Share with your CISO
OpenAI has gone public with its counter-narrative in the Apple trade secrets lawsuit, publishing iMessages and emails on its own blog to undercut Apple’s claims before a court can weigh them. Apple alleges two senior hires, former iPhone engineer Chang Liu and 25-year Apple veteran Tang Tan, carried confidential hardware information out the door to benefit OpenAI’s device ambitions. Apple has now filed for a preliminary injunction to freeze access to that alleged information. OpenAI’s response repositions the access violation as Apple’s own offboarding failure, not deliberate theft.
What this means for your business
The detail that should stop a CISO cold is buried in OpenAI’s blog post: Apple apparently contacted a former employee weeks after his departure asking him to locate files, and he could still access internal cloud storage because Apple hadn’t revoked his credentials. This isn’t a rogue actor story. It’s an identity and access management failure that Apple’s own lawsuit inadvertently confirms. If your offboarding process leaves “residual access” as a known issue rather than a hard stop, you already own some version of this exposure.
OpenAI’s decision to litigate this in public rather than wait for discovery is a calculated move, and it reveals something about how AI companies now treat legal risk. Publishing cherry-picked communications doesn’t resolve the underlying facts, but it shapes how engineers, potential recruits, and enterprise customers read the case. The implicit message to Apple employees who might consider OpenAI next: your former employer will sue, and we will defend you loudly. That recruitment signal matters more to OpenAI’s hardware ambitions right now than any courtroom outcome does.
The recruiting angle deserves a harder look from enterprise security leaders specifically. The pattern here, a senior departing employee who retains post-separation access, gets contacted by former colleagues, and then faces litigation by a new employer’s rival, is not exotic. It happens at scale wherever talent moves between companies competing on the same technology roadmap. The question this case forces isn’t whether your NDAs are tight enough. It’s whether your access termination is instant and provable on the day someone resigns, because if it isn’t, “residual access” becomes your adversary’s best defense in court.
Concept deep-dive: Residual access
Residual access describes the condition where a former employee retains valid credentials to internal systems after their employment ends, typically because offboarding processes failed to fully synchronize identity revocation across every connected service. Think of it as a hotel key card that still opens the room after checkout because the front desk only updated one of three locks. In litigation, residual access shifts culpability from the individual who used it toward the organization that left the door open.
Based on reporting from OpenAI drags Apple’s lawsuit into the court of public opinion, originally published 2026-08-04 07:27:00.

