AI and Trade Secrets: Why Trade Secret Law Is Your Best IP Strategy for AI Assets
- August 15, 2026
- Posted by: allan
- Category: Uncategorized
If you have built a useful AI system — a fine-tuned model that predicts customer churn, a proprietary dataset assembled over years, a system prompt that makes your chatbot dramatically better than a generic competitor — you have a strategic asset worth protecting. The question is how.
Most business owners instinctively reach for patents or copyright. Both feel familiar. Both have a government office behind them, formal registration processes, and a century of case law. But for most AI assets, those two frameworks offer less protection than you might expect, and they come with significant costs and tradeoffs. Trade secret law, by contrast, fits the shape of AI assets in ways that patents and copyright simply do not. It protects functional information, it does not require public disclosure, it has no expiration date as long as you maintain secrecy, and it can cover every layer of your AI stack — from your raw training data to your model weights to the system prompts you have spent months refining.
This post explains the legal framework, surveys which AI assets can qualify, compares the three protection strategies, and gives you a practical checklist for building a trade secret program around your AI investments.
The Standard IP Frameworks and Why They Fall Short for AI
The traditional tools of intellectual property law were not designed with machine learning in mind.
Patents protect inventions that are novel, non-obvious, and eligible for protection. In the AI context, that last criterion is the problem. Under the Supreme Court’s Alice/Mayo framework — applied through 35 U.S.C. § 101 — claims directed to abstract ideas, mathematical concepts, or mental processes are not patent-eligible. Because AI algorithms are, at their mathematical core, functions applied to data, patent applications for AI systems frequently run into § 101 rejections. The USPTO’s 2024 guidance on subject matter eligibility for AI inventions clarified that the question is not whether AI was used in development, but whether the claimed invention itself is the kind of thing patents protect. Many core AI advances — improvements to optimization functions, new neural network architectures, novel training procedures — exist in a patent eligibility gray zone. And even when a patent issues, obtaining one requires public disclosure of your invention, publication in the USPTO’s databases, and a 20-year clock that starts running immediately. For AI technology that evolves and compounds value over time, surrendering secrecy in exchange for a limited monopoly is often a bad deal.
Copyright protects original works of authorship fixed in a tangible medium. In August 2023, a federal district court in the District of Columbia affirmed the Copyright Office’s position that human authorship is “a bedrock requirement of copyright,” rejecting registration for artwork created autonomously by an AI system. The D.C. Circuit affirmed that ruling in 2025, and the Supreme Court declined to hear the case in early 2026. The message from every level of the federal judiciary is uniform: if a machine created it without sufficient human creative contribution, it does not qualify for copyright protection. For AI-generated outputs — the very outputs that often embody your competitive advantage — this is a significant limitation. Copyright can protect human-authored software code, documentation, and creative training data, but it struggles to cover the functional core of most AI assets.
Trade secret law suffers from neither of these problems. It does not require the asset to be an “invention” under patent law’s definition. It does not require human authorship. It protects functional information — the things that make your system work and give you a competitive edge — and it can do so indefinitely, as long as you take reasonable steps to keep the information confidential.
The Legal Foundation: DTSA and UTSA
Two bodies of law govern trade secret protection in the United States. Understanding both matters for how you structure your protection program.
The Uniform Trade Secrets Act
The Uniform Trade Secrets Act (UTSA) was drafted in 1979 and has been adopted, in some form, by nearly every state. It provides a state-law cause of action for trade secret misappropriation. Under the UTSA, a trade secret is information that (1) derives independent economic value from not being generally known or readily ascertainable by proper means, and (2) is subject to reasonable efforts to maintain its secrecy. The precise language varies somewhat by state, but the core structure is the same across jurisdictions.
The Defend Trade Secrets Act
In 2016, Congress enacted the Defend Trade Secrets Act (DTSA), codified at 18 U.S.C. § 1836 et seq., creating a federal civil cause of action for trade secret misappropriation. This was a significant development because it gave trade secret owners access to federal courts without needing to establish diversity jurisdiction, and it introduced the extraordinary remedy of ex parte civil seizure — a court order allowing law enforcement to seize misappropriated property before a hearing, available in extraordinary circumstances where other equitable relief would be inadequate.
Under 18 U.S.C. § 1839(3), the DTSA defines a trade secret broadly as “all forms and types of financial, business, scientific, technical, economic, or engineering information, including patterns, plans, compilations, program devices, formulas, designs, prototypes, methods, techniques, processes, procedures, programs, or codes, whether tangible or intangible, and whether or how stored, compiled, or memorialized physically, electronically, graphically, photographically, or in writing” — provided the owner has taken reasonable measures to keep the information secret and the information derives independent economic value from not being generally known.
That definition is broad enough to reach every meaningful component of an AI system.
The Three Elements You Must Establish
Whether you bring a claim under the DTSA or a state’s version of the UTSA, three elements must be satisfied:
-
The information qualifies as a trade secret. It must not be generally known or readily ascertainable by proper means, and it must have independent economic value by virtue of its secrecy.
-
You took reasonable measures to maintain secrecy. You must show a consistent pattern of conduct demonstrating that you treated the information as confidential.
-
Misappropriation occurred. A defendant acquired, used, or disclosed your trade secret through “improper means” — defined in the DTSA to include theft, bribery, misrepresentation, breach or inducement of a breach of a duty to maintain secrecy, and electronic espionage. Importantly, independent development and reverse engineering are explicitly excluded from the definition of improper means.
Which AI Assets Can Qualify as Trade Secrets
The broad statutory definition reaches every layer of a modern AI system. Here is how the major categories map to the legal requirements.
Training Datasets
Curated training datasets can absolutely qualify as trade secrets. Assembling a high-quality dataset involves significant labor, judgment, and cost — decisions about what data to include, how to clean and label it, how to weight different sources. The competitive value of a proprietary dataset flows directly from its secrecy: if a competitor had access to the same data, they could train a functionally equivalent model at a fraction of the cost. Courts have recognized that compilations of data qualify as trade secrets when they are not readily ascertainable and derive value from their secrecy. The key is that your dataset must represent genuine effort and curation, not merely a download of publicly available information.
The Compulife Software, Inc. v. Newman litigation, which concluded in the Eleventh Circuit in August 2024, illustrates this vividly. Compulife maintained a proprietary database of insurance rates that powered its quote-generation software. Defendants used automated bots to submit millions of queries and reconstruct the database — pulling over 43 million quotes in just four days, a task that would take thousands of human-hours to replicate manually. The Eleventh Circuit affirmed that automated scraping of this kind constituted “improper means” for purposes of trade secret misappropriation, even though each individual quote was technically accessible to the public. The method of extraction, not just the destination of the data, determined the outcome.
Model Weights and Parameters
Trained model weights — the billions of numerical parameters that encode everything a model has learned — are among the most valuable trade secrets a modern AI company can hold. They are the direct product of enormous computational investment, proprietary training data, and iterative experimentation. Unlike a patent application describing an algorithm in general terms, model weights are specific, unreproducible without your exact training process, and immediately useful to a competitor. They fit comfortably within the DTSA’s definition of “technical, economic, or engineering information” stored electronically.
A federal jury verdict in January 2026, affirmed by the Department of Justice, underscores the stakes. Linwei Ding, a former Google software engineer, was convicted on seven counts of economic espionage and seven counts of theft of trade secrets for taking over 2,000 documents related to Google’s AI infrastructure. The stolen materials included detailed information about Google’s custom Tensor Processing Unit chips, the cluster management software that coordinates thousands of chips into a supercomputer, and the AI models and applications running on that infrastructure. Ding had transferred the materials to his personal account while secretly founding an AI startup in China. He faces up to 15 years per economic espionage count.
The defense argument in that case is instructive: Ding’s attorney argued that Google did not adequately protect the information, and that because thousands of Google employees had access to the documents, they could not be trade secrets. The jury rejected that argument — access by a large internal team does not destroy trade secret protection, as long as the information is not publicly available and the company takes reasonable steps to limit access to those with a legitimate need.
System Prompts and Prompt Engineering
System prompts — the instructions that configure a large language model’s behavior for a particular use case — can qualify as trade secrets when they represent genuine innovation and are kept confidential. An effective system prompt may take months of engineering to develop, encoding expertise about how to reliably elicit certain outputs, how to prevent harmful responses, and how to maintain consistent tone and accuracy for a particular domain. That represents “methods, techniques, processes, procedures” within the DTSA’s definition.
The OpenEvidence, Inc. v. Pathway Medical, Inc. case, filed in the District of Massachusetts in 2025, made this concrete. OpenEvidence, a healthcare AI startup, alleged that a competitor used “prompt injection” attacks — crafting malicious queries disguised as legitimate medical questions — specifically to extract confidential model architecture information and portions of OpenEvidence’s system prompt. The case settled before a ruling on the merits, but it established that prompt injection attacks aimed at extracting system prompt content are recognized in litigation as a potential form of trade secret misappropriation. If your system prompt contains genuine, non-obvious know-how, keep it confidential and treat any attempt to extract it as a potential legal violation.
Model Architectures and Fine-Tuning Methods
The specific design choices that go into a model architecture — how layers are structured, how attention mechanisms are configured, what modifications were made to a base model during fine-tuning — can represent valuable proprietary information when they are not published and give you a performance advantage. Similarly, your fine-tuning methodology: the specific data mix, the training sequence, the hyperparameter choices, the evaluation criteria used to select checkpoints — these procedural elements qualify as trade secrets to the extent they are genuinely secret and valuable.
What Else Qualifies
Beyond the core technical assets, courts and practitioners have recognized that trade secret protection can reach: evaluation datasets and benchmark methodologies used to assess model performance; novel applications of known methods to specific domains; knowledge about what approaches do not work (negative know-how); internal roadmaps and research directions; and the specific combination of off-the-shelf tools, fine-tuned models, and integration approaches that make a deployment system work well.
Why Trade Secrets Beat Patents for AI Assets
The comparison between trade secrets and patents comes down to disclosure, duration, and eligibility.
No disclosure required. A patent requires you to publicly describe your invention in sufficient detail that someone skilled in the field could reproduce it. Once granted, that description is published and permanent. Trade secret protection requires the opposite: maintain secrecy and you retain your advantage. For AI companies whose competitive moat is their model weights, training data, or system architecture, public disclosure of those assets would eliminate the moat entirely.
No expiration. Patents expire after 20 years from the filing date. The formula for Coca-Cola has been a trade secret for more than 130 years. If you can maintain secrecy, your protection is perpetual. Given how long it can take to develop a high-quality AI system — and how durable that advantage can be in the right market — a never-expiring protection may be worth more than a 20-year monopoly that requires disclosure.
No eligibility barrier. You do not need to satisfy the Alice/Mayo framework to protect your AI system as a trade secret. There is no § 101 rejection, no abstract idea problem, no need to argue that your neural network is an “improvement to computer functionality.” The information either qualifies under the statutory definition or it does not, and the definition is broad.
The tradeoff you accept. Trade secret protection does not stop independent development. If a competitor builds the same model through their own work, without ever touching your assets, you have no claim. Patents give you exclusivity against independent developers. For assets that are genuinely difficult to replicate — large models trained on proprietary data, complex system prompt architectures — independent development is unlikely enough that this limitation rarely matters in practice.
Why Trade Secrets Beat Copyright for AI Assets
Copyright protects expression, not function. Trade secrets protect function directly.
The human authorship problem is now definitively settled law: courts at every level have ruled that works created autonomously by AI systems without meaningful human creative contribution do not qualify for copyright protection. If your AI generated the content — even if you operated the AI — the question of whether a human made sufficiently original creative choices to support a copyright claim is fact-specific and legally uncertain.
More fundamentally, copyright does not protect how something works. It protects how something is expressed. Your model architecture is not a creative expression — it is a technical design. Your training procedure is not a literary work — it is a process. Your dataset is not a novel — it is a compilation of information. Copyright law can protect the software code you wrote to implement these things, and it can protect creative elements of training data like original text. But it cannot protect the functional core of what makes your AI system valuable. Trade secret law can.
The “Reasonable Measures” Requirement: What You Must Actually Do
This is where most businesses have a gap. Courts do not require perfect security, but they require consistent, genuine security — a pattern of conduct showing that you actually treated the information as confidential from the beginning.
Two recent decisions make the current standard concrete.
In Trinidad v. OpenAI, decided in 2025, a court dismissed DTSA trade secret claims because the plaintiff had developed her allegedly proprietary frameworks using ChatGPT — which required voluntarily disclosing the information to OpenAI without any confidentiality protection in place. The court applied the principle from Ruckelshaus v. Monsanto Co., 467 U.S. 986 (1984): when a party discloses trade secret information to others who are under no obligation to protect its confidentiality, the property right is extinguished. Using a consumer-tier public AI platform to develop confidential material is legally equivalent to posting it on the internet.
In United States v. Heppner, Judge Rakoff of the Southern District of New York ruled in early 2026 that documents created using a public AI platform were not protected by attorney-client privilege — in part because communications shared with a third-party AI platform are not confidential when the platform’s terms of service do not obligate it to protect confidentiality. The court noted that the relevant platform’s privacy policy expressly reserved the right to use inputs for training and to disclose data to third parties, including regulators.
The implication for your AI assets: if your employees are using consumer-tier AI tools to work with your proprietary data, training sets, or model configurations, you are at serious risk of losing trade secret protection for those assets.
Courts have found the following measures sufficient or helpful:
- Storing information on password-protected, access-controlled internal systems with access limited to employees who need it
- Confidentiality and nondisclosure agreements with employees, contractors, and vendors — executed before access is granted
- Exit interviews with departing employees that specifically address trade secret obligations
- Clear internal classification of what information is considered confidential
- Policies governing use of AI tools, especially consumer-tier platforms, for work involving sensitive information
- Enterprise-tier AI licensing with contractual prohibitions on using company inputs for model training
Courts have found measures insufficient or problematic when:
- Information was freely accessible to large numbers of employees without any need-to-know limitation
- The company had no written policies on what information was confidential
- Employees used personal consumer AI accounts for company work without any controls
- NDAs existed on paper but were never enforced or communicated
The standard requires that your behavior match your policies. An NDA in a drawer that no one enforced does not satisfy the requirement.
How AI Trade Secrets Are Stolen: The Misappropriation Landscape
Understanding how misappropriation happens in the AI context helps you build defenses against the most likely vectors.
The Departing Employee
This is the most common and most serious threat. In nearly every reported AI trade secret case, a departing employee — often heading to a competitor or founding a competing company — downloaded or transferred sensitive materials before resigning. In Legend Biotech USA Inc. v. Liu, a departing employee emailed trade secrets to a personal Gmail account. In DraftKings Inc. v. Hermalyn, a departing executive transferred proprietary documents to personal cloud storage. In the Linwei Ding case, the engineer copied thousands of Google documents to his personal account during the weeks before his resignation.
The pattern is consistent: the departure date approaches, the employee needs to establish credibility at the next company, and the simplest way to do that is to take the prior employer’s crown jewels. Your legal leverage in this situation depends entirely on what you have done before the employee leaves: whether you have a valid NDA and potentially an enforceable trade secret protection or non-competition clause, whether you can quickly detect the unauthorized transfer, and whether you can move fast enough to get emergency injunctive relief.
Automated Scraping
As Compulife v. Newman established, automated scraping of data that is technically public-facing can constitute trade secret misappropriation when the method of extraction is sufficiently aggressive and the result allows reconstruction of a proprietary asset. If your API, model endpoint, or data interface is public-facing but rate-limited, and a competitor uses bots to systematically query millions of times to reconstruct your training data or reverse-engineer your model’s behavior, that may be actionable even though each individual query was technically permitted.
Technical defenses matter here: rate limiting, anomaly detection on query patterns, and terms of service that prohibit systematic scraping all contribute both to your practical defense and to your legal position.
Prompt Injection and Extraction Attacks
The OpenEvidence case introduced a category of AI-specific misappropriation: attacks designed to extract proprietary system prompt content by submitting queries crafted to override safety instructions or reveal internal configurations. This is not a theoretical concern — it is an active area of adversarial research, and it has produced litigation. Courts are beginning to recognize that technical hardening against prompt injection — input filtering, rate limiting, output monitoring for responses that include system prompt text — may be relevant to the “reasonable measures” inquiry.
Third-Party AI Tool Exposure
The Trinidad and Heppner decisions together establish a new category of risk: inadvertent disclosure through use of public AI platforms. If your employees input proprietary training data, model configurations, or system prompt content into consumer-tier AI tools without enterprise confidentiality protections, that information may enter the AI provider’s training pipeline, be accessible to that provider’s personnel, or in some scenarios be surfaced in other users’ queries. Courts treat this as a failure of reasonable measures, not as excusable inadvertence.
Employee Departure Risk: Practical Steps Before Someone Leaves
Most AI trade secret litigation is triggered by an employee departure. Here is what a well-run company should have in place before that moment arrives.
Before hiring: Every employee with access to AI systems, training data, model weights, or confidential prompts should execute an NDA and, where appropriate, an invention assignment agreement as a condition of employment. These agreements should specifically identify the categories of information that are confidential — not just in general terms, but with enough specificity that a reasonable employee would know exactly what cannot be taken.
During employment: Access controls should reflect actual need. Not every engineer needs access to the complete training dataset or the production model weights. Access logs should be maintained, and anomalous access patterns — large bulk downloads, access outside normal working hours, transfers to personal accounts — should trigger review.
When departure is announced: The moment a departure is announced is the moment to act. Immediately review recent access logs for the departing employee. Revoke access on the same day notice is given, not when the final day arrives. Conduct a thorough exit interview focused on the trade secret obligations, get a written acknowledgment of those obligations, and conduct a forensic review of the employee’s company devices and accounts before they are wiped. If the employee is going to a direct competitor, consult counsel before the departure is complete.
When you discover a violation: Speed matters. The DTSA’s ex parte civil seizure remedy exists precisely for situations where delay would allow evidence to be destroyed or secrets to be further disseminated. Courts can order seizure of devices and accounts containing misappropriated trade secrets before the defendant has an opportunity to respond. Getting to court quickly, with solid evidence of what was taken and where it went, significantly improves the outcome.
Remedies Available Under the DTSA
When trade secret misappropriation is proven, the DTSA provides a powerful remedial toolkit.
Injunctive relief. Courts may grant injunctions to prevent actual or threatened misappropriation, including orders requiring affirmative steps to protect the trade secret. An injunction can prohibit a former employee from using misappropriated information in their new role and can require return or destruction of stolen materials.
Compensatory damages. The DTSA allows recovery of actual losses caused by the misappropriation plus any unjust enrichment not already accounted for in the actual loss calculation. Alternatively, a court may impose a reasonable royalty for the misappropriator’s unauthorized use.
Exemplary damages. If the misappropriation is willful and malicious — which characterizes most cases involving employees who deliberately transfer files on their way out the door — the court may award exemplary damages of up to twice the compensatory award.
Attorney’s fees. If the claim was made in bad faith or the misappropriation was willful and malicious, the court may award reasonable attorney’s fees to the prevailing party.
Criminal prosecution. Egregious cases can result in federal criminal charges under 18 U.S.C. § 1832 (theft of trade secrets) and § 1831 (economic espionage). The Linwei Ding prosecution illustrates that the government is willing to bring these cases for AI assets and that juries are willing to convict.
Practical Trade Secret Program Checklist for AI Companies
Use this as a starting point for building or auditing your trade secret program. This is not a substitute for legal counsel, but it addresses the specific risks the AI context creates.
Asset identification
– Inventory every AI asset that gives you a competitive advantage: datasets, model weights, system prompts, fine-tuning methodologies, evaluation datasets, integration architectures
– Classify each asset by sensitivity level and document what makes it valuable and non-public
– Review the asset inventory at least annually or when significant new AI capabilities are developed
Access controls
– Apply need-to-know access controls to model weights, training data, and system prompts
– Use role-based permissions and audit logs for all access to high-sensitivity AI assets
– Prohibit bulk downloads or transfers to personal accounts without approval
Agreements
– Ensure all employees, contractors, and vendors with access to AI assets have executed current NDAs with specific language covering AI systems, training data, and model configurations
– Include trade secret protection obligations in offer letters as a condition of employment, not as an afterthought
– Require return or destruction of confidential materials upon departure
AI tool governance
– Adopt a written policy specifying which categories of information may not be entered into consumer-tier AI platforms
– Direct employees to use enterprise-licensed AI tools with contractual confidentiality protections for any work involving proprietary information
– Prohibit use of personal AI accounts for company work
– Train employees on these policies at onboarding and annually thereafter
Technical safeguards
– Rate-limit and monitor API endpoints and model interfaces that are accessible externally
– Implement input/output filtering for deployed models to detect and prevent prompt extraction attacks
– Maintain logs of model access, query patterns, and anomalous usage
Employee transitions
– Conduct exit interviews for all employees with access to AI assets that specifically address trade secret obligations
– Revoke access immediately upon notice of departure
– Review access logs and company device contents before departure is complete
– Where legally appropriate, remind departing employees and their new employers of trade secret obligations in writing
Litigation readiness
– Maintain documentation sufficient to identify, at a moment’s notice, exactly what your trade secrets are and what makes them valuable — courts will ask, and the answer needs to be specific
– Consult counsel at the first sign of potential misappropriation; the DTSA’s emergency remedies require speed
Conclusion
The legal framework for protecting AI assets is better than most business owners realize — if you know where to look. Patents and copyright, the instinctive choices, have structural limitations that make them poorly suited to the functional, fast-moving, often machine-generated assets that define modern AI systems. Trade secret law fits those assets naturally. It reaches training data, model weights, system prompts, architectures, and methodologies. It requires no disclosure, carries no expiration date, and gives you powerful remedies when someone steals what you have built.
The cases coming out of federal courts over the past two years — the Google engineer conviction, the prompt injection litigation, the scraping cases, the rulings on AI platform disclosure — are establishing a new body of law specific to AI assets. The courts are applying existing trade secret doctrine, not inventing new rules. That is good news for you, because the doctrine works well here. But the doctrine requires that you actually do the work: identify your assets, control access, document your measures, and act quickly when something goes wrong.
The businesses that will be best positioned to enforce their trade secret rights are not the ones with the largest legal budgets. They are the ones that built their protection program before they needed it.
This post is for general informational purposes only and does not constitute legal advice. The law governing trade secrets varies by state and by the specific facts of each situation. Contact a licensed attorney to obtain advice specific to your circumstances.
