Prosecution Insights
Last updated: October 02, 2026
Application No. 18/583,274

SYSTEM AND METHOD FOR GENERATING DEPLOYABLE COMPONENTS ASSOCIATED WITH SOFTWARE APPLICATIONS FOR INCOMING REQUESTS VIA AN ADAPTIVE ZERO-TRUST GENERATIVE ARTIFICIAL INTELLIGENCE ENGINE

Final Rejection §101§103
Filed
Feb 21, 2024
Examiner
VU, TUAN A
Art Unit
2193
Tech Center
2100 — Computer Architecture & Software
Assignee
Bank of America Corporation
OA Round
2 (Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
11m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
730 granted / 997 resolved
+18.2% vs TC avg
Strong +21% interview lift
Without
With
+21.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 6m
Avg Prosecution
31 currently pending
Career history
1026
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
54.3%
+14.3% vs TC avg
§102
10.1%
-29.9% vs TC avg
§112
11.6%
-28.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 997 resolved cases

Office Action

§101 §103
DETAILED ACTION DETAILED ACTION This action is responsive to the Applicant’s response filed 6/05/26. As indicated in Applicant’s response, claims 1, 8, 15 have been amended. Claims 1-20 are pending prosecution by the following office action. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 15 is/are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim(s) 15 is/are directed to Abstract Idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because of the 2-step Analysis as following. Step I: the claim is directed to a method as a statutory category. Step 2a Prong 1: The recited steps of "monitoring" (requests); "filtering" (requests based on filters); "determining" (intent requests); "generating" (multiple solutions); "identifying" (an optimized solution) are perceived as activities that can be performed by a mental process; notably when these activities are not depicted as being tied up to any special technical adaptation or unconventional equipment or physical machine. The above steps are descriptive of one human who, upon receiving information via a generic computer showing one or more requests content, is able to "filter" the contents and derive therefrom a solution (as well as one particular version thereof) which the human deems most optimized using a well-known computer-based numerical or mathematical technique (cross validation tree). The method claim includes what amounts using known techniques for determining data that can be performed by (resulted from) a mental process (using a generic computer) typical to an Abstract Idea type of Judicial Exception. See MPEP 2106.04(a) The steps of "monitoring one or more requests," "filtering... based on dynamic filters," "determining intent," "generating multiple solutions," and "identifying an optimized solution" constitute concepts performed in the human mind or steps that can be practically performed mentally (e.g., analyzing input requests, evaluating intent, comparing solutions against risk criteria, and choosing the best outcome); whereas the limitation "identifying an optimized solution... via a cross validation decision tree" recites a mathematical algorithm and statistical classification methodology. These limitations in all fall within the Mental Processes and Mathematical Concepts groupings of abstract ideas. MPEP 2106.04(a) Prong two: The method claim recites abstract concepts using generic software and hardware elements (e.g., "entity network," "isolated environment," "generative artificial intelligence engine," "channel"). Under MPEP § 2106.04(d), applying an abstract idea using generic computer components operating according to their routine, conventional functions does not integrate the abstract idea into a practical application. That is: Executing code via an "isolated environment" (e.g., a sandbox) and an "AI engine" is reciter-level functional execution of data processing, not details showing how AI is carried out or achieves a transformation or improvement to a issue or technical problem. The steps recited as "monitoring testing" and "fine-tuning" (based on test results) represent a well-understood routine, conventional post-solution activity and basic feedback loop concepts (MPEP § 2106.04(d)(ii)). The claim does not recite an improvement to the operational functioning of the computer or network system itself; rather, it merely uses generic computing resources as a tool to execute the abstract logic of threat filtering and component generation. Claim 1 limitations as mentioned above fail to integrate the abstract Idea into a practical application. Step 2b: The hardware/system limitations ("network," "channel," "isolated environment") are well-understood, routine, and conventional components in the software processing art. The mathematical decision tree and AI execution steps are stated at a high level of functional generality ("generating multiple solutions," "executing... to detect exposures"); i.e. dictating what result is achieved rather than how the system's underlying technical capabilities are structurally improved (MPEP § 2106.05(f)). The addition of the buzzword terms "zero-trust" and "generative artificial intelligence engine" does not transform the abstract idea into a patent-eligible concept, as these elements are invoked strictly to carry out standard data analysis functions without specific hardware or algorithmic structure recited in the claim. Further, additional elements identified as "generating a deployable component" and "executing" (the component). The use of generic computer for a human to derive a component or executable component amounts to a well understood implementation associated with post-activity that makes use of information obtained from a mental process, thus the "generating" and "executing" are mere post-activities that rely of result from a mental process such as monitoring, filtering, determining and identifying a solution; and as such cannot render the Abstract Idea into non- conventional technique that signifies much more than a Judicial Exception. From the claim construed as a whole, no technical feature in the preamble is seen as directly involved with the mental process of step IIA. That is, mere use of mental derivation from presented data from a computer without showing how the post activities (additional elements as set forth above ) bring forth a defined instance of transforming an existing technology into a better one, of realizing a solution to an existing problem; that is, the additional elements thus identified cannot add significantly more to the Judicial Exception identified in step 2a. See MPEP 2106.05 (II) c, d. Claim 15 is therefore non-eligible under the 35 USC § 101 statute. Claims 1 and 8 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim(s) 1 and 8 is/are directed to an Abstract Idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the following 2 steps Analysis Eligibility of claim 1 step I: this claim is directed to a system claim. Step 2a Prong one: The system of claim 1 includes instruction steps of "monitoring" (requests); "filtering" (requests based on filters); "determining" (intent requests); "generating" (multiple solutions); "identifying" (an optimized solution); and as no details are provided for coordinating a processor with the above steps in a non-conventional way, the above steps are construed as being performed with use of a generic computer to provide information to the steps of monitoring, filtering, determining and identifying, similar to the scenario about a user mentally processing information presented via a computer in order to identify, re-arrange or derive other information from the initial information, which fall under a deficiency of mental process or Abstract Idea type of Judicial Exception. See MPEP 2106.04 (a) to (d) For instance, the steps of "monitoring one or more requests," "filtering... based on dynamic filters," "determining intent," "generating multiple solutions," and "identifying an optimized solution" constitute concepts performed in the human mind or steps that can be practically performed mentally (e.g., analyzing input requests, evaluating intent, comparing solutions against risk criteria, and choosing the best outcome); whereas the limitation "identifying an optimized solution... via a cross validation decision tree" recites a mathematical algorithm and statistical classification methodology. These limitations in all fall within the Mental Processes and Mathematical Concepts groupings of abstract ideas. MPEP 2106.04(a) Prong two: The method claim recites abstract concepts using generic software and hardware elements (e.g., "entity network," "isolated environment," "generative artificial intelligence engine," "channel"). Under MPEP § 2106.04(d), applying an abstract idea using generic computer components operating according to their routine, conventional functions does not integrate the abstract idea into a practical application. That is: Executing code via an "isolated environment" (e.g., a sandbox) and an "AI engine" is reciter-level functional execution of data processing, not details showing how AI is carried out or achieves a transformation or improvement to a issue or technical problem. The steps recited as "monitoring testing" and "fine-tuning" (based on test results) represent a well-understood routine, conventional post-solution activity and basic feedback loop concepts (MPEP § 2106.04(d)(ii)). The claim does not recite an improvement to the operational functioning of the computer or network system itself; rather, it merely uses generic computing resources as a tool to execute the abstract logic of threat filtering and component generation. Claim 1 limitations as mentioned above fails to integrate the abstract Idea into a practical application. Step 2b: The hardware/system limitations ("network," "channel," "isolated environment") are well-understood, routine, and conventional components in the software processing art. The mathematical decision tree and AI execution steps are stated at a high level of functional generality ("generating multiple solutions," "executing... to detect exposures"), as rather dictating what result is achieved rather than how the system's underlying technical capabilities are structurally improved (MPEP § 2106.05(f)). The addition of the buzzword terms "zero-trust" and "generative artificial intelligence engine" does not transform the abstract idea into a patent-eligible concept, as these elements are invoked strictly to carry out standard data analysis functions without specific hardware or algorithmic structure recited in the claim. Further, additional elements identified as "generating a deployable component" and "executing" (the component). The use of generic computer for a human to derive a component or executable component amounts to a well understood implementation associated with post-activity that makes use of information obtained from a mental process, thus the "generating" and "executing" are mere post-activities that rely of result from a mental process such as monitoring, filtering, determining and identifying a solution; and as such cannot render the Abstract Idea into non- conventional technique that signifies much more than a Judicial Exception. From the claim construed as a whole, no technical feature in the preamble is seen as directly involved with the mental process of step IIA. That is, mere use of mental derivation from presented data from a computer without showing how the post activities (additional elements as set forth above ) bring forth a defined instance of transforming an existing technology into a better one, of realizing a solution to an existing problem. That is, the additional elements thus identified cannot add significantly more to the Judicial Exception identified in step 2a. See MPEP 2106.05 (II) c, d. Eligibility of claim 8 Step I: the claim is directed to a product category. Step 2a Prong one: Claim 8 includes instruction steps of "monitoring" (requests); "filtering" (requests based on filters); "determining" (intent requests); "generating" (multiple solutions); "identifying" (an optimized solution); and as no details are provided for coordinating a processor with the above steps via a non-conventional technique, the above steps are construed as being performed with use of a generic computer to provide information to the steps of monitoring, filtering, determining and identifying, similar to the scenario about a user processing information presented via a computer in order to identify, re-arrange or derive other information from the initial information, which fall under a deficiency of mental process or Abstract Idea type of Judicial Exception. MPEP 2106.04 (a to d) Prong two: This product claim recites abstract concepts using generic software and hardware elements (e.g., "entity network," "isolated environment," "generative artificial intelligence engine," "channel"). Under MPEP § 2106.04(d), applying an abstract idea using generic computer components operating according to their routine, conventional functions does not integrate the abstract idea into a practical application. For instance: Executing code via an "isolated environment" (e.g., a sandbox) and an "AI engine" is reciter-level functional execution of data processing, not details showing how AI is carried out or achieves a transformation or improvement to a issue or technical problem. The steps recited as "monitoring testing" and "fine-tuning" (based on test results) represent a well-understood routine, conventional post-solution activity and basic feedback loop concepts (MPEP § 2106.04(d)(ii)). The claim does not recite an improvement to the operational functioning of the computer or network system itself; rather, it merely uses generic computing resources as a tool to execute the abstract logic of threat filtering and component generation. Claim 8 limitations as mentioned above fails to integrate the abstract Idea into a practical application. Step 2b: The hardware/system limitations ("network," "channel," "isolated environment") are well-understood, routine, and conventional components in the software processing art. The mathematical decision tree and AI execution steps are stated at a high level of functional generality ("generating multiple solutions," "executing... to detect exposures"), as rather dictating what result is achieved rather than how the system's underlying technical capabilities are structurally improved (MPEP § 2106.05(f)). The addition of the buzzword terms "zero-trust" and "generative artificial intelligence engine" does not transform the abstract idea into a patent-eligible concept, as these elements are invoked strictly to carry out standard data analysis functions without specific hardware or algorithmic structure recited in the claim. Further, additional elements identified as "generating a deployable component" and "executing" (the component). The use of generic computer for a human to derive a component or executable component amounts to a well understood implementation associated with post-activity that makes use of information obtained from a mental process, thus the "generating" and "executing" are mere post-activities that rely of result from a mental process such as monitoring, filtering, determining and identifying a solution; and as such cannot render the Abstract Idea into non- conventional technique that signifies much more than a Judicial Exception. From the claim construed as a whole, no technical feature in the preamble is seen as directly involved with the mental process of step IIA. That is, mere use of mental derivation from presented data from a computer without showing how the post activities (additional elements as set forth above ) bring forth a defined instance of transforming an existing technology into a better one, of realizing a solution to an existing problem. That is, the additional elements thus identified cannot add significantly more to the Judicial Exception identified in step 2a. See MPEP 2106.05 (II) c, d Analysis of dependent claims under step 2b: Claims 2, 9, 16 recite "determining" more channels for executing and selecting one for executing the component; but these can be viewed as generic technique of using computer support (post-activity) that makes use of information resulted from a mental process, hence cannot make the mental process to amount to significantly more than a judicial Exception. Claims 3, 10, 17 recite "filtering" as categorizing requests based on filters, and as such fail to integrate the mental process into a practical application that otherwise necessitates special machine and non-conventional software algorithms. Claims 4, 11,18 recite instructions to generate filters and this can be viewed as pre-activity or preparation stage in place to support the mental activities; hence the "generating" fails to demonstrate how the mental process identified in step IIA perform a transformation or inventive step that improves upon an existing technological situation. Claims 5, 12, 19 recite instructions to update dynamic filters based on executing a deployment; there is not sufficient teaching with the update limitation to demonstrate that monitoring, filtering, determining or identifying acts of the base claim would actually cause transformation of an actual technology to arrive at an improved state thereof as result from the updated filter; nor is there clear relationship between the updating filters context with optimized solution and generating software component for addressing incoming requests as part of the adaptive intelligence set in the preamble; hence claims 5,12, 19 fail to transform the mental process of the base claim into a substantially much more significant inventive technology than a Judicial Exception Claims 6, 13, 20 recite instructions to identify a optimized solution using a decision tree. Use of numerical technique or mathematical processing means as a validation technique are construed as well-understood technique to support analyses or derivation of solutions, and employ of mathematical techniques can fall under one category of Judicial Exception type infringement. Claims 7, 14 recite generating a unique ID a link to the requests, but this processor action amounts to a pre-activity to the mental process of tracking and deriving data from the request, therefore cannot integrate this mental process into a practical application. In conclusion, claims 1, 8, 15 are therefore un-eligible subject matter for failing compliancy established under the USC 101 statute Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 is/are rejected under § 35 U.S.C. 103 as being unpatentable over Miller et al, USPubN: 2024/0354641 (herein Miller) in view of Loughmiller et al, USPubN: 2005/0076084 (herein Louchmiller), and Bollinger, III, USPubN: 2023/0171282 (herein Bollinger) and further in view of Jones et al, USPubN: 2025/0150474(herein Jones) and Gunnels et al, USPubN: 2025/0141916 (herein Gunnels). As per claim 1, Miller discloses a system (e.g. Fig. 3-4) for generating deployable components associated with software applications for incoming requests via an adaptive zero-trust generative artificial intelligence engine (para 0070-0071), comprising: at least one processing device; at least one memory device (para 0327-0328); and a module stored in the at least one memory device comprising executable instructions that when executed by the at least one processing device, cause the at least one processing device to: monitor (tracking technology - para 0055; tracks interaction functions, posts the user like, share spend on the platform - para 0072; interaction server - para 0031 ) one or more requests (incoming network requests - para 0031; intent of the user and entities identify and extract important information such as a request - para 0110) entering an entity network (interaction server - Fig. 2; para 0027-0028) associated with an entity (intent of the user and entities identify and extract important information such as question of the user or a request - para 0110); filter(component 404 - Fig. 4) the one or more requests (e.g. posts the user like, share spend on the platform - para 0072; incoming network requests - para 0031) based on one or more filters (e.g. component 404 filters the raw content 420 based on a set of filtering criteria to eliminate obscene words, images, or concepts or content that some may consider harmful - para 0121); determine intent ( AI agent system 400 determines the intent 422- para 0114; AI agent, understand and respond to an input of the user - para 0119; content response component 412 to generate one or more content items using the intent 422 component 412 communicates the content items to the response filter 404 - para 0120; filter component 404 generates an adjusted intent based on filtering the raw content - para 0121) associated with the one or more requests (para 0072, 0031) based on filtering the one or more requests (see above); generate multiple solutions (generate one or more content items 410 using the intent 422 - para 0120; one or more content items 410 - para 0111; using deep learning techniques more accurate and relevant content suggestions for users enables content recommendations to be generated - para 0025; generative AI system 231 inference data that is output include translations, summaries, categorization recommendation - para 0070; models to provide … relevant content recommendations – para 0188; AI agent system … responds with a recommendation – para 0177; generate more relevant and personalized content recommendations … improve various application/AR experiences – para 0175; recommendations that take into account user’s preferences and interests – para 0164; para 0156; learning model to generate recommended content – para 0152) to achieve the intent (extracted information from the intent 414 to determine the appropriate content items 410 – para 109; receive the intent 422 and generate a prompt based on the intent generates the one or more content items 410 - para 0111) associated with the one or more requests (see above); generate a deployable component (interaction options that are displayed, options to suggest chat topics to the user, to guide the user options comprise suggestions of conversations, or interaction steps - para 0123; receive output recommended content - para 0307; generate recommended content for the user - para 0315 – Note1: machine learning or AI generated recommendations or responses to a problem so that a subset of training data associated with the AI model is being testing separately and cross validated reads on one or more components associated with a AI-derived solution that is deployable as test sets or test data) associated with the optimized solution (see AI-generated recommendations from above); and monitor testing (see tuning and refinement from below) of the deployable component (para 0264; splitting the data … and testing sets, separate testing dataset – para 0270-0271; tested on a new dataset – para 0285) associated with the optimized solution (particular problem or desired response – para 0270) and perform modifications (training and testing sets, using cross-validation, tuning hyperparameters – para 0270; validation, refinement or retraining – para 0273) to fine-tune the deployable component (Note2: testing particular dataset portion of a machine learning with effect of separately and indirectly fine-tuning the model, and precluding overfit/underfit by the model – para 0264, 0271 – reads on monitoring model parameters and validating output of the model from re-assessed test results that are particularly conducted or rerun to support that validation or refinement or cross-validation) based on monitoring results of the testing of the deployable component (see Note1); execute the deployable component (applying the recommended content to a first interaction client - para 0316; see applying the recommended content - para 0307; applying the recommended content - para 0307- claim 1, pg. 30; applying the recommended content - para 0315) via a channel (identifying a preferred communication channel for the recommended content - para 0312) A) Miller does not explicitly disclose determining intent associated with the requests based on one or more dynamically changing filters Loughmiller discloses use of neural network to classify incoming messages (e.g. mail - para 0014; incoming mail traffic - para 0037) in categories (para 0010) as part of identifying spams ("unwanted messages" - para 0023; "important message" - para 0025; spam filter 250 - Fig. 2; para 0047) via a dynamic message filtering (para 0025-0026; spam messages are blocked - para 0119) approach, where a natural language processing of the incoming messages provides regular expressions (Fig. 4; para 0059) derived therefrom as input into the neural network algorithms (para 0013) to determine intent of the messages (para 0052, 0114) using classification (para 0087) underlying the artificial NN filtering or AI engine to categorize good/spam portion of the message (Fig. 3; para 0088; Fig. 5), the dynamic (message) filtering including manipulating rules (e.g. dynamically updated - para 0121) of the classification as input vector into a next instance of neural network (e.g. re-evaluated by the second neural network - para 0102) engine that implements the dynamic filtering, including provision of UI for users or administrators to interactively modify spam filtering preferences (para 0054, 0056), where learning and tagging (para 0026,0047) by the neural network can be adapted for generating defensive strategies against senders of spam (para 0117) Hence, use of artificial intelligence as in Loughmiller for filtering received message content and determining of intent as part of the re-evaluation instance of a neural network via use of classification rules or filtering preferences that are dynamically modified to support the dynamic filtering aspect of the AI engine entails AI-based determination of intent associated with the requests based on one or more dynamically changing filters. Therefore, based on the highly adaptive aspect of AI inferencing functionality in regard to tailoring the analysis and AI recommendation to the user intent (Miller: para 0071) it would have been obvious before the effective filing date of the invention for one skill in the art to implement the modifiable aspect of the Al based analysis so that Al -based categorization of user content and intent would be supported by adaptive filtering implemented with artificial intelligence engine equipped with adaptive capability to alter classification rules in terms of adjusting and dynamic changing of filter settings associated with the AI(neural network) engine - as in per Loughmiller dynamic adjusting to support a neural network-based filtering of classification outcome - in accordance to finetuning aims of the AI engine associated with classifying/reclassifying contents and determination of intent associated with tracking users messaging or incoming requests by Miller; because combining AI type of classification and finetuning effect by one such AI engine via iteratively modifying filtering information -as set forth above - as reconfigurable input into different AI or classification engine to further refine the training analytics toward achieving the most optimal set of filtered outcomes associated with monitoring of incoming NW data or requests and the underlying aim for determining user/request intent and categorizing the message or requests based thereon would enable the Al-based system to implement response that is commensurate with the identified intent, including a) issuing recommendation for application/business to conduct, b) proffering UI options to users to elect for resolving/repairing a solution/problem raised with the request; or c) dispatching countermeasures to mitigate, war- off threats envisioned from a impermissible, malicious intent detected from the monitoring; that is, a proper use of filter settings so that a modified and adjusted version thereof can be submitted into a respective run by the AI- based classification engine would highly enhance likelihood of the engine to derive the most optimal set of filtered outcomes that are representative of the most accurate identification of the intent with which to classify a request, which in turn would facilitate the AI-based multi-modality analytic in Miller to generate recommendations or alternative solution set forth above as a) b) and c). B) Miller does not explicitly disclose generating multiple solutions in terms of (i) execute, via a zero-trust generative artificial intelligence engine, each of the multiple solutions in an isolated environment to detect exposures associated with fulfilling the one or more requests; (ii) identify an optimized solution from the multiple solutions via a cross validation decision tree As for (i) Jones discloses machine learning engine as backbone for developing, deploying solutions, including model training, evaluation and hyperparameter tuning (para 0085-0086), the training including a preprocessing (or post-processing) module in form of dataset security AI engine configured to ensure that no sensitive or dubious data could lead to a security exposure (para 0048; claims 17-20, pg. 14), the generative AI security engine by way by of artificial intelligence (LLM) including intent detection, prompt context and attack detection (malicious intent, illegal breach, violent intend, unlawful intent, prompt attack, spam, phishing, privacy violation, offensive content etc.) accompanied with redaction thereof to protect against privacy leakage, the security support operating a preprocessing engine and post-processing engine over training dataset (para 0021-0024). Thus, use of a zero-trust artificial intelligence engine operating as a pre-processing or post-processing security model to detect, reveal various exposure types and bad intents to provide generative response to communication data associating a request and a response (see Abstract) is recognized. Gunnels discloses artificial intelligence ML to address vulnerabilities, with potential remediation thereof, using DB vulnerabilities (para 0029-0030) and a generative AI or ML to generate the solution or remediation on-the-fly, via a sandboxed execution, while also exposing network operators or providers in direction of bad actors thereby for the providers to implement of solutions remediations (para 0024); e.g. open-source SW, firmware based activities or script-based, user-guided remediation implementation (para 0025). Hence, use of AI operative in isolated environment to generate remediation and exposing entities associated with automating activities and solution implementation; e.g. to address vulnerabilities is recognized. Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to implement machine learning and intelligence thereof in Miller so that in seeking a most usable and efficient multiple solutions, the recommendation framework of Miller include security-bound capability configured to execute, via a zero-trust generative artificial intelligence engine – as in Jones- each of the multiple solutions derived in an isolated AI environment – as in Gunnels - to detect exposures or acting entities associated with fulfilling the one or more requests – as in Jones and Gunnels; because attaching a security screening and exposure detection AI as part of preprocessing training data and post-processing training output as set forth above using a generative AI engine operating in sandboxed runtime would provide structural and operational benefits associated with evaluating incoming client requests for potential security exposures and vulnerabilities, according to which, if client requests contain ill-conceived prompt injections, unsafe code or malicious payload designed to exploit security weakness of the system, the impact caused thereby would remained contained entirely within a isolated/sandboxed environment, so that malicious code/exploitation cannot breach the perimeter of the AI engine to contaminate the rest of the filesystem; and where study of a bad behavior or telemetry thereof in a isolated environment can be extended to trigger calls or modifications that particularly circumvent the vulnerabilities detected by the AI, assuring thereby a threat monitoring and vulnerability averting being integrated the AI framework for providing recommendations that match the intent of user requests as well as safe execution of the proposed solution/action based thereon. As for (ii) Miller discloses use of advanced modeling techniques such as artificial intelligence models or numerical methods such as decision tree (see Miller: para 0109, 0260, 0263, 0265) to resolve complexity among compared datasets; or cross-validation (see below) was known techniques to support simplification in selecting or identifying a most optimal set of configurations among comparable possibilities, as part of multi-modalities comparative analytics where such techniques are integrated with machine learning or artificial intelligence as a means of evaluation of a trained model in terms of cross-validation associating tests of datasets suspected of the ML overfit/underfit so to finetune the hyperparameter and improve outcome of the Machine learning (para 0270-0271); to reduce complexity in model selection (para 0283) and render the refinement for training more effective (para 0273, 0284), the refinement of the selected training model (Fig. 13) facilitating a corresponding deployment. Hence, optimizing performance of AI-generated solutions by finetuning its parameters via cross-validation and test refinement is recognized. Bollinger discloses environment for identifying vulnerabilities and providing solution associated therewith (see claim 1, pg. 10) wherein cross-validation is applied to subgroups of training sets (para 0079) into a machine learning to generate the most optimum set among the performance scores for respective training procedure(s), where a trained model satisfying threshold of such score (para 0080) can be used for further observation, where the best overall cross-validation score combined with decision-tree algorithm (para 0081), enables the new observation to be set for target solution, according to which, applying a trained machine learning model to a new observation can predict update software for the variable of the solution (para 0085), e.g. in association with identifying anomalies and solutions for an environment (para 0083; determine asset vulnerabilities and the solution thereof - para 0086) in that the trained machine learning may predict target variable of a solution (Fig. 6B; target variable is a determination of whether a solution should be implemented - para 0072) to be implemented in conjunction with use of decision-tree algorithm (para 0076-0077) to help hyper-parameterization narrowing among a plurality of observations complicated by multitude branching possibilities. Hence, use of cross-validation to determine the highest score dataset to be selected for further application of machine learning geared to predict a target variable indicative of whether a solution should be implemented as part of the identification of vulnerabilities and seeking of solution assisted with (training) parameter simplification via decision- tree algorithms is recognized. Thus, as AI techniques in Miller are geared for determination of intent from monitored requests or messages, it would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to implement use of artificial intelligence in conjunction with cross-validation and decision tree support in Miller so that under the AI analytics, generating solutions to correspond to the (determined) intent would be finetuned to identify an optimized solution from the multiple solutions via a cross-validation decision tree - as shown in Bollinger seeking of solution for vulnerabilities - and generate a deployable component associated with the optimized solution, the latter based on finding a most optimum cross-validation score dataset with which to applying a predictive training instance that would yield a target variable indicative whether a solution among other possibilities should be implemented; because intelligent techniques to finetune determination of request category and nature of intent can be indicative of component or applicable set to recommend to the requesting users or business entities of the provisioning platform, and artificial techniques to compute the most optimum set for the training via applying a cross-validation - and selecting of highest cross-validation score as set forth above- would enable applying the AI training to a most optimum input so to improve chance to predict/yield among multiple target solutions a best target considered the most optimal solution; and use of decision tree to narrow down parameterization of the training resulting from the cross- validated input would further improve chance that a most optimum variable or target output indicative of a most effective solution will be attained, thereby for the platform to convert this optimal solution into one or more actionable components (deployable solution) to recommend to the users whose requests have been tracked; or to implement it as countermeasure against undesirable intents such as vulnerability or malicious intrusion into assets of the system. As per claim 2, Miller discloses system according to claim 1, wherein the executable instructions cause the at least one processing device to: determine one or more channels (see below) for executing the deployable component; and select the channel of the one or more channels (preferred communication channel for the recommended content - para 0312) for executing the deployable component (applying the recommended content to a first interaction client - para 0316; see applying the recommended content - para 0307; applying the recommended content - para 0307- claim 1, pg. 30; applying the recommended content - para 0315) based on the intent (refer to claim 1; intent of the user and entities identify and extract important information such as a request - para 0110) associated with the one or more requests. As per claim 3, Miller does not explicitly disclose system according to claim 1, wherein filtering the one or more requests comprises categorizing the one or more requests based on the one or more dynamically changing filters. But use of machine learning techniques with classification function equipped with input filtering SO to better categorize user message or communicated text on basis of a intent where the filtering of trained data is effectuated with dynamically modification of the filters prior to each classification run has been rendered obvious via rationale A in claim 1 via the teachings by Loughmiller. Therefore, effect of filtering the one or more requests comprises categorizing the one or more requests based on the one or more dynamically changing filters would be deemed obvious for the same reasons set forth with rationale A from above. As per claim 4, Miller does not explicitly disclose system according to claim 1, wherein the executable instructions cause the at least one processing device to generate the dynamically changing filters based on historical request processing data. Loughmiller implements dynamic filtering of message in which the filtering preferences can be modified via a UI (para 0054-0056), where rules on blocking messages can be adjusted (dynamically updated - para 0121), as part of consolidation of filters or filter settings by administering effect of blocking and granting passage to messages, which is based in part of past or existing request processing instances recorded in form of blacklists or whitelists (para 0007, 0012) such that consulting these lists (para 0087) enable administrative action or re-evaluation thereby in regard to prioritize passing (good or important messages) or enforcing anti-spam to messages considered spams from the lists (para 0026), where maintaining the blacklists and whitelists is responsive to classification of the message (claim 12 pg. 9) Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to implement dynamic adaptation of filter setting in Miller's AI approach so that adjusting the filtering or dynamically manipulation to filter setting is based in part on historical request processing shown by blacklist and whitelist being administratively maintained in Loughmiller; because consulting past processing data - as set forth above - in evaluating incoming requests or messages for their intent and portent risk of intrusive spam would facilitate prompt administrative evaluation as to whether message or content belonging to a white-listed category be prioritized for quick pass-through, or else, content belonging to a black-listed category be turned away or inflicted with immediate anti-spam counter measures. As per claim 5, Miller does not explicitly disclose system according to claim 4, wherein the executable instructions cause the at least one processing device to update the dynamically changing filters based on outcomes associated with executing the deployable component. However, deployable content, SW component or interactive options provided as recommendation (recommended content - para 0307; generate recommended content for the user - para 0315) using the intent-based and personalized AI analytics in Miller signifies by virtue of obviousness that any deployed application, SW component or contents will eventually return as contents (para 0059) messages, posting, queries or requests from the user (see Miller: message posted by a user to the interaction system - para 0060) using component or content from the recommendation, back to the recommendation provider system. As dynamically adjusting configuration of security preventive rules or reconfiguring parameters of filters would be deemed obvious (refer to rationale of A in claim 1) so as to effectively meet complexity of activity types, user intents or disparate nature of vulnerability threats, expanding use of dynamically changing filters to the content, message or returning requests from the user application context that execute the deployable component originated from the Miller's personalized AI or recommendation framework would be also deemed evident or obvious. Thus, it would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to implement tracking of incoming requests in support of the intent-based intelligent analytics and recommendation system in Miller, so that filters of incoming user messages/ requests is configured with dynamic readjust of the filtering rules and parameters as set forth in rationale A in claim 1( per dynamically changing filters by Loughmiller) so that the same effect of applying the dynamically changing filters would also be adapted towards all incoming data resulting from the users executing components or interacting with UI content resulting from one or more deployable components or recommended solutions provided by Miller's intent-based analytics; because scaling up effect of dynamically changing filters in just proportion to a) meet the ups and downs of demand for user request resulting from the user deploying the component recommended by the system and b) adapt a front-end prevention toward further confrontation with undesirable requests or intents, unverified/untrusted intrusions, or vulnerabilities attempts caused by augmented user activities resulting from deploying component recommended from above, would fall under the ambit of having adaptive filter capability configured at the entry points into the system, so that modifying setting or rules of the filter entities per a dynamic and extended basis would represent a self-adjusting or auto-improving front-end technique that not only fends off ill-intents or malicious, undesirable, intrusions into the system in a scale commensurate with size and complexities of the incurred threat or challenge; but also would boost effectiveness of system's front-end classification in regard to received data independent of the size of data and time of day, which in turn would further enhance throughput of the AI analytics and performance of the intent-driven solution recommendation system. As per claim 6, Miller does not explicitly disclose system according to claim 1, wherein the executable instructions cause the at least one processing device to identify the optimized solution from the multiple solutions via the cross-validation decision tree based on performing impact analysis on the multiple solutions But Bollinger solution seeking for resolving vulnerabilities discloses assessing as to whether a solution should be implemented via recursive training of highly score training set so that only the training set with the highest cross-validation score (para 0080-0081) would qualify to a next training refinement that yield the best variable representative of a target solution (para 0084-0085), in accordance with purport of a risk management framework (RMF) for establishing priorities and managing risk and organization security by monitoring (Fig. 1) and categorizing (of received input, internal asset) based on impact analysis (para 0030) by means of asset management, solution component (Fig. 4), where multiple solutions are subjected to evaluation on basis of observations run through intelligent models (Fig. 6A; para 0082) seeking acceptability of a applicable solution; which is indicative of sequence of artificial intelligence runs purported for assessing whether a deployable solution would yield either a favorable deployment impact or else constitute an impact of a deployment setback. Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to implement the intent-driven evaluation of solution or recommendation of content/components in Miller personalized AI system so that identifying the optimized solution (from the multiple solutions considered for a recommendation) via machine learning combined with cross-validation-decision tree as set forth above (refer to rationale B of claim 1) would be coupled with result from an impact analysis - as per Bollinger - as guidance in establishing and weighing applicability of a solution (for a target deployment) by means of assessing multiple solutions obtained from the iterative runs of training models - as shown in Bollinger; because coordinating of AI analytics in correlation with impact analysis suggestive of solution deployment feasibility so to further re-adapt training sets into a AI machine learning, on basis of refinement made to training sets via cross-validation, decision-tree by which the intelligent training can be recursively tuned to identify the most optimized solution - as set forth above- would enable multiple solutions resulting from cycles of AI training to be consolidated into one most optimum, in that the solution would not only result from the most optimum set of training input which incorporates the most representative, significant and context relevant data from a filtering and classification stage; but would also benefit from one or more evaluations under impact analysis which pre-establishes measurable likelihood by which a given solution proposed from any stage of the AI analytics can be determined as secure, resource-compliant and fault-free for a final stage of deployment to the users. As per claim 7, Miller does not explicitly disclose system according to claim 1, wherein the executable instructions cause the at least one processing device to: generate a unique identifier (generate AR experience on the image currently being accessed, viewed by the user system AI agent generate the unique AR experience activate the AR experience on the user system - para 0092) for the one or more requests; and link the unique identifier (unique AR experience - para 0092) to the one or more requests (capture or access an image - para 0092) to allow tracking processing associated with the one or more requests (Note3: entity table storing instances of objects, events, individuals to which a access recognized as a AR experience - generated unique AR experience - by the AI agent can be linked to the table item - Table 808, Fig. 8; entity table is linked referentially to an entity graph and profile data, each entity is provided with a unique identifier - para 0194 - in association with a given user attempt to access/view the entity - e.g. image - reads on generating a unique identifier to a user access request for facilitating linkage of the user request to the unique identifier) As per claim 8, Miller discloses a computer program product for generating deployable components associated with software applications for incoming requests via an adaptive zero- trust generative artificial intelligence engine, comprising a non-transitory computer-readable storage medium having computer-executable instructions for: monitoring one or more requests entering an entity network associated with an entity; filtering the one or more requests based on one or more dynamically changing filters; determining intent associated with the one or more requests based on filtering the one or more requests; generating multiple solutions to achieve the intent associated with the one or more requests; executing, via a zero-trust generative artificial intelligence engine, each of the multiple solutions in an isolated environment to detect exposures associated with fulfilling the one or more requests; identifying an optimized solution from the multiple solutions via a cross validation decision tree; generating a deployable component associated with the optimized solution; monitoring testing of the deployable component associated with the optimized solution and perform modifications to fine-tune the deployable component based on monitoring results of the testing of the deployable component; and executing the deployable component via a channel. ( All of which having been addressed in claim 1) As per claims 9-10, refer to rejection of claims 2-3 respectively. As per claims 11-12, refer to rejection of claims 4-5 respectively. As per claims 13-14, refer to rejection of claims 6-7 respectively As per claim 15, Miller discloses a computerized method for generating deployable components associated with software applications for incoming requests via an adaptive zero-trust generative artificial intelligence engine, the method comprising: monitoring one or more requests entering an entity network associated with an entity; filtering the one or more requests based on one or more dynamically changing filters; determining intent associated with the one or more requests based on filtering the one or ore requests; generating multiple solutions to achieve the intent associated with the one or more requests; executing, via a zero-trust generative artificial intelligence engine, each of the multiple solutions in an isolated environment to detect exposures associated with fulfilling the one or more requests; identifying an optimized solution from the multiple solutions via a cross-validation decision tree; generating a deployable component associated with the optimized solution; monitoring testing of the deployable component associated with the optimized solution and perform modifications to fine-tune the deployable component based on monitoring results of the testing of the deployable component; and executing the deployable component via a channel. ( All of which having been addressed in claim 1) As per claims 16-20, refer to rejection of claims 2-6 respectively. Response to Arguments Applicant's arguments filed 6/05/26 have been fully considered but they are not persuasive. Following are the Examiner’s observations in regard thereto. (A) The Applicant has submitted that the added limitations including “generative AI executing in a isolated environment”, “monitor testing and perform modification to the deployable” are concrete operations that a human mind cannot perform, since these technical steps improve the functioning of a computer system and quality/security of deployable content such as covering a particular solution to a problem such as that affected by exposure attacks or malicious activity (Applicant's Remarks pg. 8-9). The limitations as relied upon by the argument as part of an amended language, and eligibility merits of a limitation introduced for the first time cannot be ascertained since the amended language has yet to be prosecuted with a prima facie case prior to any rebuttal to be properly presented and take effect. (B) The Applicant has submitted that the multi-modal AI generation of recommendations is fundamentally different from “executing a generative AI engine in a isolated environment, each solution to detect exposures associated with fulfilling … one or more requests” and “monitoring testing of deployable component associated with the solution” (Applicant's Remarks pg. 10, top); nor does Loughmiller’s system of filtering messages for classification suggest “isolated environment” to “detect exposures” and “monitoring testing” as claimed; nor does Bollinger’s identification of security vulnerabilities and cross-validation teach about monitoring testing and executing a AI-generated solutions in isolated environment to “to detect exposures associated with fulfilling … one or more requests” (Applicant's Remarks bottom pg. 10) The allegations made upon limitations that are newly introduced are deemed largely MOOT because changes in the grounds of rejection newly set and directed against these limitations have been necessitated just recently and may include new prior art references. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Tuan A Vu whose telephone number is (571) 272-3735. The examiner can normally be reached on 8AM-4:30PM/Mon-Fri. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Chat Do can be reached on (571)272-3721. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-3735 ( for non-official correspondence - please consult Examiner before using) or 571-273-8300 ( for official correspondence) or redirected to customer service at 571-272-3609. Any inquiry of a general nature or relating to the status of this application should be directed to the TC 2100 Group receptionist: 571-272-2100. /Tuan A Vu/ Primary Examiner, Art Unit 2193 August 25, 2026
Read full office action

Prosecution Timeline

Feb 21, 2024
Application Filed
Mar 11, 2026
Non-Final Rejection mailed — §101, §103
Jun 05, 2026
Response Filed
Aug 28, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743276
METHOD AND SYSTEM FOR A CUSTOMIZED LOCAL BUILD ENVIRONMENT IMAGE
2y 10m to grant Granted Sep 22, 2026
Patent 12737427
MULTI-SECTION SUPPORT IN GRAPHICAL APPLICATION BUILDER
2y 11m to grant Granted Sep 15, 2026
Patent 12730694
VISUAL COMPONENTS IN A DATA-AGNOSTIC DASHBOARD RUNTIME ENVIRONMENT
2y 8m to grant Granted Sep 08, 2026
Patent 12728351
NON-TRANSITORY COMPUTER-READABLE STORAGE MEDIUM HAVING DATA EDITING PROGRAM STORED THEREIN, DATA EDITING SYSTEM, DATA EDITING METHOD, AND DATA EDITING APPARATUS
2y 8m to grant Granted Sep 08, 2026
Patent 12731030
METHOD FOR TRAINING NEURAL NETWORK MODEL AND APPARATUS
2y 5m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
94%
With Interview (+21.1%)
3y 6m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 997 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month