On August 31, 2026, Apple Inc. filed a redacted supplemental brief in support of its motion for expedited discovery in the Northern District of California. The primary filing is Dkt. 94-1. The CourtListener docket is the HTML case page. This is Apple’s motion. It is not a ruling.
What Apple filed on August 31
The caption on the redacted PDF is Plaintiff Apple Inc.’s Supplemental Brief in Support of Its Motion for Expedited Discovery. Apple says counsel delivered a MacBook to forensic expert Daniel Roffman on August 21, with initial results reported August 26. Filename redactions remain on the public copy. This desk is not filling those boxes.
Apple’s conclusion: “New evidence confirms Mr. Liu used the trade secrets he misappropriated from Apple while employed by OpenAI.” That is Apple’s claim. It is not a court finding of theft. A judge has not ruled that an agent put Apple IP into a production model.
Apple’s words: Liu’s use of Apple’s “trade secret power-converter circuit while employed by OpenAI and his use of AI agents to learn to run simulations” “raise concerns extending beyond ordinary document theft.” Those are Apple’s words. This briefing does not treat them as proven facts.
“Where trade secret information is fed into an AI agent or model that ‘learn[s]’ from it, such ‘learning’ may create irreversible and continually propagating uses of the trade secret”Apple supplemental brief, citing Roffman Decl. ¶ 31; Fayed Decl. ¶ 26. Dkt. 94-1.
That quote is the operator line. Apple is telling the court that feeding a trade secret into an agent or model that learns from it may create uses that keep propagating. Apple is asking a judge to take that risk seriously. A judge has not adopted that sentence as a holding.
What Apple says the MacBook and Mac mini show
On the public pages, Apple alleges Liu left for OpenAI in January 2026 and later used a confidential Apple file that, Apple says, holds a power-converter circuit schematic and simulation input data. Apple alleges a March 7, 2026 download and a March 18 LTspice run under the profile “changliu” on a Mac mini, with outputs later syncing to a MacBook via iCloud on April 11. Those dates and tools are Apple’s forensic recitation, not findings.
Apple recites messages it says are on the MacBook: Liu writing he was “[f]eeling AI all day long,” that in the past hour his AI “agent learned how to run LTspice, look at result, tune compensation parameter,” and that he was trying to “make a behavior buck” with “voltage outer and current inner.” Apple places those lines next to power-conversion work. Recitation is not proof the court has adopted.
Apple further alleges that after Liu and Yu-Ting (“Alyssa”) Peng learned of Apple’s June investigation, they discussed the need to “restore” and then “start using” Apple-owned devices (Roffman Decl. ¶ 25, Ex. D). Apple reads that as destroying forensic data. Label that as Apple’s reading. It is not a proven fact of destruction, and this desk is not writing destruction of evidence as a fact.
What Apple is asking the court to do
Apple asks the court to grant expedited discovery. The Mac mini remains uninvestigated, per Apple. Counsel had the MacBook but had not yet looked at its data, per Apple. Apple wants forensic imaging of devices and accounts it says were used to move Apple-originated information. Those are Apple’s asks.
Defendants opposed expedited discovery on the docket (Dkt. 87, Aug. 18) and have moved to dismiss. This briefing does not quote those filings. Hearing noticed: Oct 1, 2026, 9:00 a.m., before Judge Edward J. Davila. That is a motion calendar, not a verdict date.
What Alberta operators should do
The shop query is simple: can an AI agent keep my trade secrets. If a file goes into an agent or a simulation tool, Apple’s own propagating-use claim is the useful line. You do not need a California lab feud to answer it.
Private AI security is the failover. Do not put client schematics, tenders, or credentials in an agent that trains, logs, or syncs. That is a data-classification rule. If the job has to stay on the desk, that is AI consulting work on a private AI security path, not a public paste into a sim agent.
AI automation Alberta still works when the files are classified first. If the workflow would hurt the shop if it kept learning, it does not go into a training, logging, or syncing agent. Full stop.
