Prosecution Insights
Last updated: September 18, 2026
Application No. 19/056,582

Systems and Methods for Intent Based Observability and Control of Artificial Intelligence (AI) Model Interactions

Non-Final OA §103
Filed
Feb 18, 2025
Priority
Nov 07, 2024 — provisional 63/717,878
Examiner
CRESPO FEBLES, HECTOR J
Art Unit
2657
Tech Center
2600 — Communications
Assignee
Witnessai Inc.
OA Round
1 (Non-Final)
100%
Grant Probability
Favorable
1-2
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 100% — above average
100%
Career Allowance Rate
1 granted / 1 resolved
+38.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
16 currently pending
Career history
11
Total Applications
across all art units

Statute-Specific Performance

§101
5.8%
-34.2% vs TC avg
§103
73.1%
+33.1% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
3.9%
-36.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restriction Restriction to one of the following inventions is required under 35 U.S.C. 121: I. Claims 1-17, drawn to a method that requires the use of a static multiheaded intent classifier to determine the intend of a user based on one or more user prompts and apply actions related to the policies/rules depending on the intent determination, classified in G06F 40/30. II. Claim 18-20, drawn to a method that requires the use of an adaptive task alignment (ATA) small language model (SLM) to determine the intent of a user based on one or more user prompts and apply actions related to the policies/rules depending on the intend determination describe method, classified in G06F 9/54. The inventions are independent or distinct, each from the other because: Inventions of group I. and group II. are directed to related processes. The related inventions are distinct if: (1) the inventions as claimed are either not capable of use together or can have a materially different design, mode of operation, function, or effect; (2) the inventions do not overlap in scope, i.e., are mutually exclusive; and (3) the inventions as claimed are not obvious variants. See MPEP § 806.05(j). In the instant case, the inventions as claimed utilize two different approaches to accomplish the classification of the intent of the user. Furthermore, the inventions as claimed do not encompass overlapping subject matter and there is nothing of record to show them to be obvious variants. Restriction for examination purposes as indicated is proper because all the inventions listed in this action are independent or distinct for the reasons given above and there would be a serious search and/or examination burden if restriction were not required because one or more of the following reasons apply: There would be a search burden, because a static multiheaded behavior classifier would require a different and non-overlapping search to an adaptive task alignment (ATA) small language model (SLM). During a telephone conversation with Mr. James Nachtwey (Attorney of Record) on 08/26/2026 a provisional election was made without traverse to prosecute the invention of Group 1, claim 1-17. Affirmation of this election must be made by applicant in replying to this Office action. Claim 18-20 withdrawn from further consideration by the examiner, 37 CFR 1.142(b), as being drawn to a non-elected invention. Applicant is reminded that upon the cancelation of claims to a non-elected invention, the inventorship must be corrected in compliance with 37 CFR 1.48(a) if one or more of the currently named inventors is no longer an inventor of at least one claim remaining in the application. A request to correct inventorship under 37 CFR 1.48(a) must be accompanied by an application data sheet in accordance with 37 CFR 1.76 that identifies each inventor by his or her legal name and by the processing fee required under 37 CFR 1.17(i). Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1-6, 9, 11, 12 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kale; Nikhil Sainath et al. (US 20250335573 A1) hereinafter KALE in view of Hueser; Jonathan Jakob et al. (US 20230317066 A1) hereinafter HUESER. Regarding claim 1, KALE teaches: A computer-implemented method for intent based observability and control of Artificial Intelligence (AI) model interactions, the method comprising: receiving Artificial Intelligence (AI) input data entered by a user, the Artificial Intelligence (AI) input data comprising a prompt; KALE [Abstract] ”In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0040] “At step 220, a computing system may receive a first prompt provided to a large language model (LLM).” classifying the prompt using an Artificial Intelligence (AI) model to determine an intent of the prompt entered by the user; KALE [Abstract] “In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0042] “At step 240, the computing system may perform semantic analysis and intent recognition based on the vector representation of the first prompt, comprising using a contextualized semantic graph, hierarchical semantic clustering, adaptive semantic prompt analysis, and stateful temporal analysis to jointly analyze the first prompt to determine the intent of the first prompt.” and applying a granular control Artificial Intelligence (Al) policy to the intent of the prompt entered by the user. KALE [Abstract] “In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE does not teach, but HUESER teaches: the classifying the prompt using a static multiheaded behavior classifier using a single base model, the single base model generating embeddings from input data and allowing for binary verdicts for various behaviors in a single inference pass enabling efficiency and scalability of the classifying the prompt; HUESER [0155] “FIG. 5A is a conceptual diagram illustrating an example arrangement of the shared encoder 162 and decoders. As shown, in some embodiments, the system 100 may include multiple language decoders 510 configured to process inputs corresponding to a particular natural language. The shared encoder 162 may process input data 502. The input data 502 may be ASR output data corresponding to a user input. The shared encoder 162 may determine encoded representation data 504, which may be processed by one or more language decoders 510. The language decoder 510a may correspond to a first natural language (e.g., English), a language decoder 510b may correspond to a second natural language (e.g., Spanish), the language decoder 510n may correspond to a nth natural language, and so on.” HUESER [0105] “In addition to making a binary determination regarding whether a domain potentially relates to the ASR output data 302, the shortlister component 250 may generate confidence scores representing likelihoods that domains relate to the ASR output data 302. If the shortlister component 250 implements a different trained model for each domain, the shortlister component 250 may generate a different confidence score for each individual domain trained model that is run.” HUESER [0157] ”FIG. 6 is a conceptual diagram illustrating another example arrangement of the shared encoder 162 and decoders. As shown, in some embodiments, the system 100 may include multiple domain decoders 610, which may process the encoded representation data 504 outputted by the shared encoder 162. The domain decoder 610a may correspond to a first domain (e.g., a shopping domain), a domain decoder 610b may correspond to a second domain (e.g., a music domain), a domain decoder 610n may correspond to a nth domain, and so on. The domain decoders 610 may be configured to perform domain classification as described herein (for example, with respect to the domain recognizers 263). Based on performing domain classification, the system 100 may determine a domain (e.g., a first domain) corresponding to the user input. After performing domain classification, the system 100 may process the encoded representation data 504 using one or more IC decoders 163 and one or more NER decoders 164 corresponding to the first domain corresponding to the user input. In this manner, the output of the shared encoder 162 is used for multiple tasks and by multiple decoders - the domain decoders 610, the IC decoders 163 and the NER decoders 164. This results in computation and time savings since a separate encoder is not run for each of the different tasks to be performed for NLU processing.” Wherein a multi-headed behavior classifier, using a single base model is interpreted as a shared neural network (the "base" or "backbone") processes the raw input data to extract core features, which are then passed to multiple independent output layers ("heads") that perform different classification tasks simultaneously. Architecturally, the shared decoder and the multiple decoders disclosed by HUESER present the same concept under different names. Both designs use a shared representation layer (encoder) that feeds into multiple separate output layers (heads/decoders) to predict different aspects of intent simultaneously. It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE the capability to use a static multiheaded classifier approach for the classification. The benefit and motivation of such modification is discussed by HUESER in the following portion: HUESER [0157] “… In this manner, the output of the shared encoder 162 is used for multiple tasks and by multiple decoders - the domain decoders 610, the IC decoders 163 and the NER decoders 164. This results in computation and time savings since a separate encoder is not run for each of the different tasks to be performed for NLU processing.” Regarding claim 2, the rejection of claim 1 is incorporated, furthermore KALE teaches: The method of claim 1, wherein the Artificial Intelligence (Al) model comprises a Large Language Model (LLM). KALE [Abstract] “In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0040] “At step 220, a computing system may receive a first prompt provided to a large language model (LLM).” Regarding claim 3, the rejection of claim 1 is incorporated, furthermore KALE teaches: The method of claim 1, wherein the classifying the prompt using the Artificial Intelligence (AI) model to determine the intent of the prompt entered by the user comprises fine grained intention classification that provides a precise intent classification of the prompt entered by the user, the Artificial Intelligence (AI) model being a Machine Learning (ML) model. KALE [0028] “One component may be contextualized semantic graphs (CSGs) 114. A CSG 114 may utilize graph attention networks (GATs) 116 to create a semantic graph for real-time analysis 118. The attention mechanism may allow the network to focus on semantically rich or suspicious regions of the graph. The multi-layered attention mechanism in CSGs 114 may adaptively focus on different regions of the semantic graph based on real-time data and contextual information. The edges between the nodes in the graph may be not static but dynamically weighted using real-time analytics and machine-learning algorithms. Real-time data may be continuously fed into the semantic graph, updating the nodes and initial edge weights, allowing the system to quickly respond to emerging threats or anomalies. The system can understand the context more accurately by using multiple layers of attention. The attention layers may adjust these scores based on broader contextual information. As an example and not by way of limitation, if a node represents a text prompt with potentially malicious intent, the attention scores of its neighboring nodes may be adjusted to focus more on this region of the graph. Each attention layer may have multiple heads focusing on different aspects like semantic richness, potential maliciousness, or temporal sequence. The outputs of these heads may be concatenated and passed through a linear aggregator to adjust the edge weights in the semantic graph dynamically, which allows the system to focus on semantically rich or suspicious regions adaptively.” KALE [0029] “Another component may be hierarchical semantic clustering (HSC) 120. HSC 120 may employ a hierarchical clustering algorithm 122 to create a multi-level semantic vector space, allowing for nuanced policy enforcement 124. Each level or tier may represent a different level of threat severity or type, ranging from benign to highly malicious. The process may begin with extracting semantic vectors from incoming prompts using advanced natural language processing (NLP) techniques. These vectors may be then subject to a hierarchical clustering algorithm 122 that organizes them into various clusters based on their semantic proximity. Each cluster may be further divided into sub-clusters, creating a tree-like structure. This hierarchical organization may allow for identifying not just individual malicious prompts but also entire categories of attacks, thereby providing a more comprehensive view of the threat landscape. Moreover, HSC 120 may incorporate real-time learning mechanisms. As new types of prompt injections are identified, the hierarchical clusters may be dynamically updated, allowing the system to adapt to emerging threats. The system ability to adapt to emerging threats may be facilitated by a feedback loop integrating flagged false positives and negatives to refine the clustering algorithm continually.” Regarding claim 4, the rejection of claim 1 is incorporated, furthermore KALE teaches: The method of claim 1, wherein the classifying the prompt using the Artificial Intelligence (AI) model to determine the intent of the prompt entered by the user comprises coarse intention classification that provides a coarse intent classification of the prompt entered by the user by the intent of the prompt being chosen from a predetermined list of intents using the Artificial Intelligence (Al) model, the Artificial Intelligence (Al) model being a Machine Learning (ML) model. KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” KALE [0028] “One component may be contextualized semantic graphs (CSGs) 114. A CSG 114 may utilize graph attention networks (GATs) 116 to create a semantic graph for real-time analysis 118. The attention mechanism may allow the network to focus on semantically rich or suspicious regions of the graph. The multi-layered attention mechanism in CSGs 114 may adaptively focus on different regions of the semantic graph based on real-time data and contextual information. The edges between the nodes in the graph may be not static but dynamically weighted using real-time analytics and machine-learning algorithms. Real-time data may be continuously fed into the semantic graph, updating the nodes and initial edge weights, allowing the system to quickly respond to emerging threats or anomalies. The system can understand the context more accurately by using multiple layers of attention. The attention layers may adjust these scores based on broader contextual information. As an example and not by way of limitation, if a node represents a text prompt with potentially malicious intent, the attention scores of its neighboring nodes may be adjusted to focus more on this region of the graph. Each attention layer may have multiple heads focusing on different aspects like semantic richness, potential maliciousness, or temporal sequence. The outputs of these heads may be concatenated and passed through a linear aggregator to adjust the edge weights in the semantic graph dynamically, which allows the system to focus on semantically rich or suspicious regions adaptively.” Regarding claim 5, the rejection of claim 1 is incorporated, furthermore KALE teaches: The method of claim 1, wherein the granular control Artificial Intelligence (Al) policy comprises filters, the filters comprising rules, the rules comprising actions. KALE [0020] “According to another embodiment, a method may include receiving a first prompt provided to a large language model (LLM). The method may also include generating, based on semantic and syntactic features associated with the first prompt, a semantic fingerprint for the first prompt. The method may also include generating, for the first prompt, a first vector representation incorporating the semantic fingerprint. The method may also include calculating a plurality of semantic distances between the first vector representation and a plurality of second vector representations, respectively. The plurality of second vector representations may be associated with a plurality of malicious intents, respectively. The method may additionally include determining, based on the plurality of semantic distances, an intent associated with the first prompt.<<claimed FILTERS>> The method may further include determining, based on the intent and a plurality of policies <<claimed RULES>>, a defense action <<claimed ACTIONS>> on the first prompt to mitigate a security risk associated with the first prompt.” Note, the words added between the double arrows were added by the examiner to clarify mapping and are not part of the original reference. Regarding claim 6, the rejection of claim 5 is incorporated, furthermore KALE teaches: The method of claim 5, wherein the filters comprise one or more of: data protection, model protection, and behavioral protection for the Artificial Intelligence (Al) input data comprising the prompt. KALE [0022] “Technical advantages of certain embodiments of this disclosure may include one or more of the following. The systems and methods described herein may provide a rapid injection and guarantee protection against data manipulation for incoming LLM prompts. The systems and methods described herein may diverge significantly from traditional anti-spam rules built on heuristics, particularly in addressing text-based attacks like email phishing. Unlike heuristic-based systems, the systems and methods described herein employ a multi-layered, context-aware detection mechanism that includes advanced features that allow for nuanced understanding and real-time analysis of text, capturing complex temporal dependencies and semantic manipulations that could exploit LLMs. The systems and methods described herein may offer a comprehensive, adaptive, and context-aware solution for countermeasures against prompt injection attacks in LLMs. Different from conventional anti-spam technologies, the systems and methods described herein utilize sophisticated enforcement mechanisms that leverage features not commonly found in traditional anti-spam systems such as zero-shot learning (ZSL) and dynamic policy adaptation using reinforcement learning. These sophisticated enforcement mechanisms may enable the systems and methods described herein to adapt to evolving threats and handle uncertainties, making them robust against evasion techniques.” KALE [0033] “... The system may monitor user interactions 144, including frequency, timing, and types of queries, to establish a behavioral baseline. Any deviation from this baseline may be flagged as an anomaly. The CAD module may also consider the geographical origin of the prompt, adding another layer of scrutiny. As an example and not by way of limitation, a prompt originating from a location known for cyber threats may be flagged. The contextual information may allow the system to differentiate between anomalous behavior and false positives. ...” Regarding claim 9, the rejection of claim 5 is incorporated, furthermore KALE teaches: The method of claim 5, wherein the actions comprise block the Artificial Intelligence (Al) input data comprising the prompt based on the intent of the prompt entered by the user. KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” Regarding claim 11, the rejection of claim 5 is incorporated, furthermore KALE teaches: The method of claim 5, wherein the actions comprise one or more of: generating a warning and generating an alert based on the intent of the prompt entered by the user. KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” Regarding claim 12, the rejection of claim 5 is incorporated, furthermore KALE teaches: The method of claim 5, wherein the actions comprise one or more of: sending and routing the Artificial Intelligence (Al) input data comprising the prompt based on the granular control Artificial Intelligence (Al) policy, the sending and the routing being to another specific Artificial Intelligence (Al) model. KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” Regarding claim 17, KALE teaches: A computer-implemented method for intent based observability and control, the method comprising: receiving input data entered by a user; KALE [Abstract] ”In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0034] “In particular embodiments, the HSC 120, DIR module, and CAD module are not limited to text-based prompts. They can be extended to understand and analyze multi-modal inputs, such as voice or image-based prompts, providing a more holistic security solution.” classifying the input data entered by the user using an Artificial Intelligence (Al) model to determine an intent of the input data entered by the user, KALE [Abstract] ”In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0034] “In particular embodiments, the HSC 120, DIR module, and CAD module are not limited to text-based prompts. They can be extended to understand and analyze multi-modal inputs, such as voice or image-based prompts, providing a more holistic security solution.” and applying a granular control policy to the intent of the input data entered by the user, the granular control policy comprising filters, the filters comprising rules, the rules comprising actions. KALE [Abstract] ”In an embodiment, a method includes receiving a prompt provided to a large language model (LLM), generating a semantic fingerprint for the prompt based on semantic and syntactic features associated with the prompt, generating a vector representation incorporating the semantic fingerprint for the prompt, calculating semantic distances between the vector representation and multiple vector representations associated with multiple malicious intents, determining an intent associated with the prompt based on the semantic distances, and determining a defense action on the prompt based on the intent and multiple policies to mitigate a security risk associated with the prompt.” KALE [0034] “In particular embodiments, the HSC 120, DIR module, and CAD module are not limited to text-based prompts. They can be extended to understand and analyze multi-modal inputs, such as voice or image-based prompts, providing a more holistic security solution.” KALE [0020] “According to another embodiment, a method may include receiving a first prompt provided to a large language model (LLM). The method may also include generating, based on semantic and syntactic features associated with the first prompt, a semantic fingerprint for the first prompt. The method may also include generating, for the first prompt, a first vector representation incorporating the semantic fingerprint. The method may also include calculating a plurality of semantic distances between the first vector representation and a plurality of second vector representations, respectively. The plurality of second vector representations may be associated with a plurality of malicious intents, respectively. The method may additionally include determining, based on the plurality of semantic distances, an intent associated with the first prompt.<<claimed FILTERS>> The method may further include determining, based on the intent and a plurality of policies <<claimed RULES>>, a defense action <<claimed ACTIONS>> on the first prompt to mitigate a security risk associated with the first prompt.” KALE does not teach, but HUESER teaches: the classifying the input data using a static multiheaded behavior classifier using a single base model, the single base model generating embeddings from input data and allowing for binary verdicts for various behaviors in a single inference pass enabling efficiency and scalability of the classifying the input data; HUESER [0155] “FIG. 5A is a conceptual diagram illustrating an example arrangement of the shared encoder 162 and decoders. As shown, in some embodiments, the system 100 may include multiple language decoders 510 configured to process inputs corresponding to a particular natural language. The shared encoder 162 may process input data 502. The input data 502 may be ASR output data corresponding to a user input. The shared encoder 162 may determine encoded representation data 504, which may be processed by one or more language decoders 510. The language decoder 510a may correspond to a first natural language (e.g., English), a language decoder 510b may correspond to a second natural language (e.g., Spanish), the language decoder 510n may correspond to a nth natural language, and so on.” HUESER [0105] “In addition to making a binary determination regarding whether a domain potentially relates to the ASR output data 302, the shortlister component 250 may generate confidence scores representing likelihoods that domains relate to the ASR output data 302. If the shortlister component 250 implements a different trained model for each domain, the shortlister component 250 may generate a different confidence score for each individual domain trained model that is run.” HUESER [0157] “FIG. 6 is a conceptual diagram illustrating another example arrangement of the shared encoder 162 and decoders. As shown, in some embodiments, the system 100 may include multiple domain decoders 610, which may process the encoded representation data 504 outputted by the shared encoder 162. The domain decoder 610a may correspond to a first domain (e.g., a shopping domain), a domain decoder 610b may correspond to a second domain (e.g., a music domain), a domain decoder 610n may correspond to a nth domain, and so on. The domain decoders 610 may be configured to perform domain classification as described herein (for example, with respect to the domain recognizers 263). Based on performing domain classification, the system 100 may determine a domain (e.g., a first domain) corresponding to the user input. After performing domain classification, the system 100 may process the encoded representation data 504 using one or more IC decoders 163 and one or more NER decoders 164 corresponding to the first domain corresponding to the user input. In this manner, the output of the shared encoder 162 is used for multiple tasks and by multiple decoders - the domain decoders 610, the IC decoders 163 and the NER decoders 164. This results in computation and time savings since a separate encoder is not run for each of the different tasks to be performed for NLU processing.” Wherein a multi-headed behavior classifier, using a single base model is interpreted as a shared neural network (the "base" or "backbone") processes the raw input data to extract core features, which are then passed to multiple independent output layers ("heads") that perform different classification tasks simultaneously. Architecturally, the shared decoder and the multiple decoders disclosed by HUESER present the same concept under different names. Both designs use a shared representation layer (encoder) that feeds into multiple separate output layers (heads/decoders) to predict different aspects of intent simultaneously. It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE the capability to use a static multiheaded classifier approach for the classification. The benefit and motivation of such modification is discussed by HUESER in the following portion: HUESER [0157] “… In this manner, the output of the shared encoder 162 is used for multiple tasks and by multiple decoders - the domain decoders 610, the IC decoders 163 and the NER decoders 164. This results in computation and time savings since a separate encoder is not run for each of the different tasks to be performed for NLU processing.” Claim(s) 7 and 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over KALE in view of HUESER in view of Wiggins; Shane (US 20250355947 A1) hereinafter WIGGINS in further view of NALAVADE; Satyajit Sajanrao et al. (US 20260030363 A1) hereinafter NALAVADE. Regarding claim 7, the rejection of claim 5 is incorporated, furthermore KALE in view of HUESER does not teach, but WIGGINS teaches: The method of claim 5, wherein the rules comprise a block all function, the block all function being blocking all Artificial Intelligence (Al) input data based on the intent of the prompt entered by the user except for WIGGINS [0021] “Based on the similarity of the intent of the query and the intended use of the artificial intelligence system, the intent analysis system determines whether the intent sufficiently aligns with the intended use. In some aspects, the intent analysis system compares the similarity score to a similarity threshold. If the similarity score meets the similarity threshold, the intent analysis system determines that the intent aligns with the intended use and enables processing of the query by the artificial intelligence system. But if the similarity score does not meet the similarity threshold, the intent analysis system determines that the intent does not align with the intended use and blocks processing of the query by the artificial intelligence system. Thus, the intent analysis system either allows or does not allow the artificial intelligence system to respond to the query based on the intent of the query.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to determine if the query intent is aligned with the intent of the AI and block the prompts that are not aligned to the intents associated with the AI. The benefit and motivation of such modification is discussed by WIGGINS in the following portion: WIGGINS [0024] “Additionally, the intent analysis system utilizes intelligent intent analysis to improve the flexibility and efficiency of artificial intelligence systems in computing systems. For instance, in contrast to conventional systems that utilize data classifications to manage artificial intelligence systems, the intent analysis system utilizes intent analysis to implement access controls across a variety of domains and use cases. The intent analysis system can apply intent analysis to any number of queries for a variety of machine-learning models to determine whether the queries are aligned with the intended use of the machine-learning models even if the content of each of the queries is acceptable on their face. Thus, the intent analysis system can prevent bad actors from attempting to use workarounds to fool artificial intelligence systems into being used in unintended or malicious ways.” KALE IN VIEW OF HUESER in view of WIGGINS does not teach but NALAVADE teaches: an allowed list of specific intentions. NALAVADE [0024] “In some implementations, to select the chatbot service, the chatbot risk management system may identify (e.g., based on the intent information) at least one intent of the user input. The chatbot risk management system then may determine (e.g., based on the at least one intent of the user input) whether the user input is associated with an intent blocklist or an intent allowlist (e.g., of one or more intent allowlists) to thereby determine which chatbot service should be selected.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER in view of WIGGINS the capability to explicitly have a list of allowed intentions in order to compare if the query intent is aligned with the allowed list intent of the AI and block the prompts that are not aligned to the allowed list of intents associated with the AI. The benefit and motivation of such modification is discussed by NALAVADE in the following portion: NALAVADE [0028] “In this way, the chatbot risk management system may select, when the user input is associated with the intent blocklist, a non-gen-AI chatbot service that is configured to respond to disallowed user inputs; may select, when the user input is associated with an intent allowlist associated with a particular intent type, a non-gen-AI chatbot service that is configured to respond to user inputs associated with the particular intent type; or may select, when the user input is associated with an intent allowlist associated with a non-particular intent type, the gen-AI chatbot service that is configured to respond to user inputs associated with the non-particular intent type. Accordingly, the chatbot risk management system only selects the gen-AI chatbot service to respond to the user input when the chatbot risk management system determines that a non-gen-AI chatbot service is not suitable to respond to the user input.”. Wherein the original operation of NALAVADE is directed to routing the prompt to an appropriate Gen-AI or non-gen-ai chatbot, but we are just using the are element of the intent ALLOWLIST to combine it with the blocking function discussed by WIGGINGS. The resulting invention would block (instead of rerouting) AI input having an intent that does not belong to the intents allowed for the AI, that could be listed in an intent allowlist. Regarding claim 8, the rejection of claim 5 is incorporated, furthermore KALE in view of HUESER does not teach, but WIGGINS teaches: The method of claim 5, wherein the rules comprise a allow all function, the allow all function being allowing all Artificial Intelligence (Al) input data based on the intent of the prompt entered by the user except for WIGGINS [0021] “Based on the similarity of the intent of the query and the intended use of the artificial intelligence system, the intent analysis system determines whether the intent sufficiently aligns with the intended use. In some aspects, the intent analysis system compares the similarity score to a similarity threshold. If the similarity score meets the similarity threshold, the intent analysis system determines that the intent aligns with the intended use and enables processing of the query by the artificial intelligence system. But if the similarity score does not meet the similarity threshold, the intent analysis system determines that the intent does not align with the intended use and blocks processing of the query by the artificial intelligence system. Thus, the intent analysis system either allows or does not allow the artificial intelligence system to respond to the query based on the intent of the query.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to determine if the query intent is aligned with the intent of the AI and allow the prompt to proceed to be process by the AI. The benefit and motivation of such modification is discussed by WIGGINS in the following portion: WIGGINS [0024] “Additionally, the intent analysis system utilizes intelligent intent analysis to improve the flexibility and efficiency of artificial intelligence systems in computing systems. For instance, in contrast to conventional systems that utilize data classifications to manage artificial intelligence systems, the intent analysis system utilizes intent analysis to implement access controls across a variety of domains and use cases. The intent analysis system can apply intent analysis to any number of queries for a variety of machine-learning models to determine whether the queries are aligned with the intended use of the machine-learning models even if the content of each of the queries is acceptable on their face. Thus, the intent analysis system can prevent bad actors from attempting to use workarounds to fool artificial intelligence systems into being used in unintended or malicious ways.” KALE IN VIEW OF HUESER in view of WIGGINS does not teach but NALAVADE teaches: a non-approved list of specific intentions. NALAVADE [0024] “In some implementations, to select the chatbot service, the chatbot risk management system may identify (e.g., based on the intent information) at least one intent of the user input. The chatbot risk management system then may determine (e.g., based on the at least one intent of the user input) whether the user input is associated with an intent blocklist or an intent allowlist (e.g., of one or more intent allowlists) to thereby determine which chatbot service should be selected.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER in view of WIGGINS the capability to explicitly have a list of blocked intentions in order to compare if the query intent is not aligned with the blocked list intent of the AI and allow the prompts that are not aligned to the blocked list of intents associated with the AI. The benefit and motivation of such modification is discussed by NALAVADE in the following portion: NALAVADE [0028] “In this way, the chatbot risk management system may select, when the user input is associated with the intent blocklist, a non-gen-AI chatbot service that is configured to respond to disallowed user inputs; may select, when the user input is associated with an intent allowlist associated with a particular intent type, a non-gen-AI chatbot service that is configured to respond to user inputs associated with the particular intent type; or may select, when the user input is associated with an intent allowlist associated with a non-particular intent type, the gen-AI chatbot service that is configured to respond to user inputs associated with the non-particular intent type. Accordingly, the chatbot risk management system only selects the gen-AI chatbot service to respond to the user input when the chatbot risk management system determines that a non-gen-AI chatbot service is not suitable to respond to the user input.”. Wherein the original operation of NALAVADE is directed to routing the prompt to an appropriate Gen-AI or non-gen-ai chatbot based on the intend, but we are just using the are element of the intent BLOCKLIST to combine it with the function discussed by WIGGINGS. The resulting invention would utilize NALAVADE’s blocklist as the non-permitted intentions and would permit AI input except when it is determined intent corresponds to one of the non-approved intentions represented by the intent blocklist. Claim(s) 10 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over KALE in view of HUESER in further view of PHIRI; Charles C. et al. (US 20250005060 A1) hereinafter PHIRI Regarding claim 10, the rejection of claim 5 is incorporated, furthermore KALE in view of HUESER does not teach, but PHIRI teaches: The method of claim 5, wherein the actions comprise allow the Artificial Intelligence (Al) input data comprising the prompt based on the intent of the prompt entered by the user. PHIRI [0056] “In step 220, if the moderator computer program approves the query (e.g., the query complies with the organization rules and policies, does not contain sensitive information, has a policy risk score, a session risk score, or a combined risk score below a threshold, etc.), in step 225, the moderator computer program may submit the query to the LLM-based computer program.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to allow the user allowed/approved/compliant prompt to be sent to the LLM in order to produce a response. The benefit and motivation of such modification is discussed by PHIRI in the following portion: PHIRI [0064] “In step 240, if the moderator computer program may approve the response (e.g., the response complies with organization policies and rules), in step 245, the moderator computer program may return the response to the user application.” Regarding claim 16, the rejection of claim 1 is incorporated, furthermore KALE teaches: The method of claim 1, further comprising detecting behavior of the user, the detecting behavior of the user comprising: determining intent of a plurality of prompts entered by the user; KALE [0033] “In particular embodiments, the detection mechanisms may include contextual and anomaly detection 140. A contextual anomaly detection (CAD) module may identify anomalies in the system by considering a range of contextual factors. The CAD module may utilize recurrent neural networks (RNNs) to analyze the temporal sequence of prompts for contextual anomaly detection 142, identifying patterns that could signify a coordinated attack. The system may monitor user interactions 144, including frequency, timing, and types of queries, to establish a behavioral baseline. Any deviation from this baseline may be flagged as an anomaly. …” aggregating of the intent of the plurality of prompts entered by the user for the detecting behavior of the user; KALE [0033] “In particular embodiments, the detection mechanisms may include contextual and anomaly detection 140. A contextual anomaly detection (CAD) module may identify anomalies in the system by considering a range of contextual factors. The CAD module may utilize recurrent neural networks (RNNs) to analyze the temporal sequence of prompts for contextual anomaly detection 142, identifying patterns that could signify a coordinated attack. The system may monitor user interactions 144, including frequency, timing, and types of queries, to establish a behavioral baseline. Any deviation from this baseline may be flagged as an anomaly. …” comparing the behavior of the user to a risk threshold KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” KALE [0011] “In certain embodiments, determining the intent associated with the first prompt may be further based on a threshold associated with the plurality of semantic distances. In some embodiments, the operations may include updating the threshold based on a reinforcement learning algorithm and updating the intent associated with the first prompt based on the updated threshold.” and generating an KALE [0010] “In certain embodiments, the operations may include generating, based on the first prompt and a plurality of second prompts using a hierarchical clustering algorithm, a multi-level semantic vector space. Each level of the multi-level semantic vector space may represent a distinct level of threat severity. In some embodiments, determining the defense action on the first prompt may be further based on the multi-level semantic vector space.” KALE [0011] “In certain embodiments, determining the intent associated with the first prompt may be further based on a threshold associated with the plurality of semantic distances. In some embodiments, the operations may include updating the threshold based on a reinforcement learning algorithm and updating the intent associated with the first prompt based on the updated threshold.” KALE in view of HUESER does not teach, but PHIRI teaches: an enterprise action | risk threshold for an/the enterprise PHIRI [0033] “Moderator computer program 140 may include, for example, content classifier 142, policy schema validator 144, policy selector 146, policy engine 148, session risk engine 150, and risk evaluation engine 152. Moderator computer program 140 may receive queries for large language model-based computer program 115, and may review the queries for compliance with organization standards. For example, the queries may be checked to verify that they are appropriate for the organization (e.g., not seeking an offensive or inappropriate response from large language model-based computer program 115), not an attempt to hack or jailbreak large language model-based computer program 115, etc. It may also verify that the queries do not include private or confidential information, such as personally identifiable information, etc.” PHIRI [0043] “Queries that moderator computer program 140 identifies as inappropriate, or having a risk score (e.g., policy risk score, session risk score, or combined risk score) above a threshold, may be rejected.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to be specific to an organization (or enterprise), apply policies specific to that domain and have risk thresholds specific for the organization (or enterprise). The benefit and motivation of such modification is discussed by PHIRI in the following portion: PHIRI [0036] “Policy selector 146 may select and retrieve a policy based on the mime-type from a policy database (not shown), such as frameworks, regional regulations, policies, etc. that can be expressed as a schema. Examples of policies may include the National Institute of Science and Technology (NIST) Risk Management Framework (RMF), the United Kingdom Artificial Intelligence regulations, etc.” Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over KALE in view of HUESER in further view of Brandel; Eric et al. (US 20220263828 A1) hereinafter BRANDEL. Regarding claim 13, the rejection of claim 12 is incorporated furthermore KALE in view of HUESER does not teach, but BRANDEL teaches The method of claim 12, wherein the actions comprise the sending of the Artificial Intelligence (Al) input data comprising the prompt to KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” KALE in view of HUESER does not teach, but BRANDEL teaches: security information and event management (SIEM) BRANDEL [0045] “As shown in FIG. 1B, the shim code 114 is used for monitoring all traffic 116 between the internet 100 and the client-side devices. Instead of blocking web requests, the shim code 114 can report the requests or send an alert 122 to a security information and event management system 124 (SIEM), or another endpoint for monitoring web traffic and/or security. If the traffic 116 includes a new domain 118 that does not appear on a allowlist for the webpage where the shim code 114 is injected, the shim code 114 can report the new domain to a recording service 120. The recording service 120 can be a web server or other server/system configured to update 126 the shim code 114 with the new domain 118. For example, the shim code 114 can be updated by adding the new domain 118 to the allowlist (if the new domain 118 is not malicious). As another example, the shim code 114 can be updated 126 such that the shim code 114 does not report on or alert the SIEM 124 of the new domain 118 every time it is called. Thus, if the new domain 118 is requested in subsequent traffic 116, the shim code 114 can block the request without reporting on it (e.g., alerting the SIEM 124).” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUSER the capability to have an enforcement module for monitoring such as a SIEM and to send alerts/information to that enforcement module. The benefit and motivation of such modification is discussed by BRANDEL in the following portion: BRANDEL [0045] “… can report the requests or send an alert 122 to a security information and event management system 124 (SIEM), or another endpoint for monitoring web traffic and/or security. …”. Claim(s) 14 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over KALE in view of HUESER in further view of Jain; Payal et al. (US 12147513 B1) hereinafter JAIN Regarding claim 14, the rejection of claim 12 is incorporated, furthermore KALE teaches: The method of claim 12, wherein the actions comprise the routing the Artificial Intelligence (Al) input data KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” KALE in view of HUESER does not teach, but JAIN teaches: comprising the prompt to a specific Artificial Intelligence (Al) model JAIN [Col 9 lines 64 to Col 10 line 27] “FIG. 4 is a schematic illustrating a process 400 for validating model inputs and outputs, in accordance with some implementations of the present technology. For example, a user device 402a or a service 402b provides an output generation request (e.g., including a prompt and an authentication token) to the data generation platform 102 (e.g., to the access control engine 114 for access control 404 via the communication engine 112 of FIG. 1). The access control engine 114 can authenticate the user device 402a or service 402b by identifying stored tokens within an authentication database 412 that match the provided authentication token. The access control engine 114 can communicate the prompt to the breach mitigation engine 116 for input/output validation 406. The breach mitigation engine 116 can communicate with a sensitive token database 414 and/or a data-loss prevention engine 418, and/or an output validation model 420 for validation of prompts and/or LLM outputs. Following input validation, the performance engine 118 can evaluate the performance of LLMs to route the prompt to an appropriate LLM (e.g., large language model(s) 410). The data generation platform 102 can transmit the generated output to the output validation model 420 for testing and validation of the output (e.g., to prevent security breaches). The output validation model 420 can transmit the validated output to a data consumption system 422, for exposure of the output to the user device 402a and/or the service 402b. In some implementations, the data generation platform 102 can transmit metric values, records, or events associated with the data generation platform 102 to a metric evaluation database 416 (e.g., an event database) for monitoring, tracking, and evaluation of the data generation platform 102.” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to reroute the prompt to a specific AI model. The benefit and motivation of such modification is discussed by JAIN in the following portion: JAIN [Col 11 lines 18 to 34] “The data generation platform 102 (e.g., using the access control engine 114 of FIG. 1) can compare the provided authentication token with a matching, stored token of the authentication database 412 (e.g., through the communication engine 112). For example, the access control engine 114 determines that the provided authentication token matches an authentication token previously assigned to the associated user, user device (e.g., the user device 402a), and/or module (e.g., the service 402b). As such, the data generation platform 102 can authenticate the identity of the user requesting access to an LLM of the data generation platform 102, thereby reducing the likelihood of unauthorized access to the data generation platform 102 by malicious entities. Furthermore, by verifying the identity of the originator for the output generation request, the data generation platform 102 can evaluate the request and determine any relevant prompt validation criteria and/or LLM selection recommendations.” Regarding claim 15, the rejection of claim 5 is incorporated, furthermore KALE teaches: The method of claim 5, wherein the actions comprise KALE [0032] “In particular embodiments, the detection mechanisms may include dynamic intent and behavior profiling 138. A DIR module may employ a stacked architecture of long short-term memory (LSTM) units and gated recurrent units (GRUs), augmented with a self-attention mechanism. The DIR module may dynamically weigh the importance of each token in a sequence, thereby capturing complex temporal dependencies. A probability distribution over a set of predefined malicious intents may be created and continuously updated, which is then compared in real time with the intent behind the incoming prompt. Moreover, DIR can integrate with on emerging threats and incidents, thereby enhancing its predictive accuracy. DIR can then be configured to send triggers for specific actions to the enforcement modules, such as flagging, blocking, or rerouting the prompt based on the recognized intent.” KALE in view of JAIN does not teach, but JAIN teaches: calling a third-party Application Programming Interface (API) JAIN [Col 7 lines 41 to 47] “The generative model engine 120 can execute tasks relating to machine learning inference (e.g., natural language generation based on a generative machine learning model, such as an LLM). The generative model engine 120 can include software components (e.g., one or more LLMs, and/or API calls to devices associated with such LLMs), hardware components, and/or a combination thereof. ...” It would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to include in the teachings of KALE in view of HUESER the capability to call a third party API. The benefit and motivation of such modification is discussed by JAIN in the following portion: JAIN [Col 15 lines 21 to 38] “The breach mitigation engine 116 can provide the modified and/or validated prompt to the performance engine 118 for determination of performance impacts (e.g., for performance evaluation 408) associated with providing the prompt to an LLM (e.g., one of LLMs 410). For example, the performance engine 118 determines a performance metric value (e.g., an estimated resource requirement) associated with processing the prompt through an LLM to generate an output. A performance metric can include an indication of an estimated resource use, such as a monetary cost (e.g., cost metric) associated with an API call to the requested LLM. For example, referring to FIG. 5, the performance engine 118 determines an estimated resource use 510, such as a monetary cost, for processing the prompt with the selected LLM. The data generation platform 102, through the communication engine 112, can display the estimated cost on a user interface associated with the user device.” Summary of references used as prior art KALE is used as the main reference because the disclosure of AI prompt; LLM; determine user intent; malicious intent/behaviors; intend based policies and policy enforcer action. HUESER is used as a secondary reference because of the disclosure of single shared base encoder language model; intent-classification; binary classifiers; encoder processed once. JAIN is used as a reference because of the disclosure of evaluating and validating LLM prompts, and their calls to an external API. PHIRI is used as a reference because of the disclosure of policies specific to an enterprise (organization) and the disclosure of allowing a compliant action based on intent. BRANDEL is used as a reference because of the disclosure of a Security Information and Event Management System. NALAVADE reference is used for the disclosure of allowlist and blocklist of intent of prompts. WIGGINGS is used for the allow and block functions based on the intent of the prompt. Pertinent references not used as prior art YANG; Longqi et al. (US 20250086398 A1): GENERATING AND USING INTENT TAXONOMIES TO IDENTIFY USER INTENT. YANG further discloses the analysis of the user intent based on the prompts sent to the LLM. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HECTOR J. CRESPO FEBLES whose telephone number is (571)272-4512 and email hcrespofebles@uspto.gov. The examiner can normally be reached Mon - Fri 7:30 - 5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Daniel Washburn can be reached at (571) 272-5551. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HECTOR J. CRESPO FEBLES/ Examiner, Art Unit 2657 /DANIEL C WASHBURN/ Supervisory Patent Examiner, Art Unit 2657
Read full office action

Prosecution Timeline

Feb 18, 2025
Application Filed
Aug 26, 2026
Examiner Interview (Telephonic)
Sep 11, 2026
Non-Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
100%
Grant Probability
99%
With Interview (+0.0%)
2y 1m (~6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month