The reasoning is consistent with how courts and regulators in the US and EU are beginning to treat AI tools in the confidentiality and data-protection context, and it has direct implications for how companies draft NDAs, confidentiality policies, and AI usage rules.
Key Facts
Remizova v. EnergoProf Group LLC, Babushkinsky District Court of Moscow, Case No. 2-1545/2026:
The claimant, a Sales Director, was dismissed for a single gross breach of duty – disclosure of information constituting a legally protected secret – after the employer’s information-security team detected that she had exported confidential information (sales funnel data, deal-level financials, and roughly 30 commercial performance metrics) from the company’s internal, access-restricted analytics platform into DeepSeek, a third-party AI chatbot.
The court partially sided with the employee on a procedural point (one reprimand was quashed for disproportionality), but upheld the dismissal itself, and denied both the reclassification and the severance payment for the employee.
Comparable Cases Worldwide
Regulators and courts around the world are converging on the same basic proposition – that feeding confidential business information into a third-party AI tool is a disclosure event with real legal consequences:
For any EU business, this means uploading company data to DeepSeek (or similar non-EU AI services) is a live cross-border data-transfer compliance issue under Articles 44–49 GDPR, independent of any trade secret analysis.
What This Means for Business
Traditional confidentiality frameworks were built for a world where secrets left the building through a USB drive or a personal email. Now, with AI tools, an employee trying to be more productive can move sensitive data outside the company’s control in a single prompt, often without any subjective intent to harm the business. Courts are responding by treating that transmission itself as the legally operative act of disclosure. That is good news for employers seeking to enforce confidentiality obligations, but only if the underlying compliance architecture exists.
Action List
Businesses that treat AI-tool governance as an extension of their existing trade-secret and data-protection compliance will be far better positioned both to prevent this kind of leak and to enforce their rights if one occurs. The following measures to be taken are recommended in a view of this issue:
REVERA advises businesses on adapting NDAs, confidentiality regimes, and internal policies to cover AI tool usage, on structuring evidence and disciplinary procedures for suspected data leaks, and on assessing cross-border data-transfer exposure when deploying third-party AI platforms.