On July 28, 2026, Model Context Protocol startup Runlayer filed a lawsuit against HR software giant Rippling, alleging trade secret misappropriation, unfair competition, and breach of contract. The suit, reported by TechCrunch, claims that during a nearly year-long product trial, Rippling gained access to Runlayer's source code, product roadmap, and confidential engineering plans under a non-disclosure agreement, only to terminate the trial when price negotiations failed and subsequently build what a Rippling insider described as 'almost a 1 to 1 copy' of Runlayer's MCP gateway. Runlayer has retained Sullivan & Cromwell to represent the company in a case that highlights the growing legal risks surrounding AI infrastructure partnerships, where proprietary gateway technology has become a critical competitive battleground in the expanding ecosystem of AI agents.
The Model Context Protocol, open-sourced by Anthropic in November 2024, has become the dominant standard for connecting AI agents to external data sources, enterprise systems, and third-party applications. MCP gateways serve as the secure middleware layer that allows AI agents to authenticate, query, and interact with business data, making them a strategically critical component of the agentic AI stack. Runlayer, which has raised $42 million from investors including Khosla Ventures and Felicis, has positioned itself as a leading provider of secure MCP gateways for enterprise deployments, offering features such as credential management, rate limiting, audit logging, and data governance controls that are essential for regulated industries.
The allegations center on the conduct of Rippling during what Runlayer describes as an 'intensive' year-long engineering collaboration. According to the complaint, Rippling participated in the trial as a prospective customer, gaining deep technical visibility into Runlayer's architecture, source code, and development roadmap. When the trial concluded without a purchase agreement, a Rippling insider allegedly texted Runlayer's CEO, Andrew Berman, that Rippling had 'a project internally to build essentially a clone of Runlayer' and that the internal product was 'almost a 1 to 1 copy.' Rippling has confirmed that it is launching its own MCP gateway but denies all allegations of intellectual property misuse, characterizing the lawsuit as a 'panicked effort to avoid competition' and asserting that its product was built using 'only our proprietary information.'
The legal significance of the case extends beyond the immediate parties. MCP gateways are becoming the connective tissue of the enterprise AI ecosystem, and the intellectual property surrounding how these gateways manage authentication, data routing, and security policies is increasingly valuable. If Runlayer can prove that Rippling misappropriated specific trade secrets, such as proprietary algorithms for credential rotation, custom data transformation logic, or unique security architecture, the case could establish important precedents for how AI infrastructure IP is protected during enterprise sales cycles. Conversely, if Rippling can demonstrate that its gateway was built independently using only publicly available MCP specifications and its own engineering expertise, the case may clarify the boundaries between legitimate competitive development and trade secret theft in the rapidly evolving AI middleware market.
For personal injury law firm leadership, the Runlayer v. Rippling dispute carries three practical takeaways. First, the case demonstrates that AI-related intellectual property disputes are not limited to foundation model training data or output copyright, but extend to the entire AI stack, including middleware, gateways, and integration infrastructure. PI firms that represent technology clients or handle IP disputes should develop familiarity with the emerging AI infrastructure landscape, as cases involving MCP gateways, agent orchestration platforms, and vector databases will increasingly appear in state and federal courts. Second, the allegations of a year-long trial followed by alleged cloning highlight the due diligence risks that technology companies face when sharing proprietary technical details with prospective customers during sales cycles. PI firms advising clients in the AI sector should recommend robust contractual protections, including explicit IP ownership clauses, source code escrow limitations, and post-termination audit rights, to reduce the risk of trade secret misappropriation by well-funded competitors. Third, the involvement of Sullivan & Cromwell, one of the nation's most prestigious law firms, signals that AI infrastructure litigation is attracting top-tier legal talent and will be fought at the highest level of technical and legal sophistication. PI firms that anticipate handling AI-related disputes should invest in technical expertise or expert witness relationships that can translate complex AI architecture concepts into compelling trial narratives, because the cases that emerge from this sector will require both legal acumen and deep technical fluency.



