The reality is that patent attorneys and inventors are already using AI tools to draft invention disclosures and patent specifications and, by definition, this generally occurs before any patent application is filed. But most inventors, and even many members of the patent profession, do not fully understand the risks involved. In the worst-case scenario, and depending on the jurisdiction as well as the AI product and plan used, drafting an invention disclosure or patent specification using AI may be fatal to the validity of the patent. To my knowledge there has so far been no substantive judicial consideration anywhere in the world of this specific issue, so it is difficult to predict where the law may land.
A recent UK tribunal decision, in which the related issue of waiver of legal professional privilege was discussed, does not inspire confidence that decision-makers have sufficient understanding of the technology, terminology, and relevant contractual arrangements to reach sensible conclusions. The tribunal wrongly classified AI tools as being either ‘open source’ – the use of which, it said, would lead to a public disclosure and waiver of privilege – or ‘closed source’ – use of which the tribunal considered would not result in a waiver of privilege. The terminology here is incorrect and, indeed, the entire distinction on which it rests is legally irrelevant. Yet several law firms have already repeated it, without question, in their own client guidance. The error matters beyond the immigration case the tribunal was deciding. If other courts and firms adopt it, practitioners will ask the wrong questions. A waiver of privilege is bad enough, but for patent attorneys the problem could be more serious. A fatal disclosure prior to a priority date is considerably worse than an awkward discovery dispute!
In this article I will cover what the tribunal said, and why its use of ‘open source’ is wrong. I'll also explain what the term actually means, and why I think that the error matters. What protects your input to an AI tool isn't the ‘open’ or ‘closed’ nature of the model, or the provider's brand name. It's the terms and conditions attached to the specific product and plan you're using, and I’ll discuss what to look for. I’ll also discuss why I think the risk is greater for patent attorneys than for the privilege question on which the tribunal was commenting. Under the patent law in many jurisdictions – including Australia – a disclosure can destroy novelty even when the information never reaches ‘the public’ in the ordinary sense. (It is worth noting, however, that the US test is different.) And I’ll review recent developments that will affect the ability to prove when AI has been used. AI providers have started adding invisible watermarks to their output. This means it will be possible to establish with confidence that a document was drafted with AI, where previous this may have been nothing more than an allegation.
None of this is entirely new. Chatbots and other AI tools are hardly the first internet-based services that have been used by legal professionals and their clients. Have you ever paused to wonder whether you have any reason to believe that your email communications are secure, or whether the provider of a webmail service or web-based document editing tool is under any legal obligation to keep your correspondence confidential? In many cases, especially if the service is free, they may not be, and yet this does not seem to have arisen as an issue in the past two decades. Whether the same will turn out to be true of AI services remains to be seen.
What the Tribunal Said, and Why it Matters
UK and R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC) is a recent Upper Tribunal decision. It dealt with two all-too-familiar cases of lawyers citing AI-hallucinated authorities (you would think that everybody would know better by now). Most of the decision is unremarkable. But paragraph [21], which is already being copied uncritically into law firm client alerts, contains a statement that should concern anyone drafting technical content with AI assistance:
We also observe that to put client letters and decision letters … into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege …. Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks.
The tribunal treats this as the confidentiality and privilege problem that it is. But the same words apply to patent work. ‘Place this information on the internet in the public domain’ is just as apposite to describe a novelty-destroying disclosure. The tribunal was willing to say this about a letter of advice. The same reasoning, right or wrong, applies just as easily to an unfiled invention disclosure drafted with the same tool.
This is a Bigger Risk for Patents than for Privilege
A privilege problem may be embarrassing or inconvenient, and it might weaken the position of a party to litigation. If privilege is held to be waived, a document becomes discoverable. That's bad, but it is unlikely to be fatal in and of itself. The same cannot be said for a patent novelty problem. If an invention is made public before the priority date – and in many jurisdictions it is sufficient that it be disclosed to just one person with no obligation of confidence – the patent claims are invalid (subject to any grace period that might be available).
To complicate matters, the rules vary between jurisdictions. In the United States the position is not so bad – prior art depends on public availability. The information must actually be accessible to someone who would think to look for it. Opting out of an AI provider's ability to use your data for training removes most of this risk, because there is no prospect of a model subsequently surfacing your information in its responses to other users.
The test in Australia – and many other countries – is stricter. Section 7 of the Patents Act 1990 asks whether the invention is novel against the ‘prior art base’. Schedule 1 defines that term to include ‘information made publicly available through doing an act, whether in or out of the patent area.’ The Full Federal Court explained what ‘publicly available’ means in Jupiters Ltd v Neurizon Pty Ltd [2005] FCAFC 90. Citing UK authority, the Court held that disclosure occurs if the information is made available to even one person, provided that person is free, in law and equity, to use it (at [141]). In other words, they must have no obligation of confidentiality. The information doesn't need to become widely known. Nobody besides that one person need ever see it.
The Australian risk doesn't depend on whether an AI provider's systems ever make your invention public. It doesn't depend on how many people see it either. It depends on one thing: was the recipient of your prompt bound by an obligation of confidence at the moment you typed it in? That recipient might be a person, or it might be an automated system acting for the provider. A training opt-out therefore does not address the disclosure risk in Australia (and the UK, and many other jurisdictions – for example, the European Patent Office takes a similar approach). For that, you need contractual terms that create an obligation of confidence running from the provider back to you. This is a stricter requirement than simply declining to have your data used for training.
This is why the tribunal's ‘open source vs closed source’ and ‘GhatGPT vs Copilot’ framing is unhelpful. It's the wrong question, asked with the wrong words, discouraging anybody from asking the questions that would actually determine whether a disclosure has occurred.
‘Open Source’ Doesn't Mean What the Tribunal Thinks it Means
In software, ‘open source’ means the code, and associated digital resources, are published and freely licensed, so anyone can inspect it, modify it, and redistribute it. The AI equivalent is ‘open weights’. An ‘open weight’ model is one whose trained parameters are published, so anyone can download the model and run it on their own hardware.
ChatGPT is neither open source nor open weight. It's a proprietary, closed-weight model. You can only access it through OpenAI's hosted interface or API (‘application programming interface’). Your prompt goes to OpenAI's servers, and a response comes back. You never touch the model itself.
The tools that are genuinely open-weight give you the most confidentiality control, not the least. Examples include Meta's Llama family, Google’s Gemma family, Mistral's open models, and Alibaba's Qwen. You can download these models and run them entirely on infrastructure you control. Nothing leaves your network, so no third party ever receives your information.
So the tribunal has this backwards. Here is the distinction that actually matters:
- Self-hosted (open-weight, or otherwise licensed for local deployment). You have full control. Nothing is sent to a third party. There's no disclosure risk from the AI processing itself.
- Hosted, contractually restricted (enterprise or API tiers with a data processing agreement). A third party processes the input, under specific negotiated terms covering retention, training use, and confidentiality.
- Hosted, consumer or free tier. A third party processes the input under specified terms of service. The provider can change these terms at any time. They are usually more permissive than enterprise terms.
Both ChatGPT and Copilot can sit in either of the last two categories, depending on the specific product and plan. Brand name tells you nothing.
Three Consequences of the Tribunal's Mistake
It would be easy to dismiss this as an unimportant line in a longer judgment, particularly because the UK Upper Tribunal’s decisions are not binding on any court, and its comments about waiver of privilege appear to be obiter dicta. But that would be a mistake. This decision has been issued into a vacuum and, due to its novelty, has generated far more interest and commentary than might otherwise have been the case. There is the potential for courts and practitioners to treat ‘trailblazing’ decisions like this one as guidance. When a tribunal gets something wrong in a published, citable decision, the mistake has consequences.
First, it has created a false ‘rule’ that is spreading without question. Several firms' client alerts on Munir have already repeated the claim that ‘open source’ and/or ChatGPT is bad, and ‘closed source’ and/or Microsoft Copilot is fine, stated without qualification. Readers who rely only on these summaries, without understanding the underlying technology and legal issues, will believe that switching from ChatGPT to Copilot solves the problem. It doesn't. A free consumer account of either service can leave you just as exposed.
Second, and more important, the tribunal never asked the right question. The judgment contains no finding about which specific product or plan either practitioner used. It contains no finding about what that product's terms said on training, retention, or human review. Instead, the tribunal used a rule based on brand name, skipping the necessary factual inquiry. That work is exactly what a future court, examiner, or opposing party would need to do, to determine whether a real disclosure or waiver occurred. By skipping it, the tribunal set a bad example for anyone who follows its reasoning.
Third, this causes two opposite mistakes. Some practitioners and clients may avoid genuinely safe tools, such as a properly licensed enterprise deployment or a self-hosted open-weight model, because they now believe ‘open source’ means risky. Others may treat a brand switch, such as moving from ChatGPT to Copilot, as enough due diligence on its own, when their actual plan and terms may leave them just as exposed.
What to Check, Regardless of Provider
Here are some of the questions that patent practitioners, inventors, and others involved in the patenting process, should be asking about any AI tools they might be considering.
- Does the subscription plan permit inputs to be used for training future models? If so, is there a genuine opt-out?
- Does the provider reserve an express right of human review? If so, under what circumstances?
- Is there a data processing agreement or something similar? Does it create a real contractual obligation of confidence, or is it just a policy statement (or, worse yet, a marketing statement) that the provider is free to change or ignore without notice?
- Where is the data processed and retained, and for how long?
- For patent work specifically: what does the jurisdiction's novelty test depend on? If it depends on actual, provable, public availability, a training opt-out may be enough. If it depends on disclosure to even one person with no obligation of confidentiality, as in Australia, an opt-out is not enough. In that case, you need an actual confidentiality undertaking from the provider.
If you can't answer these questions for a tool that you, a colleague or a client used to draft an invention disclosure, you have a problem. You don't yet know whether that disclosure is novelty-destroying.
Watermarking Creates Evidence of AI Use
Anthropic recently confirmed that its newer Claude models embed invisible statistical watermarks in generated text. Other providers are doing something similar. This is part of an industry-wide response to EU AI Act transparency rules, and it changes what can be proven in relation to AI use. In future, watermarking will make it possible to prove that a particular document was processed or generated by a specific AI system. With the use of AI established beyond doubt, the key question will become whether that use constituted a disclosure of the kind that might result in a waiver of privilege or a pre-filing disclosure of an invention. The onus might then fall on the owner or producer of the document to establish which product, plan, and terms of use applied to the AI tool used.
This creates extra paperwork. Best practice would be for anyone using AI tools on unfiled technical subject matter to keep contemporaneous records of which service and plan was used, and what its terms said, on that date. Merely hoping that nobody will be able to prove the involvement of AI is risky when the document may have been silently and invisibly marked.
The Good (?) News – Third Party Data Processing is Not New
We might well ask: what’s so special about AI? We have been channelling our data, including sensitive correspondence and confidential documents, through third party online service providers since long before most everyday consumers had even heard of ‘the cloud’. The discussion below uses email as an example, but could equally apply to other well-established cloud services such as file storage (e.g. Dropbox, Google Drive, OneDrive) or office productivity apps (e.g. Google Docs Editors suite, Microsoft 365 Online).
Some of the earliest webmail clients like Hotmail and Gmail were built entirely on a business model that traded free storage for data access (e.g. automated scanning of messages in order to display targeted advertising), lacking any contractually binding confidentiality guarantees. To this day, the terms of most free webmail services (including free Gmail) do not impose a legal obligation on the service provider to keep user data confidential. Assurances that your correspondence and data are secure and inaccessible to any human reader might be made in good faith, but are really subject only to ‘best efforts’, and (potentially) the whims of the provider. From a legal perspective, however, sending an invention disclosure or draft patent specification via these services may constitute a disclosure to a party ‘free in law and equity’ to use it. By contrast, enterprise alternatives like Google Workspace have contractual terms that legally classify user correspondence as ‘Customer Data’ and bind the provider to strict, legally-enforceable non-disclosure terms.
Furthermore, email has historically not been secure. The contents of unencrypted email can, in principle, be disclosed – either intentionally or unintentionally – at any network node, router or email server along the path from source to destination. A draft encryption standard for internet email was first published in 1999. According to Google’s transparency reports, by January 2014 around 50% of outbound email from Gmail servers was encrypted, while just 30% of inbound email was encrypted. Today these figures have risen to 99% of outbound email and 100% of inbound email. Since Gmail has long supported encryption, these numbers are dependent upon implementation of the encryption standards on the other servers with which email is exchanged, making it likely that fewer than half of all servers at the start of 2014 supported bidirectional encryption.
Courts and legal practitioners appear to have adopted a pragmatic approach in relation to disclosure risk resulting from the use of email. I say ‘appear’ because I am unaware of any case in which the validity of a patent has been challenged on the basis of pre-filing communications via email services that were either insecure, or whose terms did not incorporate any contractual confidentiality obligation. In part, it is likely that this is because the law contains historical precedents that treat post offices, telecommunications networks and ISPs as neutral conduits, rather than ‘members of the public’, that have (often implicitly) been extended to encompass email services.
In the early 2000s, US bar associations considered a specific question: does using free email services that scan message content compromise client confidentiality? The New York State Bar's Ethics Opinion 820 (2008) gave a qualified answer: machine-only scanning for advertising purposes doesn't breach confidentiality. But the answer changes in two situations: if a human reviewed the content; or if the provider reserved a right to disclose the substance of communications without consent.
That's a more careful distinction than Munir draws, and it applies directly to AI tools. Is review automated-only? Does the provider use or disclose content beyond running the service? On that test, many free-tier AI products fare worse than free email. They often state explicitly that they reserve a right of human review. Gmail's terms never explicitly reserved that right, and Google's public statements that ‘no one reads your email’ were a marketing pinky swear, not a contractual promise.
Even with some paid AI services a limited right of human review may be reserved. For example, Anthropic’s consumer-grade Claude plans (including paid Pro and Max plans) reserve the right to conduct human review if a conversation is flagged for violations of usage policies, or if a user explicitly chooses to share conversation data with Anthropic as part of submitting feedback or bug reports. My own view is that such limited rights of review, restricted (in the case of Anthropic’s terms) to designated staff members, should not leave the AI service provider free in law and equity to use the information for any purpose other than those stated in the terms. But until and unless the issue arises in litigation, and the courts rule on it, uncertainty remains as to how such terms will be interpreted.
Conclusion – Be Alert, Not Alarmed
Munir is right about one thing: careless AI use by legal professionals can have serious consequences. But it's wrong about how. For patent attorneys, this error matters more than the privilege question on which the tribunal actually commented. There are many jurisdictions in which an inadvertent pre-filing disclosure will invalidate a patent, absent a clear obligation of confidentiality. But the question was never ‘which company made this tool’ – and certainly not ‘is the tool open or closed source’. It was always ‘what do this specific agreement's terms actually say will happen to what I upload or type into the tool?’
As AI is increasingly deployed in professional workflows, it is likely to become as commonplace and indispensable as email. My hope is therefore that the law will adopt the same pragmatic approach to this technology as it has done with email, taking a narrow view of terms of service that reserve a right of human review only in specific circumstances and for limited purposes. This approach is consistent with the language of the terms themselves, and would preserve confidentiality in many disclosures that may have already been uploaded to AI tools by inventors and patent practitioners.
The same cannot be said where the service provider reserves a right to employ user data for model training. Acceding to such a condition, either because you have no choice or because you fail to opt out, involves an implicit acknowledgement that information provided to the AI service may be surfaced in future responses to other users. Inherent in this is an assumption that the service provider and any such future users are free to do as they wish with that information.
I would suggest the following as key takeaways from all this.
- The ‘gold standard’ for professional AI use is either to host the service on infrastructure that you control – so that data never leaves your organisation – or to use an enterprise grade service with strong contractual data protection and confidentiality terms. These are also, generally, the most expensive options, especially if your usage levels are reasonably high.
- Despite their less stringent terms, consumer or ‘prosumer’ grade services may provide legally adequate levels of confidentiality. Look for very clear provisions around privacy and data protection (e.g. encryption of your data both ‘in transit’ and ‘at rest’) along with express limitations on the purposes for which you data may be subject to human review, and on the people within the service provider company who may have access for those purposes. This is so far untested in court, however, so don’t take my word for it – form your own opinion and/or obtain appropriate advice.
- Under no circumstances upload or enter confidential information into an AI service that reserves a right to use your data for training purposes. Make sure that you exercise the option to opt out, if available. If a service has no ‘opt out’ option, do not use that service!
- Use a paid account. This is not to deny that some free services, on the face of it, appear to offer reasonable protection. Claude’s free tier, for example, has the same terms as the paid Pro and Max tiers, and the same option to opt out of training. But I can’t help wondering whether you can really have an enforceable contract with Anthropic if you are not giving them anything – either money or training data – in return for their service. Where is the consideration?
- When using AI to work with confidential information, keep records. Which provider(s) did you use? What service tiers? What were the relevant terms and conditions at the time? Keep in mind that AI outputs may be watermarked, enabling other parties in the future to prove that they were generated using specific AI tools, and turning the onus back on you to show that confidentiality was adequately protected.
- Be transparent. If you are a patent attorney, or other professional adviser, inform your clients of how you use AI, which service provider(s) you use, and the steps you have taken to protect the confidentiality of their information. If you are an inventor or other client working with a professional adviser, be up-front about any use you may have made of AI in preparing instructions or other documentation so that they can evaluate the impact and advise you of any potential implications.
Before You Go…
Thank you for reading this article to the end – I hope you enjoyed it, and found it useful. Almost every article I post here takes a few hours of my time to research and write, and I have never felt the need to ask for anything in return.
But now – for the first, and perhaps only, time – I am asking for a favour. If you are a patent attorney, examiner, or other professional who is experienced in reading and interpreting patent claims, I could really use your help with my PhD research. My project involves applying artificial intelligence to analyse patent claim scope systematically, with the goal of better understanding how different legal and regulatory choices influence the boundaries of patent protection. But I need data to train my models, and that is where you can potentially assist me. If every qualified person who reads this request could spare just a couple of hours over the next few weeks, I could gather all the data I need.
The task itself is straightforward and web-based – I am asking participants to compare pairs of patent claims and evaluate their relative scope, using an online application that I have designed and implemented over the past few months. No special knowledge is required beyond the ability to read and understand patent claims in technical fields with which you are familiar. You might even find it to be fun!
There is more information on the project website, at claimscopeproject.net. In particular, you can read:
- a detailed description of the study, its goals and benefits; and
- instructions for the use of the online claim comparison application.
Thank you for considering this request!
Mark Summerfield

0 comments:
Post a Comment