Skip to content
Braincap
← All articles

The person who leaves takes more than the laptop

by Claudiu Hulea · IT Management Consultant

Illustration of proprietary knowledge leaving in a person's memory — the one channel that passes through no technical control

What the Apple–OpenAI lawsuit shows about a risk vector nobody monitors.

On 3 August 2026, Apple filed a motion for a preliminary injunction in its lawsuit against OpenAI and two of its own former employees. The hearing is set for 1 October, before Judge Edward J. Davila, at the federal court in San Jose. The case, Apple Inc. v. Liu, 5:26-cv-07078-EJD, began with a complaint filed on 10 July.

Everything below is an Apple allegation. No court has ruled on the merits, OpenAI contests them publicly and point by point, and the actual description of the trade secrets is under seal. The case interests me here not for who is right, but for the type of failure it exposes — one that reproduces identically in any organization that works with integrators, with technology vendors, and with people who, inevitably, leave.

The thesis is simple and, I think, insufficiently discussed in the local market: recruiting a key person out of a technology vendor is a supply-chain security event. It is the only information-transfer vector that passes through no technical control — no DLP, no egress monitoring, no access log — because the information travels in a person’s memory.

Part I. What broke, concretely

Six failure modes can be extracted from the filings. I treat them as working hypotheses, not as established facts.

  1. Offboarding that stops at disabling the account. Apple claims a former engineer did not return the work laptop and that an authentication defect let him keep accessing the company’s network storage after leaving. He allegedly downloaded dozens of files — technical presentations, engineering data, information about unannounced products. This is not a sophisticated attacker. It is the difference between disabling an account and actually revoking every access path: federated tokens, active sessions, device certificates, SSH keys, links to personal cloud accounts, apps that keep credentials in cache.

  2. The “helpful former colleague” channel. The most instructive part comes, paradoxically, from OpenAI’s public response: it includes message exchanges said to show Apple employees asking the former colleague for help locating files after he had left. Regardless of who is legally right, the operational observation stands: if your team needs a departed person to find internal information, the problem is not the person. It is knowledge management. And every such interaction is a transfer channel that appears in no report.

  3. Recruiting as a collection process. Apple alleges that its own former employees, now at OpenAI, used internal project code names in interviews and asked candidates to bring “real parts” — prototypes and CAD artifacts — to show and tell sessions, including batteries, logic boards, screens. One candidate was reportedly surprised, saying he did not know such components could be taken out of the office.

  4. The shared vendor as a lateral bridge. A separate allegation targets a trusted Apple supplier, said to have been asked to run a proprietary metal-finishing process for a third party. Your supplier knows your process. If it also serves the competitor, the confidentiality boundary runs through a process engineer’s head, not through a contract.

  5. Detection latency. By some accounts, part of the evidence was discovered months later, incidentally, on someone else’s laptop. Detection was accidental, not systemic.

  6. Pre-litigation correspondence hygiene. OpenAI claims that Apple’s outside counsel sent the initial notice to the wrong person, confusing two Asian surnames, and that a phone call Apple invoked never happened — something Apple reportedly later acknowledged. OpenAI published the email chain. The lesson: if you ever intend to defend your secrets in court, your pre-litigation correspondence file becomes evidence. Here it became the other side’s best PR material.

Part II. The distinction without which the article becomes propaganda

Before the controls, a clarification missing from most material on this topic — and without which you quickly end up in an indefensible position.

Professional mobility is not an attack. Free movement of workers is a fundamental EU right (art. 45 TFEU), and the right to work is constitutionally guaranteed in Romania (art. 41). An engineer who moves to a competitor takes with them, entirely legitimately, everything they learned: skills, judgment, patterns, experience. This is called general know-how and cannot be confiscated by any employer.

Romanian case law makes the distinction explicit: a former employee may work with the employer’s previous clients if those clients freely choose them, based on their legitimate knowledge, without abusive use of confidential information.

What is protected, then, is much narrower. Under OUG 25/2019, the act by which Romania transposed EU Directive 2016/943, amending Law 11/1991 on combating unfair competition, a trade secret must cumulatively meet three conditions:

  1. it must be secret — that is, not generally known or readily accessible to persons who normally deal with that type of information;
  2. it must have commercial value precisely because it is secret;
  3. it must have been the subject of reasonable protection measures by its legitimate holder.

Hold on to the third condition, because it is the one that completely changes the nature of the discussion.

The controls described below are not just prevention. They are the condition for the secret’s legal existence. If you cannot demonstrate classification, access restriction, confidentiality agreements and consistent enforcement, you do not have a trade secret to defend. You only have information you chose not to publish.

Romania maintains a dual system: Law 11/1991 holds the definitions and the administrative/criminal side; OUG 25/2019 (amended by Law 230/2024) brings the civil remedies and interim measures from the directive.

I am not a lawyer. The legal references above must be validated with a lawyer before being used as a basis for contractual clauses.

So: a channel is not an attack. Recruiting is a permanent, legitimate and unmonitored channel. The attack is the subset in which someone uses it deliberately to obtain protected information. You design your controls for the channel, because you cannot know in advance which recruitment is which.

Part III. The technology vendor, the special case

Here is the core, and it is the part the Apple case suggests but does not spell out.

When a person leaves you, they leave with what they know about you. When a key person leaves your technology vendor, the situation is qualitatively different, for four reasons:

The knowledge is privileged by construction. The architect who implemented your firewall, the engineer who designed your network segmentation, or the consultant who configured your backup platform did not learn these things by deduction. They designed them. They know the topology, the configuration exceptions, what you postponed fixing and why.

The knowledge is multiplied. The same person almost certainly also worked for the vendor’s other clients. In a concentrated market — and the Romanian integrator market for the financial sector is concentrated — a senior architect carries in memory the security posture of several competing entities at once.

The transfer produces no artifacts. There is no exfiltrated file, no DLP alert, no egress anomaly. The ICT third-party register required by DORA (art. 28–30) tracks contracts, not people. A contract can remain perfectly valid while all the operational knowledge behind it has left for a competitor.

The risk is bidirectional. If you recruit the key person from a competitor’s vendor, you become the recipient of a potential contamination. And in cases of this kind, the company that hires is the one that ends up as defendant. Apple did not sue only the two engineers — it also brought the employer and the hardware subsidiary to court.

What to actually do

In the vendor contract. Key-personnel clauses: an obligation to notify, within a defined period, when a person named on the account team leaves the vendor or exits the project. Confidentiality obligations that survive termination and that pass down to individual staff, not just to the legal entity. The right to request confirmation that access has been revoked.

A caution: reciprocal non-recruitment (no-poach) clauses are competition-law minefields. Competition authorities, including Romania’s Competition Council, treat no-poach agreements between undertakings as potential labor-market restrictions. Do not build your strategy on them. Check every such clause with a competition lawyer.

In identity management. Each vendor consultant gets a named identity. Zero shared vendor_admin accounts. Without this, you can neither revoke selectively nor reconstruct who saw what. Access is tied to a person and a time window, not to a contract.

In architecture. A vendor does not need global visibility to deliver a bounded scope. Segmentation, just-in-time access, recorded sessions for privileged operations, a jump host. The rule of thumb: if a single consultant can draw your entire security architecture from memory, you have a design problem, not a personnel problem.

In documentation. If the only source of knowledge about your infrastructure is one person’s head at the vendor, their departure is simultaneously a confidentiality risk and a continuity risk. Your own documentation, kept current, at your side, solves both.

In the recruitment process, when you are the one hiring. This is the counter-intuitive part, and the most important one from a legal-exposure standpoint:

  • A written rule, communicated to the candidate before the interview: do not bring or discuss confidential information from your current or previous employer.
  • The technical interview is built on your own or generic problems, never on the candidate’s current employer’s casework.
  • Interviewers are trained to explicitly stop the candidate who begins describing proprietary details, and to record that they did so.
  • At onboarding, a signed attestation that the person brings no former-employer materials, plus a check of personal devices before connecting to the network.
  • For senior roles coming directly from a competitor or a competitor’s vendor: a documented period of isolation from overlapping projects.

The last two points look bureaucratic until the day you receive a letter from someone’s lawyers. Then they are your only defense.

Part IV. What the compliance framework requires

For organizations under NIS2 or DORA, nothing above is optional — it is usually just poorly implemented.

NIS2 explicitly requires supply-chain security measures, taking into account the vulnerabilities specific to each direct supplier, as well as human-resources security and access-control policies.

DORA requires the register of contractual arrangements with ICT third parties, concentration-risk assessment, and exit strategies. Add to the assessment a question few institutions ask themselves: how many of our critical suppliers also serve our direct competitors, with the same teams?

ISO/IEC 27001:2022, Annex A covers the components: A.6.1 screening, A.6.5 responsibilities on termination, A.6.6 confidentiality agreements, A.5.19–A.5.22 supplier relationships, A.8.10 information deletion, A.8.12 data-leakage prevention.

GDPR, the limit. Monitoring departing employees is not unrestricted. Law 190/2018 (art. 5) conditions workplace monitoring on specific legitimate purposes, prior information to employees, consultation with the union or representatives, proof that less intrusive methods are ineffective, and it limits the storage period. A detection program built without a DPIA and without prior information turns your defense mechanism into your own incident.

Checklist

Offboarding

  • Revocation covers federated tokens, active sessions, device certificates, SSH keys, links to personal cloud accounts — not just disabling the account
  • Equipment return is a blocking condition, with a record
  • A check at 30 and 90 days that no residual access path remains
  • A written reminder of confidentiality obligations that survive the contract

Vendors

  • Named identities per consultant, zero shared accounts
  • A notification clause on key-personnel departure from the account team
  • Overlap mapping: which suppliers also serve competitors, with which teams
  • Architecture documentation exists at your side, not only at the vendor

Recruitment

  • A written “do not bring, we do not accept” policy, communicated before the interview
  • Interviewers trained to stop and record
  • Onboarding attestation + a check of personal devices
  • Documented isolation for senior roles from overlapping areas

Legal foundation

  • A trade-secret register: what exactly, where it is stored, who has access, what protection measures
  • Confidentiality and, where justified, non-compete clauses, legally validated
  • A DPIA for any monitoring mechanism, with prior information

Conclusion

The Apple–OpenAI case will be judged on allegations we cannot verify and on sealed evidence. But the structure of the problem is visible and does not depend on who wins: the most effective path for transferring proprietary knowledge does not go through the network. It goes through an interview, an offer and a start date.

You cannot, and should not try to, stop people from moving. What you can do is make sure that, when they move, what they take with them is their own competence, not your security architecture. And the difference between the two is set years in advance, through boring controls nobody notices until the day the only question that matters becomes: what reasonable protection measures did you take?

All statements about the parties’ conduct in Apple Inc. v. Liu are unproven allegations. The full docket is publicly available on CourtListener (docket 73602437). This article is not legal advice.

Frequently asked questions

Why is recruiting a supply-chain security problem?

Because it is the only information-transfer vector that passes through no technical control — no DLP, no egress monitoring, no access log. The information travels in a person's memory. When a key person leaves a technology vendor, the knowledge is privileged by construction (they designed the system, they did not deduce it), multiplied (they also worked for other clients), and it produces no detectable artifact.

Is professional mobility an attack?

No. Free movement of workers is a fundamental EU right (art. 45 TFEU) and the right to work is constitutionally guaranteed in Romania (art. 41). An engineer who moves to a competitor legitimately takes everything they learned — skills, judgment, patterns. That is general know-how and cannot be confiscated. The attack is only the subset in which someone deliberately uses this channel to obtain protected information.

What, legally, is a trade secret in Romania?

Under OUG 25/2019 (Romania's transposition of EU Directive 2016/943, amending Law 11/1991), information must cumulatively meet three conditions: it must be secret (not generally known or readily accessible to specialists in the field), it must have commercial value precisely because it is secret, and it must have been the subject of reasonable protection measures. Without the third condition — classification, access restriction, NDAs, consistent enforcement — you do not have a trade secret you can defend; you only have information you chose not to publish. (This is not legal advice.)

Can I put no-poach clauses in vendor contracts?

With great care. Competition authorities, including Romania's Competition Council, treat no-poach agreements between undertakings as potential labor-market restrictions. Do not build your strategy on them, and check every such clause with a competition lawyer. Key-personnel clauses (notification on departure, confidentiality surviving the contract) are the solid ground.

Related articles