top of page

No Rule Protects Your Trade Secrets. Only Secrecy Does.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 25
6 min read

Every industry we have covered in this series had a rule waiting for the AI era: HIPAA for medical practices, Reg S-P for advisers, confidentiality duties for lawyers, CUI clauses for defense contractors. Manufacturing is different. For the designs, tooling, process parameters, and pricing that actually make you competitive, there is no regulator, no fine, and no compliance checklist. There is only one shield, secrecy itself, and the law withdraws it once you stop guarding it. The AI tools your team started using this year are the fastest way to stop guarding it without ever noticing.

That sentence deserves unpacking, because the mechanics matter and most manufacturers have never had a reason to look at them.

The AI is already on the engineering workstations

Start with what is actually happening, because policy conversations that skip this step describe a company that does not exist.

An estimator pastes the notes from a customer drawing into a chatbot to draft the quote letter faster. An engineer pastes process parameters into an AI tool to troubleshoot a tolerance problem. Someone in purchasing uploads a supplier pricing sheet to get a summary table. A CAD workstation gets a browser extension that reads every open page and promises to answer questions about it. Nobody in those scenes is stealing anything. They are saving twenty minutes.

The numbers say this is your shop too, not just someone else's. Verizon's 2026 data breach report found the share of employees regularly using AI tools at work tripled in a year to 45 percent, and 67 percent of the people using AI services on corporate devices were signed in with non-corporate accounts, outside any control the company has. IBM's 2026 breach study found shadow AI involved in 43 percent of the security incidents it examined, up from 20 percent the year before. Those are cross-industry figures, and manufacturing has no exemption from them.

What manufacturing does have is a bigger target on its back. IBM's X-Force threat report has ranked manufacturing the most attacked industry for the fifth year running, with 27.7 percent of the incidents its teams observed, and the most common thing X-Force saw in those incidents was not encrypted machines. It was stolen data. Read those two paragraphs together: the industry attackers most want to steal data from is also watching its own staff carry data out to services nobody vetted, for free, with good intentions.

The rule that protects your IP only works while you do

Here is the legal mechanic that makes this different from every other industry we have written about.

A trade secret is not like a patent. Nobody registers it, nobody grants it, and nothing protects it by default. Under the federal Defend Trade Secrets Act and the state laws that mirror it, information qualifies for protection only while two things stay true: it derives value from not being generally known, and you have taken reasonable measures to keep it secret. Courts look hard at that second element. Locked drawings, NDAs, access controls, marked documents, that is the evidence that your process sheet is a trade secret and not just a document.

Now put the paste into that picture. A consumer AI account is an outside service, running on someone else's infrastructure, under terms most people have never read, and on personal accounts the inputs can be retained and used to train the models. IP and employment lawyers have started warning, in plain terms, that feeding trade secrets into a public AI tool risks being treated as a voluntary disclosure to an outside party, and that a finding like that can be fatal to the reasonable measures element. Not because a competitor read your prompt that afternoon, but because you handed the information to a third party with no duty to keep it secret, and the whole claim rests on you never doing that.

This is not hypothetical corporate paranoia. In 2023, Samsung staff fed sensitive material into ChatGPT three times in under three weeks, twice pasting confidential source code to debug it and once uploading a meeting recording to generate minutes, and the company went on to ban consumer generative AI tools on company devices. That was one of the most sophisticated technology companies on earth, with a security budget your shop will never have, and the paste still happened.

And there is a second layer for a job shop or contract manufacturer: much of what is on your floor is not even your secret. It is your customer's, sitting in your hands under an NDA that obligates you to protect it. The customer drawing pasted into a chatbot is not just your risk. It is a confidentiality clause you signed, tested by an employee who was trying to be efficient.

If you also make parts for defense primes, another layer stacks on top of all of this, because some of what you hold is Controlled Unclassified Information with contract clauses attached. We covered that world in our government contractor piece, and everything in it applies to a defense-supplying manufacturer too.

The honest part

In this series we always tell you what the enforcement picture really looks like, and for manufacturing it is strange: nobody is coming to fine you. There is no OCR, no SEC, no bar counsel for a leaked process sheet. That sounds like good news until you sit with it, because a fine is a number you pay once. Trade secret protection, once secrecy is actually lost, does not come back. You cannot re-secret a secret, and the value walks into your competitors' quotes for good. The industries with regulators get penalties. You get the only loss in this series that is permanent.

One more detail worth knowing: X-Force also reported that infostealer malware exposed more than 300,000 ChatGPT credentials in 2025. Personal AI accounts are themselves getting breached at scale. Whatever your team has pasted into one is sitting behind a password the company does not control and cannot reset, in an account criminals actively harvest. Ransomware still matters in manufacturing, and a stopped line is expensive in a way an idle office is not. But the quiet copy of your data is the loss you never get a report about.

Visibility comes before policy

You cannot write a truthful AI policy, an honest NDA compliance story, or a defensible account of your reasonable measures around tools you have not found. So the first move is not a memo. It is an inventory.

Find every AI tool, browser extension, and AI agent on the machines that touch drawings, quotes, process documentation, or customer files, and note which account each one is signed into, company or personal, because those are different worlds legally. Then decide, deliberately, what is allowed: one rule that removes the judgment call, along the lines of nothing from a drawing, a quote, a process sheet, or a customer file goes into an AI tool that is not on the approved list, and rewriting or summarizing counts as going in. Then give people an approved path, because your team adopted these tools to save time, and a ban with no alternative just teaches them to hide the time-saver.

Done in that order, the same work that protects your IP becomes the paper trail that shows you guard it, which is the kind of evidence the reasonable measures element asks about.

Where we fit, and where we do not

Two honest boundaries first. We do not touch your plant floor: no PLCs, no SCADA, no production machinery, and no OT networks. And we are not lawyers: what counts as reasonable measures for your trade secrets is a question for your IP counsel, not for any vendor.

What we run is the IT layer where every scene in this article actually happened: email, endpoints, and the engineering and front-office workstations. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next. It is the inventory step above, done for you. From there we enforce the tool list you approve and keep watching as new AI shows up. Alongside it we run managed email security, endpoint detection, and security awareness training for small and medium manufacturers, the same everyday IT layer that stops the phishing and ransomware manufacturing is famous for. None of it guarantees an outcome, legal or otherwise. It gives you the visibility and the enforcement those outcomes depend on.

The question worth asking this week

Not "do we have an AI policy somewhere." Ask instead: could anyone in your company list, today, every AI tool that has seen your drawings, your pricing, or your process sheets this quarter?

We work with manufacturers nationwide from our home base in McLean, Virginia. If you run a small or medium manufacturer in Washington DC, Northern Virginia, Maryland, or anywhere in the country and you want that list to exist, book a free 15-minute call. The discovery that produces it is free, and the answer is yours either way.

Comments


bottom of page