The situation
A patent agent sends a client a reporting letter explaining why she recommends narrowing claim 1 in response to an examiner's report, and what that means for the client's competitors. A clerk at the firm pastes the letter into a chatbot to produce a plain-language summary. A week later, the client's head of engineering pastes the same letter into a different AI tool to prepare slides for the board. The question is whether either paste puts the statutory privilege for agent communications at risk.
What the rules actually say
The privilege and its conditions
Canadian patent and trademark agents have a statutory privilege. Section 16.1 of the Patent Act protects a communication in the same way as solicitor-client privilege (or professional secrecy in Quebec civil law) if three conditions are met: it is between a patent agent and their client, it is intended to be confidential, and it is made to seek or give advice on any matter relating to the protection of an invention. Section 51.13 of the Trademarks Act does the same for trademark agents, for advice on protecting a trademark, a geographical indication or certain other marks.
Four details in the text matter here:
- Waiver. Subsection (2) of each section says the privilege does not apply if the client expressly or implicitly waives it. The client holds the privilege, not the agent.
- People acting on behalf. Subsection (5) extends "agent" and "client" to include an individual acting on their behalf, which is what brings firm staff and the client's employees inside the privilege. The text speaks of individuals, so it does not obviously reach an AI service.
- Confidentiality at the core. Condition (b) turns on the communication being intended to be confidential, and subsection (6) applied the privilege to older communications only if they were still confidential when the section came into force.
- Scope is narrow. In Janssen v. Sandoz, 2021 FC 1265, the Federal Court held that advice on whether a product infringes someone else's patent does not relate to the protection of an invention, so it falls outside section 16.1. Some agent advice is not privileged at all.
How an AI paste could bear on it
No Canadian decision we could find has applied section 16.1 or section 51.13 to an AI tool, and commentators describe the Canadian position as unsettled. Reasoning from the text, two arguments are open to an opposing party in later litigation.
The first is about confidentiality. If a privileged letter was submitted to a third-party service whose terms allow it to retain, review or train on the content, an opponent can argue that the communication was not kept confidential. The second is about waiver. If the client's own staff pasted the advice into a tool, an opponent can argue that the client implicitly waived. Whether an unauthorized paste by the agent's staff can be attributed to the client is a harder and open question. The answers will likely depend on who pasted, whether the client knew, and what the provider's terms said.
None of this means a single paste automatically destroys privilege. It means the firm has handed the other side an argument over material that may be the heart of a patent dispute. Early US decisions on AI and privilege are discussed in how one AI prompt can waive privilege.
The professional duty sits alongside
Separately from privilege, the CPATA Code requires agents to hold client information in strict confidence (Rule 2(1)) and to take reasonable care to protect it (Rule 2(2)), and Rule 1(5) requires agents to keep up with developments in the law of agent privilege. The guide to the CPATA Code and generative AI covers those duties.
Why policies and bans fall short
A policy that says "do not paste client advice into AI" is aimed at the firm's own staff. It does nothing about the client's employees, who act for the client that holds the privilege and are often the ones summarizing long reporting letters for management. A ban inside the firm tends to push the same work onto personal accounts.
The distinction that matters is also hard to make at speed. A published patent can go into any tool. A reporting letter with the agent's reasoning on claim scope is the kind of communication section 16.1 was written to protect, but it looks like ordinary correspondence. Staff need the reminder at the moment of the paste.
What a practical control looks like
- Label privileged communications. Mark reporting letters and advice on claim strategy, prosecution and trademark protection as privileged and confidential, so staff and clients can recognize them.
- Restrict privileged material to approved tools. If the firm uses AI on advice at all, limit it to a vetted enterprise tool whose terms on retention, training and access have been reviewed.
- Tell clients. Add a line to engagement terms or reporting letters asking clients not to paste the firm's advice into AI tools, and explain why.
- Train on the difference. Contrast a published patent with a reporting letter, and a register entry with advice on an unannounced mark.
- Have an incident path. If privileged advice reaches an unapproved tool, record what was shared, where and when, tell the responsible agent the same day, and consider with counsel whether the client needs to be informed.
Sanitized Ai is a browser extension that supports steps 2, 4 and 5 inside the firm. When someone is about to submit client names and identifiers, invention details, claim strategy or other sensitive content to an AI tool, it redacts or blocks it before submission and explains in plain language what was flagged and why. Once a prompt is submitted it cannot be recalled, so the control has to act before that point.
Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without seeing prompt content. That record can help show the firm took reasonable steps to keep advice confidential, though it cannot decide a privilege dispute, and it does not check the accuracy of AI output. See Sanitized Ai for law firms for the broader picture, and confirm privilege questions with litigation counsel.