Intellectual property comes in several kinds, and public argument about AI has settled on one of them.
Copyright covers expression, which is where the fight over training data has taken place. Patents cover inventions, granting twenty years from filing in exchange for disclosing how the invention works. Trademarks cover the signs that tell a customer whose product they are buying.
Trade secrets are different, and most organisations rely on them without using the term. A pricing model, or the record of what each client pays. Nothing gets registered and nothing expires. Under the EU Trade Secrets Directive, and under the US Defend Trade Secrets Act and the state laws alongside it, protection holds while the information stays secret, holds value because it is secret, and the holder takes reasonable measures to protect it. Disclosure to a consortium partner under a proper confidentiality obligation does not end that. Losing track of where the information went can.
Which is what makes an essay published on 12 July worth reading. Satya Nadella argues that companies using AI systems pay twice, once for the service and again by supplying the knowledge that makes the output worth anything. Providers learn from what he calls exhaust: the prompts staff write, and above all the corrections people make when an answer comes back wrong.
Nadella runs Microsoft, which introduced Frontier Tuning as a private preview in June, built to keep exactly this kind of learning inside the customer’s own environment. The argument arrives with a product attached to it.
It also remains an argument. Major providers commit contractually not to train their models on business customer inputs. Whether a separate layer of operational knowledge accumulates outside those commitments, and where it ends up, has not been publicly shown.
One government has taken a position on what this means for secrecy. Japan’s Ministry of Economy, Trade and Industry revised its trade secret management guidelines in March 2025, with generative AI among the stated reasons. Where secret information is entered into an external service, used for training, and left in a state where it could surface in answers given to others, that may indicate an absence of intent to keep it secret, and protection may fail. Where the same information is entered under a corporate contract guaranteeing no training, or with training excluded by setting, entering it does not by itself end protection.
A company that wants to know whether it still holds a secret needs to know where the information went. On that question there is no published answer yet, and one ministry’s footnote is doing a great deal of work.
Sources
- Nadella’s essay: https://snscratchpad.com/posts/reverse-information-paradox/
- Microsoft on Frontier Tuning: https://devblogs.microsoft.com/microsoft365dev/frontier-tuning-teaching-ai-to-work-the-way-you-do/
- METI Trade Secret Management Guidelines, revised 31 March 2025: https://www.meti.go.jp/policy/economy/chizai/chiteki/guideline/r7ts.pdf