China’s AI Trade-Secret Case Draws a Line Beyond Source Code

China’s competition regulator has offered a consequential test of what can count as proprietary technology in an AI business. In a typical case released by the State Administration for Market Regulation, or SAMR, the authority concluded that a set of prompt templates, review rules, and annotation specifications connected to a vertical-domain AI review model could qualify as protected trade-secret material. The official SAMR notice is important because it shifts the discussion beyond source code and toward the practical instructions, workflows, and operational data that make a model useful in a specific setting.

The case does not create a blanket property right over every prompt or AI instruction. Trade-secret protection depends on particular legal conditions, including non-public status, commercial value, and reasonable confidentiality measures. But the decision gives Chinese AI companies a clearer reason to treat their non-code materials as assets that need governance, access controls, and documentation.

The Hangzhou Case Focused on an AI Review Model

SAMR published six typical trade-secret-infringement cases on Aug. 20. The third involved a former senior algorithm expert at an unidentified Hangzhou AI company. According to the regulator, the employee had led development of a vertical-domain AI review model and had access to confidential materials. While still employed, the person allegedly used a spouse’s identity to register and control another company, then sent model-related materials to its research staff.

The materials included prompt templates, review rules, and annotation specifications. SAMR says they were used to develop a model with functions similar to the original company’s product. After expert review, authorities determined that the combination formed an integrated technical solution with the required characteristics of a trade secret: it was not publicly known, had commercial value, and was protected through confidentiality measures.

The Hangzhou market-regulation bureau ordered the individual, identified by surname as Sun, to stop disclosing and using the materials without authorization. It imposed a 350,000-yuan fine in May. SAMR says the matter involving the other company is being handled separately. The facts are specific to this administrative case, and the outcome should not be treated as a judgment on all employment disputes involving AI staff.

Prompts and Rules Can Carry Competitive Value

The regulatory reasoning matters because commercial AI systems are assembled from more than a base model. A working product can include prompts that steer behavior, taxonomies that classify information, human-review processes, annotation guidelines, retrieval structures, tool permissions, evaluation routines, and domain knowledge built into workflows. The source code may be important, but it is not always the only part of the system that took time and money to create.

As the National Law Review noted, SAMR’s case describes natural-language integrated technical schemes and nonstandardized operating rules as potentially distinct from source code for trade-secret purposes. That is legal analysis of the regulator’s release, not a substitute for the legal requirements that apply in an individual dispute. Still, it captures the central commercial point: an AI company’s advantage can reside in how it turns a general model into a repeatable domain product.

That question is becoming more urgent as China’s AI market moves toward specialized deployment. The recent discussion of China’s AI data providers moving beyond annotation showed how companies are building services around evaluation, alignment, and higher-value model work. The relevant materials are often less visible than a public model release, yet they may determine whether an AI system is trustworthy enough for a bank, factory, hospital, or government customer. The same issue sits behind RedNote’s move to build in-house models: competitive advantage increasingly comes from the surrounding system, not only the base model.

Compliance Must Follow the Knowledge, Not Just the Code Repository

For employers, the practical implication is not to claim ownership over every employee idea. It is to identify which AI materials are genuinely confidential, mark them clearly, restrict access, track transfers, and establish proportionate agreements with people who work on sensitive systems. A prompt library placed in an open internal chat channel is harder to defend than a carefully governed set of materials accessible only to a defined team.

For employees, the case is a warning that knowledge gained in a role is not all treated alike. General skills and experience are different from documents, templates, and business-specific rules removed from a company’s protected environment. The distinction will matter as AI talent moves between startups, established platforms, research groups, and customer-facing integrators.

For the wider industry, the decision may encourage more formal treatment of AI operating assets. Companies could classify prompt packages, annotation specifications, and evaluation protocols alongside code and customer data. They may also invest more in access logging, confidentiality training, exit procedures, and internal reviews before staff move to competitors or launch new ventures.

China’s AI economy is often described through model parameters, chips, and funding rounds. This case points to another layer of competition: the small, cumulative operational choices that turn a general system into a specialized product. By recognizing that some of those materials can be trade-secret capable, SAMR is putting the legal system closer to how AI businesses actually create value.