Your AI Governance Software May Be Walking Through a Patent Minefield
A basic AI compliance product may have very little proprietary technology in it. It may be a dashboard, questionnaires, policy templates, reporting and conventional workflow. There is nothing wrong with that. It may be perfectly useful.
Bob McTaggart edited with AI
8/26/20267 min read


Your AI Governance Software May Be Walking Through a Patent Minefield
You will recognize the toaster.
A 1960s toaster looks simple now, but it was the product of decades of invention. Heating systems, timers, carriage mechanisms, switches, controls, browning systems, release mechanisms and safety features were all improved over time. Many of those improvements were patented.
By the 1960s, though, the toaster was already a mature technology. The basic architecture was understood, the major manufacturers were known, earlier patents could be searched, some had expired, and others could be licensed or designed around. A manufacturer could see a good part of the intellectual property landscape in front of him.
That is what makes the comparison with AI governance software so interesting.
A basic AI compliance product may have very little proprietary technology in it. It may be a dashboard, questionnaires, policy templates, reporting and conventional workflow. There is nothing wrong with that. It may be perfectly useful.
But once you move into a genuine governance platform, the picture changes very quickly.
A serious AI governance system may control when an AI system can act, who can authorize it, what evidence must be created, how an output is verified, how provenance is established, how a human intervenes, how an exception is escalated, how activity is monitored, how policies are enforced and how an autonomous agent is prevented from doing something it was never authorized to do.
Now we are not talking about one software feature.
We may be talking about ten or fifteen different technical problems being solved inside one product.
That is where patents start to matter.
A basic policy or compliance SaaS product might have no patents at all, or perhaps one relevant application. A specialized governance tool might sit on one to three patent families. A more developed proprietary platform could have three to eight. A serious multi-module governance platform could quite reasonably sit on five to fifteen related patent families.
A large enterprise technology company may have dozens or hundreds of patents somewhere around a product category, although only a portion of those would map directly to one particular product.
The number itself, however, does not tell you everything.
One strong patent application can contain a number of claims covering different ways of implementing the same core invention. Another company might file twenty narrow applications and still end up with a weaker position than somebody with five well-written, strategically connected patents.
I tend to look at it this way.
One or two patent families tells me there may be something interesting there. Three to five begins to look like a credible portfolio. Six to ten strategically related families begins to look like a substantial technology position. Ten to twenty can start looking like a licensing platform. Beyond that, assuming the inventions are actually useful and coordinated, you may be looking at an intellectual property estate rather than protection around one software product.
That distinction matters because ten inventions do not necessarily mean ten products.
Ten underlying governance technologies might support dozens of different products built by different companies for completely different industries.
One software company might use the human authorization technology. Another might combine verification and evidence generation. An MSP might build execution controls into a cybersecurity platform. An insurer might be interested in proving that governance actually occurred. A government contractor might care about human oversight and auditability. Someone in healthcare, employment, financial services or a public-trust institution might combine several technologies in a way the original inventor never considered.
That is how I think about a real patent portfolio.
Not as a finished product, but as a toolbox.
I have ten issued patents, and the process taught me a few things about how strange the patent system can sometimes be.
There was one application where we spent years going back and forth with the Patent Office. Office action after office action.
At one point we actually had to obtain an expert opinion to explain the difference between two-dimensional printing and three-dimensional printing.
You read that correctly.
We had to get an expert to explain that 2D printing and 3D printing were not the same thing.
The expert opinion went in.
A few days later the patent was allowed.
I cannot tell you what happened inside the examiner's office, but my guess at the time was that somebody may have realized just how far down the wrong road the examination had gone.
That experience stayed with me because it reminds you that patents are examined by human beings. Inventors are human beings. Patent lawyers are human beings. Technology often moves faster than the language used to describe it, and sometimes faster than the institutions responsible for examining it.
Now put artificial intelligence into that environment.
We are developing technologies today around concepts that barely had accepted names a few years ago. Human oversight. Agent containment. AI execution control. Machine-generated evidence. Decision provenance. Operational governance. Distributed Human-in-the-Loop control.
Different inventors can be solving almost the same problem while describing it in completely different language.
That alone makes the emerging patent landscape much harder to see.
There is another lesson inventors learn fairly quickly.
Having your own patent does not necessarily give you freedom to operate.
A patent gives you rights over what your claims cover. It does not automatically give you permission to practise every technology required to build your product.
You can invent an improvement, patent that improvement and still discover that your implementation depends on an earlier patent owned by somebody else.
The toaster world worked the same way.
You could patent a better automatic release mechanism and still depend on somebody else's protected heating technology.
AI software is no different.
You may invent a very good AI governance workflow and still encounter earlier patents covering identity, authorization, cryptography, cybersecurity, distributed systems, workflow orchestration or another technology underneath it.
That is why serious technology companies ask two separate questions.
Can we patent this?
And do we have freedom to operate?
Those are not the same question.
People also ask what percentage chance there is that an AI solution without patent protection might infringe somebody else's patents compared with something like a 1960s toaster.
There is no reliable universal statistic for that.
Anyone who tells you that a particular percentage of AI software infringes patents is pretending to know something that cannot really be known without examining the actual patent claims and the actual software.
But you can think sensibly about relative exposure.
If I were trying only to illustrate the risk, I might think of an independently developed 1960s toaster with no patent or freedom-to-operate work as perhaps having a relatively modest chance of running into an important third-party patent issue.
A modern AI governance platform is different because the technical surface area is so much larger.
A toaster has heating, timing, switching, carriage and release.
An AI governance platform can touch identity, cybersecurity, authorization, artificial intelligence, cryptography, workflow management, distributed computing, compliance systems, data management, human-machine interaction and autonomous execution.
Every additional layer is another place where somebody may already have invented something.
That is why I would expect the relative exposure of sophisticated AI governance software to be several times greater than that of a mature appliance like a toaster.
And AI developers have another problem the toaster manufacturer did not face to the same degree.
Part of the patent landscape is invisible.
Patent applications generally spend a period of time out of public view before they are published.
That means a developer can independently build something today without knowing that another inventor filed an application covering similar technology months earlier.
Nobody copied anybody.
Nobody necessarily did anything wrong.
Two people simply solved the same emerging problem.
Then the application becomes public. Perhaps the patent eventually issues. Only then does the second developer discover that the ground underneath the product has changed.
That is why I keep coming back to the toaster.
A toaster manufacturer in 1965 could see much of the minefield.
An AI developer in 2026 may be walking through a minefield while it is still being mapped.
Open source does not make that problem disappear either.
Using GitHub can help establish where your code came from. It does not automatically tell you whether the system you built with that code practises somebody else's patent claims.
The invention may not be the code.
The invention may be what the system does.
How does a human authorize an AI action? How is that authorization recorded? How is evidence created? How is the output verified? How is provenance established? How is an AI agent stopped before it carries out an unauthorized action? How does governance follow the decision across several systems? How do you prove later that the human actually remained in control?
Those are architectural questions.
They are increasingly engineering questions.
And engineering questions eventually become patent questions.
This is also why I think people sometimes misunderstand the value of a portfolio.
Suppose someone has ten related patent-pending inventions covering different parts of AI governance.
The natural assumption is that all ten are meant to go into one giant software platform.
That may be completely wrong.
One licensee may need two of them. Another may need four. Another may need one. Someone else may combine five into a product for an industry the inventor knows almost nothing about.
That is where licensing starts becoming very interesting.
The semiconductor industry learned this a long time ago. Telecommunications companies learned it. Cybersecurity companies learned it.
A strong technology portfolio can become infrastructure underneath other people's products.
That is why I think the question, "How many patents does your software have?" is probably the wrong question.
The better question is:
How many commercially useful solutions can be built using one or more of the protected technologies?
That number may be many times larger than the number of patents.
The first phase of AI was largely about models.
Who had the biggest one. Who had the fastest one. Who could produce the best answer.
I think the next phase is going to be much more about what surrounds the model.
Who is in control? Who authorized the action? What did the machine actually do? What evidence exists? Can we verify it? Where did the information come from? What happens when the machine is wrong? Who stops it? Can we prove that a human actually exercised oversight?
Control, verification, evidence, provenance, security, human authority and accountability are becoming technical systems of their own.
Once that happens, intellectual property follows.
The toaster industry went through that process over decades.
AI governance may go through it in a handful of years.
The people building in this space should probably understand that before they discover it the hard way.
I did.
And to this day, having to hire an expert to explain the difference between 2D and 3D printing remains one of the stranger moments of my patent career.
Supporting
Getting Veterans and First Responders back on mission.!
Veteran-inspired AI Governance & Trust Infrastructure
Trusted by Heroes and Mounted Rifles Management
Leadership and peer support are taught through RedFridayTalks.Help
The same governance protections are available to everyone.
© 2026. All rights reserved.