Guide
Prompts and System Prompts as Trade Secrets
When prompt libraries, system prompts and AI workflows can be protected, and what defeats protection.
Law checked through
Short Answer
Prompt libraries, system instructions and AI workflows can qualify as trade secrets when they meet the same value, ascertainability and reasonable-measures tests as other information. A public or routine prompt may not meet them. Protectable detail needs specific identification: a workflow, combination, instruction sequence or controlled library, with evidence of its value and secrecy. Extraction risk is a practical reason to keep especially sensitive logic outside a public-facing prompt. A claim that extraction is legally improper still needs facts and the applicable statutory or contractual basis.
Which Laws Apply
Texas AI-specific: none.
Generally applicable Texas law: TUTSA, Civil Practice and Remedies Code § 134A.002 (definitions of trade secret, improper means and proper means); contract law (terms of use barring extraction).
Federal: DTSA, 18 U.S.C. § 1839; Computer Fraud and Abuse Act questions.
What Makes a Prompt Protectable
Value from secrecy: the prompt or library produces results competitors cannot match without similar effort. Not readily ascertainable: a competitor could not recreate it from public information or simple experimentation. Reasonable measures: access limits, confidentiality agreements, technical protections against extraction, and terms of service barring attempts to reveal system instructions.
Extraction and Improper Means
Civil Practice and Remedies Code § 134A.002 distinguishes improper means from proper means, including independent development and reverse engineering unless prohibited. A prompt-extraction dispute can involve access restrictions, deception, confidentiality or use terms; a terms breach does not automatically prove every trade-secret element. Keep particularly sensitive logic outside public-facing prompts where possible, monitor extraction attempts and document actual access restrictions. The factual question is what was obtained, by which means and under which permissions.
Identification
A plaintiff must identify its trade secrets with particularity. “Our prompts” will not do; a specific library, version and the elements that give it value will. Keep versioned records of prompt libraries and who had access.
Illustrative Example (Hypothetical)
A Texas legal technology company builds a library of tested prompts for contract review that took two years to refine. It restricts the library to engineers under NDA, does not expose prompts to users, blocks extraction attempts and logs access. A competitor that hires a departing engineer and launches a similar product quickly faces a stronger claim than one that obtained the prompts by questioning a public demo.
What Is Unsettled
Whether prompt injection is improper means; how much effort to reconstruct a prompt makes it not readily ascertainable.
Sources
- Texas Uniform Trade Secrets Act
- Federal Trade Secret Definitions
- DeWolff, Boberg & Associates v. Pethick
