Enterprise AI runs on information. The more context a company gives an AI system, the more useful that system becomes. Such context routinely includes documents and information such as internal reports, technical specifications, product roadmaps, source code, customer data, research, workflows, communications, and invention disclosures that have not yet been filed.

The intellectual property consequence has not caught up to the increasingly rapid adoption of AI in enterprise software. Each information transfer among systems is an election between two protection regimes that can fail in opposite directions, and in many companies the election is made by whoever signs the order form.

The Bargains Run in Different Directions

Patent law is built on a trade. An inventor puts an enabling disclosure into the public record and receives, in exchange, a right of limited duration that operates "against the world," including against a later independent inventor, as the Supreme Court put it in Kewanee Oil Co. v. Bicron Corp., 416 U.S. 470, 490 (1974). The right survives the disclosure because the disclosure is the consideration for it. Pfaff v. Wells Electronics, Inc., 525 U.S. 55, 63 (1998), states the same bargain from the inventor's perspective.

Trade secret law runs on the opposite premise. Federal law defines a trade secret as information whose owner "has taken reasonable measures to keep such information secret" and that "derives independent economic value . . . from not being generally known to, and not being readily ascertainable through proper means by, another person who can obtain economic value from the disclosure or use of the information." 18 U.S.C. § 1839(3)(A)-(B). Secrecy is the asset itself rather than a formality attached to it. Disclosure to a party under no obligation of confidence extinguishes the property right, as the Supreme Court held in Ruckelshaus v. Monsanto Co., 467 U.S. 986, 1002 (1984).

Enterprise AI inverts the direction of the disclosure that matters. The party who must reveal proprietary knowledge is the buyer, not the seller, and the revelation is a precondition to getting anything useful back. Satya Nadella named this structure the "Reverse Information Paradox" in a July 12, 2026 essay: a company "essentially pay[s] for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful."

Nadella's observation on the legal gap is precise and worth quoting exactly, as there is a risk in overstating it. "Patents solve one aspect of Arrow's paradox. They let an inventor disclose an idea without simply giving it away. The Reverse Information Paradox needs its own equivalent." No instrument is proposed. Rather, the operative remedy is architectural and contractual, a trust boundary across which nothing crosses without consent. The later framing in PCMag's coverage, that Nadella actually floated a new AI patent concept, is the outlet's characterization rather than the essay's text.

Whether contract and architecture are sufficient is the question the case law is now beginning to answer.

Trade Secret Status Turns on the Recipient's Obligation

The first available data point is easy to misread. In Trinidad v. OpenAI, Inc., No. 4:25-cv-06328-JST, 2026 WL 21791 (N.D. Cal. Jan. 5, 2026), the Northern District of California dismissed a pro se plaintiff's Defend Trade Secrets Act claim because, the court found, the plaintiff "has not alleged that she took any reasonable measures to keep these 'protocols and frameworks' secret," having admitted that she developed them using ChatGPT. The court applied Ruckelshaus, not any AI-specific rule, and the decision is an unpublished district court order with no binding precedential force. The Ninth Circuit dismissed the plaintiff's appeal on April 6, 2026, No. 26-721.

To the extent this decision becomes more widely adopted, the outcome is an argument for enterprise contracting rather than against AI use. The operative fact was that the recipient owed no duty of confidence. Enterprise terms that impose such a duty change the analysis. Trinidad does not validate those terms, as they were not at issue.

Enterprise terms usually impose such a duty. OpenAI's Services Agreement defines Confidential Information to include Customer Content, which it defines in turn as the input and the output. Anthropic's commercial terms state that "Customer Content is Customer's Confidential Information." The Microsoft Customer Agreement brings Customer Data inside Confidential Information expressly. Google Cloud's terms provide that "Customer Data is considered Customer's Confidential Information." Each obligation is mutual, each survives termination, and the customer can enforce it. Consumer terms are a different document: the word "confidential" appears nowhere in OpenAI's or Anthropic's consumer terms of service, for either party, and Microsoft's consumer agreement mentions it only to require that the user safeguard account credentials.

The enterprise problem is therefore characterized by the distance between a commercially reasonable promise and the discipline a trade secret requires. The standard in most agreements is reasonable care or reasonable measures, a negligence-grade duty rather than an absolute one. The definitions subtract independently developed information, which is important when the information recipient is building its own AI models. Microsoft's residual-knowledge provision states that use of information retained in its representatives' unaided memories "does not create liability under this Agreement or trade secret law," and its protection for Customer Data runs only "until it is deleted from the Online Services," whereas a trade secret must be protected for as long as it is worth protecting. Fully compliant vendor conduct can still produce a disclosure that destroys the trade secret.

Sharper warnings can be found in older cases. In Fail-Safe, LLC v. A.O. Smith Corp., 674 F.3d 889 (7th Cir. 2012), the Seventh Circuit affirmed summary judgment against a plaintiff that had taken no protective measures at all. Nothing was marked confidential, no expectation of confidentiality was ever communicated, and "the topic of confidentiality was never even broached by FS, a sophisticated party familiar with such agreements." Fail-Safe had signed A.O. Smith's standard one-way confidentiality agreement without asking for reciprocal protection, though it had demanded such agreements in earlier relationships, which left A.O. Smith as "the only party that took any protective steps." Thus, the absence of protective steps by Fail-Safe sank the claim.

Tax Track Systems Corp. v. New Investor World, Inc., 478 F.3d 783 (7th Cir. 2007), makes the companion point about relying on a single technical control. The case is not a trade secret case; it enforced a confidentiality agreement under Illinois law as a restrictive covenant, borrowing the reasonable-efforts test from trade secret law. The asset was a pitch memo the owner kept password-protected on a computer, while personally handing unmarked copies to six or seven hundred outsiders over five years, obtaining agreements from at most 190 of them, and keeping no record of the recipients. The computer storage precaution, the court held, "was entirely undermined by [the owner's] widespread nonconfidential disclosure of the memo to hundreds of outsiders." This is the shadow-AI problem stated in pre-AI terms. A company can run a well-governed enterprise tenant with single sign-on, access limits, and logging, and still lose secrecy because the same technical material also travels through personal accounts on consumer tiers that sit outside every one of those controls. The governed channel is undermined by the ungoverned one running beside it.

The Second Circuit's guidance in Turret Labs USA, Inc. v. CargoSprint, LLC, No. 21-952, 2022 WL 701161 (2d Cir. Mar. 9, 2022), frames reasonableness in a way that maps directly onto vendor selection: the inquiry "focus[es] on who is given access, and on the importance of confidentiality and nondisclosure agreements."

Yet some important issues remain unresolved. No court has held that cloud or vendor hosting under contractual confidentiality preserves trade secret status. The practitioner consensus that it does is an inference from Rockwell Graphic Systems, Inc. v. DEV Industries, Inc., 925 F.2d 174 (7th Cir. 1991), and its successors. Rockwell involved a manufacturer that gave engineering drawings to outside machine shops under signed confidentiality agreements, and the court held only that whether its precautions were reasonable was a question for the jury. Companies and their counsel should weigh this uncertainty when making enterprise contracting decisions.

Generative AI Also Attacks the Value Requirement

The definition of a trade secret sets two independent requirements, and a misappropriation claim fails if either one is missing. The first is about the owner's conduct: were reasonable measures taken to keep the information secret. The second is about the character of the information itself: does it derive independent economic value from not being generally known and not being readily ascertainable through proper means. Commentary on AI and trade secrets often focuses on the first, asking whether putting material into an AI tool destroyed the owner's secrecy measures. But courts have also opined on the economic value prong.

In Fiskars Finland Oy Ab v. Woodland Tools Inc., No. 22-cv-540-jdp (W.D. Wis. Aug. 26, 2024), on appeal, Nos. 2026-1234 & 2026-1235 (Fed. Cir.), Judge Peterson granted summary judgment against a trade secret misappropriation claim over roughly 75 pages of Python code a departing employee had written to automate the download and cleaning of retailer point-of-sale data. The court was persuaded in part by an uncontested defense expert opinion that the code implemented ordinary data-processing steps using publicly available Python packages, and that "any junior programmer could generate" it. On the record, the court concluded the material "would be readily ascertainable to anyone familiar with Fiskars business and capable of basic programming." The court then added that Fiskars "provides no evidence to contradict [the departing employee's] assertion that ChatGPT could now recreate the Python Code that he put together."

A few points of precision matter in this case, which has received some secondary coverage. First, the court made no affirmative finding that ChatGPT could recreate the code; it noted an unrebutted assertion, and the observation came after the expert opinion had already carried the ruling. Moreover, the holding rests on the "readily ascertainable" prong of the statutory definition of trade secret, § 1839(3)(B), not on any failure of secrecy measures. The court also rejected defendants' other arguments that the secrets were insufficiently identified, which makes this case a rather clean illustration of the importance of the value prong.

The strategic implication for companies may be counterintuitive. As general-purpose models get better at reconstructing routine engineering work, the category of information that qualifies as a trade secret narrows on its own, independent of anything an employee pastes anywhere. Secrecy is becoming a weaker default election, not merely a riskier one.

The cross-appeals remain pending, with no merits decision as of this writing, so this analysis is not yet settled.

Where the Data Sits Is a Jurisdictional Issue

The Fourth Circuit's decision in dmarcian, Inc. v. DMARC Advisor BV, Nos. 23-1790 & 25-1084 (4th Cir. July 10, 2026), supplies some guidance practitioners have been missing on data residency. A Dutch company licensed to distribute dmarcian's software in Europe and Africa was found to have exceeded that license, where its engineers in the Netherlands and Bulgaria had access to source code that dmarcian housed and maintained in North Carolina.

On the trade secret misappropriation claim, the panel found the presumption against extraterritoriality was rebutted at step one of the framework set out in Abitron Austria GmbH v. Hetronic International, Inc., 600 U.S. 412 (2023), on the strength of statutory text rather than on any weighing of contacts. The Defend Trade Secrets Act expressly reaches conduct abroad, and the panel held that this language "provides the 'unmistakable instruction' from Congress that is needed to rebut the presumption against extraterritoriality at step one of Abitron's framework," adding that "the DTSA's reach is global." The remaining question was only whether the statute's domestic limit was met, which requires "an act in furtherance of the offense" in the United States. As the defendant "originally gained access" through "data stored on servers within the United States," the court found it was.

A couple of qualifications to note: the decision affirms a preliminary injunction under an abuse-of-discretion standard, and thus is a ruling on likelihood of success rather than a final merits judgment. Further, the statutory analysis on the trademark side is different in kind, as Abitron requires domestic use in commerce rather than conduct merely directed at the United States. Prof. Maggie Gardner's analysis on the Transnational Litigation Blog discusses more about what the panel did and did not decide.

This decision affects AI procurement. Server location, not merely an infrastructure decision or compliance issue, is the jurisdictional hook that determines whether a federal trade secret remedy is available at all. A company that lets a vendor host information in a non-U.S. processing region may be unknowingly limiting which statutes it can sue under if something goes wrong. The corollary is uncomfortable in the other direction: this jurisdictional reach could also give a U.S. court authority over data the customer believed was governed somewhere else.

The Advantages and Limitations of Contracts

Enterprise AI vendors offer real contractual protections to their commercial clients. OpenAI states that it does not train on business data by default and offers zero-data-retention endpoints for eligible use cases. Anthropic's commercial terms state that "Anthropic may not train models on Customer Content from Services," with enterprise-configurable retention. Microsoft states that Microsoft 365 Copilot prompts and Graph-accessed data are not used to train foundation models, and that Azure-sold model inputs are not available to the model providers. Google states that Gemini Enterprise does not use customer prompts or outputs to train its models, and documented a zero-data-retention path for the Gemini Developer API in May 2026. OpenAI reaffirmed both of its commitments in an August 19, 2026 note describing how zero data retention is preserved for frontier models alongside a new automated safety-signal layer.

Those commitments are meaningful and should be obtained in writing. However, these obligations have some structural limits.

No court has construed the clauses. A full-text search of the CourtListener opinion corpus for "zero data retention" returned no results as of August 2026. The no-training, no-human-review, and retention-ceiling terms on which enterprise IP strategy now rests appear to be judicially untested. Companies may still be wise to insist on these clauses, but they do not shift or eliminate all risk of loss of rights due to inadvertent disclosure.

Third-party litigation can create obligations the customer cannot contest. In the consolidated OpenAI copyright litigation, No. 1:25-md-03143 (S.D.N.Y.), Magistrate Judge Ona T. Wang ordered OpenAI on May 13, 2025 to "preserve and segregate all output log data that would otherwise be deleted," expressly reaching data slated for deletion at a user's request or under privacy law. The order's terms are quoted in the court's June 20, 2025 ruling. OpenAI represented that ChatGPT Enterprise, Edu, and zero-data-retention API endpoints were unaffected, while Free, Plus, Pro, Team, and non-ZDR API usage were covered. The going-forward obligation terminated as of September 26, 2025 under a stipulation the court approved on October 9, 2025, though previously segregated logs and certain identified account domains remain preserved.

OpenAI defined the scope of that carve-out itself, and the characterization went untested in court. The enterprise customer sat outside the proceeding, so its protection rested on the vendor's litigation posture rather than on a right the customer could assert.

Beyond the breach lies no restoration. A confidentiality clause converts a leak into a damages claim. But it does not restore secrecy. Trade secret status is like a tamper-evident seal that, once opened, cannot be resealed. Once information ceases to be a secret, it ceases to be a secret against everyone in the world. A contract can allocate the losses but does not preserve the asset.

The Regulatory Map Points Elsewhere

This enterprise data disclosure problem does not yet appear to be drawing much regulatory attention. The Texas Responsible Artificial Intelligence Governance Act, effective January 1, 2026, Colorado's SB 26-189, signed May 14, 2026, California's AB 2013 training-data transparency law, and the CPPA's automated decisionmaking regulations are consumer-protection and personal-data instruments. None imposes an obligation on an AI vendor with respect to a business customer's trade secrets.

The closest federal statement is a January 2024 FTC Office of Technology staff blog post, which expressly contemplates customers revealing "internal documents" and vendors inferring business information "such as their scale and precise growth trajectories" from API usage. This staff guidance has less force than a true regulation or rule, and no enforcement action has followed as of August 2026.

One instance where the two bodies of law have actually met is instructive and unflattering. In X.AI LLC v. Bonta, No. CV 25-12295 JGB (C.D. Cal. Mar. 4, 2026), a challenge premised on the trade secret status of training data, the court denied a preliminary injunction where the plaintiff had "not identified any dataset or approach to cleaning and using datasets that is distinct from its competitors in a manner warranting trade secret protection." Enterprise claimants face the same legal requirement. A company whose proprietary information reached a vendor through thousands of small prompts and uploads may be unable to point to any single identifiable secret, even where the aggregate loss is substantial. The denial is on appeal, No. 26-1591 (9th Cir.).

The European Union has come closest to legislating an answer. The Data Act, Regulation (EU) 2023/2854, applicable since September 12, 2025, requires trade-secret-bearing data be disclosed "only where the data holder and the user take all necessary measures prior to the disclosure to preserve their confidentiality," obliges the holder to identify protected data in the relevant metadata, and permits withholding where safeguards are not agreed. The scope is confined to connected products and related services, and its mechanism is mandatory contract terms backed by regulators. But the EU regulation falls short of creating a new property right. The one jurisdiction that has acted required compulsory safeguards and declined to establish a so-called "inverse patent" right for trade secret information.

Patents Operate on Different Rules

Once a patent application is filed, later disclosure generally does not affect the earlier filing date. This asymmetry is a strong argument in favor of filing before proprietary technical material enters a third-party vendor's tech stack. But less apparent patent risks merit more discussion.

Confidentiality restrictions face real-world limits. In Weber, Inc. v. Provisur Technologies, Inc., 92 F.4th 1059 (Fed. Cir. 2024), the PTAB found Weber's operating manuals unavailable as prior art because copyright notices stated the material "may not be reproduced or transferred in any way" and the sales terms carried intellectual property clauses. The Federal Circuit reversed, finding the Board's conclusion rested on "inordinate emphasis on alleged confidentiality restrictions," as the manuals went to every customer who bought the product and were available at trade shows and factory showrooms. The copyright assertion did not undo public dissemination that actually occurred. Likewise, an AI vendor confidentiality clause and a no-training label state an intention, while a tribunal asked to treat submitted material as confidential will look at what the agreement actually permitted as well as what actually happened. Complete due diligence should include not only a search for the right contract clause, but also an investigation of the data flows and opportunities for non-confidential disclosure the clause leaves open.

Keeping the material confidential concedes one defense. Suppose a company transmits unfiled technical material to an AI vendor under confidentiality, and a third party then files an application on similar subject matter that later publishes. Under § 102(a)(2), that published application becomes prior art against the company's later filings. The patent prior art statute gives an inventor two ways relevant here to remove such a reference, and private disclosure to a vendor likely cannot satisfy one of them.

The first is § 102(b)(2)(B), which applies where an inventor publicly disclosed the subject matter before the third party filed. Sanho Corp. v. Kaijet Technology International Ltd., 108 F.4th 1376 (Fed. Cir. 2024), holds that "'publicly disclosed by the inventor' must mean that it is reasonable to conclude that the invention was made available to the public," so a private sale by the inventor fell outside the exception and failed to disqualify an intervening patent publication. A confidential submission fails the same test, which matters if the owner later decides to file an application on the subject matter. The confidentiality protecting the trade secret therefore forfeits the inventor's own-disclosure defense.

Exposure under § 102(a)(2) remains with an available defense untested. The second way to remove a patent application as prior art is § 102(b)(2)(A), which applies where the subject matter in the third party's application was "obtained directly or indirectly from the inventor." This exception requires no public disclosure and imposes no one-year limit. As the statute reaches subject matter obtained "indirectly," an applicant or patent owner could argue that a chain running from the inventor through a model to a later filer still traces back to the inventor. No decision has yet tested that reading, and proving such a chain of disclosure would require vendor-side evidence the customer does not hold.

Export controls must also be considered. The USPTO's April 2024 practitioner guidance, 89 Fed. Reg. 25609, warns that AI use "may result in the inadvertent disclosure of client-sensitive or confidential information to third parties," and that data "may be exported outside of the United States, potentially in violation of existing export administration and national security regulations." Entering an unfiled invention disclosure into a foreign-hosted service implicates the foreign filing license regime and export administration rules, not only confidentiality and 37 C.F.R. § 11.106. Data processing agreements with vendors and company use policies should be structured to ensure compliance with these controls on exporting technology. The risks of violation multiply for companies operating multi-nationally.

Shadow AI Lurks in the Shadows

A sophisticated enterprise agreement protects nothing if employees prefer using other services. Available evidence across different methodologies shows consistent risks.

Each source has some notable methodological limits. The self-report figures likely understate socially undesirable behavior, and the telemetry studies draw from security-vendor customer bases with their own selection effects. The survey's headline percentages also combine "rarely" with "sometimes or more often," and thus describe behavior that has occurred but is not necessarily routine. The convergence across methods, however, shows a strong trend.

For patent teams, a high-value control is classification gating on unfiled inventions. Invention disclosure forms, technical questionnaires, source code associated with a contemplated filing, and unpublished draft applications should be named explicitly in AI-use policy and blocked at the tool boundary. The purpose is to keep the patent-versus-trade-secret election in the hands of the people authorized to make the decision.

A Practical Framework

Companies deploying enterprise AI face four categories of practical questions to understand and address:

What is going in. An inventory of what prompts, uploads, agent workflows, and connected repositories actually contain, distinguishing trade secrets, unfiled inventions, source code, and ordinary business information. The inventory should record the service tier employees are actually using, which may differ from the enterprise tier the company purchased.

What happens to it. Know the actual path the material takes: which systems receive it, who can see it, where it is stored, how long each holder keeps it, and what each is permitted to do with it. Cover retention, training, evaluation, human review, subprocessors, data residency, deletion, and response to legal process. A no-training commitment often leaves evaluation, safety review, and human labeling permitted. Get data residency in writing. Ask for notice and a chance to intervene if a third party's litigation reaches your material, which some vendors offer only on request.

Which regime protects it. The election between patenting and secrecy ideally should be made before any material enters a vendor system, as the choice of system can foreclose some options after the fact. Where an invention would be detectable in a competitor's product or service, filing for a patent generally beats secrecy, as secrecy fails the moment someone reverse-engineers the technology. Reserve trade secret treatment for the layer that stays genuinely unobservable. A provisional application secures priority only for what it actually enables, so a two-page concept filed after the fact risks failing to cover the far larger body of technical material already fed into a vendor's AI model.

Whether the controls can be proved later. Access logs, an approved-tool list with safeguards blocking everything else, executed confidentiality terms, classification procedures, and training records can demonstrate a company took reasonable measures to protect secret information. Logging should be granular enough to identify the secret with particularity if required in litigation.

The Election Has Changed on Both Sides

The premises underlying the secrecy-by-default posture adopted by many companies have weakened.

On the eligibility side, USPTO examination has moved measurably. Ex parte Desjardins, Appeal No. 2024-000567, an Appeals Review Panel decision designated precedential on November 4, 2025, vacated the Board's new ground of § 101 rejection of machine learning training claims, holding that claim 1 "considered as a whole, integrates an abstract idea into a practical application" where the recited parameter adjustment was "an improvement to how the machine learning model itself operates." This represented a shift in application of the existing patent-eligibility inquiry (Step 2A Prong Two) rather than a new framework.

An August 4, 2025 memorandum to the examining corps, signed by Deputy Commissioner for Patents Charles Kim, instructed that a claim "does not recite a mental process when it contains limitation(s) that cannot practically be performed in the human mind," and directed that close calls resolve toward eligibility under a preponderance standard. A December 5, 2025 memorandum announced conforming revisions to MPEP § 2106, including new examples crediting technological improvements such as reduced storage and reduced system complexity. Subject matter eligibility declaration practice, introduced by a December 4, 2025 memorandum and now governed by April 30, 2026 best practices, emphasizes a procedural route for applicants to put technical evidence in front of an examiner under 37 C.F.R. § 1.132. Substantive AI eligibility guidance remains based on the 2024 Guidance Update, 89 Fed. Reg. 58128, with Examples 47 through 49.

The movements above, however, are confined to patent prosecution. Courts have moved in the opposite direction over the same period. Recentive Analytics, Inc. v. Fox Corp., 134 F.4th 1205 (Fed. Cir. 2025), held that applying generic machine learning to a new data environment, without a disclosed improvement to the model itself, is ineligible, and the Supreme Court denied certiorari on December 8, 2025. Two precedential Federal Circuit decisions in early 2026 invalidated software claims under § 101. US Patent No. 7,679,637 LLC v. Google LLC, No. 2024-1520 (Fed. Cir. Jan. 22, 2026), affirmed a Rule 12(b)(6) dismissal. GoTV Streaming, LLC v. Netflix, Inc., Nos. 2024-1669 & 2024-1744 (Fed. Cir. Feb. 9, 2026), wiped out a jury-backed judgment by holding every asserted claim ineligible, and directed entry of judgment for the defendant. Thus, prospects at examination have improved, while enforcement challenges for issued claims have not diminished.

On the secrecy side, Fiskars undermines the assumption that quiet is safe. The set of information that can carry trade secret status is contracting as the tools capable of reconstructing it improve.

A company that elected secrecy over disclosure in 2019 made a defensible judgment on the record then available. Changes to that record on both sides of the ledger warrant revisiting those decisions with legal counsel.

The Missing Instrument

The reason no legal instrument answers Nadella's problem is that the patent and trade secret regimes both assume the discloser controls the disclosure. A patent trades disclosure for a right on the inventor's timetable. A trade secret survives only while its owner governs who learns it. Enterprise AI is the first mass-market arrangement in which a company's most valuable technical information leaves on someone else's schedule, in fragments too small to identify, to a counterparty whose obligations courts have yet to construe.

Congress has built an instrument of this kind before, and the comparison is not encouraging. FIFRA requires pesticide registrants to hand proprietary health and safety data to EPA, and supplies in return a ten-year exclusive-use period and a fifteen-year window in which a later applicant must offer compensation, enforceable through binding arbitration. 7 U.S.C. § 136a(c)(1)(F). Every element of this machinery depends on an agency chokepoint that can refuse to consider the data, and on a discrete submission with a cost basis an arbitrator can price. No such framework exists between an enterprise and its AI vendor. The pharmaceutical examples also bar filing or approval without creating any compensation entitlement.

The Supreme Court's decision in Ruckelshaus provides a warning. The Court held that parties submitting data on or after October 1, 1978 "could not have had a reasonable, investment-backed expectation that EPA would keep the data confidential beyond the limits prescribed in the amended statute itself," as the parties were on notice of how EPA was authorized to use it. 467 U.S. at 1006. Every vendor terms of service performs a similar notice function.

New legal rights get defined after losses grow large enough to litigate, and that takes years. Until then, the reliable measure is an old one involving good governance: decide how valuable technical information will be protected before it moves to a vendor, as the alternative may be letting an employee's prompt make the election for you.