Skip to content

Leadership and readiness

Employees selling work files to AI platforms: what employers should do

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When employees sell company data to AI platforms, employers should act on three fronts: add a clear policy clause banning uploads of work files, watch for the signals that uploads are happening, and offer a company-controlled alternative. Work files usually belong to the company, and tolerating uploads can weaken trade secret protection.

Key takeaways

  • Files employees create at work generally belong to the company under employment agreements and confidentiality terms.
  • Trade secret protection generally depends on reasonable measures to keep information secret, so an explicit ban and consistent enforcement matter.
  • A policy clause should cover paid and unpaid uploads, during and after employment, and name AI data platforms explicitly.
  • Detection relies on signals most companies already have: DLP alerts, bulk downloads, new browser extensions and offboarding reviews.
  • Licensing records through the company, with de-identification and approvals, replaces the temptation with a governed process.

Why are employees selling work files to AI platforms?#

Employees sell work files to AI platforms because some platforms pay individuals for documents, conversations, code and examples of expert work. A support engineer may see an offer to upload resolved tickets, a project manager may be asked for real proposals, and a developer may be invited to share code with its review history.

Many employees do not see this as taking anything. The deck or the runbook feels like their own work, and a platform's sign-up flow rarely asks who owns it. The result is company records, sometimes with customer details inside, leaving through a channel nobody approved.

The pull is real. TechCrunch reported in October 2025 that Mercor's CEO described AI labs tapping former senior employees of investment banks, consulting firms and law firms because the firms themselves do not want to hand over data; Mercor says it tells contractors not to upload former employers' documents. Expert knowledge is in demand, and the line between what a person knows and what their employer's files contain is exactly where a policy needs to speak.

Treat this as a policy gap rather than a wave of bad actors. Most people stop once the rule is clear and a legitimate path exists.

Who owns the files an employee created at work?#

Files an employee created at work generally belong to the employer. Employment agreements, invention assignment terms and confidentiality agreements usually cover documents, code and records produced in the job, and copyright in work made within the scope of employment generally belongs to the employer.

Ownership is only part of the risk. Trade secret protection generally depends on the owner taking reasonable measures to keep information secret; DOJ guidance notes those measures need not be absolute and cites examples such as confidentiality agreements and need-to-know access. A company that knows uploads are happening and does nothing may weaken a later claim. Customer information in those files raises a separate problem: the upload can breach customer contracts and may trigger privacy obligations for the company.

Each case turns on the specific agreements and the laws that may apply, so involve counsel before acting on a particular situation.

What should the policy clause say?#

The policy clause should name the behavior plainly, cover paid and unpaid uploads, and apply during and after employment. Place it in the confidentiality or acceptable use policy and reference it from the data licensing policy, so all three point to the same rule.

  • Scope: company records, work product, customer and vendor information, code and internal communications, in any form.
  • Prohibited acts: uploading, selling, licensing, sharing or otherwise providing them to any AI platform, data marketplace, training-data program or model developer, paid or unpaid.
  • Exception: only through the company's approved data licensing process, with written authorization.
  • Duration: the obligation applies during employment and continues after it ends.
  • Personal content: skills, general knowledge and material that contains no company or customer information remain the employee's own.
  • Reporting: employees approached by such platforms about work materials tell a named contact.

A detection checklist for security and HR teams#

Detection relies mostly on signals companies already collect. The goal is to notice patterns early and respond proportionately, not to monitor every keystroke.

Check your monitoring notices before relying on any of these signals. Some states require employers to tell employees about electronic monitoring, and collective bargaining or employment agreements may add rules, so confirm with counsel that your acceptable use policy and notices cover the logs you plan to review.

A detection checklist for security and HR teams
SignalWhere to lookFirst response
Uploads to AI data platforms or marketplacesWeb proxy, DLP or CASB alerts by site categoryReview the alert with HR before contacting anyone
Bulk downloads or exportsHelp desk, CRM, file storage and repository audit logsCheck whether the export had a business reason
Unusual repository cloningSource control audit logsConfirm the repositories and the employee's role
Screen or activity capture toolsEndpoint management and browser extension inventoryRemove unapproved tools and ask why they were installed
Activity before departureOffboarding review of recent downloadsRemind the employee of continuing obligations in writing
Tips from colleagues or customersEthics line or manager reportsPreserve evidence and escalate to counsel

What to do when you find an upload#

When you find an upload, act in a measured order: preserve, assess, contain, then fix the cause. A rushed accusation can create employment claims and does nothing to get the files back.

  • Preserve the evidence: logs, alerts and any platform account details, without altering them.
  • Bring in HR and counsel before contacting the employee.
  • Identify what was uploaded and whether it includes customer, personal or trade secret information.
  • Ask the platform to remove the material through its process for reports from rights holders, if it has one.
  • Assess with counsel whether customer contracts or breach notification laws require you to notify anyone.
  • Close the gap: update the policy, brief the team and adjust controls.

The company-controlled alternative#

The company-controlled alternative is to license records through the company itself, under a policy, with approvals and de-identification. That replaces an unmanaged leak with a governed process, and it protects the employees whose names, emails and notes appear in the records.

Explain the difference to employees directly. An individual upload sends raw work files, often with customer details, to an unknown party with no limits on use. A company license sends a prepared, de-identified package to a known buyer under written permitted use and deletion terms, after the company approves the release. The records are licensed, not sold, and the company keeps ownership.

Employees usually want to know whether their work will be used and whether they will be identifiable. A short notice or FAQ that answers those questions does more to stop side uploads than a warning alone.

Illustrative: a software company finds runbooks on a data platform#

Illustrative: the security team at a fictional B2B software company receives a DLP alert showing that a support engineer uploaded files to a site that pays for expert work samples. The files include internal runbooks, ticket macros and several exported Zendesk conversations containing customer names.

HR and the general counsel review the alert before speaking to the engineer, who explains that the platform said contributors could share their own work. The company asks the platform to remove the files, counsel reviews the customer contracts for notice duties, and the engineer closes the account.

The company then adds the policy clause, blocks the platform category at the web proxy and publishes an employee FAQ. Later, leadership runs a metadata-only fit check on its own support history to see whether a company license makes sense.

How SourceX approaches employee-created records#

In a SourceX transaction the supplier is the company that holds the records, acting through its authorized signer, not an individual employee. Within the SourceX five-step transaction, the Rights and Preparation steps review employee-created records and remove personal details before the supplier approves any release.

Each release is documented in a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization, which gives the company a clear answer for employees and customers about what left and under which terms.

Frequently asked questions

Can we stop former employees from selling files they kept?

Confidentiality obligations in employment agreements often continue after employment ends, and trade secret law may also apply. Remind departing employees of those obligations in writing during offboarding, recover company files where possible and involve counsel if you find a former employee offering company material.

Should we ban employees from contributing to AI data platforms at all?

Usually the policy should target work materials, not personal activity. An employee who records their own voice or writes original content unrelated to the job is generally outside the company's interest. Focus the rule on company records, customer information and work product.

Is pasting work files into an AI assistant the same problem?

It is related but different. Using an approved AI assistant under company terms is a tool decision governed by your acceptable use policy. Uploading files to a platform that pays for training data transfers company records to a third party for its own use.

Do we need to tell customers if their data was uploaded?

Possibly. It depends on what was uploaded, your customer contracts and the breach notification laws that may apply. Have counsel assess the specific facts quickly, since some contracts and laws set notice deadlines.

Will a company license make employees feel exploited?

It can if handled poorly. Explain what is licensed, how names and personal details are removed and who approves each release. A clear notice and FAQ issued before any license gives employees answers instead of rumors.

Sources

  • TechCrunch reported on October 29, 2025 that Mercor CEO Brendan Foody described AI labs tapping former senior employees of investment banks, consulting firms and law firms because the companies themselves do not want to hand over data; Mercor says it tells contractors not to upload former employers' documents. Source
  • DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing examples such as limiting access on a need-to-know basis and requiring confidentiality agreements. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify