
Corporate Espionage
Corporate espionage refers to the covert spying on a company's trade secrets by competitors or state actors. In the tech industry today, this primarily involves research data, source code, and the blueprints of AI systems.
Corporate espionage is the English term for what is called Wirtschaftsspionage in German. It refers to the covert acquisition of information that a company deliberately keeps secret. This includes blueprints, price calculations, customer lists, or research results. Such information is called trade secrets because it gives a business an edge over the competition. Whoever obtains it without permission saves themselves years of work and millions in costs. The term covers two very different types of perpetrators: rival companies on the one hand, and state intelligence services on the other.
What a stolen blueprint is worth
Developing a modern AI model costs hundreds of millions of dollars. A large part of that goes not into hardware but into knowledge: which data to use, in what order to train, which settings actually work. This knowledge is written down in no manual. Whoever copies it can close a years-long gap in just a few weeks.
That is why corporate espionage has long since become a matter for governments. In recent years, the US has repeatedly imposed export bans on high-performance chips in order to slow down competitors technologically. Such bans increase the incentive to obtain the missing knowledge by other means. Security agencies in Germany and the US regularly warn of poaching attempts and targeted attacks on research departments.
For investors, this topic is relevant because the value of many tech companies rests almost entirely on intellectual property. A chipmaker owns factories; an AI lab owns, above all, ideas. If those ideas are copied, market value can drop quickly.
From the poached employee to the data leak
The most common route is surprisingly unspectacular: people. An employee moves to a competitor and takes files along. Sometimes this happens out of greed, sometimes out of resentment toward the former employer. Experts call this an insider threat, because the perpetrator already has legitimate access to the data. That is precisely why this route is so hard to prevent.
The second route runs through the network. Attackers send fake emails that look like a message from the company’s own IT department. If someone clicks on it and enters their password, the door to the corporate network opens. This approach is called phishing. Afterward, the attackers often move through the system unnoticed for months, copying data in small portions.
With AI systems, a third variant comes into play. One doesn’t even need to steal the source code to rebuild a model. It is enough to query the finished system millions of times and train one’s own model from the answers. This rebuilding through querying is called model distillation. Whether it legally counts as theft remains disputed to this day.
When espionage makes the business news
A well-known case is the dispute between Google and Uber over self-driving car technology. A former Google engineer took thousands of files with him when he moved to a start-up that Uber later acquired. The case ended with a multimillion-dollar payment and a prison sentence. Such proceedings usually drag on for years.
Incidents have also occurred at AI labs. In 2024, a former Google employee was charged with copying confidential documents related to AI chips. Reports of this kind now appear in the business news almost every month.
A common misconception is that only large corporations are affected. Mid-sized specialists in particular are attractive targets, since they are often world market leaders in a niche and spend less money on security. The term should also be distinguished from competitive intelligence: this involves analyzing publicly accessible sources such as patents or job postings. That is entirely legal and is part of everyday business in many companies.