Into uncharted waters: Trade secrets law in the AI era
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Kilic, Burcu Working Paper Into uncharted waters: Trade secrets law in the AI era CIGI Papers, No. 295 Provided in Cooperation with: Centre for International Governance Innovation (CIGI), Waterloo, Ontario Suggested Citation: Kilic, Burcu (2024) : Into uncharted waters: Trade secrets law in the AI era, CIGI Papers, No. 295, Centre for International Governance Innovation (CIGI), Waterloo (Ontario) This Version is available at: https://hdl.handle.net/10419/299992 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/
CIGI Papers No. 295 — May 2024 Into Uncharted Waters: Trade Secrets Law in the AI Era Burcu Kilic
CIGI Papers No. 295 — May 2024 Into Uncharted Waters: Trade Secrets Law in the AI Era Burcu Kilic
About CIGI The Centre for International Governance Innovation (CIGI) is an independent, non-partisan think tank whose peer-reviewed research and trusted analysis influence policy makers to innovate. Our global network of multidisciplinary researchers and strategic partnerships provide policy solutions for the digital era with one goal: to improve people’s lives everywhere. Headquartered in Waterloo, Canada, CIGI has received support from the Government of Canada, the Government of Ontario and founder Jim Balsillie. À propos du CIGI Le Centre pour l’innovation dans la gouvernance internationale (CIGI) est un groupe de réflexion indépendant et non partisan dont les recherches évaluées par des pairs et les analyses fiables incitent les décideurs à innover. Grâce à son réseau mondial de chercheurs pluridisciplinaires et de partenariats stratégiques, le CIGI offre des solutions politiques adaptées à l’ère numérique dans le seul but d’améliorer la vie des gens du monde entier. Le CIGI, dont le siège se trouve à Waterloo, au Canada, bénéficie du soutien du gouvernement du Canada, du gouvernement de l’Ontario et de son fondateur, Jim Balsillie. Credits Managing Director of Digital Economy (until February 2024) Robert Fay Director, Program Management Dianna English Program Manager Jenny Thiel Publications Editor Susan Bubak Senior Publications Editor Jennifer Goyder Graphic Designer Sami Chouhdary Copyright © 2024 by the Centre for International Governance Innovation The opinions expressed in this publication are those of the author and do not necessarily reflect the views of the Centre for International Governance Innovation or its Board of Directors. For publications enquiries, please contact [email protected]. The text of this work is licensed under CC BY 4.0. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/. For reuse or distribution, please include this copyright notice. This work may contain content (including but not limited to graphics, charts and photographs) used or reproduced under licence or with permission from third parties. Permission to reproduce this content must be obtained from third parties directly. Centre for International Governance Innovation and CIGI are registered trademarks. 67 Erb Street West Waterloo, ON, Canada N2L 6C2 www.cigionline.org
Table of Contents vi About the Author vi Acronyms and Abbreviations 1 Executive Summary 1 Introduction 2 The History of Trade Secrets 3 The Paris Convention 4 The TRIPS Agreement 7 Trade Secrets Protection in US Law 10 Trade Secret Dilemma: At the Crossroads of Secrecy and Transparency 12 Trade Secrets in the Automation Era 14 AI and Trade Secrets: Hidden Barriers 17 Public Interest Exceptions for Trade Secrets 18 Domestic Pathways for Trade Secret Exceptions 20 Looking Forward 22 Works Cited
vi CIGI Papers No. 295 — May 2024 • Burcu Kilic About the Author Burcu Kilic is a CIGI senior fellow, and a scholar, tech policy expert and digital rights advocate. She has worked with a diverse range of organizations across civil society, philanthropy and academia. Her research and writings cover digital rights, intellectual property (IP), innovation and trade, and she has provided technical advice and assistance in countries in Asia, Latin America, Europe and Africa. As the former head of policy of Frontier Technology — a Minderoo Foundation initiative — Burcu guided the organization’s approach to emerging technology, advocating for responsible, equitable and just solutions. Before joining Minderoo, she directed the Digital Rights Program at Public Citizen, a non-profit consumer advocacy organization in Washington, DC, and also led their research on access to medicines. Her influence in tech policy, IP and trade underscores her commitment to policy entrepreneurship and rights-based advocacy. She champions collaborative civil society engagement, policy entrepreneurship and innovative policy development on a global scale. In 2015, she was recognized as one of the 300 Women Leaders in Global Health for her work on health and trade policy. From 2021 to 2022, she was a practitioner fellow with the Digital Civil Society Lab at the Stanford Center on Philanthropy and Civil Society. She completed her Ph.D. at Queen Mary University of London and holds L.L.M. degrees in IP law from Queen Mary University of London, and information technology law from Stockholm University. She obtained her law degree from Ankara University, Türkiye. Acronyms and Abbreviations ACLU American Civil Liberties Union AI artificial intelligence CBP Customs and Border Protection DHS Department of Health Services DTSA Defend Trade Secrets Act EEA Economic Espionage Act EPA Environmental Protection Agency FDCA Federal Food, Drug, and Cosmetic Act FIFRA Federal Insecticide, Fungicide, and Rodenticide Act GDPR General Data Protection Regulation IP intellectual property IPRs intellectual property rights LLMs large language models MDA Massachusetts Disclosure Act PRA Public Records Act TRIPS Trade-Related Aspects of Intellectual Property Rights UTSA Uniform Trade Secrets Act WTO World Trade Organization
1Into Uncharted Waters: Trade Secrets Law in the AI Era Executive Summary As artificial intelligence (AI) rapidly evolves and integrates into our lives, discussions around transparency and accountability in AI systems become increasingly crucial. A critical yet often overlooked aspect of these discussions is the protection of trade secrets. There is a delicate balance between safeguarding proprietary rights and fostering an environment where AI can be scrutinized for fairness, bias and societal impact. The crux of the issue lies in the legal ambiguity of trade secrets protection across jurisdictions. In the United States, trade secrets are considered intellectual property rights (IPRs), but the European Union does not provide them an exclusive IP protection. In international law, unlike the detailed provisions for patents and copyrights, the Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS Agreement)1 lacks a clear protection and exception framework for trade secrets, leading to diverse interpretations and practices around the world. Exploring the legal uncertainties surrounding trade secrets, this paper demonstrates how expansive protection impedes the drive for transparency and accountability in AI. It argues that the current legal framework overly protects trade secrets in AI technologies, applying proprietary protection to source code, algorithms, training materials and data sets, thus creating barriers to accessing information essential for the public interest, including health, safety and policy development. Addressing this challenge requires a rethinking of trade secrets law to establish clear limits and exceptions similar to those in other domains of IPRs. This paper contributes to the debate on AI by providing legal insights and suggesting reforms to balance proprietary rights with the need for transparency. It advocates for a legal reform incorporating public interest exceptions within trade secrets protection. Such reform would not only align with broader societal needs but also support innovation by ensuring that AI technologies are developed and deployed in an ethical and accountable manner. 1 WTO, Agreement on Trade-Related Aspects of Intellectual Property Rights (unamended), Annex 1C of the Marrakesh Agreement Establishing the World Trade Organization, 15 April 1994, 1867 UNTS 154, 33 ILM 1144 (1994) (entered into force 1 January 1995) [TRIPS Agreement], online: WTO <www.wto.org/english/docs_e/legal_e/ 27-trips_01_e.htm>. Introduction Rarely does a day pass without news, op-eds, reports or events centred on AI. Its widespread influence has led to a mix of excitement and significant concerns. The companies behind these technologies paint a grim picture of the future, while continuing to develop new tools, technologies and policy initiatives. AI now touches upon every policy area, from labour and global health to nutrition, finance and more. The landscape is filled with regulatory initiatives, global forums and policy proposals driven by tech giants and their allies, along with new government mandates and task forces. The rush to engage with AI is widespread, with experts from all sectors eager to contribute to the conversation. With critical discussions on AI policy, regulation and infrastructure gaining momentum, there is growing agreement on the need for transparency and accountability in AI systems. These concepts have evolved beyond simple buzzwords and are now crucial for thoughtful and advanced policy dialogue. However, this raises several questions: For whom is transparency beneficial, and how can we ensure accountability? What are the necessary tools, systems and measures? A significant but often neglected aspect of these discussions is the role of trade secrets. The foundational elements of AI systems, such as source code, algorithms, data sets and training manuals, are often protected as trade secrets. This poses a complex challenge at the crossroads of technology, proprietary rights and policy discussions shaping the AI landscape. Trade secrets have a vague status in legal systems, varying greatly from one jurisdiction to another. In the United States, trade secrets are treated as a form of IPRs, while in contrast, the European legal systems do not recognize trade secrets as an exclusive IPR. The lack of legal consistency is primarily because there is no international consensus on the issue. Unlike patents and copyright, which are clearly defined under the TRIPS Agreement, trade secrets are not thoroughly regulated in international law, leading to a wide range of interpretations and applications in different legal systems.
2CIGI Papers No. 295 — May 2024 • Burcu Kilic The legal ambiguity surrounding trade secrets poses considerable challenges to AI policy development, particularly for initiatives aimed at enhancing transparency and accountability. Trade secrets are increasingly being used as a counterargument against requests for disclosure, access, data sharing and due process. Discussions on AI governance often only lightly touch on or entirely sidestep trade secrets. Recently, it has become simpler to assert trade secrets protection claims but more challenging to dispute them, leading to overly broad protection of data, data sets, training materials, source code and algorithms. The lack of scrutiny of trade secrets, combined with a reluctance to discuss their limitations, impedes progress toward achieving transparency, accountability, regulation and innovation in AI. There is a clear need for more in-depth discussions and actionable solutions, as trade secrets currently lack defined boundaries, flexibilities and exceptions that are typical of other IP rights. A growing body of literature discusses the challenges posed by the protection of trade secrets, creating barriers to accessing data and information crucial to the public interest, such as details about pharmaceuticals and vaccines, criminal justice and surveillance technologies, and environmental hazards. This trend toward greater secrecy conflicts directly with crucial public interests, including accountability, public safety and policy. This paper aims to synthesize key insights from this body of work by focusing on the legal aspects of trade secrets. It sets out to be the legal voice in the room, examining the often overlooked yet crucial world of trade secrets. It explores how trade secrecy can hinder access to vital information necessary for testing and evaluating AI technologies, particularly in identifying biases and discrimination, thereby impeding public policies and initiatives aimed at transparency and accountability. The goal is to provide legal clarity and direction in conversations on AI, focusing on this essential but frequently overlooked aspect. If AI policy is a complex puzzle we aim to solve, then trade secrets represent a cornerstone piece. Without addressing this key element, our puzzle remains incomplete, missing a critical dimension. The History of Trade Secrets The origins of trade secrets law can be traced back to Roman law (Yenerall 2021), but its modern formulation was developed by the Anglo-American legal system. The courts in England and the United States first recognized a cause of action for damages based on the misappropriation of trade secrets in the nineteenth century (Lemley 2008). The Anglo-American doctrine of trade secrets incorporates a series of related common law torts, such as breach of confidence, breach of confidential relationship, common law misappropriation, unfair competition, unjust enrichment, and torts pertaining to trespass or unauthorized access to a plaintiff ’s property (ibid.). However, this modern concept of trade secrets is less firmly established in non-commonlaw countries. Its foundation rests on various legal theories, such as contract, property, fiduciary relationships and unjust enrichment (Czapracka2012). The question of whether trade secrets can be treated as property rights, akin to copyrights, patents or trademarks, remains unresolved. Civil law jurisdictions have traditionally shown reluctance to recognize trade secrets as IP rights.2 This illustrates a key distinction in legal perspectives between common law and civil law systems. In civil law systems, the protection of property rights, including intangible assets, is acknowledged as a fundamental right. Central to this protection is the numerus clausus3 doctrine. This doctrine establishes that the number, nature, creation, transfer and termination of real rights are limited (and closed). As such, property rights as absolute rights are set using strictly defined parameters. They offer protection only for categories that are explicitly recognized and governed by law (ibid.). The doctrine does not allow for the autonomous 2 “Given that trade secrets are not a form of exclusive intellectual property right”; see https://single-market-economy.ec.europa.eu/industry/ strategy/intellectual-property/trade-secrets_en. 3 Directly translated from Latin, this term means “the number is closed.” See Merrill and Smith (2000, 4).
9Into Uncharted Waters: Trade Secrets Law in the AI Era trade secrets may be unnecessary, as other legal frameworks, such as contracts and tort law, already provide adequate tools to safeguard against the misappropriation of ideas. This perspective challenges the need for distinct trade secrets protection, suggesting that existing legal tools are sufficient to address concerns related to the protection of secret information (Simpson 2005). Following the landmark Ruckelshaus v. Monsanto decision, the rise of trade secrets protection in US law continued with the enactment of the Economic Espionage Act (EEA) in 1996. This legislation, which came in the wake of heightened awareness and legal recognition of trade secrets post-Monsanto, significantly expanded the legal framework for trade secrets, strengthening the safeguards available to industry. It is specifically tailored to address foreign espionage, imposing criminal penalties for the theft of trade secrets that benefit foreign governments, their instrumentalities or agents.24 Congress has shifted the foundation for trade secret misappropriation liability more firmly into the domain of property than ever before. The enhanced protections embedded in the law have created a powerful tool for industry, enabling it to exclude valuable discoveries from wider society (ibid.). Designed to safeguard information that is valuable and creates a competitive advantage, derives its value from its secret nature and has been the subject of reasonable efforts to keep it secret, the EEA has a scope that is broader than that of the UTSA, encompassing a wider variety of technological and intangible information (Nashkova 2023, 645). It defines trade secrets as “all forms and types of financial, business, scientific, technical, economic, or engineering information, including patterns, plans, compilations, program devices, formulas, designs, prototypes, methods, techniques, processes, procedures, programs, or codes, whether tangible or intangible.” Nonetheless, determining what constitutes a trade secret remains highly fact specific, dependent on the nature of the information and the particulars of how its confidentiality is maintained. The legislative history of the EEA has raised significant concerns. Notably, Congress did not consult any IP experts during the legislative process. There was no substantial discussion about how the EEA would interact with the trade secrets law’s 24 18 USC § 1831 – Economic espionage. objective of promoting innovation for societal benefit. Instead, the committee reports and floor debates surrounding the EEA predominantly reflect a pro-business stance. The testimony that was heard came exclusively from industry experts, who naturally had self-interested perspectives (Simpson 2005). The EEA has received considerable criticism from scholars for its lack of balance and consideration of broader societal impacts (ibid.). Building upon the foundation set by the EEA, the US Congress took another significant step in 2016 with the passage of the Defend Trade Secrets Act (DTSA). This act was the result of a multi-year effort to federalize trade secrets protection, marking a significant expansion of trade secrets law. It established a federal private cause of action for cases involving the misappropriation of trade secrets, further solidifying the legal framework in this area, but it did not pre-empt state trade secrets law.25 In response to concerns about the potential conflict between trade secrets protection and public interest in accessing information, the DTSA incorporated whistle-blower protections, granting immunity to whistle-blowers who confidentially share information while reporting illegal activities to law enforcement or in the context of a legal suit, provided that their disclosures are made under seal. These whistle-blower protections are designed to strike a critical balance between maintaining the confidentiality of trade secrets and ensuring transparency and accountability, particularly in sensitive areas such as health, safety, civil rights, financial markets, consumer rights and environmental protection (Katyal and Graves 2021). In conclusion, while the DTSA does provide some safeguards, they are far from being comprehensive or satisfactory. This aspect of the DTSA underscores its intent to protect trade secrets, but it also highlights the need for a stronger focus on public oversight and the enforcement of various laws that safeguard the broader interests of the public. 25 18 USC § 1838 – Construction with other laws.
10 CIGI Papers No. 295 — May 2024 • Burcu Kilic Trade Secret Dilemma: At the Crossroads of Secrecy and Transparency Trade secrets protection, broadened and strengthened through the decisions of US courts, presents a significant yet often overlooked challenge, potentially undermining access to information and various civil rights and protections. A core issue is the overly broad application of trade secret claims. The determination of what exactly constitutes a trade secret often relies significantly on the expertise and creativity of corporate legal counsel. This leads to an expansive interpretation, stretching the traditional boundaries of what is considered a trade secret. It is likely that a significant portion of IP related to AI is being protected as trade secrets in the United States, contributing to the broad application (Quinn Emanuel Trial Lawyers 2020). Often, information labelled as proprietary fails to satisfy the established legal criteria for trade secrets protection. This becomes particularly critical when the public interest demands a certain level of transparency, even in instances involving legitimate trade secrets. Trade secret disputes increasingly involve not only direct competitors but also third parties, extending beyond the scope originally intended by trade secrets law. This expansion of trade secrets to cover basic services and publicly available information illustrates how trade secrets law can be strategically used or “weaponized” for the purpose of concealing information (Katyal and Graves 2021). This trend not only challenges the conventional understanding of trade secrets but also raises concerns about the implications of such practices for transparency, public access to information, and public health and safety. For example, having access to the source code of software used for essential government services, such as benefit administration or understanding the inner workings of AI systems and their training data, is often vital for public policy and oversight. It underscores the need for a more equitable approach to trade secrets protection. While it may be important to safeguard proprietary information that meets the protection criteria, this should not come at the cost of concealing information that is crucial for public welfare and safety. Trade secrets law has evolved to offer broad protection for what companies label as trade secrets, treating terms such as “secret,” “proprietary” and “confidential” as synonyms for restricting access (Pooley 2022). This trend encourages extensive use of trade secret claims, often blocking disclosure demands and hindering public access and regulatory oversight. This is not a new problem, yet it is frequently overlooked in the context of public policy debates. Various sectors, including pharmaceuticals, tobacco, software and chemicals, have encountered and continue to grapple with the trade secret problem. In numerous cases, civil liberties advocates, consumer groups, public health organizations, community leaders and individuals confront the expansive trade secret claims. Regrettably, courts have failed to support efforts to set limits on this kind of information secrecy. This section aims to highlight the intimidating narrative constructed by companies around trade secrets, a narrative that demands immediate reflection and action. This is particularly urgent as emerging technologies such as AI increasingly influence our lives, shaping our future, rights and democracies. There are valuable insights to be gained from other sectors — insights that can inform discussions on potential future directions and reforms in trade secrets law. In the years following the Monsanto decision, courts often interpreted trade secrets broadly, expanding the limits of trade secrets protection, especially in matters of disclosure and access. In the post-Monsanto legal landscape, one particularly troubling case is Philip Morris, Inc., v. Reilly.26 This case originated from the Massachusetts Disclosure Act (MDA), requiring cigarette manufacturers seeking to sell their products in the state to disclose any tobacco additives. The law’s intention was to reduce public health risks and foster research on the health effects of components such as additives and flavourings, which tobacco companies typically keep 26 Philip Morris, Inc v Reilly, 312 F (3d) 24 (1st Cir 2002) [Philip Morris].
11Into Uncharted Waters: Trade Secrets Law in the AI Era confidential.27 Despite its significant implications for public interest, this law was never implemented but instead resulted in prolonged litigation. The court ultimately sided with Philip Morris, recognizing that the cigarette ingredients were both a trade secret and property. It recognized that the companies had legitimate investmentbacked expectations and ruled that the mandatory disclosure of their secrets constituted an unconstitutional taking of their property under the Fifth Amendment. While acknowledging the public interest in disclosure, the court expressed concerns28 about the law’s perceived lenient standards for disclosure, which stipulated that information could be released if it “could” benefit public health. This, the court feared, could result in significant private loss in the event of disclosure.29 The court was convinced that the tobacco companies had a property interest in their trade secrets. It viewed the MDA as transforming “private property into public property without compensation,” constituting a clear violation of the Fifth Amendment’s takings clause.30 In the ongoing struggle between the government’s authority to regulate the common good and the property interests of companies, there is a growing concern that the balance may have shifted away from the public interest. The Philip Morris case provides an insightful but disconcerting perspective, suggesting that private property rights, especially those concerning trade secrets, have taken precedence over broader public health considerations and public interest. This expansion has turned trade secrets protection into a significant legal hurdle, especially evident in legislative efforts addressing public interest policies on access, safety and health. Fracking chemicals, linked to serious health risks, including cancer and neurological disorders, illustrate the tension between trade secrets and public interest (Kapczynski 2022). Despite the 27 US, Massachusetts Disclosure Act: Massachusetts General Laws, 1996, c 94, § 307B. 28 Philip Morris, supra note 26 at 32 (“For a state to be able to completely destroy valuable trade secrets, it should be required to show more than a possiblebeneficialeffect”). 29 Ibid.Thecourtreasonedthat“specificlawssimplycannotdestroy property interests.” 30 Ibid. clear health implications of these chemicals, companies can claim them as trade secrets, often with minimal justification, merely by ticking a box. This practice, supported by the fossil fuel lobby, limits public access to crucial information about the chemicals contaminating groundwater.31 Despite growing concerns, the industry continues to lobby the EPA to claim trade secrets protection by asserting that “[h]ydraulic fracturing is a highly complex and competitive industry where trade secrets are critical assets” (Zink 2018, 1162). Consequently, public access to detailed information about these chemicals remains limited. Even in incidents of likely water contamination, companies such as Halliburton have managed to keep the list of chemicals used confidential (Kapczynski 2022). While state regulators might know these chemicals, their ability to share this information is restricted, limiting access for researchers and the public. State-level regulatory bodies, where fracking oversight primarily occurs, frequently face resource constraints that limit their ability to provide extensive oversight (ibid.). This illustrates the impact of trade secrets protection claims on public health and safety, demonstrating the challenges in balancing corporate secrecy with the public’s right to information in crucial health and environmental matters.32 From chemicals to cigarettes, trade secrets have frequently been utilized by corporations to restrict public access and disclosure, even in areas crucial to public health and safety that are regulated and subject to public oversight. This raises significant concerns about emerging technologies such as AI, where public oversight is minimal, and underscores the need to rethink trade secrets protection to ensure it does not obstruct public access to information. 31 “For instance, in Texas, after that state adopted a disclosure law, between April 2011 and December of 2012, fracking companies claimed trade secret or proprietary protection 10,120 times in reporting related to 12,140 instances of fracking. An investigation by the Obama-era DOE [Department of Energy] in 2014 came to a similar conclusion: trade secrets were being invoked 84% of the time” (Fink 2019, 1002). 32 Ibid.
12 CIGI Papers No. 295 — May 2024 • Burcu Kilic Trade Secrets in the Automation Era The responsibility for managing and operating public infrastructure and services, which traditionally lay with the government, is increasingly being transferred to private companies in the United States. In delivering essential services such as telecommunications, Medicare, Medicaid and welfare programs, these private companies adhere to commercial law standards and practices, including trade secrecy as a crucial tool (Levine 2011). Automated decision making, be it via software or AI systems, suffers from a lack of transparency, enabling corporate dominance in public spheres, reducing transparency and accountability, and undermining public expectations of due process. This issue has been at the centre of countless cases, varying in facts, parties and years, but the underlying narrative remains consistent. When individuals challenge these automated decisions, they frequently receive the response that the systems or algorithms are protected as trade secrets, preventing government officials from disclosing the algorithms or source code. Often, those adversely affected by these decisions are from poor, marginalized and/or minority communities. They may find ways to bring their cases to court, either through class action lawsuits or with the help of pro bono lawyers, but then face resistance from companies that claim the algorithms are trade secrets, hence resisting disclosure. When courts eventually compel disclosure and experts review the systems, it frequently becomes evident that the algorithms or systems are biased, lack critical data points or employ a one-size-fits-all approach that is unsuitable for the intended services. This pattern underscores the significant impact of automated decisionmaking systems on public welfare and the pressing need for greater transparency and accountability in their deployment and operation. To provide a concrete example, in Idaho, the state implemented a new AI program in 2011 to determine budget allocations for Medicaid’s homecare services. Individuals with developmental and intellectual disabilities who depended on the Medicaid program began noticing reductions in their homecare hours, typically between 20 and 30 percent (Stanley 2017). Under this program, beneficiaries were required to visit a medical assessment centre where an assessment provider would complete a proprietary form. This form detailed each individual’s need for assistance in daily activities such as feeding, toileting and dressing (Brown et al. 2020). The data from this form was then manually entered into a digital budget tool, essentially an Excel spreadsheet, which then calculated a dollar amount for the assessed needs based on a proprietary database. This amount represented the annual budget for their services.33 However, when beneficiaries questioned how these dollar amounts were determined and the rationale behind these cuts, especially since their disabilities and needs had not changed, the response from the Medicaid program was obstructive. Officials stated that the details of the calculation could not be disclosed because they were protected as trade secrets, thereby leaving recipients in the dark about the specifics of their service budget calculations. The American Civil Liberties Union (ACLU) stepped in, representing 4,000 Idaho residents in a lawsuit demanding the disclosure of the formulations and assessment tools. The court sided with the ACLU, ruling that it was a violation of due process to reduce someone’s health-care services by US$20,000 annually without a transparent explanation and relying on “black box” systems (Stanley 2017). Once the ACLU obtained the algorithms, it was revealed that the state had developed the formulas in-house, without proper validation, standardization or auditing. An expert review of these formulas revealed significant issues with both the data and the modelling. During the trial, trade secrets emerged as a point of controversy, especially when a third-party vendor that developed one of the assessment tools sought to restrict access to its assessment booklets, invoking trade secrets protection (ACLU 2023). The court concluded that the department’s formulas and assessments were so unreliable that they deprived people of their Medicaid budgets arbitrarily, violating the due process rights 33 “We asked a federal court to order the Department to disclose its system.Withinafewweeksoffilingsuit,wegotthatorder.Thenwe got the system. It was a set of formulas in a fairly basic Microsoft Excel spreadsheet.TheDepartment’sassessorsenterannualassessmentresults into a copy of the spreadsheet for each person. The spreadsheet, in hiddencells,computestheperson’sbudgetamount”(ACLU2023).
13Into Uncharted Waters: Trade Secrets Law in the AI Era guaranteed by the Constitution. Ultimately, the court ordered a complete overhaul of the system.34 Despite being one of the most enlightening legal challenges against a black box system, it took the ACLU extensive effort — months of work, three experts and more than US$40,000— to deconstruct and critique the system and an additional 2,000 hours of attorney and paralegal work to secure a settlement following the court’s decision (ibid.). Trade secrets litigation is not only costly but also time-consuming, often stretching over years. For individuals without significant resources or support from organizations such as the ACLU, challenging these automated decisions becomes extremely difficult, highlighting a significant barrier to justice and accountability. This pivotal case dates back to 2016, and one might have expected its lessons to guide the Idaho Department of Health and Welfare, which administers the Medicaid program, in its future practices. Unfortunately, it seems those lessons were overlooked. According to the ACLU of Idaho, the department introduced a new system created by a third-party vendor and once more used trade secrets to limit transparency and due process. As a result, people with developmental disabilities and their advocates are blocked from checking the system’s manual for any biases, mistakes or other problems (ibid.). The Idaho department’s actions reflect a broader trend among public agencies: the procurement of AI systems shrouded in trade secrecy in crucial public welfare systems, a practice that contributes to widespread confusion and harms beneficiaries. Similarly, in Arkansas, the Department of Health Services (DHS) replaced nurse evaluations for homecare services with an algorithmic system. The rationale was that computers would be less expensive and less biased than nurses (Lecher 2018), who previously conducted comprehensive assessments using a 286-question form to determine a person’s weekly homecare needs. However, once implemented, this new system produced arbitrary and illogical results (Citron and Calo 2021). For example, the algorithm classified a foot amputee as having “no foot problems,” ignoring the increased need for assistance due to amputation. 34 K. W. v Armstrong, 180 F Supp (3d) 703 (D Idaho 2016); see also K. W. v Armstrong, 789 F (3d) 962 (9th Cir 2015). Key individual details and continence history were overlooked, and the severity of conditions was not differentiated despite regulations requiring such distinctions (Lecher 2018). “Algorithmic absurdities” in automated decision making become evident in decisions such as the one where an algorithm allocated the same level of care to a person with quadriplegia, dementia or schizophrenia as it did to someone with only quadriplegia, blatantly ignoring the additional care needs associated with dementia and schizophrenia (Citron and Calo 2021). In 2016, Legal Aid of Arkansas filed a lawsuit against DHS on behalf of physically disabled residents in Arkansas whose homecare was reduced by an average of 43 percent following the implementation of this algorithmic system. In extreme cases, aid was cut by more than 56 percent. The system left many severely disabled individuals without access to essential needs such as food, toileting and medicine for extended periods (De Liban 2017). The lawsuit, which led to an injunction preventing DHS from using the automated system until it could justify its decisions, eventually resulted in a ruling that the state had failed to follow its own rulemaking procedures, including not providing adequate notice to those affected by the new methodology.35 This case in Arkansas underscores the far-reaching consequences of relying on automated systems without oversight, particularly when critical public welfare services are involved. In an encouraging development, a recent Federal Circuit decision from July 2023 may have farreaching implications for those aiming to challenge the use of AI on due process grounds (Coglianese 2023). A recent Federal Circuit case, not directly related to AI but addressing the conflict between due process and trade secrets, ruled that trade secrets protection must yield to due process.36 The dispute involved a company importing pencils purportedly manufactured in the Philippines. US Customs and Border Protection (CBP) contended that the importer violated trade rules by transshipping pencils from China through the Philippines to avoid anti-dumping duties assessed on pencils of Chinese origin. The importer protested that its due process rights 35 Ark. Dep’t of Human Servs. v Ledgerwood, 530 SW (3d) 336, 340 (2017). 36 Royal Brush Manufacturing, Inc v United States, 75 F (4th) 1250 (Fed Cir 2023).
14 CIGI Papers No. 295 — May 2024 • Burcu Kilic were violated because CBP did not grant access to confidential photos and business data from the Philippine manufacturer. This information was critical as it demonstrated the Philippine manufacturer’s inability to produce the volume of pencils imported to the United States. CBP maintained it could not disclose this information due to confidentiality obligations (ibid.). The Circuit Court rejected the government’s argument, stating that the due process clause of the Constitution mandates that parties affected by government decisions have the right to view the evidence against them. This constitutional mandate takes precedence over statutory prohibitions on disclosing trade secrets. The court noted, “Because the Constitution authorizes, and indeed requires, the release of confidential business information in this case, the Trade Secrets Act does not stand in the way of such release” (ibid.). It held that CBP could have shared the confidential business information under a protective order, preventing further disclosure (ibid.). Cary Coglianese (2023) suggests that this ruling opens a new avenue for legal challenges to agencies’ AI applications, facilitating access to crucial information about the algorithms. This is particularly relevant when these algorithms are developed and deployed by private contractors claiming trade secrets protection (ibid.). This interpretation indicates a significant (and ideally lasting) shift in balancing trade secrets protections with due process considerations, especially regarding AI technologies employed by government agencies. AI and Trade Secrets: Hidden Barriers In his Senate testimony, Richard Eppink, legal director of the ACLU of Idaho, shed light on why the K. W. v. Armstrong case has become a significant reference point in discussions about AI systems. The case is referenced in the White House’s October 2022 Blueprint for an AI Bill of Rights37 and featured prominently in civil 37 See www.whitehouse.gov/ostp/ai-bill-of-rights/. and human rights scholarship articles. Eppink highlighted that the case is particularly instructive because it vividly demonstrates the various ways automated decision-making systems can fail. The case implications are profound, especially considering the simplicity of Idaho’s system. The fact that simple Excel spreadsheet formulas could give rise to a multitude of constitutional issues underscores the urgent need for robust governance to safeguard against potential problems in today’s more advanced AI systems (ACLU 2023). This concern, as articulated by Eppink, who has spent years challenging these systems to protect the most vulnerable, is crucial. The insights from all these cases demonstrate how trade secrets can create barriers to access and due process, highlighting the importance of challenging “trade secret thickets” that companies have woven around various types of data aggregation. These thickets can include an array of data aggregated on the source and processing of toxic waste; details about water and energy consumption, which Google required for constructing an innovative data hub in North Carolina; and information held by ride-sharing companies such as Uber and Lyft regarding the zip codes of their pick-ups and drop-offs (Fia 2022). Nonetheless, they also shed light on the overwhelming challenges involved — the extensive time, effort and financial resources required to bring these systems to court and challenge trade secrets protection. These factors further complicate the pursuit of transparency and due process, making this a lengthy and costly endeavour. This reality should fundamentally inform and shape our approach to AI governance and regulation. The shift from human to AI systems becomes particularly critical when AI systems take over tasks and make decisions once handled by humans, which are inherently accompanied by accountability mechanisms tailored for human oversight. This transition has led to a potential erosion of guarantees for transparency, accountability and due process. Unfortunately, accountability mechanisms and legal standards governing decision making have not evolved at the same pace as technological advancements (Kroll et al. 2017, 636). To address this, there is a pressing need for laws to adapt, aiming to reinstate the rights and values that were protected under the previous human-driven system. There have been proposals for legal and technical
15Into Uncharted Waters: Trade Secrets Law in the AI Era mechanisms to restore the status quo that existed before this shift (Citron and Calo 2021). Since these suggestions were made in 2017, AI technologies have become more integrated into our lives, yet the fundamental problem remains unresolved. The increasing reliance of many government agencies on private companies for expertise and skills in AI systems has introduced a critical legal dilemma. Our legal frameworks and accountability standards continue to lag behind these rapidly advancing technologies. When these companies assert trade secrets protection over their algorithms, training data, input parameters or any aggregated data, they effectively create a legal black box. This raises a critical question: Does the trade secrets protection claimed by these companies inevitably lead to the denial of due process rights for individuals or corporations (Coglianese 2023)? When the broadened and strengthened scope of trade secrets is factored into this equation, the problem becomes even more complex and opaque. This highlights the tension between proprietary protection in AI systems and the principles of transparency, accountability and the fundamental right to due process. A comprehensive and multifaceted response is needed that not only addresses the advancements in AI but also addresses the intricacies of trade secrets law. In a landmark case from Seattle, Lyft and Uber (Lyft, Inc. v. City of Seattle) invoked the trade secret argument in an attempt to avoid submitting standardized quarterly reports to the city.38 These reports included various data categories, such as the total number of rides and pick-up and drop-off zip codes. According to an agreement between the city, Lyft and Uber, the companies were obligated to provide these reports quarterly. However, Lyft’s lawyers argued that the zip code reports constituted trade secrets under the UTSA and expressed concerns about confidentiality in transferring data to municipal authorities, despite the city’s implementation of measures to safeguard the data. The situation escalated in 2016 when an Austinbased ride-share analyst, under the Public Records Act (PRA), requested access to reports containing data from late 2015 to analyze evidence of redlining — to see if the companies 38 Lyft, Inc v City of Seattle 94026-6 (Wash Sup Ct 2018). were fairly serving communities of colour. The City of Seattle informed him that Lyft had claimed these reports were confidential, leading to legal action under the PRA for access to the reports (Gutman 2018). The King County Superior Court initially issued a permanent injunction, preventing the disclosure of these reports and agreeing with Lyft that the zip code reports were trade secrets under the UTSA (Monsees 2018). However, the injunction decision was eventually overturned by the Washington Supreme Court, which granted access to the reports. The court ruled that the reports in question qualified as “public records” despite containing trade secrets. According to the court’s decision, the disclosure of these records could be lawfully withheld only if it was determined that such disclosure “would clearly not be in the public interest and would substantially and irreparably damage a person or a vital government interest.”39 The Lyft case provides crucial insights into the extent of trade secrets protection claims, or more accurately, the extent to which companies can assert trade secrets protection over data (Fia 2022). Despite the court’s eventual ruling in favour of Seattle, the journey to that decision was lengthy, involving multiple courts, legal proceedings and significant legal costs, ultimately borne by taxpayers. For the City of Seattle, gaining access to data sets over which legal and contractual rights were established in a 2014 mediation agreement proved to be a resource-intensive endeavour. Despite their agreement to share data, both Lyft and Uber did not hesitate to assert trade secret claims over it. This case underscores the challenges posed by increasingly broad trade secrets protection, or claims thereof, and their far-reaching implications for data governance and public policy across various sectors, including transportation, labour and competition. Since ChatGPT’s launch in November 2022, large language models (LLMs) and generative AI have dominated AI discussions, catalyzing a broad industry-wide rush to adopt these advanced technologies. LLMs are revolutionizing how we live, work and conduct business with unprecedented speed. Yet they present several challenges, notably the risk of generating inaccurate, unreliable and, at times, hallucinated outputs. This issue stems 39 Ibid.
16 CIGI Papers No. 295 — May 2024 • Burcu Kilic from the “garbage in, garbage out” principle, which is exacerbated by poorly labelled, inaccurate, biased or incomplete data sets (Awati, n.d.). Most leading LLMs are developed by major tech companies such as Google, Meta, Microsoft and OpenAI. These companies typically prefer trade secrets protection over other IP rights for their LLMs, covering algorithms, training data, data sets and infrastructure as proprietary. This approach helps them preserve their competitive advantage without disclosing the specifics of their models to the public or to competitors. When required, they only disclose minimal details about the model architecture, training data and decision-making processes. The secrecy surrounding the development of LLMs leads to opacity in their operation, significantly obstructing efforts to scrutinize these systems for biases, errors or ethical issues. It becomes challenging to ensure the safety of the data used in training or to identify inherent unfair biases within the models. As a result, the public is left with no choice but to trust companies’ assurances, despite the fact that even the developers themselves may lack complete insights into how their models function. While they may understand the models’ basic architecture, the complex behaviours that emerge from these models are often beyond clear explanation (Ramlochan 2023). This is not a new challenge; it has deep roots within the tech industry. For instance, a 2021 internal memo from Facebook already highlighted engineers’ concerns about their limited understanding and control over their systems (Zuboff 2022): “We do not have an adequate level of control and explainability over how our systems use data, and thus we can’t confidently make controlled policy changes or external commitments such as ‘we will not use X data for Y purpose.’ And yet, this is exactly what regulators expect us to do, increasing our risk of mistakes and misrepresentation” (Facebook Ad and Business Product Team 2021, 1; quoted in Zuboff 2022). The emergence of LLMs such as GPT-4,40 which are built on massive data sets, has only intensified this problem. Additionally, companies developing LLMs often refuse to disclose the sources of their training data, adding another layer of complexity. 40 GPT-4 incorporates billions of text entries and operates with millions of parameters(Griffith2023). Given the high financial stakes, they favour trade secrets-protected, closed-source systems. However, the transparency offered by open-source projects not only enables the identification and resolution of vulnerabilities but also enhances the systems’ quality through collaborative efforts within the community (Kreps 2024). A leaked internal Google document from May 2023 underscores this strategy, cautioning, “Keeping our technology secret was always a tenuous proposition” (Dickson 2023). This scale and complexity of the models complicate not only the task of managing and overseeing but also understanding these advanced AI systems. Shielding AI systems — whether it is an algorithm or training data — as trade secrets tends to overly prioritize commercial interests, thereby creating barriers to due process. When algorithms or data sets are protected as trade secrets, there is an increased risk that they might reinforce existing biases and inequalities, leading to the emergence of a “techno-social divide.” This divide essentially creates a barrier to accessing information, with profound implications for privacy, democracy, human rights, competition and social justice. It calls for continued efforts, comprehensive strategies and more rigorous legal frameworks to ensure that the deployment of AI systems does not compromise transparency, accountability or due process. For better data governance, it is crucial to acknowledge and address the conflict between transparency, due process and trade secrets. Regulators and lawmakers must be aware of this inherent tension and incompatibility from the beginning. As they seek to balance the protection of trade secrets with the right to information access, the focus should be on the public’s right to know. This perspective is key to ensuring transparency and accountability, thus keeping public interest at the core of discussions about the governance of AI technologies.
17Into Uncharted Waters: Trade Secrets Law in the AI Era Public Interest Exceptions for Trade Secrets Finding the Right Forum IP protection has always been considered a form of public policy, with a balancing act between rights holders and the public interest at its core. However, the power dynamic inherent in the ability to own and control technological innovations has often led to IP serving as a tool of power and, when captured, a means for further consolidating it (Sell 2004). Today’s IP standards, including trade secrets protections, have been largely shaped by the relatively small group of IP-intensive industries. These industries were able to recognize the value of IPRs early, shaping the laws in their best interest (Fia 2022). Starting in the 1980s, US laws began to view IP protection more as a system of protection and exclusion rather than as a public policy instrument to encourage competition and diffusion. Global capitalism led by the United States exerted new pressure on the domestic landscape for IP protection (Sell 2004). The Supreme Court’s recognition of trade secrets as property rights in 1984 and the post-Monsanto movement toward strengthening and broadening trade secrets should be viewed in this broader context. Trade secrets protection has historically been closely intertwined with competitive and innovative progress, where the government has played a relatively modest role. However, the emergence of new technologies has amplified the need for robust safeguards in areas such as education, public health, civil rights, privacy, environmental protection and worker rights. The evolving technology landscape calls for greater government involvement and enhanced public oversight. The current landscape is marked by extensive property rights and economic concentration in key industries, including technology. Trade secret protections that were once considered privileges have increasingly overshadowed the public policy obligations of the companies. As a result, the legal framework for trade secrets often falls short of delivering benefits to the public and protecting the public interest. This shift in perspective reflects a broader trend in IP law, highlighting the need for re-evaluating and potentially recalibrating the balance between private interests and the public good. The concept of a public interest exception within trade secrets protection remains underdeveloped and inadequately explored. While briefly mentioned in the commentary to the UTSA and the Restatement (Third) of Unfair Competition, these references lack detailed explanation (Sandeen and Mylly 2021). Case law in this area is often confusing, with courts siding with companies and granting extensive protection to trade secrets (Levine 2011). This raises a crucial question: How can a clear and effective public interest exception for access and disclosure be integrated into trade secrets law and practice? Looking at international law, key legal frameworks such as the Paris Convention and TRIPS do not explicitly address the exceptions for trade secrets. While the international IP regime may not directly provide the answers we seek, it does offer the flexibility and policy space necessary for incorporating public policy considerations into the evolving landscape of trade secrets protection. The policy space is crucial for aligning trade secrets protection with broader societal needs. However, the emergence of trade secrets protection over source code and algorithms in recent free trade agreements raises significant concerns. Since the conclusion of the Trans-Pacific Partnership Agreement in 2015, there has been a notable trend in incorporating trade secrets protection within the e-commerce chapters of trade agreements. These provisions extend beyond TRIPS, establishing exclusivities over source code and algorithms with only minimal exceptions. As technology advances, trade negotiators have started to recognize the limitations of these exceptions. Consequently, each subsequent trade agreement attempts to refine and make these exceptions applicable to the current state of technology. Yet as technology continuously evolves, these efforts consistently fall short. For instance, limited exceptions introduced in the United StatesMexico-Canada Agreement in 2018 are already outdated by the rapid advancements in generative AI and LLMs. This situation is reminiscent of the classic tale of the tortoise trying to catch up to the hare, where trade negotiators (the tortoise) consistently lag behind the technology (the hare).
18 CIGI Papers No. 295 — May 2024 • Burcu Kilic The inclusion of extensive trade secrets protection in trade agreements merits a detailed separate review. For this discussion, it is important to note that trade agreements are not suitable forums for introducing public interest exceptions to address the growing challenges of extensive trade secrets protection. Instead, trade negotiators should be guided by domestic policies, incorporating exceptions established in national laws rather than dictating these standards internationally. Domestic Pathways for Trade Secret Exceptions Given the current trend toward recognizing trade secrets law as a form of IP, it logically follows that trade secrets should also encompass exceptions and limitations similar to those found in other IP domains. Developing these exceptions is essential for ensuring that trade secrets law balances the protection of commercial interests with the protection of broader public interest, particularly in contexts involving transparency, accountability and access to information. Turning to US law, the challenge appears not to be a lack of familiarity among courts considering public interest in trade secret cases. Instead, the challenge lies in the absence of a structured framework or defined parameters within US law that explicitly outline the public interest considerations that should be factored into trade secret litigation. US law lacks a defined list of specific (although not necessarily exclusive) public interest issues that should be taken into account during trade secret litigation. The list may include concerns such as free speech and freedom of the press, free competition, employee mobility, regulatory oversight, the rights of collective organizations such as unions, and personal privacy interests (Sandeen and Mylly 2021). For instance, the European Trade Secrets Directive,41 enacted in 2016 and implemented into the laws of EU member states by 2018, presents a somewhat 41 Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure, [2016] OJ, L 157/1. balanced approach to trade secrets protection. Unlike under US law, the directive does not establish such an exclusive property right over trade secrets. The recital of the directive explicitly states that it does not create any exclusive right.42 The directive’s stance on trade secrets is somewhat ambivalent. It does not define trade secrets as either IP rights or as part of unfair competition law, although it tends more toward the latter (Aplin 2021). It is important to note that when the directive was introduced, the main lobbying industries were pharmaceuticals and chemicals (EDRi 2015), suggesting that considerations of the data economy or AI were not central to its formulation. However, its technology-neutral regime, which protects a wide array of know-how and business information, makes it a significant legal tool for today’s data and AI economy (Fia 2022). Rather than adopting an approach of broad rights with narrow exceptions, the directive seeks to establish a fair balance between rights and interests. It provides for exceptions to protection, placing the burden on the defendant to successfully establish these exceptions (ibid.). Article 5 of the directive lists these exceptions, aiming to balance the rights and interests of non-owners, such as small companies, consumers, researchers, journalists, public authorities and non-profit organizations. These exceptions include the right to freedom of expression and information; general public interest in revealing misconduct, wrongdoing and illegal activity; disclosure by workers and their representatives; and protection of legitimate interests recognized by EU or national law. The interpretation of article 5 continues to be ambiguous. However, some suggest that within the framework of the General Data Protection Regulation (GDPR), the data subject’s right to be informed might fall within the scope of this exception to trade secrets. As a result, the right to explanation cannot be denied on the grounds of safeguarding trade secrets (Mylly 2023). Likewise, if a direct link between the personal data and the algorithm can be established, the GDPR’s transparency requirements could potentially supersede the trade secret claims of the companies (Foss-Solbrekk and Glenster 2022). 42 Ibid, recital 16 (“In the interest of innovation and to foster competition, the provisions of this Directive should not create any exclusive right to know-how or information protected as trade secrets”).
67 Erb Street West Waterloo, ON, Canada N2L 6C2 www.cigionline.org