A year ago, Runlayer, an AI infrastructure startup, invited Rippling, a major enterprise SaaS player, to test its Model Context Protocol (MCP) gateway. The trial was meant to be a mutual exploration: Runlayer would show how its product could integrate with enterprise workflows, and Rippling would evaluate whether it could fit into its own platform. Both sides signed non-disclosure agreements and trial terms that explicitly prohibited intellectual property theft. But now, Runlayer says Rippling didn’t just violate those terms, it stole the core idea.
According to Runlayer, Rippling began building a near-identical clone of the MCP gateway shortly after the trial ended, citing pricing disagreements as the reason for termination. The company alleges that an insider at Rippling informed them of an internal project to replicate their product, a claim Rippling has not publicly addressed. Runlayer’s legal team says the timing is suspicious: development began almost immediately after the trial concluded, suggesting a deliberate move to capitalize on the idea before Runlayer could fully protect it.
This isn’t just a legal dispute, it’s a case study in how AI startups must navigate the minefield of enterprise partnerships. When you’re building something novel and valuable, especially in a space as competitive as AI infrastructure, you’re not just selling a product, you’re exposing your IP to a company with deep engineering talent and a history of acquiring or replicating technology. The stakes are high. Runlayer’s case highlights the need for startups to think beyond NDAs and trial agreements, they must build technical and legal safeguards into their engagement processes.
One of the most overlooked risks is the lack of enforceable IP clauses in trial agreements. Many startups assume that signing an NDA is enough, but NDAs are often designed to prevent disclosure, not to stop reverse engineering or internal replication. Runlayer’s experience suggests that startups should consider including clauses that require the trial partner to disclose any internal projects that might use or replicate the product, and to provide a timeline for when such projects would be publicly announced or released.
Another layer of protection is technical. Startups can implement telemetry and usage tracking that logs how a product is being used during a trial, not just what features are accessed, but how they’re being integrated. This creates a digital audit trail that can be used in court if IP is stolen. Runlayer, for example, could have embedded usage metrics that would show how Rippling’s engineers interacted with the MCP gateway, and whether they were copying code or architecture.
The legal side also requires more proactive planning. Startups should consult with IP attorneys before entering any enterprise trial, not just to draft NDAs, but to design IP protection strategies that are enforceable in court. This includes registering patents or trademarks for core components, even if they’re not yet ready for public filing. It also includes setting up a legal framework for when a trial ends, for example, requiring the trial partner to return all code, documentation, and prototypes.
This case also raises questions about how enterprise tech companies evaluate startups. Rippling, for example, has a history of acquiring or integrating AI startups, sometimes through acquisition, sometimes through open-source contributions. But when a startup is testing its product with a large enterprise, it’s not just about the potential for revenue, it’s about the risk of IP theft. Startups must be more selective about who they engage with, and enterprises must be more transparent about how they handle third-party IP.
As AI infrastructure becomes more valuable, the legal and technical risks for startups will only grow. Runlayer’s case is a warning, and a call to action. Startups must build IP protection into their business models from day one. Enterprises must be more transparent about how they handle third-party IP. And the legal community must adapt to the new realities of AI-driven innovation.
This is not just about Runlayer and Rippling, it’s about how the entire AI startup ecosystem will evolve. As AI becomes more embedded in enterprise workflows, the lines between innovation and imitation will blur. Startups must be prepared to defend their ideas, not just with NDAs, but with technical safeguards, legal frameworks, and strategic partnerships.
As first reported by TechCrunch, this case is a reminder that in the AI space, the most valuable thing you can build is not just a product, it’s a legal and technical defense against those who might try to steal it.
For startups looking to scale, there’s a lesson here: don’t just focus on building a great product. Build a great defense around it. Because in the AI world, the product is only as valuable as the IP that protects it.
And if you’re an enterprise evaluating AI startups, remember this: the best product is not the one that works, it’s the one that can’t be stolen.
For more on how AI startups are navigating enterprise partnerships, check out our recent piece on Listen Labs Raises $69M to Scale AI Customer Interviews After Viral Hiring Stunt.