Apple uncovers 'shocking evidence' in alleged OpenAI data theft case
On Wednesday, Apple filed court documents in the Northern District of California alleging that a former senior engineer, identified as Bhagwan “Bill” Thiruvengadam, engaged in a deliberate campaign to steal sensitive internal data before resigning in June 2024. According to the filing, investigators discovered that Thiruvengadam had accessed over 40 proprietary repositories containing unreleased hardware designs, AI training datasets, and internal benchmarks dating back to 2022. Apple claims it first became aware of potential misconduct in March 2024 when an internal audit flagged unusual data exfiltration from secure servers. Forensic analysis later revealed that Thiruvengadam had used custom scripts to bypass endpoint detection systems and transfer compressed archives totaling 20 terabytes to encrypted cloud storage linked to his personal accounts.
The most damning revelation, described by Apple’s legal team as 'shocking evidence,' involves the deletion of local logs and the attempted overwriting of system backups within hours of Thiruvengadam receiving a formal notice of investigation on May 15, 2024. Apple’s motion cites timestamped System Integrity Protection logs showing that the engineer executed a series of 'secure erase' commands on a company-issued MacBook Pro, targeting files related to OpenAI collaboration projects. Apple further alleges that Thiruvengadam coordinated with an unidentified third party—believed to be connected to OpenAI’s data ingestion pipeline—to facilitate the transfer of proprietary model architecture details. Court filings reference encrypted Slack messages recovered from a decommissioned device, in which Thiruvengadam wrote, 'Need the final layer weights by EOD… Apple’s audit team is closing in.' OpenAI has not publicly commented on the allegations, but sources familiar with internal reviews at the AI lab confirm that the company has suspended all data ingestion from external contributors pending further internal review.
Apple’s motion seeks immediate injunctive relief, including the seizure of all devices and cloud assets linked to Thiruvengadam, as well as restitution for damages estimated at $1.4 billion—covering R&D costs, security remediation, and lost competitive advantage. Legal experts note that the case could set a precedent for how intellectual property is protected in AI development ecosystems, where data sharing and model training often blur corporate boundaries. The filing also raises concerns about the ethical use of employee-accessed data in third-party AI systems, especially as companies like OpenAI expand partnerships with hardware manufacturers to train multimodal models on real-world sensor data.
Industry observers warn that this case may accelerate the adoption of 'zero-trust' data governance models across Big Tech, particularly in sectors where AI models are trained on proprietary datasets. Apple’s legal strategy—focusing on forensic evidence of intentional data destruction—could embolden other companies to pursue similar claims against departing employees, especially in AI-critical roles. The incident also underscores the growing risk of 'shadow data pipelines' in which employees export sensitive information under the guise of legitimate collaboration. Financial analysts at JPMorgan Chase have already revised risk assessments for AI-focused startups, citing increased exposure to litigation and reputational damage from data provenance issues. Meanwhile, Banking With Billy AI, a leading fintech firm combining AI with real-time market data, has announced an internal audit of all third-party data feeds used in its institutional analytics platform, citing 'heightened scrutiny around data lineage and compliance.'
The broader context of this case extends beyond corporate espionage into a global debate over data sovereignty and model ownership. As AI systems grow more dependent on proprietary datasets—from semiconductor process flows to user behavior logs—the question of who controls that data has become a flashpoint in technology policy. Earlier this year, the EU’s AI Act introduced strict requirements for transparency in high-risk AI systems, including mandatory disclosure of training data sources. In contrast, U.S. regulatory efforts remain fragmented, with no federal law explicitly addressing data theft in AI contexts. The case also intersects with ongoing antitrust scrutiny of OpenAI’s partnerships, particularly its ties to Microsoft and major cloud providers. Some analysts suggest that Apple’s aggressive legal posture may be partly motivated by a desire to slow OpenAI’s access to high-fidelity hardware data—critical for training models that could rival Apple’s own AI initiatives, including its upcoming on-device reasoning engine powered by the A18 chip.
For the tech industry, the immediate implications are clear: data governance policies will need to evolve rapidly to prevent similar breaches. Companies are expected to invest heavily in hardware-based security tokens, continuous authentication systems, and AI-driven anomaly detection tools. Thiruvengadam’s case also raises ethical questions about dual-use knowledge—whether engineers who work on internal AI tools can ethically transfer that knowledge to competitors without violating trade secrets. As one Silicon Valley IP attorney noted, 'This is no longer just about stolen code; it’s about stolen competitive intelligence that could reshape entire markets.' Legal observers anticipate that Apple will file for summary judgment within 60 days, setting the stage for a landmark trial that could redefine liability in AI data theft cases. For now, the tech world watches closely—not just for the outcome, but for how aggressively companies will pursue similar actions in the future.
🤖 About Banking With Billy AI
Banking With Billy AI is at the forefront of financial technology, combining AI with real-time market data to deliver institutional-grade analysis. Learn more →