Deleting Files Won't Wipe AI Memory: Ex-Apple Engineer Fed Confidential Schematics into OpenAI Models

Deleting Files Won't Wipe AI Memory: Ex-Apple Engineer Fed Confidential Schematics into OpenAI Models

AppleOpenAITrade Secrets

Sources:HN + web research

On August 31, 2026, a forensic report submitted in Apple’s lawsuit against OpenAI delivered a wake-up call to the entire technology industry. Former Apple systems electrical engineer Chang Liu not only departed with confidential circuit schematics, but also directly fed these engineering files into AI systems. Trade secrets are no longer merely reviewed manually by competitors—they are being absorbed en masse by large language models, putting corporate defenses for core IP to an unprecedented test.

In its latest court filing, Apple disclosed four key findings from the preliminary forensic examination of a MacBook:

Forensic FindingDetails
Finding 1Liu downloaded confidential Apple circuit schematics and actively used them in his work at OpenAI
Finding 2Both Liu and OpenAI colleagues were aware of unauthorized access to Apple’s third-party cloud storage
Finding 3Upon learning of Apple’s internal investigation, Liu instructed an OpenAI colleague to destroy evidence, and the colleague confirmed compliance
Finding 4A tool used by Liu at OpenAI shared the exact same name as an internal Apple engineering application

From Cloud Storage Directly into AI Agents

Liu left Apple in January 2026 to join OpenAI, subsequently exploiting security vulnerabilities to download engineering files from Apple’s third-party cloud storage. According to preliminary forensic findings, he ran circuit simulation software LTspice using these schematics in March 2026, noting in contemporaneous communications that his AI agent had learned how to run LTspice and analyze the outputs. IP thieves no longer need to analyze complex schematics manually; instead, they build automated agents to digest specialized, high-barrier confidential information.

Upon discovering Apple’s internal investigation, Liu immediately messaged an OpenAI colleague to destroy evidence, a command the colleague acknowledged and carried out. While such traditional cover-up attempts might have been effective in historic digital forensics, they fall short in AI research environments. Wiping local files and chat histories cannot erase the indelible knowledge imprint left behind when agents execute simulations.

Apple vs. OpenAI Lawsuit Key Visual Image: Apple vs. OpenAI lawsuit key visual. Source: 9to5Mac

Physical Deletion Cannot Erase Parametric Memory

Apple’s motion to expedite discovery stems from a fundamental concern: once trade secrets are absorbed by AI, their ongoing proliferation and utilization become irreversible. In the past, a leaked schematic might result in a single competing product from a rival. Today, it can turn into a permanent, embedded capability within a circuit design agent. Even if Apple prevails in court and forces the physical deletion of all source files, it cannot prevent trained agents from applying that abstracted engineering expertise in future tasks.

Furthermore, a tool used by Liu at OpenAI shared the exact name of an internal Apple engineering application, pointing to a wholesale transplantation of engineering methodology and toolchains. Apple is firmly pressing for access to Liu’s synchronized Mac mini, fearing that data synced across the iCloud ecosystem may have already been scraped into broader automated workflows and crawlers.

Screenshot of Apple's July Lawsuit Filing Image: Screenshot of Apple’s July lawsuit filing. Source: 9to5Mac

Cross-Device Sync Shatters Isolation Boundaries

The seamless flow of data—from third-party cloud storage to Mac mini, and over iCloud to a MacBook—highlights the fragility of corporate data perimeters. In response to Apple’s request for expedited discovery, OpenAI has filed to dismiss the suit, asserting that device logs refute the claims. This clash highlights a fundamental divide in evidentiary standards: defendants argue that no relevant files remain on physical devices, whereas plaintiffs contend that once secrets touch an AI agent, a substantive and irreversible leak has already occurred.

At the core of Apple’s lawsuit is the realization that traditional remediation is rendered powerless once trade secrets enter AI models. As confidential data converts into an agent’s implicit domain knowledge, exposure becomes permanent. Future trade secret litigation will no longer center on who deleted physical files, but on who can prove an agent’s capabilities encode their proprietary blueprints.

Reference Links:

  • 9to5Mac Report
  • HN Discussion