Apple has filed a federal lawsuit accusing OpenAI of trade secret theft, and the headlines are focused on the rivalry between two of the biggest names in tech. The detail that matters for most businesses is smaller and far more relatable. At the centre of the complaint is a former Apple employee who left the company, kept a work laptop, and used it to keep accessing internal systems for months afterwards. That is not a story about AI competition. It is a story about offboarding.
Apple Accuses OpenAI Of Building Its Hardware Ambitions On Stolen Information
Apple’s complaint, filed in the Northern District of California, names two former staff members. Tang Yew Tan spent close to 25 years at Apple before co-founding the hardware studio that OpenAI acquired for a reported $6.5 billion. Apple alleges he sent supplier information to his personal email before leaving and encouraged job candidates to bring unreleased Apple hardware to OpenAI interviews as “show and tell” material.
The second name is Chang Liu, a systems electrical engineer who left Apple for OpenAI earlier this year. Apple alleges Liu kept a company issued laptop and, crucially, was still able to log into Apple’s internal systems after departing. OpenAI has denied any wrongdoing, stating publicly that it has no interest in other companies’ trade secrets.
The Access Control Detail Most Coverage Has Missed
Most of the reporting on this case has focused on the drama of hardware secrets and Silicon Valley rivalry. The more useful detail sits underneath that. According to Apple’s complaint, Liu retained system access after leaving because of what the company describes as an authentication gap, and used that access to download confidential engineering files while working for a competitor. Apple also alleges Liu advised another employee, still at Apple but interviewing elsewhere, on how to copy files without attracting attention from Apple’s own security team.
Strip away the celebrity names and this is a scenario every UK business should recognise. An employee leaves. A device is not returned promptly. Access is not revoked at the point of departure. Whatever happens next is no longer a hypothetical risk, it is a live one.
Why This Matters For Every Apple Fleet, Not Just Big Tech
In Dr Logic’s experience, offboarding is one of the most consistently underweighted parts of IT security for growing businesses. Onboarding gets attention because a new starter needs to work on day one. Offboarding often gets treated as an administrative afterthought, handled by whoever remembers to do it once the leaver has already gone.
Under Cyber Essentials, this falls squarely under Control 3, user access control, which requires organisations to remove or disable access as soon as it is no longer needed. A departing employee who retains access to email, shared drives, or DMS (formerly MDM) enrolled devices is a straightforward compliance failure, regardless of whether anything is ever misused.
A basic offboarding process should cover:
- Revoking all account access on the employee’s last working day, not at the end of the month
- Collecting and wiping all company devices before final access is removed
- Auditing shared logins, shared drives, and any third-party tools the employee had access to
- Reviewing whether any personal devices were ever enrolled for email or file access, and removing that enrolment
- Confirming removal in writing, so there is a record the control was actually applied
On a Jamf or Addigy managed Mac fleet, most of this can be actioned within minutes of a leaver being flagged, which is precisely the point. The tools to close this gap already exist for most Apple businesses. What is usually missing is the process that triggers them consistently, every time, regardless of how amicable or rushed the departure is.
The Broader Lesson for Mac-First Businesses
Whatever the courts eventually decide about Apple and OpenAI, the underlying lesson does not depend on the outcome. A retained laptop and a lingering login are unglamorous failure points compared with allegations of stolen hardware designs, but they are the failure points that actually cause damage in most real world cases. Dr Logic recommends treating offboarding as a security control with the same rigour as patching or MFA, not as a task to be handled whenever HR gets round to it.
If your current process for departing staff would not stand up to the same scrutiny Apple’s lawyers have just applied to OpenAI, that is worth fixing before it becomes a real incident rather than a cautionary headline.
Ready to close the gaps in your offboarding process? Talk to Dr Logic about strengthening your access controls.



















































