Canadian patent agents and firms practising before the USPTO

Canadian firms prosecuting at the USPTO: how do you meet US guidance on AI use?

Sources verified Sanitized Ai Team

The short answer

Canadian agents registered to practise before the USPTO are bound by its rules, and the USPTO's April 2024 guidance explains how those existing rules apply to AI tools. In practice, that means keeping client information confidential under 37 CFR 11.106, personally reviewing anything filed under 37 CFR 11.18, disclosing information material to patentability, and supervising staff. The guidance specifically warns that entering invention details into AI tools can disclose confidential information and raise export control issues, so firms need controls on what reaches those tools.

The situation

A Toronto IP firm files most of its clients' US applications directly. Two of its agents are registered with the USPTO, and assistants prepare drafts and responses. One assistant uses a chatbot to tighten claim language in a US continuation before the agent signs it. A US client's in-house counsel then asks, in an outside counsel questionnaire, how the firm complies with the USPTO's guidance on AI. The managing partner realizes nobody has checked.

What the rules actually say

Who is bound

Under 37 CFR 11.6(c), a foreign agent in good standing before their own country's patent office can be registered as a patent agent before the USPTO for the limited purpose of prosecuting applications for applicants located in that country, where the other office offers substantially reciprocal privileges. Once registered, the agent is subject to the USPTO Rules of Professional Conduct and the USPTO's disciplinary jurisdiction under 37 CFR 11.19. The agent still owes CPATA Code duties at home, covered in the guide to the CPATA Code and generative AI.

The April 2024 guidance

On April 11, 2024, the USPTO published guidance on the use of AI-based tools in practice before the USPTO. It states that it is not substantive rulemaking and does not have the force of law. It reminds practitioners how existing rules apply. Those rules are binding, and these matter most:

  • Confidentiality. 37 CFR 11.106 prohibits revealing client information without informed consent or another exception, and paragraph (d) requires reasonable efforts to prevent inadvertent or unauthorized disclosure. The guidance warns that inputting aspects of an invention into AI tools for searching or drafting can disclose it to the tool's owner, which may retain the data, use it for training, or share it with third parties. It tells practitioners to understand a tool's terms of use, privacy policy and cybersecurity practices before using it.
  • Signature and review. Under 37 CFR 11.18(b), whoever presents a paper certifies it after a reasonable inquiry. The guidance says simply relying on an AI tool's accuracy is not a reasonable inquiry, and that each reference listed in an information disclosure statement must be reviewed.
  • Candor and disclosure. 37 CFR 1.56 imposes a duty of candor and a duty to disclose information material to patentability. The guidance says AI use must be disclosed when it is material in that sense.
  • Competence and supervision. 37 CFR 11.101 requires competent representation, which the guidance links to understanding the benefits and risks of technology. 37 CFR 11.501 and 11.503 require partners and supervisors to make reasonable efforts to ensure that practitioners and non-practitioner assistants comply, including when they rely on AI tools.
  • Export control. The guidance warns that AI tools may use servers outside the United States, so entering technical data may amount to an export under US export or foreign filing licence rules. For a Canadian firm handling inventions made in the United States, that is a point to settle with US counsel.

What changed since

On November 28, 2025, the USPTO rescinded its February 2024 inventorship guidance for AI-assisted inventions and replaced it, confirming that only natural persons can be inventors and that the ordinary conception standard applies. The April 2024 notice had used that earlier guidance as an example of material information, so firms should read the two together. As of September 30, 2026, we found no notice withdrawing the April 2024 practice guidance.

Why policies and bans fall short

A firm can write a policy that tracks every rule above. The weak point is the assistant preparing a response at 6 p.m. who does not think of a continuation's claims as confidential client information, or does not know that the chatbot on their phone retains what they type. Rules 11.501 and 11.503 ask partners for measures giving reasonable assurance, and a document nobody reads at the moment of use is thin assurance.

Banning AI also cuts against the direction of the guidance, which accepts that practitioners will use these tools and focuses on using them responsibly. Staff who are told never to use AI often move the same work to personal accounts, where the firm cannot see it. The practical risk for prosecution work is set out in keeping pre-filing inventions out of public AI tools.

What a practical control looks like

  1. Map your USPTO exposure. List who is registered before the USPTO, who supports them, and which files involve inventions made in the United States.
  2. Adopt one policy that satisfies both regimes. Tie it to 37 CFR 11.106, 11.18 and 1.56 and to the CPATA Code's confidentiality and supervision rules, and define restricted data: unfiled inventions, draft claims, unpublished continuation material, and client identities.
  3. Vet the tools. Review the terms of use, privacy policy, data location and security practices of any AI tool approved for US work, as the guidance asks.
  4. Require human review. Nothing AI-assisted is signed or filed without the signing practitioner reviewing it, including every reference in an information disclosure statement.
  5. Train assistants. Supervisors are responsible for non-practitioner staff, so include them.
  6. Prepare the client answer. Keep a short written description of these controls for client questionnaires.

Sanitized Ai is a browser extension that supports steps 2 and 5 where the risk actually arises. When someone is about to submit invention details, draft claims, client names and identifiers or other sensitive data to an AI tool, it redacts or blocks that content before submission and explains in plain language what was flagged and why. It does not review filings, check citations or verify prior art; step 4 remains the practitioner's work.

Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without seeing prompt content. That gives partners a record of the reasonable efforts that 37 CFR 11.106(d), 11.501 and 11.503 describe, although it does not determine any USPTO outcome. See Sanitized Ai for law firms, and confirm US obligations with registered US counsel.

Frequently asked questions

Does the USPTO's AI guidance apply to a Canadian patent agent?

It applies to practitioners before the USPTO. A Canadian agent can be registered under 37 CFR 11.6(c) for the limited purpose of prosecuting applications for applicants located in Canada, and registered practitioners are subject to the USPTO's disciplinary jurisdiction under 37 CFR 11.19. A Canadian firm that instructs US associates instead is still bound by the CPATA Code for its own handling of the file.

Did the USPTO withdraw its AI guidance in 2025?

In November 2025 the USPTO rescinded its February 2024 inventorship guidance for AI-assisted inventions and replaced it with revised guidance. As of September 30, 2026, we found no notice withdrawing the April 2024 guidance on the use of AI tools in practice before the USPTO, which restates existing rules. Check the USPTO's AI pages for updates.

Do we have to tell the USPTO we used AI to draft an application?

There is no general AI disclosure requirement in the guidance. The duty of disclosure in 37 CFR 1.56 requires disclosure of information material to patentability, and the guidance says AI use must be disclosed when it meets that test. Whether it does in a given case is a question for the responsible practitioner.

Is an enterprise AI tool enough to satisfy 37 CFR 11.106?

The rule requires reasonable efforts to prevent inadvertent or unauthorized disclosure, and the guidance tells practitioners to understand a tool's terms of use, privacy policy and cybersecurity practices before using it. An enterprise tool with reviewed terms helps, but staff can still paste the same material into a personal account, so it is one control among several.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading