Key points of AI compliance in intellectual property work

Author:

SuChen

Published on:

2026-08-11 17:45

Introduction

Artificial intelligence (AI) technology has penetrated deeply into the field of intellectual property, becoming a crucial tool for empowering intellectual property practitioners to enhance quality and efficiency. Accurate mastery of relevant laws, regulations, and regulatory requirements is not only the bottom line for the legal operation of service institutions, but also the key for frontline practitioners to prevent professional risks, safeguard the legitimate rights and interests of client enterprises, and uphold professional credibility.

catalogue

Core AI compliance laws, regulations, and regulatory requirements

(1) General core laws and regulations for AI

(II) Special AI regulatory requirements in the field of intellectual property

Key considerations in practical operations (combining scenarios with typical cases)

(1) AI tool selection and compliance with basic models

(II) Data processing compliance

(III) Compliance of AI-generated content

Conclusion:

Core AI compliance laws, regulations, and regulatory requirements

Currently, China's AI application compliance follows a framework of "general supervision + industry-specific regulations", and intellectual property practitioners need to pay close attention to the following requirements.

(1) General core laws and regulations for AI

1. The Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law jointly constitute the core framework for AI data compliance.

The key points of compliance include:

Data processing requires full-process security management and graded and classified protection to prevent leakage, tampering, damage, and abuse.

The processing of personal information must adhere to the principles of legality, propriety, necessity, and integrity; sensitive information requires separate consent.

Data circulation, such as external provision, sharing, and transmission of data, must comply with laws and regulations.

Strict confidentiality must be maintained for undisclosed intellectual property information, such as trade secrets, undisclosed technical solutions, and intellectual property materials under review, to prevent unauthorized leakage or use for model training.

2. The "Regulations on the Administration of Deep Synthesis in Internet Information Services" is the first specialized departmental regulation to govern the application of deep synthesis technology, covering six major technical scenarios such as face/voice generation and image enhancement.

Core requirements:

Mandatory identification of generated content;

Real-name authentication and content control are implemented, and the production and dissemination of illegal and false news are strictly prohibited;

Separate consent is required for biometric editing;

Service providers need to establish a full-process management system.

3. The "Interim Measures for the Administration of Generative Artificial Intelligence Services" [1] clarifies the primary responsibilities of providers of generative AI services. It applies to services that offer generated text, images, audio, video, and other content to the domestic public. It does not apply to self-developed applications that are not provided to the domestic public.

Whether it is self-developed or outsourced AI services, commercial secrets/personal information must be protected;

One shall not take advantage of algorithms, data, platforms, and other advantages to engage in unfair competition;

ablish an audit ledger to meet the needs of regulatory traceability and dispute evidence.

4. The "Measures for the Identification of AI-Generated Synthetic Content" requires network information service providers to add dual identifications to all AI-generated synthetic content: explicit identifications that need to be clearly perceptible to users, and implicit identifications that need to be embedded in file metadata.

Concealing AI's participation in creation, deleting or tampering with identifiers, and evading disclosure obligations may expose one to verification and regulatory risks.

(II) Special AI regulatory requirements in the field of intellectual property

The new patent examination guidelines (effective from January 1, 2026) have added detailed examination rules related to artificial intelligence and big data.

Key points for practical operation:

Verify the identity of the inventor and prevent AI from fabricating inventors;

AI models and training patents must clearly document essential modules, hierarchical or connectivity relationships, as well as necessary training steps and parameters, to meet the reproducibility standard;

If an algorithm feature patent application violates laws, social ethics, or harms public interests, it shall not be granted.

2. The "Regulations on Patent Agency", "Measures for the Administration of Patent Agency", and "Provisions on the Supervision and Administration of Trademark Agency" establish industry practice standards, with core compliance principles consistent with AI compliance logic, specifically encompassing honesty and credibility, quality control, prohibition of false/malicious applications, confidentiality obligations, prohibition of improper promotion, etc.

The "Code of Professional Ethics and Practice Discipline for Patent Agents" [2] (revised in 2025) clarifies:

"Patent agents shall not utilize artificial intelligence to directly generate patent application documents that are ultimately submitted."

two

Key considerations in practical operations (combining scenarios with typical cases)

AI applications in the field of image intellectual property are primarily focused on scenarios such as information retrieval and analysis, document processing, infringement monitoring, and customer service. In practical operations, the following three core dimensions require special attention.

(1) Selection of AI tools and compliance with basic models

1. Preferably choose AI tools and large models that have completed compliance filing and possess formal commercial authorization. Focus on verifying the legality of their training data to ensure that they do not infringe on others' intellectual property rights or personal information. Do not use AI tools that are unqualified, of unknown origin, or lack overseas compliance guarantees.

[Case 1]

In February 2026, the Economic Information Daily revealed that some companies were offering software services for AI-assisted patent writing. After purchasing the software, applicants could utilize AI to draft patents. A company in Anhui charged fees ranging from 1,000 to 8,800 yuan for such services[3]. The agency has been summoned for administrative talks and ordered to improve technical prevention and control measures within a specified time limit, aiming to plug the loopholes of patent fraud from the technical aspect[4].

2. Strictly implement official warnings: On April 1st, the China National Intellectual Property Administration warned of the risks of using intelligent agents such as OpenClaw to write patent application documents [5].

The first is the risk of "technical information leakage".

The second risk is the "substantive defect" risk, which may lead to issues such as logical contradictions in content and unclear descriptions of technical features due to "AI illusion".

The third risk is "dishonest application".

To this end, applicants need to enhance their awareness of risk prevention and carefully choose compliant patent agency services; patent agencies and agents must be highly vigilant about the risks of using intelligent agents, and must refrain from using them to engage in dishonest patent application behaviors, in order to effectively protect the legitimate rights and interests of clients.

3. Sign a formal service agreement with AI tool providers: stipulate data security responsibilities, intellectual property ownership, prohibition of data backflow training, and clauses for pursuing compensation in case of illegal disclosure. Avoid high-risk operations such as verbal cooperation and trial use without an agreement.

[Case 2]

In March 2023, within 20 days after Samsung Electronics introduced ChatGPT, three consecutive core data leakage incidents occurred. Since Samsung did not sign a formal enterprise-level service agreement with OpenAI, the two parties did not stipulate data backflow restrictions. As a result, all input content was implicitly incorporated into the model training dataset by OpenAI and permanently stored on third-party servers. After the incidents were exposed, Samsung urgently issued an internal ban.

(II) Data processing compliance

Intellectual property practitioners naturally come into contact with a large amount of confidential information, and AI data processing must strictly adhere to the principles of legality, propriety, necessity, and minimal retention.

1. Data collection: When collecting enterprise/personal information, if AI application is involved, the purpose of use (such as for AI retrieval and proofreading) must be clearly stated, and consent must be obtained. The purpose of use must not be concealed, and excessive collection is prohibited.

2. Data storage and protection: Establish an AI data storage system, adopt security measures such as access permission control, specify the data storage duration (not exceeding business needs), conduct regular data security inspections, and avoid illegal retention or leakage of AI tools.

[Case 3]

In 2025, Google Gemini Enterprise was exposed to have a vulnerability known as "GeminiJack". Attackers only needed to implant hidden instructions in shared files. When employees used Gemini for search, the AI's Retrieval Augmented Generation (RAG) system would automatically retrieve malicious documents and execute the hidden instructions. Although Google has fixed this vulnerability, this case serves as a warning: as AI integrates into office systems, the risk of injection may become a common threat. Enterprises need to rebuild the trust boundary of AI, monitor the RAG process, and restrict data sources. [6]

3. Data usage and sharing: AI usage of data must be strictly limited within authorized scopes; customer data shall not be used for AI model training or shared with third parties. If sharing is indeed necessary, consent must be obtained again, and a data security and confidentiality agreement must be signed.

4. Data destruction: After the matter is concluded, promptly destroy any data that is not required to be retained, and ensure that the destruction process is documented.

[Case 4]

The AI image restoration tool, Wondershare RepairIt, has been revealed to have security vulnerabilities. Despite its promise of "not storing user data," the app actually retains uploaded photos/videos in an unencrypted cloud for extended periods. Furthermore, the developer has hardcoded the cloud access token into the app, making it accessible to anyone with basic technical knowledge. [7]

The case reveals:

When using AI to process data, enterprises need to ensure that AI providers adhere to the principle of data minimization.

(III) Compliance of AI-generated content

1. Implement AI-generated content identification requirements: When publishing AI-generated content online, it should be proactively declared and identified; for proposals and reports submitted to clients/for internal use, AI identification must not be maliciously deleted, tampered with, forged, or concealed.

[Case 5] (2024) Zhe 0108 MC No. 10311

We-Media blogger Li Moumou published an AI-generated article titled "Is Ali Digital Holdings Limited Real?" on his operated online account, fabricating false information and including images with the "Alibaba" logo and brand icon. He only marked "AI Generated" in the background of his We-Media account, without prominently marking it at the front of the article, making it impossible for the public to know the uniqueness of the content source. The court determined that his behavior constituted unfair competition.

2. Prevent intellectual property infringement: Unauthorized use of AI to imitate well-known works or use copyrighted characters/elements is prohibited; AI-generated designs must undergo similarity checks in advance, and AI-generated content must incorporate human creative labor to enhance originality and reduce the risk of infringement.

[Case 6]

Mr. Li intercepted over 20 images of the "Medusa" character from the anime "Doupa Cangqiong", and used the "Train LoRA" function of a certain AI platform to train a model capable of generating Medusa's image for others to use. The court determined that he infringed on the reproduction right and the right of communication through information network, and awarded compensation of 50,000 yuan for economic losses and reasonable expenses for safeguarding rights. [8]

3. Strengthen the responsibility of manual review: Document materials processed by AI must be manually reviewed and confirmed to ensure that the content is authentic, compliant, and accurate. The review process needs to be documented, with responsibility assigned to individuals. It is not allowed to rely on AI to piece together technical solutions or generate false application materials.

[Case 7]

The Ningbo Intellectual Property Protection Center found that two agencies had technical content generated by AI in the case materials during the agency of patent pre-examination cases. In accordance with relevant regulations, the patent application pre-examination services of the two agencies were suspended for one year. [9]

In addition, the Nanjing Intellectual Property Protection Center mentioned in the Notice of Typical Quality Issues in Patent Application Pre-examination (January-March 2026) that four agencies were suspected of irregular patent applications due to their involvement in AI-generated technology content.

4. Clarify the ownership of intellectual property rights for AI-assisted achievements: For external parties, the ownership of intellectual property rights should be stipulated in agreements based on the principle of "human-led, intellectual input". For internal parties, the ownership of job-related achievements should be clarified through internal systems.

[Case 8] (2024) Su 0581 Min Chu No. 6697

Mr. Lin created a nighttime river scene using AI and registered the copyright after manual modifications. However, two companies appropriated it without authorization, which was determined by the court to constitute infringement. Works created with AI assistance may also possess originality and are protected by copyright law. Therefore, it is necessary to agree on ownership in advance to avoid disputes. [10]

three

Conclusion:

Image AI is profoundly reshaping the working mode of the intellectual property industry, but efficiency improvement must not be at the expense of compliance. From general data security to industry-specific professional guidelines, from the scientific selection of AI tools to the division of responsibilities for generated content, every link is related to the professional bottom line of intellectual property service institutions and the career lifeline of practitioners.

In the rapidly evolving field of "AI + intellectual property", only by internalizing legal norms into operational procedures and integrating risk awareness into daily habits can we navigate steadily and achieve long-term success amidst the technological tide.

Compliance is not a constraint, but the cornerstone of high-quality development in the industry.

For business inquiries, please email: info@aciplaw.com

References

[1] Interim Measures for the Administration of Generative Artificial Intelligence Services. China Government Network. https://www.gov.cn/zhengce/zhengceku/202307/content_6891752.htm

[2] Notice of the All-China Patent Agents Association on the issuance of "Regulations on Professional Ethics and Practice Discipline for Patent Agents". All-China Patent Agents Association http://www.acpaa.cn/article/content/202509/6936/1.html

Can you "buy" a patent for just 600 yuan? - Uncovering the gray industrial chain of "patent fraud" Economic Information Daily https://www.jjckb.cn/20260205/707758071b9640f8985c65928b253cf9/c.html

[4] Cracking down on "unlicensed agents" and cleaning up "certificate hanging", Anhui takes strong measures to rectify the intellectual property agency industry. Wanmei Supervision. https://mp.weixin.qq.com/s/sYOiQLwgDVS2w2lO9Bc_oQ

[5] Risk Warning on Using Agents like OpenClaw to Write Patent Application Documents. China National Intellectual Property Administration. https://mp.weixin.qq.com/s/6ZqIze99Dx9veViu_HhnvQ

[6] Gemini Zero-click Vulnerability: Stealing Corporate Office Confidential Information Through RAG Data Poisoning. Kanxue Academy. https://www.secrss.com/articles/85933

[7]AI App Wondershare RepairIt Found Leaking User Images and Data. Amar


Translation from AI

Copyright © 2018 ADVANCE CHINA IP LAW OFFICE All Rights Reserved.
粤ICP备12081038号