Patent and trademark agents

Can patent and trademark agents use ChatGPT under the CPATA Code?

Sources verified Sanitized Ai Team

The short answer

Yes, with care. The CPATA Code of Professional Conduct does not mention or prohibit generative AI, and CPATA's 2025 guidance treats it as a tool agents may adopt if they use it safely and competently. The Code does require agents to hold client information in strict confidence, take reasonable care to protect it, and directly supervise their staff, so confidential client material should not reach AI tools the firm has not vetted.

The situation

A trademark agent at a 30-person IP firm is drafting a response to an examiner's report. An agent in training is summarizing a 40-page inventor disclosure before a client call. Both open a chatbot on a personal account, paste in the file, and get a useful draft in seconds. The principal agent hears about it later and asks two questions: is this allowed under the CPATA Code, and if it is, what is the firm now expected to do about it?

What the rules actually say

The Code of Professional Conduct for Patent Agents and Trademark Agents is a federal regulation. Under section 32 of the College of Patent Agents and Trademark Agents Act, a licensee must meet the Code's standards, and a licensee who does not commits professional misconduct or is incompetent. The Code contains no rule about artificial intelligence. Its general duties do the work.

Confidentiality

Rule 2(1) in Part 2 requires an agent to hold in strict confidence all information about the client's business and affairs acquired in the professional relationship, and to disclose it only when the client has expressly or impliedly authorized it, when the law or a court requires it, or when the Code permits it. Rule 2(2) requires reasonable care to protect the privacy and confidentiality of that information.

The commentary adds two points that matter for AI use. The ethical duty is wider than the statutory privilege and applies even if others know the information. And the implied authority to share client affairs with staff inside the firm comes with a duty to impress confidentiality on those staff and take reasonable care to prevent them from disclosing it. Privilege itself is a separate question, covered in the guide to patent and trademark agent privilege and AI prompts.

Competence and supervision

Rule 1(3) makes an agent fully responsible for the agency services they provide and requires direct supervision of staff and assistants such as agents in training, students, clerks and legal assistants. Rule 7(7) repeats it. Rule 1(4) requires appropriate office procedures and systems, and Rule 1(2) treats deficiencies in a practice's systems or procedures as a competence failure where they create a reasonable apprehension that client service may suffer. Rule 1(5) requires agents to keep up with developments in the law affecting their practice, including the law on patent agent and trademark agent privilege.

CPATA's generative AI guidance

CPATA published an article on generative AI in patent and trademark agent practices in January 2025, last updated July 2025. It is guidance, not a binding rule. It says agents must decide whether, when and how to use these tools in their own setting, and that they are responsible for safe, competent and ethical use if they adopt them. It cautions against putting confidential, privileged or identifying client information into AI tools, links that caution to Rule 2(2), and notes that in IP work, public disclosure can jeopardize trade secrets and patentability. It also suggests firm policies for employees, training and quality assurance, verification of AI output, and attention to AI guidance in other filing offices.

One nuance for lawyer-agents: section 3 of the regulation says the Code does not apply to the extent it conflicts with a provincial law society's code, so agents who are also lawyers should check their law society's guidance as well.

Why policies and bans fall short

CPATA's guidance recommends an AI use policy, and every firm should have one. But a policy on the intranet does not deliver the direct supervision that Rule 1(3) describes when an agent in training is alone with a deadline at 9 p.m. A ban tends to move the same work onto personal accounts, where the firm sees nothing. IBM's 2025 Cost of a Data Breach Report found that only 17% of organizations have technical controls that block or redact sensitive data at the point of entry.

The judgment call is also harder than it looks. A published patent is public. The client's unfiled claims, filing strategy, and the fact that it is considering a new mark are not. Staff need that distinction at the moment they paste, which is why AI acceptable use policies struggle on their own. For patent work, the stakes are described in keeping pre-filing inventions out of public AI tools.

What a practical control looks like

  1. Find out what is already in use. Ask staff which AI tools they use, including on personal accounts.
  2. Write a short policy tied to the Code. Map it to Rule 2 (confidentiality), Rule 1(3) (supervision) and Rule 1(4) (office systems), and define restricted data: unfiled inventions, draft claims, client identities, filing strategy, and unannounced marks.
  3. Sanction a tool and review its terms. Choose an approved AI tool, review its terms on retention, training and access, and configure it before anyone uses it on client work.
  4. Train with real examples. Show agents in training and assistants what can and cannot go into a prompt, and that AI output must be verified.
  5. Set an incident path. Decide who is told when client information reaches an unapproved tool, how the firm assesses whether the client should be informed, and when to make an ethics inquiry to CPATA or consult counsel.
  6. Revisit it regularly. CPATA's guidance treats testing as ongoing, and Rule 1(5) expects agents to keep current.

Sanitized Ai is a browser extension that supports steps 2, 4 and 5 at the prompt itself. When someone is about to submit client names and identifiers, invention details, draft claims or other sensitive data to an AI tool, it redacts or blocks that content before submission and explains in plain language what was flagged and why, so the training happens at the moment it is needed.

Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without ever seeing prompt content. That record can help a firm show reasonable care and supervision, though it does not decide any regulatory outcome. It does not check AI output for accuracy; that remains the agent's job. For how this fits a firm's broader duties, see Sanitized Ai for law firms. Confirm your own obligations with CPATA or your counsel.

Frequently asked questions

Does the CPATA Code say anything about artificial intelligence?

No. The Code of Professional Conduct for Patent Agents and Trademark Agents came into force in 2021 and contains no AI-specific rule. The general duties of competence, confidentiality and supervision apply instead. CPATA's article on generative AI, first published in January 2025 and updated in July 2025, is guidance on how those duties apply, not a new rule.

Is an enterprise AI tool acceptable where a free chatbot is not?

The Code does not approve or ban specific tools. The test is whether the agent took reasonable care to protect client information, which in practice means reviewing the provider's terms on retention, training and access, configuring the tool, and limiting what goes into it. If in doubt, CPATA accepts ethics inquiries from licensees, and firm counsel can review the vendor terms.

Do we need client consent before using AI on a file?

The Code allows disclosure of client information that the client has expressly or impliedly authorized. Neither the Code nor CPATA's guidance says whether sending client information to an outside AI provider falls within implied authority. A cautious approach is to address AI use in engagement terms and to confirm the position with counsel.

Is the supervising agent responsible if an agent in training pastes a client file into ChatGPT?

The Code makes the agent fully responsible for the agency services they provide and requires direct supervision of staff and assistants, including agents in training, students, clerks and legal assistants. CPATA's guidance notes that this supervision duty extends to how staff use generative AI tools.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading