Prosecution Insights
Last updated: August 17, 2026
Application No. 18/789,397

SECURITY POSTURE GENERATION USING AN ARTIFICIAL INTELLIGENCE (AI) MODEL

Final Rejection §101§103
Filed
Jul 30, 2024
Examiner
ZOUBAIR, NOURA
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Google LLC
OA Round
2 (Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
264 granted / 361 resolved
+15.1% vs TC avg
Strong +61% interview lift
Without
With
+61.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
14 currently pending
Career history
379
Total Applications
across all art units

Statute-Specific Performance

§101
8.2%
-31.8% vs TC avg
§103
54.7%
+14.7% vs TC avg
§102
7.3%
-32.7% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 361 resolved cases

Office Action

§101 §103
DETAILED ACTION -Claims 1-3, 5-10, 12-17 and 19-20 are amended. -Claims 1-20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s Remarks filed on 5/15/2026 have been fully considered. With respect to the 101 rejection, the arguments were not found to be persuasive. Regarding Step 2A, Prong One, Applicant argues that a human cannot maintain a data structure storing cybersecurity data of an organization, however the claims do not recite maintaining such a data structure, the claims only recite retrieving data from the data structure. In addition, the data structure, even if positively claimed, may maintain only a limited number of data items. Regarding Step 2A, Prong Two, Applicant argues that the invention enables an AI model to produce more accurate or contextually aware responses, however it is not clear, based on the claim language, how this benefit is achieved. The claims simply recite providing input to a model, obtaining outputs from the model, and extracting, from the outputs, a set of generated features. Regarding Step 2B, the arguments are not persuasive since the claims still recite retrieving data based on a natural language description, combining the retrieved data with the natural language description and providing the combined data and additional telemetry data to a trained AI model. No additional elements are recited that amount to significantly more than the judicial exception. With respect to the 103 rejections, the argument that Ayyadurai teaches vector constraints being manually input by users is not persuasive because the same paragraph states that "machine learning algorithms can be employed to automatically identify and extract vector constraints 102 from unstructured text data, reducing the need for manual intervention in the data collection process”. Applicant’s arguments that are directed to the newly added features are moot in in view of the newly cited paragraphs, as necessitated by the claim amendments. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s) receiving data, analyzing the data, providing an output and extracting a set of generated features from the output and implementing the extracted features or adding further features. These steps may be performed in the human mind and are therefore they are mental steps. This judicial exception is not integrated into a practical application because it is not evident that the implementation of the features or the addition of further features provides a benefit or improvement to an existing technology. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because a general recitation of a trained AI model, without recitations of how the model operates or how it is trained such that a human cannot perform its functions, is not sufficient to add elements that are more than the abstract ideas. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ayyadurai et al (US Patent No.12,198,030). Re Claim 1. Ayyadurai discloses a method comprising: retrieving, based on a natural language description of a set of desired features of a security posture of a client organization of a cybersecurity platform, from a data structure storing cybersecurity data of the client organization, a subset of the cybersecurity data (i.e. Guidelines 302 can be any of the vector constraints 102 illustrated and described in more detail with reference to FIG. 1…….the relevant guidelines 302 can be specifically selected based on the specific context and requirements of the AI application being evaluated. For example, the system analyzes metadata tags, keywords, or categories associated with the guidelines 302 stored in the system's database. Using the specific context and requirements of the AI application, 308 the system filters and retrieves the relevant guidelines 302 from the database…….. the system identifies relevant compliance requirements and operational boundaries that must be complied with in an AI application.) [Ayyadurai, (54-56) (25)]; (i.e. train an ML model to construct validation actions that evaluate the AI application's compliance with the operation boundaries, ……………………. ………….vector constraints 102 are obtained from pre-existing databases or repositories maintained by regulatory bodies, industry organizations, and/or third-party providers. The databases can be periodically updated and synchronized with the validation engine 104 to ensure alignment with the latest regulatory changes and industry standards. Additionally, machine learning algorithms can be employed to automatically identify and extract vector constraints 102 from unstructured text data, reducing the need for manual intervention in the data collection process……….For example, even if the vector constraints 102 exist in different formats and structures, Natural Language Processing (NLP) techniques can be used to parse each text and identify key regulations, policies, and practices embedded within the differently formatted vector constraints 102. The validation engine 104 can identify specific terms, phrases, or clauses that likely denote regulatory requirements, as well as understand the context and intent behind the provisions….., the vector constraints 102 are categorized and tagged based on the extent of the vector constraint's relevance to different aspects of AI compliance (e.g., fairness, transparency, privacy, security)) [Ayyadurai, (28, 39-41)]; combining the retrieved subset of the cybersecurity data with the natural language description to generate a first input; providing the first input to a trained artificial intelligence (AI) model [Ayyadurai, Fig. 2 depicts the AI specific regulations and the organization regulations are combined and input into the ML/AI validation engine model]; providing telemetry data pertaining to a computing environment of the client organization as a second input to the trained AI model (i.e. The AI application 308 processes the command set and generates an outcome 310 and explanation 312 on how the outcome 310 was determined based on the AI application's 308 internal algorithms and decision-making processes. The outcome 310 and explanation 312 are evaluated by the assessment module 314, which compares the outcome 310 and explanation 312 against the expected outcomes and explanations specified in the test case 304 derived from the relevant guidelines 302……………..The AI application 1102 generates outputs based on input data and internal algorithms. These outputs are fed into the validation engine 1104, which employs algorithms and validation scripts to assess the compliance of the AI model in the AI application 1102 with predefined guidelines and criteria (e.g., test cases 1006a-n, 1008a-n, and 1010a-n in FIG. 10)) [Ayyadurai, (60, 143), Note: the outputs of the AI application are telemetry data and is input into the ML/AI model]; obtaining one or more outputs from the trained AI model; and extracting, from the one or more outputs, a set of generated features for the security posture of the client organization (i.e. Once the ML model is trained, the ML model can receive responses generated by the AI model in response to a given command set. The responses of the AI model can contain alphanumeric characters, and the ML model can identify the vector representations associated with each character within the response. …..…… In some implementations, the system can use a probabilistic approach, where the ML model assigns likelihood scores to different alignment indicators based on the observed frequency and significance ……….The meta-model 810 evaluates the AI application's compliance with the vector constraints through the use of validation actions 812 (e.g., using semantic search, pattern recognition, and machine learning techniques). Further evaluation methods in determining compliance of AI applications are discussed with reference to FIGS. 5-7) [Ayyadurai, (95, 99, 112, 127)], (i.e. allows organizations to identify areas of concern within the AI model and take appropriate actions to mitigate risks, ensure compliance) [Ayyadurai, (67)]. Ayyadurai does not disclose all the above in one embodiment however it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to combine the embodiments because: The elements and acts of the various examples described above can be combined to provide further implementations of the technology [Ayyadurai, col.41]. This motivation applies to the dependent claims. Re Claims 8 and 15. these claims recite features similar to those in claim 1, therefore they are rejected in a similar manner. Re Claims 2, 9 and 16. Ayyadurai discloses the features of claims 1, 8 and 15, further comprising: determining whether the set of generated features satisfies a security threshold criterion; and responsive to determining the set of generated features satisfies the security threshold criterion, implementing the set of generated features in the computing environment of the client organization (i.e. training is carried out iteratively until a convergence condition is met (e.g., a predefined maximum number of iterations has been performed, or the value outputted by the AI model 1230 is sufficiently converged with the desired target value), after which the AI model 1230 is considered to be sufficiently trained. The values of the learned parameters are then fixed and the AI model 1230 is then deployed to generate output in real-world applications) [Ayyadurai, (156)]. Re Claims 3, 10 and 17. Ayyadurai discloses the features of claims 1, 8 and 15, further comprising: determining whether the set of generated features satisfies a security threshold criterion based on a security specification (i.e. the vector constraints 102 can be encoded into a structured representation (e.g., JSON, XML), with specific fields for criteria, requirements, and/or thresholds. In some implementations, the vector constraints 102 are categorized and tagged based on the extent of the vector constraint's 102 relevance to different aspects of AI compliance (e.g., fairness, transparency, privacy, security)) [Ayyadurai, (41)]; and responsive to determining that the set of generated features does not satisfy the security threshold criterion, adding one or more additional features to the set of generated features (i.e. The set of generated validation actions 908 is provided as input to an AI application 910 in the form of a prompt. The AI application 910 processes the validation actions 908 and produces an outcome along with an explanation 912 detailing how the outcome was determined. Subsequently, based on the outcome and explanation 912 provided by the AI application 910, the system can generate recommendations 914 for corrective actions. The recommendations are derived from the analysis of the validation action outcomes and aim to address any identified issues or deficiencies. For example, if certain validation actions fail to meet the desired criteria due to specific attribute values or patterns, the recommendations can suggest adjustments to those attributes or modifications to the underlying processes…………… if certain attributes exhibit unexpected associations or distributions, the system can retrain the tested AI model with revised weighting schemes to better align with the desired vector constraints) [Ayyadurai, (130-131)]. Re Claims 4, 11 and 18. Ayyadurai discloses the features of claims 1, 8 and 15, further comprising: providing the set of generated features as an input to a second trained AI model; obtaining one or more outputs from the second trained AI model; and extracting from the one or more outputs, an indication of a validity of the set of generated features (i.e. In some implementations, where hyperparameters are used, a new set of hyperparameters is determined based on the measured performance of one or more of the trained ML models, and the first act of training (i.e., with the training set) begins again on a different ML model described by the new set of determined hyperparameters. The steps are repeated to produce a more performant trained ML model. Once such a trained ML model is obtained (e.g., after the hyperparameters have been adjusted to achieve a desired level of performance), a third act of collecting the output generated by the trained ML model applied to the third subset (the testing set) begins in some implementations. The output generated from the testing set, in some implementations, is compared with the corresponding desired target values to give a final assessment of the trained ML model's accuracy) [Ayyadurai, (155)]. Re Claims 5, 12 and 19. Ayyadurai discloses the features of claims 4, 11 and 18, further comprising: providing the natural language description of the set of desired features of the security posture of the client organization as a second input to the second trained AI model (i.e. In some implementations, where hyperparameters are used, a new set of hyperparameters is determined based on the measured performance of one or more of the trained ML models, and the first act of training (i.e., with the training set) begins again on a different ML model described by the new set of determined hyperparameters. The steps are repeated to produce a more performant trained ML model. Once such a trained ML model is obtained (e.g., after the hyperparameters have been adjusted to achieve a desired level of performance), a third act of collecting the output generated by the trained ML model applied to the third subset (the testing set) begins in some implementations. The output generated from the testing set, in some implementations, is compared with the corresponding desired target values to give a final assessment of the trained ML model's accuracy) [Ayyadurai, (155), Note: since the output is compared to desired target values, it implies that the desired target values are input into the second trained model]. Re Claims 6, 13 and 20. Ayyadurai discloses the features of claims 1, 8 and 15, further comprising: causing a visual representation of the set of generated features to be visually rendered via a graphical user interface (GUI) associated with a prompt to confirm whether the set of generated features satisfies a security threshold criterion (i.e. HITL validation 1106 allows users to provide feedback and annotations on the validation engine's 1104 conclusions and recommendations, assessing the validation engine 1104 for accuracy, fairness, and/or ethical compliance. The user feedback helps further ensure the AI application's 1102 compliance with regulatory requirements. In some implementations, the system includes user interfaces and feedback mechanisms that allow users to review the validation engine's 1104 conclusions and recommendations. For example, the system can include dashboard interfaces for visualizing the validation engine 1104's outputs, annotation tools for highlighting potential issues, and communication channels between users for adjusting the operational parameters of the validation engine) [Ayyadurai, (144)]. Re Claims 7, 14. Ayyadurai discloses the features of claims 1 and 8, further comprising: determining whether the set of generated features satisfies a security threshold criterion; and responsive to determining the set of generated features does not satisfy the security threshold criterion, extracting, from the one or more outputs, a second set of generated features for the security posture of the client organization (i.e. The set of generated validation actions 908 is provided as input to an AI application 910 in the form of a prompt. The AI application 910 processes the validation actions 908 and produces an outcome along with an explanation 912 detailing how the outcome was determined. Subsequently, based on the outcome and explanation 912 provided by the AI application 910, the system can generate recommendations 914 for corrective actions. The recommendations are derived from the analysis of the validation action outcomes and aim to address any identified issues or deficiencies. For example, if certain validation actions fail to meet the desired criteria due to specific attribute values or patterns, the recommendations can suggest adjustments to those attributes or modifications to the underlying processes…………… the ML model discussed in FIG. 6, the corrective actions can include implementing post-processing techniques in the tested AI model to filter out responses that violate the vector constraints (e.g., filtering out responses that include the identified vector representations of the alphanumeric characters)…………………………………………… use the overall metric to generate a set of actions to remove a portion of the set of responses generated by the AI model) [Ayyadurai, (130-131), (claim 1)]. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NOURA ZOUBAIR whose telephone number is (571)270-7285. The examiner can normally be reached Monday - Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Jul 30, 2024
Application Filed
Feb 17, 2026
Non-Final Rejection mailed — §101, §103
May 15, 2026
Response Filed
Jun 29, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12682022
SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR WORKSPACE CREATION IN EMBEDDED APPLICATIONS
3y 6m to grant Granted Jul 14, 2026
Patent 12682389
SECURE EMAIL AUTHENTICATION SYSTEM FOR COMPLETING E-COMMERCE TRANSACTIONS
1y 7m to grant Granted Jul 14, 2026
Patent 12665934
CYBERSECURITY AI-DRIVEN WORKFLOW GENERATION USING POLICIES
2y 0m to grant Granted Jun 23, 2026
Patent 12647454
TIMEOUT HANDLING FOR VIRTUAL DEVICES
3y 9m to grant Granted Jun 02, 2026
Patent 12647459
HETEROGENOUS NETWORK DEVICE EXTENSION AND STANDARDIZATION WITH DEVICE INSTRUMENTATION
2y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+61.3%)
2y 8m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 361 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month