OpenAI has 400 former Apple employees. Apple just sued over it.The Ready Memo

OpenAI has 400 former Apple employees. Apple just sued over it.

Apple's lawsuit against OpenAI raises a question every enterprise deployer needs to sit with. Here's what it actually says.


Apple filed a 41-page trade secrets lawsuit against OpenAI on Friday. The complaint alleges that more than 400 former Apple employees were coached by OpenAI's chief hardware officer on how to evade Apple's security exit procedures so they could copy files before leaving. OpenAI denied the allegations. Today's issue is the read on what the lawsuit actually contains, and why "our AI vendor is being sued for systematic trade-secret theft" belongs in your vendor risk register regardless of outcome.

In today's issue:

  • Main story: OpenAI has 400 former Apple employees. Apple just sued over it.

  • Since Friday: Netflix pays $587M for a generative AI filmmaking startup, enterprise buyers are now running multiple AI models simultaneously, and Qwen3.8 launches at 2.4 trillion parameters as open weights

Apple filed a 41-page trade secrets lawsuit against OpenAI on July 11, and the complaint is not written like a business dispute. It reads like a criminal referral.

The allegations: more than 400 former Apple employees now work at OpenAI. According to the filing, some of them were coached by OpenAI's chief hardware officer on how to avoid Apple's security exit procedures, including how to sidestep the "dreaded walkout" that would terminate their access on the spot, so they would have more time to copy files. One employee allegedly texted, "LOL, I found out I can access the [network storage], so funny." OpenAI's chief hardware officer, Tang Yew Tan, spent 24 years at Apple as VP of product design for iPhone and Apple Watch. He is named in the complaint.

Apple's theory of the case is not subtle: "OpenAI's nascent hardware business now rests on the shakiest of foundations, rotten to its core by its illegal reliance on misappropriated trade secrets."

OpenAI denied the allegations, and the timing is not coincidental: OpenAI is reportedly planning an IPO, and Apple is reportedly developing a response to an OpenAI hardware device that may compete with iPhone. Both companies have obvious strategic reasons to be fighting right now.

But the question the lawsuit puts on the table is separate from the question of who wins in court.

The standard read misses what's in the complaint

Most coverage is treating this as a big-company IP dispute: Apple and OpenAI both have hardware ambitions, they're fighting over employees and secrets, and the lawsuit is one opening move in that fight. That framing is accurate as far as it goes.

It misses the specific nature of what Apple is alleging.

The complaint describes conduct that, if proven, goes beyond aggressive recruiting. OpenAI allegedly circulated an internal Apple document, one marked "Need to know," to new hires to help them avoid detection during their departure. Job candidates were reportedly asked to bring actual Apple prototypes and CAD artifacts to interview sessions for "show and tell." One candidate texted that he "didn't even know we could take those from the office," suggesting the ask was unusual even to the person being asked.

Apple's lawyers were deliberate about framing this as cultural rather than individual: "Normalized and exemplified by leadership," the complaint states. The argument is not that a few rogue employees went too far. It's that the misconduct was institutionalized.

Discovery will determine what's true. Apple's own lawyers acknowledge they expect the full scope to be "many times greater" than what the complaint currently documents.

For now, the complaint is a primary source. And what it describes, regardless of outcome, is the kind of vendor conduct question that every enterprise deploying AI on sensitive workloads should now be sitting with.

Why it matters beyond the courtroom

The standard enterprise AI vendor evaluation covers capability, cost, and integration: does the model do the task, what does it cost per call, and how hard is the API to work with?

What the Apple lawsuit adds to that list is conduct. Specifically: how does this vendor handle the people and information it comes into contact with?

That question is not hypothetical when you are running OpenAI's models on your customer data, your internal documents, or your employees' communications. The lawsuit does not allege that OpenAI mishandled enterprise customer data. What it alleges is a pattern of behavior toward a competitor, behavior that was allegedly coached and coordinated at the leadership level.

Operators have been making vendor decisions based almost entirely on capability and price. The governance layer, which is accountable for vendor conduct, what standards the vendor is held to, and what would trigger a review, is often absent. The Apple lawsuit is a useful forcing function for building it.

Three things are worth understanding about the architecture of this problem.

First, AI vendor risk is not the same as software vendor risk. When you buy a SaaS product, the vendor handles your data according to a contract and a privacy policy. When you deploy an AI model in your workflows, you are in a relationship where the vendor's research decisions, hiring practices, and competitive priorities all have some bearing on how your data is handled and how the product evolves. The risk surface is different, and most standard vendor management frameworks were not built for it.

Second, the lawsuit illustrates that frontier AI labs are in an arms race where competitive pressure is intense enough to create bad incentives. That does not make OpenAI guilty of what Apple alleges. It does mean that the pressures which could produce this kind of conduct, if it happened, are real and structural, not specific to one bad actor.

Third, the timing matters for enterprise buyers. OpenAI is preparing for an IPO, and IPO scrutiny is a forcing function for disclosure. Whatever is in those discovery documents will eventually be more public than it is now. Enterprise buyers who want to understand who they're actually dealing with have a window to ask harder questions before the IPO locks in a new tier of investor scrutiny.

TEAM READINESS AUDIT

Get your team’s AI readiness score. Leave with an AI readiness brief.

A 15-minute assessment that turns your answers into a real decision artifact: your readiness level, your six-axis shape, where you're strongest, where you're constrained, and what not to build yet.

Counterargument

The obvious objection: Apple is not a neutral party here. OpenAI is apparently building a hardware product that could compete with iPhone. Apple has enormous financial and strategic incentive to slow OpenAI's hardware ambitions, damage its IPO prospects, and make the entire sector think twice before hiring away more Apple employees. A lawsuit filed on those terms is not objective evidence of wrongdoing.

My honest answer: that's correct, and Apple's motivations are not disinterested. OpenAI has denied the allegations, and discovery will determine what happened. That process will take years.

But the conduct Apple is describing, if any of it turns out to be true, is not a trivial compliance failure. It is a pattern that reached the chief hardware officer. And the question for an enterprise deploying AI today is not whether the lawsuit will succeed. It's whether "our AI vendor is currently being sued for systematic trade-secret theft" is a fact that belongs in your vendor risk register. I think it does, regardless of outcome.

What this means for you

The Apple lawsuit does not require you to stop using OpenAI. Most of the operators I talk to do not have a realistic alternative for the specific capabilities they have built on. Switching costs are real.

What it does require is being honest about what your vendor evaluation process actually covers.

Most vendor reviews assess capability (does it work?) and reliability (is it up?). Almost none of them assess conduct: how does this vendor behave under competitive pressure? What is their track record with the data of the people around them? Who at their company is accountable when something goes wrong?

The questions worth taking into your next leadership conversation: do you have a process for reviewing AI vendors on criteria beyond capability and cost? If an allegation like this one were proven, what would your response be, and does your contract create any leverage? What data are you currently running through these systems that you would want to think harder about?

None of those questions are answerable by a lawyer on short notice. They are answerable by a team that has done the governance work in advance.

From the field

I've been having a version of this conversation with operators for most of this year, and it keeps coming up in the same place: after the deployment is already live.

Someone runs the AI on a document they later realize contained something sensitive. Or they want to pull out of a vendor contract and discover the switching costs are larger than anyone estimated. Or they ask "wait, who owns the outputs?" and nobody has a clean answer.

The Apple lawsuit is the loudest version of a question the industry has been quietly avoiding. Vendor capability has been the only thing that mattered, because capability has been the bottleneck. That's shifting. The operators who build the governance layer now, before they need it, are going to have a lot more options than the ones who build it in response to something going wrong.

SPONSORED BY CLUTCH

Hire secure AI teammates that work 24/7.

Hire pre-built AI teammates. Give your engineers and operators a platform to ship their own AI apps. Stop losing sleep about what is running where.

Clutch is the platform behind both: pre-built agents for the workflows your ops team should automate first, plus the integration plane your team's vibe-coded apps and Claude Code projects plug into. One platform. Real production. Visible and safe by default.

Built for ops, engineering, and security teams that are tired of the shadow-AI surface area inside their own company.

SINCE FRIDAY

P.S. If you are trying to figure out what your AI vendor risk register should actually cover, that is a conversation I am happy to have. Hit reply and tell me: what is the one AI vendor decision you made in the last year that you now wish you had evaluated more carefully? I read every reply.

If you know someone who is making AI vendor decisions right now without a conduct framework, this is worth forwarding.

Haroon

Get the next The Ready Memo as it lands.
Free. Four sends a week.

Get every issue, as it lands.