate ledgers that never reconcile, and only one of them is what a court will ask about.
What Shadow AI Governance Actually Requires
Shadow AI governance is the set of controls that allow an organization to see, attribute, and demonstrate compliance for AI interactions across the platforms its employees actually use, sanctioned or not, in a form that holds up as evidence of reasonable measures rather than a policy document nobody can prove was followed.
A credible framework requires three things working together.
1. Cross-Platform Attribution, Not Account-Level Blocking
Blocking a single vendor's account does not stop shadow AI. It moves it. Samsung's three-year ban demonstrates the pattern at scale: prohibition holds until the operational cost of blocking a widely useful category of tool outweighs the perceived risk, at which point usage either goes underground or the ban gets lifted. Governance that depends on employees staying inside one sanctioned platform is governance that assumes away the problem it exists to solve. Attribution has to work regardless of which platform, which account type, or which device the interaction happened on.
2. A Durable Record, Not a Log That Can Be Deleted
A log that IT can edit, that expires after 30 days, or that lives only inside a single vendor's platform is not evidence. It is a claim. The Sundstrom case is instructive here for the opposite reason Trinidad is: the company had no record of the shadow tool at all until it interrupted a live call. A verifiable record that an AI interaction occurred, tied to the account and platform where it happened, is what turns "we believe our policy was followed" into something a court, an auditor, or a board can actually check.
3. Policy Enforcement That Is Demonstrable, Not Aspirational
An AI usage policy that exists in an employee handbook and nowhere else will not satisfy a reasonable measures standard that courts are now actively applying. The distinction that matters legally is not whether a policy exists. It is whether the organization can show the policy was operational: that AI activity was visible, attributable, and reviewable, not simply prohibited on paper.
The Legal View: What "Reasonable Measures" Means After Trinidad
For general counsel and the board, Trinidad v. OpenAI changes the cost-benefit calculation around shadow AI governance in a specific way. Before the ruling, the primary framing was risk mitigation: fewer leaks, lower breach cost. After it, the framing includes enforceability: an organization's ability to protect its own intellectual property depends on being able to demonstrate reasonable measures were in place at the time the information was created or shared.
That is a discovery-posture problem, not just a policy problem. In litigation, "we have an AI policy" invites the next question: can you show it was followed? A cross-platform, verifiable record of AI interactions is direct evidence in that conversation. Its absence is also evidence, just for the other side.
This is not a claim that any single tool guarantees trade secret protection or satisfies reasonable measures as a matter of law. Reasonable measures is a fact-specific standard that courts assess case by case, and organizations should treat this as an emerging, unsettled area rather than a solved one. What the Trinidad and Sundstrom rulings establish is the direction: courts are beginning to scrutinize whether shadow AI governance existed and functioned, not just whether a policy was written.
The Security View: Detection vs. Reconstruction
For CISOs and IT leadership, the operative distinction is the same one that separates metering from governance in AI coding spend: detection after the fact versus a durable record from the start.
Most current shadow AI tooling, including the browser-based DLP and CASB products built to address this problem, is detection-oriented. It flags a risky paste, warns a user, or blocks a known consumer AI domain. That is useful. It is also retrospective by design, built around the assumption that the primary goal is stopping the next incident, not producing a record that survives the one that already happened.
Reconstruction cost is what IBM's $670,000 figure actually measures: the cost of investigating an incident after the fact when no attributable record existed at the time. An organization with a standing, cross-platform attribution record does not eliminate that investigation. It compresses it from weeks of log correlation and interview-based reconstruction to a query against a record that already exists.
Why Blocking and Redaction Alone Don't Solve This
Two categories of tool dominate the current shadow AI response, and both address part of the problem while leaving the core gap open.
Account and domain blocking (CASB and browser-level tools that restrict access to consumer AI domains) reduces one access path but not the underlying incentive. Verizon's DBIR data shows AI use on corporate devices growing sharply during the exact period these tools proliferated. Samsung's own three-year experience with an outright ban is the clearest single data point available: prohibition did not eliminate demand for the tool, it deferred the decision about how to govern it.
Gateway redaction tools (LLM firewalls that scan and strip PII or secrets before a prompt reaches the model) address content-level exposure but not attribution. Stripping a prompt of sensitive fields before it reaches a model can also degrade the reasoning quality that made an employee route around sanctioned tools in the first place, which recreates the same bypass incentive at a different layer. Even where redaction works cleanly, it produces no record of what was originally in the prompt, who sent it, or when, which is exactly the gap that matters in a reasonable measures analysis.
Governance requires attribution as the substrate underneath both of these categories, not a replacement for them. An organization still needs policy, still needs boundary protection for its most sensitive fields, and still needs a verifiable, cross-platform record that ties every interaction back to who did what, where. Blocking and redaction reduce the frequency of bad outcomes. Attribution is what lets an organization prove, after the fact or in advance of litigation, what actually happened.
Getting Started: A Practical Approach
Phase 1: Establish Baseline Visibility
Before writing new policy, most organizations do not know which AI platforms employees are actually using, sanctioned or not. Instrument the browser layer across the major consumer and enterprise AI platforms and collect a full cycle of usage data before making any policy change. The gap between assumed usage and actual usage is typically large.
Phase 2: Attach Attribution to Every Interaction
Move from aggregate visibility to a per-interaction record: which platform, which account type, which employee, and when. This is the layer that converts a policy document into something that can be checked.
Phase 3: Align Policy to What the Record Shows
Set or revise AI usage policy based on the baseline, not before it. A policy that bans tools employees are already using at scale invites exactly the pattern Samsung spent three years working through.
Phase 4: Build the Audit Trail Legal and Security Both Need
Once attribution is running, the same record serves two audiences without duplicating the work. Security teams use it for detection and incident response. Legal and compliance use it as evidence of reasonable measures if a trade secret, regulatory, or discovery question arises.
Frequently Asked Questions
What is shadow AI governance?
Shadow AI governance is the set of controls that allow an organization to see, attribute, and demonstrate compliance for AI interactions across the platforms employees use, sanctioned or not. It combines cross-platform visibility, a durable attribution record, and enforceable policy, and is distinct from blocking or content filtering alone.
What is the reasonable measures standard for trade secrets?
Under the DTSA, information only qualifies for trade secret protection if its owner has taken reasonable measures to keep it secret. Courts assess this on the specific facts of each case. Trinidad v. OpenAI (N.D. Cal., Jan. 5, 2026) tested this standard against AI tool use, dismissing a claim because the alleged secret was developed inside ChatGPT with no protective measures around the disclosure.
Does Trinidad v. OpenAI mean companies cannot use AI tools?
No. The ruling does not prohibit AI tool use. It establishes that using AI tools without any governance, policy, or protective measures around sensitive information can undermine an organization's ability to later claim that information as a trade secret. Organizations that use AI tools within a governed framework are in a different legal position than an individual using a consumer tool with no controls at all.
What is shadow AI?
Shadow AI is the use of AI tools, consumer or unauthorized, by employees without IT approval or oversight. It differs from traditional shadow IT because AI tools ingest and can retain the data entered into them, creating exposure that persists even after the interaction ends.
Does blocking ChatGPT solve shadow AI risk?
Blocking a specific AI platform reduces one access path but does not eliminate the underlying demand. Verizon's 2026 DBIR shows AI use on corporate devices rising sharply during a period when blocking tools were widely deployed. Samsung banned generative AI company-wide for three years before replacing the ban with governed, enforced access in 2026. Blocking alone tends to defer the governance decision rather than resolve it.
What is cross-platform AI attribution?
Cross-platform AI attribution is a record of AI interactions that holds regardless of which AI platform or account type was used, rather than a log limited to a single vendor's own dashboard. It is the layer that lets an organization answer what was shared, where, and by whom, across ChatGPT, Claude, Gemini, Copilot, and other tools employees use.
How do I demonstrate reasonable measures for AI-era trade secret protection?
Legal commentary following Trinidad v. OpenAI points to three components: a documented AI usage policy, employee training that specifically addresses AI tools, and technical controls that make AI usage visible and attributable rather than assumed. A durable, cross-platform record of AI interactions is what allows an organization to demonstrate the third component rather than simply assert it.
What is the difference between AI usage logging and shadow AI governance?
Logging records that an interaction occurred within a single platform. Governance requires that the record be durable, cross-platform, and tied to policy enforcement, so it can function as evidence rather than a partial internal log that a single vendor controls and can alter or delete.
How does Receipts implement shadow AI governance?
Receipts is Weilliptic's browser extension for cross-platform AI interaction attribution. It logs AI interactions across the platforms employees already use, including ChatGPT, Claude, Gemini, and Copilot, and writes a durable record to WeilChain that ties each interaction to the account and platform where it occurred. It is built to complement existing blocking and redaction tools rather than replace them: those reduce exposure at the point of use, Receipts provides the attribution record that lets an organization demonstrate its AI usage policy was actually enforced.
About Receipts
Receipts is Weilliptic's AI interaction governance layer. It is a browser extension that logs AI interactions across the platforms employees already use, including ChatGPT, Claude, Gemini, and Copilot, creating a durable, cross-platform record that attributes each interaction to the account and platform where it occurred. That record is written to WeilChain.
Receipts is built by Weilliptic, founded by Avinash Lakshman (co-inventor of Amazon Dynamo and creator of Apache Cassandra) and backed by True Ventures.
Learn more at weilliptic.ai or contact us to discuss a pilot for your organization.
