Read

April 21, 2026

5 minute read

When advising clients on how best to protect software and AI technologies, the discussion almost always turns to whether patent protection or trade secret protection is the better path. In those conversations, patent protection is frequently met with skepticism. Clients raise familiar objections: patents are expensive to obtain and maintain; enforcing them can be difficult because infringement may be hard to detect; and, perhaps most importantly, patents require the inventor to disclose how the technology works—effectively giving competitors a roadmap they can study and attempt to design around. With software and AI innovations, these concerns are often compounded by worries about patent-eligible subject matter, particularly the risk that inventions will be characterized as abstract ideas.

Given those perceived drawbacks, many clients gravitate toward trade secret protection, sometimes reflexively and sometimes without seriously considering alternatives. Trade secrets are attractive because they avoid disclosure, can theoretically last forever, and do not require navigating § 101 eligibility issues. But an important and often underappreciated point gets lost in that reasoning: a trade secret only works if the technology can actually be kept secret.

The recent, high‑profile leak of Anthropic’s Claude Code provides a stark and timely reminder of how fragile trade secret protection can be—even for sophisticated, well‑resourced companies whose business is AI.

The Anthropic Leak: A Trade Secret Failure in Real Time

In late March 2026, Anthropic accidentally exposed roughly 500,000 lines of source code underlying Claude Code, its flagship AI coding agent. The company described the incident as a “human error,” not a cyberattack or security breach, but the distinction offers little comfort from an IP-protection perspective. The leaked material did not include user data or the model weights at the mathematical core of Claude. Instead, it revealed something arguably more commercially sensitive: the internal “harness” code—the techniques, tools, and instructions that orchestrate how Anthropic’s AI models behave as agents, manage context windows, interact with tools, and maintain performance and safety.

As reported in The Wall Street Journal, the leak handed competitors a “detailed roadmap” for replicating Claude Code’s features without needing to reverse engineer them. Developers quickly mirrored, forked, and adapted the code on GitHub, prompting Anthropic to issue thousands of DMCA takedown requests in an effort to contain the spread. Although Anthropic later narrowed the scope of its takedowns, the practical reality was unmistakable: once a secret is out, it is out.

This is precisely the nightmare scenario for trade secret protection. No matter how robust a company’s internal policies or access controls may be, trade secrets remain vulnerable to human error, misconfigurations, insider leaks, or ordinary operational mistakes. The Anthropic incident underscores that even companies with strong security cultures and elite engineering talent are not immune.

Trade Secrets Depend on Trust—and Trust Is a Weak Link

An instinctive concern, echoed by an acquaintance of mine who said, “I can’t trust my engineers and developers to keep their mouths closed,” is not cynical; it is realistic. Trade secret law presupposes reasonable efforts to maintain secrecy, but it cannot eliminate the human factor. Engineers change jobs, talk at conferences, publish blog posts, reuse mental models, or—sometimes—make mistakes. In modern AI development, where code is often generated, refactored, or shipped at extraordinary speed, the risk surface grows even larger.

The Anthropic leak adds an additional layer to this problem. It highlights the rise of what some observers are calling “dark code”—software written or heavily assisted by AI agents so rapidly that even its creators may not fully understand or document how it works. In that environment, traditional safeguards erode. Nontechnical employees can generate complex functionality, security reviews may lag behind deployment, and reasoning steps taken by AI coding agents may effectively vanish. From an IP perspective, this makes secrecy even harder to maintain and provenance harder to prove.

Reverse Engineering Is Not the Villain—and It’s Getting Easier

Even absent a leak, trade secrets face another structural weakness: legally permissible reverse engineering. If a competitor can lawfully obtain a product and deduce how it works, trade secret law generally offers no remedy. This has always been true, but AI significantly accelerates the process. Today, competitors can use AI tools to analyze behavior, outputs, performance characteristics, and interfaces to infer underlying algorithms or system architectures. The Anthropic leak simply skipped that step and handed observers the answers directly.

Once information enabling independent re‑implementation enters the public domain—through a leak, a talk, a public repository, or even a detailed technical article—trade secret protection collapses. At that point, the only remaining IP tools are those that do not depend on secrecy.

Copyright: Helpful, But Fundamentally Limited

In response to the leak, Anthropic turned to copyright law, issuing DMCA takedown notices to GitHub. That tactic may have slowed dissemination at the margins, but it also exposed the inherent limits of copyright protection for software and AI.

Copyright protects code as written—not the underlying ideas, functions, methods, or systems. If a third party studies leaked code, understands how it works, and then rewrites similar functionality in a different expression, copyright protection may offer little to no barrier. In fact, the irony was not lost on commentators that Anthropic—long involved in litigation arguing for expansive fair‑use doctrines in AI training—suddenly found itself clinging to copyright as a defensive shield.

This is a critical lesson for clients: copyright does not stop independent development. It does not prevent competitors from building functionally equivalent systems so long as they avoid copying protected expression. In fast‑moving markets, that is a thin line of defense.

Why Patents Deserve a Second Look

Patents are not perfect. They are relatively expensive, public, time‑limited, and sometimes difficult to enforce. Patent eligibility remains a real hurdle. But patents offer something trade secrets and copyright cannot: protection that does not evaporate when secrecy fails.

A patent can be enforced even if the invention becomes publicly known—even if it is independently developed—even if it is reverse engineered. Indeed, patents are specifically designed for a world where disclosure eventually occurs. In hindsight, a company like Anthropic would likely have preferred that at least some of the techniques embodied in its harness code were protected by issued patents. Once leaked, those patents could still act as enforcement tools or deterrents. The absence of such protection leaves the company relying on fragile copyright theories and public appeals to fairness.

The Strategic Takeaway

The real lesson is not that patents are always better than trade secrets or vice versa. Rather, it is that trade secret protection is only as strong as a company’s ability to maintain secrecy, and that ability is increasingly precarious in modern software and AI development environments.

For technologies that:

  • are core to competitive differentiation,
  • are difficult to compartmentalize,
  • will be deployed widely or at scale,
  • or are at high risk of leakage, observation, or inference,

patent protection—even with its costs and imperfections—may be the most reliable long-term option. In many cases, a layered strategy makes sense: patents for foundational concepts and architectures; trade secrets for tunable parameters, data, or operational know-how; and copyright for code expression.

The Anthropic incident powerfully illustrates the downside of assuming trade secrets will always suffice. When secrecy fails—and sometimes it will—only patents remain standing.

Related People

Related Capabilities