Short Answer: There Is No Separate 'Deepfake' Prosecution Track at the USPTO

As of September 23, 2026, the United States Patent and Trademark Office has no prosecution protocol dedicated specifically to deepfake inventions. Nothing in Title 35 of the United States Code singles out synthetic face or voice technology, and there is no examiner instruction manual devoted to deepfakes. What does exist is general patent law plus technology-neutral USPTO guidance on AI-related inventions, most notably the memorandum on AI-related patent subject-matter eligibility issued July 17, 2024, which the agency has since revised. Inventors and their attorneys routinely search for 'AI deepfake patent prosecution guidelines' and expect a bespoke rulebook; in reality, they should expect the ordinary §§ 101, 102, 103, and 112 analysis applied to a dense, fast-moving technical field.

Also worth reading: How Should Patent Teams Use AI to Improve Prosecution in 2026? · What are the definitive best practices for AI patent prosecution in 2026? · What is the USPTO AI prior art search pilot program and how does it impact patent prosecution strategy?

The core legal sources are 35 U.S.C. § 101 (eligibility and utility), § 102 (novelty), § 103 (non-obviousness), and § 112 (written description, enablement, and definiteness), interpreted by the USPTO and the courts. The 2024 USPTO AI memorandum states three positions that matter directly to deepfake filings: AI inventions are patent-eligible when they produce a technical improvement, users' interactions with AI systems are patent-eligible contributions, and the USPTO will not search for or evaluate the human contribution to an AI invention. That memo has functioned as the closest thing to 'AI deepfake prosecution guidance,' and it never mentions deepfakes. The USPTO has updated it at least once, and practitioners should always confirm the current version at uspto.gov rather than relying on a cached copy of the 2024 text.

The broader policy debate in 2026, including the White House AI policy framework reported on March 20, 2026 and the U.S. copyright litigation challenging whether training on protected works is fair use, does not change patentability standards. The USPTO is an agency within the Department of Commerce administering the patent system; executive-branch AI policy and pending copyright litigation are separate tracks. Other jurisdictions, notably China, regulate synthetic media through content and platform rules enforced by the Cyberspace Administration, including restrictions on unauthorized deepfakes of real individuals, but those are censorship regimes, not patent prosecution guidelines. The honest answer to 'what are the AI deepfake patent prosecution guidelines' is: general AI eligibility guidance plus foundational statute, with no deepfake carve-out in either direction.

How Deepfake Claims Are Actually Evaluated: §§ 101, 102, 103, and 112

Under § 101, the Alice two-step framework from Alice Corp. v. CLS Bank International asks whether the claim is directed to a judicial exception (abstract idea, natural phenomenon, or unpatentable process) and, if so, whether it integrates that exception into a practical application or adds an inventive concept. A deepfake applicant should draft toward the architecture of the invention, the synchronization method, or the detection signal analysis, rather than the end result of 'a realistic fake face.' Contrast a result-oriented claim such as 'a method of synthesizing a photorealistic talking-head video' with a claim directed to 'a method of synchronizing a synthesized audio stream to a target frame rate using a per-frame lip-movement score computed by a trained network, reducing synchronization latency below 50 milliseconds.' The second is far easier to defend as a technical improvement because it recites a measurable effect tied to the computer and its operation.

Under § 102, novelty must be assessed against the dense prior art of the deepfake field, which includes peer-reviewed computer-vision papers, corporate product releases, and open-source repositories. A 2023 Nature paper mapping the technological evolution of generative AI through patent network analysis illustrates how crowded the citation environment has become. The drafting tactic is to identify the closest five to ten academic papers before filing, map each against the proposed claims, and ensure the independent claims recite features absent from all of them. Patents, unlike papers, have a 20-year term running from the earliest effective non-provisional filing date, so a two-year drafting delay can matter commercially even when it does not defeat the application.

Under § 103, a deepfake claim that merely combines known components in an obvious way, such as a face-swap network plus an audio encoder plus a lip-sync model, may be rejected over a predictable combination. Claim amendments should surface non-obvious interactions, such as adversarial training against a specific detector family, or a quantization scheme that cuts inference cost by a stated percentage on named hardware. Under § 112, the specification must show the invention works, and for AI systems this means describing architecture, training procedure, and inference pipeline in enough detail that a skilled person could reproduce it. In practice, the hardest rejections in this field are often § 102 and § 103 rejections supported by a careful reading of the literature, not eligibility rejections, and applicants should budget for multiple office actions rather than expecting an easy allowance.

Eligibility Is Only the First Hurdle: Disclosing Deepfake Training Realities

The July 17, 2024 USPTO memorandum is favorable on eligibility: it instructs examiners to stop applying an 'artificial intelligence' exception under § 101 and to treat AI inventions as patentable when they recite a technical improvement. It also says the USPTO will not evaluate the human contribution to an AI-generated output. But eligibility under § 101 and inventorship under § 101's 'inventor' language are distinct questions, and the D.C. Circuit and the Federal Circuit have drawn a firm line that no one can invent who is not a natural person. The 2023 Federal Circuit decision in Thaler v. Perlmutter confirmed that a patent naming only a non-human 'inventor' fails for lack of inventorship, and the Supreme Court denied review in that litigation. A second Thaler line of cases, decided by the Federal Circuit in 2023, confirmed the USPTO's authority to refuse patents naming an AI as sole inventor.

That leaves the practical inventorship question for deepfake teams: if engineers trained a model on millions of scraped videos, including celebrities' likenesses, can they patent an improvement to that pipeline without exposing themselves to unrelated liability? The inventorship rule is settled; the unsettled part is whether the training itself is lawful. Copyright owners have sued AI companies over training, and as of September 2026 the U.S. case on whether ingesting copyrighted works for training is fair use is still contested, with commentary ranging from the Holland & Knight discussion of the gap left by Cox v. Sony to the Baker Botts intellectual property report of December 2025. That litigation does not directly decide patent validity, and an issued patent is not automatically void because the training data was unlawfully obtained. But if a court later holds that a platform's training pipeline was infringing, the patent's practical value can collapse, because the patented method may be inseparable from the unlawfully derived model. Practitioners should treat training legality as a client-advice issue at drafting time, not as an afterthought for litigation counsel.

Disclosure obligations compound the problem. Section 112 requires written description of the claimed invention, and if the claims recite a specific trained network, a specific dataset, or a specific preprocessing pipeline, the specification should describe them concretely. Claiming 'a model trained on a dataset of licensed video' is far safer than claiming 'a model trained to reproduce any public figure,' because the former is bounded and the latter both reads as unpatentable and invites scrutiny from privacy regulators. The USPTO does not require disclosure of an entire training corpus, but vague functional claiming in an AI specification is a reliable route to a § 112 rejection. In short, a deepfake application that is clean on eligibility but vague on how the system was built will not survive prosecution.

Drafting and Prosecution Tactics That Survive Alice and § 112 Scrutiny

Start with a problem statement in engineering terms. A defensible specification says what breaks in existing systems and how the invention fixes it: frame desynchronization above 40 milliseconds at 60 fps, a 12 percent reduction in inference memory on a specific accelerator, or a detector operating at 98 percent accuracy on a defined benchmark. These numbers should come from real experiments, and the specification should report them honestly, including failure cases. Examiners in this technology area have become attuned to grandiose claims, and a claim that 'solves deepfakes' with no measured effect invites both a § 101 rejection and a § 112 indefiniteness rejection.

Build the claim ladder around technical sub-components rather than the product. For a synthesis invention, candidates include the audio-feature extraction stage, the temporal alignment module, the identity-embedding decoder, and the adversarial training loop. For a detection invention, candidates include the spatial-frequency inconsistency detector, the temporal blink analysis, and the cross-modal consistency score. These sub-components are less likely to be characterized as mental processes or mathematical abstractions, and they give the examiner concrete language to work with during amendments. One practical safeguard is to file a provisional application within days of a demonstrable technical milestone, because the specification that supports later claims must exist by the provisional's filing date.

Plan the prior-art narrative before drafting claims. A 2024-2025 deepfake prosecution is unusually document-intensive: the examiner's search will hit arXiv papers, CVPR and ACM Multimedia proceedings, GitHub projects, and product datasheets, none of which the examiner must disclose in an obviousness rejection. A good response brief walks through the closest references chronologically and identifies the specific feature each lacks, usually a particular training objective, a particular synchronization constraint, or a particular efficiency result. Claim amendments should track that analysis, moving from a broad system claim to narrower method or apparatus claims that recite the genuinely novel elements. Applicants who rely solely on the 2024 AI memorandum to argue eligibility, without pre-empting novelty and obviousness attacks, frequently find themselves defending the wrong issue.

Finally, keep inventorship clean. The 2023 Thaler v. Perlmutter decision, together with D.C. Circle v. AMA from 2021, means the named inventors must be natural persons who conceived the claimed subject matter. Enumerating every engineer who touched the codebase is not required; naming the engineers who conceived the specific claimed features is required. The USPTO's 2019 guidance on inventors who contribute to AI-generated material, updated after Amgen v. Sanofi, remains the reference point, although the D.C. Circuit in Thaler v. Vidal in 2022 narrowed how broadly that guidance can be read. For a deepfake team, the practical rule is simple: document in writing who proposed each claimed inventive feature, and date that record.

Timing, Regulatory Pressure, and When to File

The phrase 'guidelines' in a search query usually reflects a practical question: when should a deepfake startup or research lab file, and what changed in 2024-2026 that makes timing matter? The 2024 USPTO AI memorandum shifted the eligibility analysis toward technical improvement, which made filing for measurable technical advances materially less risky than under the 2020-2023 climate. The agency's 2025 updates to AI-related subject-matter eligibility guidance continued that direction, and applicants should confirm the current text on uspto.gov before relying on any summary, including this one. Filing decisions should also account for the 20-year term: for a fast-moving field where a generation model may be obsolete in three years, a provisional filed in 2026 may still have only a sliver of commercially useful term left by the time a patent issues in 2029.

Regulatory pressure runs in parallel. The 2024 federal TAKE IT DOWN Act criminalized certain non-consensual intimate imagery, including digitally created depictions, and state laws in California, Texas, Tennessee, and others impose disclosure duties and civil liability on creators and distributors of deepfakes. Illinois's amended Biometric Information Privacy Act, effective January 1, 2026, now expressly covers video, audio, and other biometric identifiers, and class-action plaintiffs have already used BIPA against companies that processed biometric data without written consent. The FTC has pursued enforcement against companies deploying deepfakes for fraud or impersonation. None of these laws is a patent prosecution guideline, but together they raise the value of patents that recite technical improvements rather than rights to a person's likeness, and they can affect the damages analysis if a patented method is used in a way that triggers statutory liability.

The practical timing rule is to file when two conditions are met: the technical improvement is demonstrated in a written or experimental record, and the closest prior art still leaves a defensible gap. Waiting for perfect benchmarks risks losing patentable subject matter to public disclosure, and a paper, a demo, or a conference talk can start the one-year grace period clock. For inventions that are still research-stage, a provisional that captures the architecture and the first measured result is usually worth more than waiting. For inventions with a large training-data component, counsel should also assess whether foreign filing, particularly in China and the European patent states, remains worthwhile given local content rules and costs before the provisional deadline expires.

Patents Versus Alternatives: What Actually Protects a Deepfake Innovation

A patent is one instrument among several, and for some deepfake products it is the wrong one. The table below compares the main options an applicant has, using the USPTO's current fee schedule as a cost anchor and noting that foreign costs vary widely by office.

FeatureU.S. PatentCopyright (code, model weights as literary work, outputs)Trade secret (inference pipeline, training recipe)Contract (platform terms, likeness licenses)Output-side regulation (state deepfake statutes, TAKE IT DOWN Act, FTC)
What it protectsA claimed technical method or apparatus and its equivalentsOriginal code and, in principle, weight files and specific outputs, not the ideaConfidential know-how that is not generally ascertainableBargained rights between specific partiesRed lines on misuse, applied by enforcers not by the owner
Term20 years from earliest non-provisional filingGenerally life of author plus 70 years; code protection varies by jurisdictionUnlimited while secrecy holdsDuration of the agreementVaries by statute; Illinois BIPA amendments apply from Jan 1, 2026
DisclosureFull enabling disclosure; claims define the boundaryPublication-ready public filingReasonable secrecy measures requiredPrivate negotiationPublic law
Cost anchorUSPTO base filing fee about $2,150 large entity, $1,600 small, $1,300 micro (2025 schedule); attorney drafting typically $12,000-$30,000$0 for registration; $600-$800 for copyright depositsLow, mainly operational cost$0 to high, driven by negotiation$0 to legal cost of compliance and monitoring
Best forNovel architecture with measurable technical effectsCode, documentation, and specific creative outputsFast iteration, inference weights, data curationUsing celebrities' likenesses or training on licensed videoReducing exposure, not securing exclusivity
Main weaknessDoesn't grant rights to likeness or training data; invalid if prior artDoesn't stop a competitor's independent implementationLost if reverse-engineered or leakedParty-specific; does not bind othersPenalties, not a licensing or defensive right
The comparison shows why a sound strategy is layered. Copyright covers code and documentation cheaply. Trade secret protects the training recipe and inference tricks when the product evolves faster than a three-year prosecution cycle allows. Contracts and likeness licenses address the celebrity and copyright exposure that patents do not touch. Output-side regulation, including the 2024 federal law and the Illinois rules, sets behavioral boundaries but confers no exclusivity. Patents earn their cost only when the invention is genuinely novel, produces a measurable technical effect, and can be described without depending on rights the applicant does not own.

Common Prosecution Mistakes and How to Avoid Them

The first mistake is over-claiming. Applicants routinely draft 'a method of detecting any deepfake' or 'a system for generating realistic human video,' and examiners correctly treat these as abstract result-oriented processes. The fix is to recite the mechanism: which signals are extracted, which thresholds are applied, which network layers produce the improvement, and what the measured effect is. The second mistake is relying on the 2024 AI memorandum as a blanket shield. It instructs examiners to stop applying an AI exception, but it does not override Alice analysis of genuinely abstract claims, and it does not touch § 103. A third mistake is black-box claiming, using phrases such as 'a module configured to perform' without describing the module's inputs, outputs, and operation; in an AI specification this reliably produces a § 112 written-description or enablement rejection.

The fourth mistake is ignoring non-patent literature. Examiners can and do cite arXiv papers, conference proceedings, and open-source code in § 103 rejections, and applicants who did not read the closest references cannot rebut them effectively. The fifth mistake is inventorship hygiene. After the 2023 Thaler v. Perlmutter decision, a patent naming only a non-human inventor is invalid for lack of inventorship, and engineers who merely ran experiments are not inventors. The sixth mistake is treating training-data legality as someone else's problem. The pending U.S. fair-use litigation over training on copyrighted works is unresolved as of September 2026, and a deepfake application that silently depends on scraped video of real people carries commercial risk regardless of how cleanly it is drafted.

A seventh mistake is timing the provisional to a demo or a press release. Non-publication agreements with investors and collaborators should be in place before any public showing, because a public disclosure can start the one-year grace period and, in some foreign jurisdictions, destroy novelty outright. An eighth mistake is budgeting as if allowance is automatic. A deepfake application that survives § 101 often receives a § 102 or § 103 rejection grounded in a well-read paper, and a response that argues eligibility while ignoring the cited reference will not issue. None of these mistakes is fatal, but each adds months to an already slow timeline and each is avoidable at drafting time.

Cost, Timeline, and What 'Guidelines' Should Actually Mean to a Practitioner

The USPTO's current fee schedule sets the filing anchors. As of the 2025 schedule, a utility application carries a base filing fee of roughly $2,150 for a large entity, $1,600 for a small entity, and $1,300 for a micro entity, with additional fees for excess claims, excess pages, and searches; the international PCT filing fee has been $2,600. Attorney drafting for a well-prepared deepfake specification with experimental data typically runs $12,000 to $30,000 for a provisional and non-provisional pair, and more for complex international families. China and Japan national-phase costs, including translation, can add several thousand dollars per jurisdiction, and the European patent route carries its own translation and examination fees. The overall timeline from first filing to allowance commonly runs 18 to 36 months, longer for complex specifications with heavy experimental disclosure.

Set against those numbers, the 'guidelines' a practitioner should treat as authoritative are the statutes and the current USPTO memoranda, not secondary summaries. The most useful guidance remains the July 17, 2024 AI memorandum and its subsequent revisions, which state that AI inventions reciting a technical improvement are eligible and that the USPTO will not evaluate the human contribution to an AI-generated output. Pair that with the Federal Circuit's Thaler decisions on inventorship, the D.C. Circuit's decisions requiring a natural-person inventor, and the Alice framework, and a deepfake applicant has a complete and defensible playbook. What does not exist, as of September 23, 2026, is a deepfake-specific prosecution manual, and any source claiming otherwise should be treated with suspicion.

The bottom line is practical. File when the technical improvement is measured and the prior art gap is clear. Draft around measurable effects such as latency, artifact rate, frame-level synchronization, and compute cost, not around the goal of making a convincing fake. Disclose the architecture honestly, name only natural-person inventors, and disclose the provenance of any training data the claims depend on. And budget for the litigation track running in parallel, because the pending U.S. case on whether training on copyrighted works is fair use, alongside state deepfake statutes and Illinois BIPA amendments effective January 1, 2026, can affect the commercial value of any patent that depends on scraped likeness data. Patents are appropriate for a genuinely novel deepfake architecture with a technical effect; they are not a one-click solution to deepfake risk.