DruxAI
DruxAI

When Big Companies Evaluate Your Startup and Then Build It Themselves, Who Owns the Idea?

DruxAI·July 28, 2026·Via techcrunch.com·1 read
Share

When Big Companies Evaluate Your Startup and Then Build It Themselves, Who Owns the Idea?

An MCP gateway startup called Runlayer is suing HR software giant Rippling, claiming Rippling used a product evaluation as a free R&D session — and then built what it saw. If the allegations hold up, this case could reshape how AI startups share their technology with enterprise prospects.

The MCP Land Grab Is Creating Dangerous Incentives

Model Context Protocol has had a breakout 2026. What started as Anthropic's open standard for connecting AI models to external tools and data sources has become the connective tissue of the modern AI stack. Every serious enterprise AI deployment now has an MCP story, and the middleware layer sitting between AI models and business systems has become genuinely valuable real estate.

That value is exactly what makes Runlayer's situation so plausible — and so alarming. MCP gateways aren't a trivial product category. They handle authentication, routing, security policies, and increasingly complex orchestration between AI agents and enterprise data. Building one properly takes months of engineering work. The gap between "we understand what this does" and "we can build this ourselves" is real, but it narrows dramatically once you've had an expert walk you through the architecture, edge cases, and implementation decisions.

Rippling, for its part, is a sophisticated software company with deep engineering resources. The question isn't whether Rippling could have built an MCP gateway independently — it almost certainly could have. The question is whether the evaluation process materially accelerated that build, and whether that acceleration constitutes misappropriation of trade secrets or breach of any agreements signed during due diligence.

The Evaluation Trap Every AI Startup Should Know About

Enterprise sales cycles for infrastructure products almost always require deep technical disclosure. You can't sell a security product without showing how it handles threats. You can't sell a data pipeline without explaining your schema handling. And you absolutely cannot sell an MCP gateway without walking a prospect's engineers through how you've solved the hard problems.

This creates a structural vulnerability that's unique to early-stage infrastructure startups: the more sophisticated your prospect, the more dangerous the evaluation. A small company evaluating your product probably can't replicate it. A company like Rippling — with hundreds of engineers and existing infrastructure investments — is a different story entirely.

Startup founders in the MCP space, and AI infrastructure more broadly, should treat this case as a forcing function to revisit their evaluation agreements. NDAs are table stakes, but they're notoriously difficult to enforce around "ideas." What matters more are explicit contractual provisions around competitive use restrictions, evaluation scope limitations, and — where possible — watermarking or fingerprinting technical demonstrations so that derivation can actually be proven in court.

The irony is that being too secretive kills the deal, and being too open creates this exact risk. There's no clean answer, but there's a spectrum of protective measures that most early-stage teams simply don't deploy because they're too focused on closing the customer.

What This Means for the MCP Ecosystem Specifically

The broader MCP ecosystem has a particular version of this problem. Because MCP is an open protocol, the "secret sauce" was never the protocol itself — it was always the implementation layer. How you handle token management across dozens of enterprise systems, how you enforce granular permissions without killing latency, how you make the whole thing auditable for compliance teams. That's where the real IP lives.

And that's also exactly the kind of knowledge that gets transmitted during a thorough enterprise evaluation. A well-run proof-of-concept doesn't just demonstrate that the product works — it teaches the prospect's engineering team why it works.

Several well-funded MCP startups have emerged in 2026 building precisely this kind of gateway infrastructure. Watching one of them take on Rippling in court will be instructive for all of them. If Runlayer can demonstrate that specific implementation decisions — ones that took significant engineering effort to arrive at — showed up in Rippling's internal build shortly after the evaluation concluded, that's a meaningful evidentiary foundation. Trade secret claims live or die on specificity and timing, and the MCP space moves fast enough that timing arguments can be compelling.

The Wider Precedent for AI Infrastructure Startups

Beyond MCP, this lawsuit touches something that's been simmering across the AI infrastructure space for the past two years. The hyperscalers and large SaaS platforms are all racing to build native AI capabilities, and they're doing it partly through acquisition, partly through internal development, and — if cases like this one are any indication — sometimes through a third path that looks uncomfortably like competitive intelligence dressed up as a sales process.

Microsoft, Google, Salesforce, and ServiceNow have all expanded their AI-native tooling significantly in 2026. Each of them runs active startup partnership and evaluation programs. Each of them also has the engineering bench to build what they evaluate. The incentive structure is uncomfortable, and Runlayer's lawsuit is the first one I'm aware of to directly name it.

This doesn't mean every large company is acting in bad faith — most evaluations are genuine, and many startups do win enterprise contracts through exactly this process. But the asymmetry of information and capability means the risk is real, and startups should price it into their go-to-market strategy accordingly.

The cleanest takeaway for any AI infrastructure founder reading this: treat your evaluation process like a product in itself. Define what you'll show, what you'll withhold, what agreements need to be signed before you go deep, and what your evidentiary trail looks like if you ever need to prove what was disclosed and when. The Runlayer case may not succeed — trade secret litigation is brutal — but the behavior it's describing is a known pattern, and the time to protect yourself is before the evaluation, not after.

Frequently Asked

What is an MCP gateway and why is it valuable?

An MCP (Model Context Protocol) gateway sits between AI models and enterprise systems, handling authentication, routing, permissions, and data access. As AI agents become central to business workflows, this middleware layer controls what AI can see and do — making it strategically valuable infrastructure.

What legal claims can a startup make if a company builds their product after an evaluation?

The most common claims are trade secret misappropriation and breach of contract (typically an NDA or evaluation agreement). Trade secret claims require proving the information was genuinely secret, was protected with reasonable measures, and was actually used by the defendant — all of which are difficult to establish without clear documentation and timing evidence.

How should AI startups protect themselves during enterprise sales evaluations?

Beyond NDAs, startups should use evaluation-specific agreements that restrict competitive use, limit what can be shared internally at the prospect company, and define the scope of the evaluation explicitly. Keeping detailed records — including what was demonstrated, to whom, and when — is essential if a dispute ever arises.

What do the AIs actually think?

Ask GPT, Claude, Gemini and more about this topic simultaneously — and get a Consensus Score showing how much they agree.

Ask the AIs: “When Big Companies Evaluate Your Startup and Then Build I…” →