// knowledge base · practical note · September 2026
AI and trade secrets: when uploading data to a public service is disclosure
A diff.legal material, September 2026. General information, not a legal opinion on a specific task.
What the court said
In employment case No. 02-1545/2026 (Babushkinsky District Court of Moscow, judgment of 26.05.2026, reasoning of 13.07.2026, under appeal), among the grounds for dismissal for disclosing a secret protected by law was the uploading of reports from an internal protected resource to a third-party AI service. The court stated directly: uploading information constituting a trade secret into an artificial-intelligence system constitutes disclosure of that information. Case details are in the review of court practice on AI.
The court applied the logic of the Constitutional Court from its Resolution of 26.10.2017 No. 25-P: the transfer of data to an uncontrolled resource in itself creates the conditions for its uncontrolled use. A public AI service is precisely such a resource: it is impossible either to restrict further use of what has been sent or to guarantee its deletion.
What a company should put in place
- A trade-secret regime. Only a formalised regime gives legal protection: a list of protected information, need-to-know access, access restrictions and a confidentiality marking — under Article 10 of Federal Law No. 98-FZ. Without a regime there is nothing to protect.
- A legitimate alternative. A ban without an alternative does not work: employees are already using AI. Provide approved corporate tools in a closed environment — where data does not go to uncontrolled servers.
- An AI policy. Put in writing: which tools are allowed, what data may be submitted to them, what is prohibited, who is responsible. A policy removes the “but I didn't know” question and becomes a basis for disciplinary measures.
- Recording breaches at two levels. Technically — logs and leak monitoring; procedurally — official records, memoranda and requests for explanations. Dismissal on that ground requires procedural cleanliness, not only the fact itself.
What an employee should bear in mind
- Separate the tool from the data: the ability to “ask AI” does not permit submitting protected information to it.
- Use only approved corporate tools; as for personal accounts in public services holding work data, the question has been closed by court practice.
- Do not rely on anonymisation: removing names and identifiers does not always rule out the identification of information, and the court assesses the very fact of transfer to an uncontrolled resource.
How this relates to the work of diff.legal
An AI policy and rules for protecting data in a closed environment are part of continuous legal support; diff.legal processes client documents only in an agreed closed environment, without public AI services and without training on client data — data processing policy. The team can review your company's documents and policy after an enquiry.