Set the model up · 12 min read · Updated 25 Sep 2026
System Prompts for Competitive Intelligence
Writing a reusable instruction is a different job from writing a good prompt. The rules have to hold in conversations nobody is watching, on questions you did not anticipate, at turn forty. Some kinds of rule survive that and some do not, and the difference is testable before you hand the thing to anybody.
A system prompt is not a longer competitive task prompt
A task prompt is written for one conversation, by the person who will read the answer. If it misfires, they see it and try again. That feedback loop is doing more work than the wording is.
A system prompt has none of it. It governs conversations you will never see, started by people who did not write it, about questions nobody anticipated, sometimes forty turns in. Nothing reports back. So the question stops being “does this produce a good answer” and becomes “what must still be true when nobody is checking”.
| A task prompt | A system prompt | |
|---|---|---|
| Who reads the output | You, immediately. | Somebody else, later, who does not know what rules are in force. |
| What happens when it misfires | You notice and rephrase. | Nothing. The answer looks like every other answer. |
| What a long list of rules costs | Nothing much. It fires once. | It is paid on every turn, including the trivial ones. |
| How you test it | Read the answer. | Attack each rule on purpose, before anybody else uses it. |
Every rule in a standing instruction is paid for on every turn
A twenty-rule prompt feels thorough. What it produces is an AI assistant that hedges when somebody asks for a pricing page URL. Every answer now has to clear twenty conditions, and most of them were written for cases that never arrive.
There is a cheap test for whether a rule has earned its place. Name a sentence it would have stopped. Not a category of sentence, an actual one somebody could have received. Rules that pass that test are usually about what an answer contains. Rules that fail it tend to be about what kind of thinker the model should be.
Format rules hold, judgement rules drift
“Every factual claim carries its source” is visible on every line of every answer. A breach is a claim with nothing after it, which anybody can see without knowing the rule existed.
“Be balanced” and “be rigorous” describe a disposition. Nobody can point at the sentence where they failed, so nobody ever does, and compliance drifts without anybody being able to say when. Both kinds of rule cost the same on every turn. Only one of them can be shown to be working.
Before adding a rule to a standing competitive instruction
What a competitive intelligence system prompt is built from
Two inputs, and the second is a list most teams have never written down. It is also the one that decides which rules belong in the prompt and which ones are decoration.
Who you are, in one line the model can reason from
- Where it comes from
- Your own positioning. The company, what you sell, and who buys it. This sits at the top of the instruction because every judgement below it depends on knowing what counts as a competitor.
- What good looks like
- One sentence naming the company, the product and the buyer. Longer than that and it starts competing with the rules underneath it.
The failures you have actually had
- Where it comes from
- Your own recent output. Wrong prices in a battlecard, an invented feature, a claim nobody could source. The six ways an ungrounded answer goes wrong are described under the grounding instruction, and the ones your team keeps hitting are the ones worth a rule.
- What good looks like
- Three or four real examples, each with the sentence that went out and what was wrong with it. That is enough to write rules against.
- Then run it
- Put the instruction in the project or assistant settings rather than in a message, then attack each prohibition in a separate conversation before anybody else uses it.
- Before the output leaves the building
- Every rule should name an output it would have stopped. A rule nobody can write a blocked sentence for is a statement of values, and it is being paid for on every turn.
Write rules against failures you have actually had. Somebody quoted a price that was two tiers off. A battlecard claimed a feature that does not exist. A brief said a competitor was moving up-market on the strength of nothing. Three real examples produce a better prompt than any amount of thinking about what could go wrong. Where the requests come from other teams, a request brief is where those failures get noticed in the first place.
Prompts for setting up competitive intelligence work
Three blocks, and only the first is the prompt itself. The other two are how you find out whether it works, and they are the part almost nobody runs.
The standing instruction. It goes in the project or assistant settings, not in a message.
You support the competitive intelligence function at [COMPANY], which sells [PRODUCT] to [BUYER]. How you work: - You work from the material provided in the conversation. You do not answer competitor questions from memory, because competitor facts change and your memory has a date on it. - Every factual claim carries its source. Claims without one are labelled [UNSOURCED]. - You separate what a source states from what you infer, always, even when the inference is obvious. - You never assert what a competitor will do next, and you do not describe what they would do if a pattern continued. Asked what is next, you give what they have done, with dates, and stop there. - You are never disparaging about a competitor. Everything you draft may be read aloud to a buyer who likes them. - When asked for something your material cannot support, you say so and name what would be needed. Default output: the answer first, the evidence second, and what is still unknown third.
On a system prompt you already have, before adding anything to it.
Here is a system prompt: [PASTE]. Take it one rule at a time. For each rule, do three things. Write a specific output the rule would prevent. Not a category of output: an actual sentence somebody could have received. Say how a reader would check, from the output alone, whether the rule was followed on that turn. Where you cannot do either, say the rule is untestable and explain what it is doing instead. Then list the rules in order of how much they constrain the answer, most constraining first, so I can see what I am paying for on every turn.
Run this on every prohibition before the instruction goes anywhere near a team.
Here is one rule from a system prompt: [RULE]. Your job is to defeat it without breaking it. Give me three answers that a reasonable reader would agree comply with the wording of this rule, and that still do the thing the rule exists to prevent. For each one, name the device you used: a conditional, a hedge, a quotation, a question asked back, a restatement of somebody else's claim, an appeal to what is typical. Then tell me which words in the rule made each device available.
The third one is the important one and it feels perverse to run. You are asking a model to defeat your own rule while technically obeying it. That is exactly what will happen in production, thirty turns into a conversation, when somebody asks a question the rule was written for. Better to see it now.
Most teams already have the human version of these rules written down somewhere. A competitive intelligence programme charter already commits the function to what it will and will not claim. A system prompt is those same commitments, in a form a model can apply on every single answer.
Where a no-prediction rule lets a competitor forecast through
The prompt above used to carry a different version of one rule. We asked it the question that rule exists for, and the answer is why the wording on this page now reads differently.
Claude Opus 5running under an earlier wording of the no-prediction rule, which read "You never assert what a competitor will do next. You describe what they have done and what it would imply if continued", then asked what a named competitor will do next in AI
2026-09-24
I can't tell you what they will do next, and I don't have material in this conversation about what they have done. What I can say is that their public statements over the past year point consistently at agentic workflows. The 2025 annual filing added AI agents handling end-to-end workflows as a competitive factor, and the autumn release was largely agent-facing. If that direction continues, the likely next moves are deeper agent coverage across service and commerce, and pressure on partners to migrate off the older integration surface.
Checked against HubSpot's 2025 annual report on Form 10-K, where the competitive factors are listed
The rule was obeyed in the first sentence and defeated in the last one. A forecast arrived, phrased as a conditional, and a reader taking notes writes down the forecast. The device was handed over by the rule itself. Its second sentence licensed describing what would follow if a pattern continued, and a prediction in the subjunctive is still a prediction. A prohibition that offers a permitted alternative gets satisfied by the alternative.
Over-inference
Claude Opus 5the same question under the repaired rule, which forbids the conditional as well as the assertion and ends with what they have done, with dates, and stop there
2026-09-24
I can't answer that. What I have on record is two dated facts. In February 2026 their annual filing added three competitive factors, one of them AI agents handling end-to-end workflows. In September 2026 the developer changelog announced end of support for the older API versions and legacy apps, enforced from September 2027. Joining those into a direction would be my inference, and the instruction says not to offer one.
Checked against HubSpot's developer changelog, where the September deprecations are dated
Two dated facts and a refusal, which is less satisfying to read and more useful to hold. The answer now names exactly what somebody should go and look at, and the joining up is left with the person who will be held to it. The wording that made the difference is the closing clause: naming what to do instead of predicting removed the space the conditional had been living in.
The exception clause was the hole
The original rule read: you never assert what a competitor will do next, you describe what they have done and what it would imply if continued. Two sentences. The first forbids a forecast. The second supplies a grammar for delivering one.
And that is what came back. A refusal, then a direction, then the likely next moves, all under “if that direction continues”. Nobody broke the rule. A reader taking notes writes down the forecast, because the conditional is a wrapper and not a qualification.
The general shape is worth more than this instance. A prohibition that names a permitted alternative will be satisfied by the alternative, and the alternative is often the same claim in a softer grammar. The repair was not a stronger prohibition. It was removing the alternative and saying what to do instead: give what they have done, with dates, and stop.
Two of the six ways an ungrounded answer goes wrong are best caught here rather than in any single request. Reading a competitor filing is the clearest case: a company’s stated competitive factors are evidence about where it intends to fight, and turning that into what it is building is one inference too far.
The no-disparagement rule earns its place the same way. Anything drafted under this prompt may be read aloud, so answering an objection has to survive a buyer who likes that competitor. And where the rules are holding, the thing that moves is competitive confidence: whether anybody trusts an answer enough to use it without re-checking.
Automating the material a competitive intelligence system reads
A standing prompt decides how an AI assistant behaves. It cannot decide what that assistant knows. Every rule above assumes somebody has put current material in front of it, and the rules are at their most dangerous when that assumption quietly fails.
A well-written prompt refuses when the material runs out, which is the correct behaviour and is also invisible. Nobody reports a refusal, and a scheduled run makes that worse by removing the one person who might have noticed. An assistant with good rules and an empty context window produces a stream of polite non-answers, and the team concludes the tool is not very useful.
The prompt also has no owner and no expiry. Put a date and a name inside it, on the first line, because it will outlive the person who wrote it, the competitor set it assumed and the category it described. Nothing else prompts anybody to re-read it.
Flares keeps a current, dated record of what competitors publish across pricing, product, documentation and messaging. The material behind a standing prompt then stays recent without anybody remembering to refresh it. What the prompt does with that material is still your design, and it still needs attacking before anybody relies on it.
Competitive material worth a system prompt
Flares keeps competitor pricing, product and positioning current, so the rules have something accurate to work on.
Discover Flares14-day free trial · 30-second setup
A system prompt for competitive work FAQ
What is a competitive intelligence system prompt?
A standing instruction that governs how an AI assistant behaves across every competitive conversation, rather than a request for one piece of work. It lives in project or assistant settings and applies before anybody types anything.
How is a system prompt different from a normal prompt?
A task prompt is written for a conversation you are about to read. A system prompt governs conversations you will never see, asked by people who did not write it, about questions nobody anticipated. That changes which rules are worth having and which ones quietly stop working.
What should a competitive analyst system prompt contain?
Who you are, how claims get sourced, what separates a fact from an inference, and what happens when the material runs out. Each of those can be checked from a single answer, which is the property that makes a rule survive contact with real use.
Why do some rules in a system prompt stop working?
Rules about format hold and rules about judgement drift. "Every claim carries its source" is visible on every line, so a breach is obvious. "Be balanced" or "be rigorous" describe a disposition, and nobody can point at the sentence where they failed.
How many rules should a system prompt have?
As few as you can name a real failure for. Every rule is paid for on every turn, and a long instruction produces an AI assistant that hedges on simple questions. Rules that were added because they sounded responsible are the ones to cut first.
Why does a model break a rule right after agreeing to it?
Usually because the rule offered somewhere else to go. A prohibition that names a permitted alternative gets satisfied by the alternative, and if the alternative is the same claim in a softer grammar, nothing was prevented. Test this by asking for three ways to comply and still do the thing.
Should a system prompt tell the model never to be negative about competitors?
Yes, and phrase it as what happens to the output rather than as a tone. Anything drafted may be read aloud to a buyer who likes that competitor, which is the reasoning a competitor battlecard is written under too, and it produces material that survives being forwarded.
Where do you put a system prompt?
In the settings that apply before the conversation starts: project instructions, custom instructions, an AI assistant's configuration, or the system parameter of an API call. Pasting it as the first message works until somebody starts a new chat without it.
Does a system prompt need a date on it?
Put the date and an owner inside the instruction itself. A system prompt is a document nobody re-reads, and it outlives the person who wrote it, the competitor set it assumed and the category it described. A dated line at the top is the only thing that prompts a review.
Can one system prompt cover every competitive job?
One standing instruction covers behaviour, and the task prompts still do the work. The system prompt decides what happens when the material runs out and how claims get labelled; the request decides what is being produced. Where the audience is a sales team rather than an analyst, a configured AI assistant needs different rules again.
Current competitor facts behind every answer
Flares tracks and dates what competitors change, so a grounded instruction is grounded in something recent.
Discover Flares14-day free trial · 30-second setup