AI Tool Compliance Checklist for Patent Practitioners
Regular AI use among patent professionals sits at roughly 15% (IPKat/HGF), while general legal AI adoption has reached 79% (Clio 2025). Survey definitions of "adoption" vary, so treat the exact figures as directional. The direction is the point: the gap is not technophobia. Patent work involves the most sensitive pre-filing information a law practice handles, namely unpublished disclosures whose value depends on confidentiality, whose export is separately regulated, and whose inadvertent release cannot be undone.
This page provides a structured evaluation procedure for patent attorneys and in-house counsel who need to assess an AI tool before using it on client material. It is organized as a checklist you can work through tool by tool, with a decision framework at the end.
This page is informational only and not legal advice. Every practitioner makes their own determination about what their duties require.
Before You Evaluate: What Makes Patent Work Different
Most AI compliance guidance was written for lawyers generally. Patent practice has three characteristics that make the analysis sharper.
Unpublished disclosures are trade secrets
Before filing, an invention disclosure is protected by confidentiality duties, trade-secret law, and contractual controls. The asset being protected is the non-publicness of the disclosure itself. Sending it to a third-party system is a disclosure event that must be evaluated deliberately, not incidentally.
Export control reaches technical data
Filing in the United States is treated as including a petition for a foreign filing license under 35 U.S.C. 184. Sending an unpublished disclosure to infrastructure abroad is a data movement that practitioners should reason about before any US filing exists. Export rules treat release of controlled technology to a foreign person inside the country as an export, so what matters is who can reach the material, not only where the hardware sits.
Attorney-client privilege implications
When a practitioner sends client material to a third-party AI tool, the question of whether privilege is maintained depends on the specific terms, security posture, and data handling of that tool. Under the reasoning in Heppner v. Agilent Technologies, voluntary disclosure to a third party can waive privilege unless adequate confidentiality protections are in place. The analysis is fact-specific.
The Evaluation Checklist
Work through each section for every tool you are considering. A tool that passes Section A may still fail Section B.
Data Handling
Identify the geographic jurisdiction of the servers handling your inputs. This affects both export control analysis and data protection law applicability.
Some providers retain inputs for abuse monitoring (30 days is common), others indefinitely. Retention terms may differ between consumer, API, and enterprise tiers of the same product.
A terms-of-service opt-out is different from a contractual no-training clause. Check whether the opt-out is a toggle in settings, a contractual commitment, or a statement in a privacy policy that can change with notice.
Enterprise tiers often provide DPAs. Consumer and API tiers usually do not. A DPA creates contractual obligations around data handling that a privacy policy does not.
Confirm deletion timelines and procedures. Some providers retain data in backups for extended periods after account closure.
Legal Framework Compliance
Practitioners must make reasonable efforts to prevent inadvertent or unauthorized disclosure of information relating to the representation of a client. The USPTO AI guidance flags two specific hazards: material retained for training, and tools operated outside the United States.
Opinion 512 calls for evaluation of: the client, the matter, the task, the sensitivity of the information, the safeguards, and the particular tool. Depending on how a system uses or exposes matter information, informed client consent may be required.
These are two different regimes and conflating them produces the wrong answer. A foreign filing license under 35 USC 184 governs filing patent applications abroad. Routing data to a server in another country is not itself a foreign filing. Ask the filing question on its own terms: was the invention made in the US, is a foreign or international application being prepared, and has a license issued on the filing receipt?
Export rules reach technical data, and a release of controlled technology to a foreign person counts as an export even when it happens inside the United States. So the question is who can reach the material: provider personnel, subprocessors, support and abuse-review teams, and any distributed infrastructure. Note that a USPTO foreign filing license does not authorize exporting subject matter abroad to prepare a US application. Data residency is a useful input here, but it is not a substitute for the analysis.
Voluntary disclosure to a third party can waive privilege unless adequate confidentiality protections are in place. Enterprise agreements with confidentiality terms reduce this risk. Consumer-tier tools with broad license grants may increase it.
Security and Access
Check for encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent). Verify authentication supports MFA or SSO integration.
The provider's employees with access to your data are, for privilege analysis, third parties. Determine the scope of human review, whether it is opt-in or opt-out, and which subprocessors handle data.
For matters subject to litigation holds or regulatory scrutiny, you may need to demonstrate who accessed what and when. Check whether the provider offers access logs and how long they are retained.
Review the provider's incident response commitments: notification timeline, scope of disclosure, and remediation procedures. Compare against your jurisdiction's breach notification requirements.
The Local Alternative
Local inference removes the cloud provider from the data path entirely. Open-weight models now handle many patent-adjacent tasks (claim drafting, prior art summarization, disclosure review) at usable quality levels on workstation hardware.
Local models are smaller and slower. On a 64 GB machine, the best local model scores roughly 12 points behind the best cloud model on patent drafting benchmarks. On 32 GB hardware, the gap is wider. The tradeoff is real and quantifiable.
Published patents and applications carry lower confidentiality risk when processed through cloud tools. Unpublished disclosures, draft claims, and prosecution strategy carry the highest risk. Note that publication status of the attached document is not the whole test: a prompt built around a public patent can still carry claim strategy, planned amendments, or your own impressions. The same practitioner may reasonably use different tools for different material on the same day.
Accuracy and Human Review
Opinion 512 addresses competence, not just confidentiality. A tool that produces fluent, well-formatted output raises the cost of review rather than lowering it, because errors no longer look like errors. Name the reviewer before the workflow starts.
This one is not hypothetical. In our own drafting benchmark, every local model tested produced quotations that were real and verbatim but taken from the claims being evaluated rather than from the specification, in one run 81 times out of 81. The claims were being offered as evidence for themselves. "The quote is real" is not verification. Confirm the document, the location, and the evidentiary role. See the benchmark.
USPTO submissions carry a personal certification. AI assistance does not change who is responsible for the accuracy of the assertions, the existence of the citations, or the consistency of positions taken. There is no general duty to disclose that an AI tool was used, but the duty of candor creates a narrow exception where the use itself is material.
Decision Framework
A simplified decision tree for choosing between cloud and local processing on a given piece of work.
Published patents and applications are public record. Confidentiality risk from processing is lower, though prompt content (strategy, analysis, attorney impressions) may still warrant care.
Work through Sections A through C above. Enterprise terms reduce but do not eliminate risk. Consider data residency, subprocessor access, and the specific sensitivity of this matter.
Without contractual protections against training on inputs, sending unpublished client material to a consumer-tier cloud tool creates risk that is difficult to justify under current guidance.
Frequently Asked Questions
Do I need to complete this checklist for every AI tool?
You need to evaluate each tool you use on client material. Tools used only on internal, non-client work (scheduling, general research on published material) carry lower risk. The checklist is designed for tools that will process confidential client information, particularly unpublished technical disclosures.
Does an enterprise agreement make cloud AI safe for patent work?
It reduces risk materially but does not eliminate analysis. Enterprise agreements typically include no-training clauses, data processing agreements, and contractual security commitments. These address some of the ABA Opinion 512 factors. They do not change the export control analysis or the fact-specific privilege assessment. "Enterprise" is a starting point, not a conclusion.
What if my client consents to cloud AI use?
Informed client consent can address some confidentiality concerns, but ABA Opinion 512 notes that generic engagement-letter language may not suffice. The consent should be specific to the tool, the type of information being processed, and the risks involved. Consent also does not resolve export control obligations, which are regulatory rather than contractual.
How often should I re-evaluate a tool I already approved?
Terms of service and privacy policies change. Re-evaluate when: the provider announces changes to data handling or training practices, you change tiers (API to consumer, or the reverse), a new version of the tool launches with different architecture, or regulatory guidance updates (new USPTO guidance, new state bar opinions).
Can I use this checklist for AI tools beyond patent work?
Sections A and C (data handling, security) apply broadly. Section B is specific to patent practice regulatory requirements. Section D (local alternatives) is relevant wherever confidentiality is a primary concern. General legal AI compliance may require additional considerations not covered here (court-specific rules, jurisdiction-specific bar opinions).
Related Resources
From ObviouslyNot
- Drafting with Local AI: What It Protects, and What It Costs
- Why Local-First Matters for Patent Discovery
- Patent Documents and the Cloud: What Developers Need to Know
- AI Agents and Intellectual Property: What Builders Need to Know