What an AI patent diligence review actually covers
An AI patent diligence checklist is the ordered set of questions and evidence checks used to judge whether an AI company's intellectual property is what it claims to be. In plain terms, the review answers four questions: who owns the rights, do those rights exist and can they be enforced, can the company operate its product without blocking someone else's patent, and is the supporting know-how protected at all. Because the phrase is used loosely, it helps to separate a true diligence review from a casual audit or a pure novelty search. A diligence review is tied to a decision, such as funding, acquisition, licensing, or entry into a new jurisdiction, and its output is documented evidence with risk ratings rather than a patent application.
Also worth reading: What Is the Definitive Patent Application Review Checklist for AI-Driven Drafting in 2026? · What is a defensible AI patent strategy, and how do I build one that survives USPTO scrutiny and investor diligence in 2026? · What are the best AI patent analysis tools for conducting prior art searches and due diligence in 2026?
For AI products specifically, the reviewer has to look past the patent list itself. A software portfolio usually mixes issued patents, pending applications, provisional filings that were never converted, trade-secret pipelines, and open-source components, and each category fails in a different way. A clean chain of title can still sit on top of code copied from a repository under a GPL license, and a technically promising application can still be owned by a contractor who never signed an assignment. The review therefore moves through six workstreams: portfolio scope and status, ownership and inventorship, validity, freedom to operate, encumbrances and funding, and data and know-how.
The last workstream is the one that generic patent checklists often skip. Reuters' AI-era framework for protecting trade secrets treats models, weights, and evaluation data as assets that patents cannot fully cover, and many 2026 AI transactions treat those assets as the center of gravity. A reviewer who stops at the patent register will miss the assets that actually determine whether the business keeps operating after closing. In a transaction valued in the €25 million to €250 million range, as the healthcare.digital acquisition-readiness material describes for HealthTech, MedTech, and Healthcare AI targets, buyers typically run all six workstreams in parallel rather than one after the other.
Why AI changes the diligence playbook in 2026
AI products break three assumptions that a conventional software patent review relies on. First, inventorship becomes contested: the USPTO's 2023 Inventorship Guidance and the D.C. Circuit's ruling in Thaler v. Vidal confirm that a natural person must be the inventor, yet models and tools now propose much of the inventive work. Second, prior art is unusually dense outside the patent database, with transformer and diffusion techniques published in rapid succession on preprint servers and model hubs since 2017, years before a filing is drafted. Third, the asset itself is increasingly a moving target, because a product line may ship a new model version every few quarters while the patent application describing it will not publish for 18 months and will not mature for several more years.
A fourth factor is regulatory. The EU AI Act's general-purpose model obligations, applicable since August 2025, require documentation and copyright-policy practices that diligence teams now cross-check against the company's actual training-data records. This is why an AI patent review increasingly includes questions about data provenance, not just claim charts. The 2026 reporting environment reinforces the shift. LawSites covered Anthropic releasing more than 20 connectors and 12 practice-area plugins for legal work, IPWatchdog reported that patent law firms face pressure as clients internalize more work with AI, Lexology published a roundup of 11 AI legal tools for 2026, and understandingai.org framed AI's effect on legal practice as a structural change rather than a productivity tweak.
The practical effect is that reviewers now spend as much time on engineering records as on legal documents. Version-control history, dataset manifests, model cards, and experiment logs frequently decide whether a claim is enabled, whether trade-secret measures were maintained, and whether a contributor had a duty to assign. None of that appears in a register search, which is exactly why a checklist built for hardware companies underperforms for AI targets.
Portfolio scope, family status, and deadline risk
The opening workstream is administrative but unforgiving, because most valuation disputes about AI portfolios start with a clerical error. The reviewer reconstructs each family: provisional filings, non-provisional filings, continuations, national-phase entries, and issued patents, then confirms that the 20-year term runs from the earliest effective non-provisional filing date under 35 U.S.C. 154. Provisional filings must be converted within 12 months, the Paris Convention and PCT routes preserve priority, and a PCT national-phase entry typically falls due at 30 or 31 months from the priority date, depending on the receiving office. Missing a single national-phase or continuation deadline can strip value from an otherwise strong family.
Annuities and maintenance fees form the second trap. In the United States, maintenance fees fall due at 3.5, 7.5, and 11.5 years from grant, and a missed payment can cause lapse, subject to a six-month reinstatement period with a surcharge. In Europe, annual fees to the EPO and to national offices must be paid in the correct year or the patent lapses there, and lapse in one country does not affect the others but does affect a unified European patent validated there. Reviewers therefore check the docket against the USPTO Patent Center, the EPO Register, WIPO PATENTSCOPE, and the relevant national registers such as CNIPA, rather than trusting an internal spreadsheet.
A further distinction matters for AI companies: a large application count can dilute quality. A target with 200 pending applications may face a substantive examination or eligibility objection on the core ML claims, while a smaller set of continuation positions may survive. Diligence should test whether prosecution history notices, terminal disclaimers, or repeated office actions narrow the claims below the product's current architecture. The output of this workstream is a status table scored red, yellow, or green, with the reason for each rating documented for the deal team.
Prior-art searching and validity stress-testing
Validity review asks whether the claims are patent-eligible, novel under 35 U.S.C. 102, non-obvious under 35 U.S.C. 103, and adequately described and enabled under 35 U.S.C. 112. Novelty searches for AI inventions must reach well beyond patent databases. The most damaging art is often a conference paper, a technical report, a GitHub commit, a Hugging Face model card, or a blog post that predates the priority date, and the USPTO's one-year inventor grace period under 35 U.S.C. 102(b) only protects certain disclosures by the inventor or derived from the inventor, not a third party's earlier independent release.
Obviousness is harder with machine-learning claims because combining a known transformer architecture with a known training technique can be obvious unless the specification shows a specific technical effect. Reviewers test whether the application actually recites how the model handles data, hyperparameters, loss functions, and inference constraints in enough detail to achieve the claimed result, or whether it merely says train a model to predict the target. In Europe, the same weakness is framed as lack of inventive step or sufficiency under the EPC, and computer-implemented inventions must be evaluated across the board for technical character. An application written for a 2019 architecture and prosecuted in 2025 may also face enablement objections for later product versions.
A serious search runs in three passes: a family and citation pass, a non-patent-literature pass, and a product-level reverse-engineering pass that maps the accused feature to each element of the claim. The third pass is the one most often skipped, and it is where open-source implementations and undocumented experiments surface. The deliverable is not an opinion of ultimate validity, which no attorney can guarantee, but a prioritized list of vulnerabilities, the documents that create them, and the probability-weighted exposure they represent in the deal model.
Ownership, inventorship, and chain of title
Chain-of-title diligence for AI companies starts with human beings, because the law still counts natural persons as inventors. Every named inventor on every application must be a person who contributed to the conception of the claimed subject matter, and a team using Copilot, an internal model, or an automated experimentation platform does not relieve the company of proving that contribution. Joint inventorship rules under 35 U.S.C. 116 mean one omitted contributor can invalidate the naming on a claim set, so reviewers compare the inventors listed on each application against the contributors recorded in pull requests, lab notebooks, and design documents.
The contractual layer is where most gaps appear. Employee invention agreements, contractor statements of work, and university-sponsored research agreements should all contain present-tense assignments to the company, and the executed originals should be produced, not just policy pages. Assignment recordation with the USPTO under 35 U.S.C. 261 protects against a later assignee but does not cure a missing assignment in the first place. Federally funded work raises Bayh-Dole questions under 35 U.S.C. 200 to 212, including the government march-in and license rights, and a startup spun out of a European university may face the employee-invention statutes that apply in the UK under the Patents Act 1977 and in Germany under the 1991 employee invention act, each of which can leave the employer with only a non-exclusive license.
The reviewer also traces any liens, security interests, exclusive licenses, and field-of-use restrictions recorded in the file, and checks that the IP actually sits in the entity being acquired rather than a founder or a sister company. A 2026 diligence file that cannot produce a signed assignment for a principal inventor is a red flag regardless of how strong the technical claims look, because the patent can be assigned later or contested now, and both outcomes change price.
Validity review versus freedom-to-operate analysis
These are two different engagements that buyers often confuse. A validity review asks whether the company's own patents would survive challenge; a freedom-to-operate analysis asks whether someone else's valid patent blocks the product. A company can own a strong patent that is valid yet infringe a competitor's earlier-filed claim, and it can own a weak patent that no one can assert because the likely patentees are inactive. Transaction documents, indemnities, and insurance all turn on keeping the two analyses separate.
| Feature | Validity review | Freedom-to-operate analysis |
|---|---|---|
| Primary question | Are our own claims patentable and enforceable? | Can we build and sell without a third party's claim? |
| Core work | Prior-art and statutory challenge, claim construction, prosecution history | Claim chart of accused feature, all-elements and doctrine-of-equivalents mapping, search for blocking rights |
| Typical output | Validity risk per claim, art references, vulnerability ranking | Non-infringement position, design-around options, licensing targets |
| Indicative time | 2 to 4 weeks per family set | 2 to 6 weeks per product or feature |
| Indicative cost | $15,000 to $40,000 per focused opinion | $10,000 to $30,000 per product search |
Trade secrets, data, and open-source code
The Reuters framework for protecting trade secrets in the AI era argues that patents and secrecy are complements, not substitutes. Patents publish the invention and buy exclusion rights, while secrecy protects the weights, the curated dataset, the human-feedback pipeline, and the evaluation harness that make a product hard to copy. Diligence confirms that the company treated these assets as trade secrets through reasonable measures, including need-to-know access, access logs, confidentiality agreements with departing staff, and technical controls such as logging and encryption. A model that was posted publicly or shipped to customers without restrictions may have lost secrecy, and the diligence file should show when that happened.
Open-source code is the mirror image. Apache-2.0 and MIT licenses are generally permissive, but LGPL, GPL, and AGPL terms can impose source-disclosure and redistribution duties that conflict with a proprietary hosted model. Reviewers run a software bill of materials against the repositories, check notices and attribution files, and confirm whether contributors signed a CLA or whether a copyleft dependency was introduced by an employee who was not authorized to accept its terms. The weight licenses on public model hubs and the terms of training data are also checked, because ongoing litigation over training-data rights means a company that cannot show provenance may face a claim later.
An acquisition such as Juniper Square's purchase of Sightglass, reported by PR Newswire in 2026, illustrates the pattern: acquiring an AI capability means acquiring a stack, and the diligence question is whether that stack is cleanly owned, properly licensed, and separable from the seller's other services. The practical output of this workstream is a two-column register of what is patented, what is secret, and what is borrowed, with the last column reviewed far more carefully than the first.
Common mistakes that derail AI patent reviews
The most frequent error is treating an issued patent as a guarantee. Issuance means an examiner allowed the claims, not that they survive a validity challenge, and AI claims that recite generic model training are especially exposed to obviousness and eligibility attacks. The second error is running a freedom-to-operate search but no validity work, or the reverse, so the deal team prices a risk it has never tested. The third is time compression: in competitive processes, sellers often produce a portfolio list three days before the data room closes, and reviewers have no time to reconstruct families, locate assignments, or read prosecution histories.
A fourth mistake is over-reliance on automated tools. AI assistants can draft search queries, summarize office actions, and spot metadata inconsistencies, which is useful, but they cannot judge obviousness, inventorship, or the legal effect of an assignment without a human reviewing the output. The 2026 tool landscape reported by Lexology and LawSites is real, and it does not remove the need for attorney judgment. A fifth mistake is missing jurisdictional traps, such as failing to confirm that a Chinese invention was first filed in China with a confidentiality request, or overlooking annuity lapse in a country where the patent is validated but not enforced. China Briefing's 2026 Hong Kong M&A analysis notes that risk often sits in title and regulatory compliance rather than in the financials, and the same is true of the patent file.
A sixth mistake is ignoring the clinical or technical evidence base in regulated verticals. In healthcare AI, a patent claim may describe an algorithm whose claimed performance is not supported by validation data, and in consumer AI a claim may cover a product feature the company has already redesigned around. Diligence should therefore sample the evidence behind the strongest claims, because a patent with unsupported performance is both a validity liability and a marketing liability.
Timing, scope, and realistic cost
The right moment to commission the review depends on the event. Founders typically run a portfolio and chain-of-title check before a Series A or bridge round, when investors will ask about pending applications and founder-owned IP. In M&A, the useful window opens about two to six weeks before signing, but a full portfolio reconstruction takes three to six months, so sellers should start earlier. For an IPO on Form S-1, diligence, disclosure, and any needed amendments should be underway roughly 90 days before the confidential submission, because materiality assessments and SEC comments do not compress well.
Indicative market rates in the United States place a focused prior-art or status search at roughly $5,000 to $15,000, a validity opinion at $15,000 to $40,000, and a freedom-to-operate analysis at $10,000 to $30,000 per product. A full portfolio diligence for an AI target with 50 to 200 filings commonly runs $30,000 to $100,000 or more, and international components add cost. USPTO fee discounts reduce government charges, with qualifying small entities receiving roughly a 60% discount and micro entities roughly an 80% discount, but those discounts do not touch attorney time. European and Asian associates bill in local currencies and add coordination overhead, which is why cross-border deals often use a lead firm and a small panel of local counsel.
AI tools can compress drafting and first-pass research time, but they do not change the fee structure, which is still driven by attorney judgment hours. Buyers who budget only for a register search are effectively buying the cheapest version of the review. A workable middle ground is a two-stage engagement: a two-week triage covering status, title, and red flags before signing, followed by deeper validity and freedom-to-operate work on the top three product families, with the remainder scheduled post-signing under an escrow or indemnity structure if the risk is priced.
Turning the review into a decision
The output of a diligence review should be a scored matrix, not a memo. Each workstream receives a red, yellow, or green rating with the supporting document, the reviewer, and the date. Red items, such as an unassigned invention from a lead engineer or a blocking claim with no design-around, become price, escrow, indemnity, or a condition precedent. Yellow items, such as a pending application under office action, become post-closing actions with deadlines. Green items, such as a clean chain of title and current annuities, close the review without further cost.
The review also produces a forward program. A 30-day plan fixes priority filings and converts unconverted provisionals, a 60-day plan addresses office actions and design-arounds, and a 90-day plan formalizes trade-secret measures and open-source compliance. Thereafter, the portfolio is refreshed at least annually and after each major product release, because AI architecture moves faster than the 18-month publication cycle. In board and investor reporting, three numbers usually matter more than any narrative: the percentage of revenue covered by a valid, enforceable right; the count of open red flags; and the annuity and deadline status of the top families.
That is the substance of an AI patent diligence checklist as of September 2026. It is a verification exercise built on six workstreams, grounded in the documents engineers and lawyers actually create, and calibrated to a decision with a date and a price. Generic patent checklists miss the trade-secret and open-source layers, pure novelty searches miss the transaction question, and AI-assisted review without human review simply relocates the error. Used properly, the checklist tells a buyer or investor not just what the AI company claims, but what it can actually keep.