What Is OpenAI Actually Patenting?
A PatentVest Pulse analysis of OpenAI’s patent portfolio
OpenAI's patents tell a story that goes far beyond ChatGPT. Rather than protecting the underlying science, the company has spent the last several years building intellectual property around the products, platforms, and infrastructure that transform AI models into scalable businesses. This report examines what those patents reveal about OpenAI's strategy, and what they may signal about the future of competition in generative AI.
- OpenAI is patenting products, not model architecture, pretraining, or alignment methods.
- The portfolio spans AI agents, generative media, memory, developer platforms, and infrastructure.
- The report distinguishes OpenAI's internally developed portfolio from the patents acquired through Rain and Rockset.
- The patents closely mirror OpenAI's expanding product roadmap, from ChatGPT and Canvas to Sora and computer-use agents.
- Together with Anthropic's portfolio, they reveal a broader shift in how frontier AI companies are building defensible competitive positions.
Executive summary
Almost everyone who follows artificial intelligence agrees on one thing: the technology has no patent moat. The valuable ingredients, people say, are computing power, data, and talented researchers, and none of those sit behind a patent. OpenAI itself seemed to prove the point. It gave away its most influential ideas for free, publishing the training methods and scaling insights that the whole industry now runs on. So we asked a simple question with an awkward answer. A company that is reportedly valued at about 852 billion dollars, and that confidentially filed to go public in June 2026, must own something it thought worth fencing off. What is it?
To find out, we read every one of the sixty-nine patents OpenAI owns. A patent is a narrow no-trespassing sign. It does not protect an idea or a goal. It protects one specific method of doing one specific thing, described in detail and registered with the government, in exchange for making that method public. If a rival can invent a different route to the same result, the sign does not stop them. That detail turns out to be the whole story here. Drug companies often cannot patent the basic chemistry of a medicine, so they patent the auto-injector pen that delivers it. OpenAI does the same thing. It does not patent the intelligence. It patents the product built around the intelligence.
Read as a group, OpenAI’s patents almost never touch the science. There is not one patent in the portfolio on how to build the model itself, on the recipe used to train it, or on the methods used to make it behave. Instead, the patents fence the product layer, meaning the visible machinery a competitor can watch and copy: the way ChatGPT writes and edits inside a document, the way Sora turns text into video, the way an agent clicks around a screen, the way the service caches repeated text to lower a bill. When you line the patents up against OpenAI’s product launches, they read like an annotated roadmap. OpenAI filed its Canvas writing-tool patent three days before Canvas appeared, and its Sora patent the day before it announced Sora.
There is a second surprise. The sixty-nine patents are not one portfolio. They are three portfolios wearing a single trench coat. OpenAI filed forty-nine of them itself, and it filed nothing at all before mid-2022. The rest it bought, acquiring sixteen patents along with a hardware startup called Rain and four more along with a search-database startup called Rockset. Every patent in OpenAI’s name that predates 2022 came from one of those purchases, not from OpenAI’s own labs. So a portfolio that looks like a decade of invention is really about three years of it, stitched to two companies’ older work.
The absences say as much as the patents. When you notice what OpenAI chose not to fence, the strategy develops like a photo negative, where the dark areas show you the shape of the thing. OpenAI leaves the science unpatented for two different reasons, and honesty requires separating them. Some of it it keeps as a trade secret, which is the opposite bet from a patent: a patent trades disclosure for protection, while a trade secret protects by never showing anyone the room. The rest it already published years ago, which permanently bars anyone, including OpenAI, from patenting it later. There is also a quieter reason a gap can be an illusion. Patents stay hidden for about eighteen months after they are filed, so everything OpenAI has filed since roughly early 2025 is invisible today, and even the portfolio we can see is already a year and a half out of date.
The same posture holds across the frontier, which turns an OpenAI quirk into a field-level truth. OpenAI’s chief rival, Anthropic, owns about seventeen patent families, and independent analysis confirms it originally filed only about one of them. Nearly all the rest are older patents it acquired, and the patent-office records name IBM on the oldest ones, filed years before Anthropic existed. Anthropic’s single homegrown patent covers a computer-use agent, which is to say a product. Two labs at the top of the field, opposite in how much they patent, land in exactly the same place: the science stays unpatented, and the product gets the fence.
For anyone weighing OpenAI as an investment, this matters in a concrete way. When a company reportedly worth hundreds of billions of dollars files to go public, buyers of the stock will ask what it actually owns. As of July 2026, the honest answer on patents is one product-tracking software estate that OpenAI built in about three years, plus two smaller estates it bought. That is a narrower and more specific asset than the hype implies, and it is also a legible one. The patents map the exact layer OpenAI believes it can defend, and they hint at how a shield built for defense could be picked up as a sword later. A reader who stops here has the whole thesis. The pages that follow simply walk the map.
Highlights
If you read nothing else, read these. Each one is sourced where the fact can move.
- OpenAI filed zero patents before the middle of 2022. Every priority date in its portfolio older than that came from a company it bought, not from its own labs. (A priority date is the day a patent stakes its claim, the date that decides who was first.)
- There is not a single patent in OpenAI’s entire portfolio on a model’s architecture, on a pre-training recipe, or on an alignment method. The science that makes the models work is nowhere in the fence.
- OpenAI tried to patent a price. Its prompt-caching patent claims the automatic fifty percent discount on reused input as protected subject matter, so the exact number on its own price sheet became part of the invention.
- One made-up phrase, “generative response engine,” runs through many of OpenAI’s patents. It is the in-filing alias for the company’s own model, which lets the claims describe what ChatGPT does without ever naming ChatGPT.
- OpenAI wrote a literal web address into a patent. The path .well-known/ai-plugin.json, the exact spot a website would post its instructions for an AI, appears in the plugins filing.
- Four of OpenAI’s video patents share the priority date February 14, 2024, the day before the company announced Sora to the world.
- The sixty-nine patent families describe only about thirty-four to thirty-six distinct inventions. OpenAI files the same invention several ways, which inflates the count by roughly a third.
- OpenAI’s most influential ideas are owned by no one. It published reinforcement learning from human feedback and its scaling research without patenting them, which makes them permanent prior art against everyone, including OpenAI itself. (Prior art is earlier public knowledge that blocks a later patent.)
- OpenAI filed the training pipeline behind computer-use agents in April 2023, roughly two years before “computer use” became a product category anyone was racing to fence.
- OpenAI’s patents lean on the incumbents it is disrupting. They cite Microsoft ninety-six times, IBM seventy-six times, and Google seventy times, so the new company’s paper trail runs straight through twentieth-century enterprise computing. (Source: portfolio citation analytics, PatSnap, 2026-07-20.)
- Anthropic, OpenAI’s closest rival, owns about seventeen patent families and originally filed only about one of them itself. The rest were acquired, and that one homegrown filing covers a computer-use product. (Source: PatSnap portfolio analytics and Lumenci analysis, 2026-07-20.)
- Everything OpenAI has filed since roughly early 2025 is still legally invisible. Patents publish about eighteen months after filing, so the portfolio the public can read today is already a year and a half stale.
Introduction: what does a soon-to-be-public AI giant actually own?
Start with the number that makes people lean in. As of July 2026, OpenAI is reportedly valued at about 852 billion dollars, a figure set in a roughly 122-billion-dollar funding round that closed in March 2026 with money from SoftBank, Microsoft, and Nvidia. (Source: CNBC, 2026-03-31.) In June 2026 the company confidentially filed the paperwork to go public, with reporting that it is aiming for a debut around September 2026 at a valuation that could reach a trillion dollars, though the timing is contested inside the company. (Source: CNBC, 2026-06-08.) Every one of those numbers can change, so treat them as reported and dated, not fixed.
When a company that large prepares to sell shares to the public, a blunt question follows it: what does it actually own? Not what it hopes to build, and not how many people use its app this month, but what durable, defensible property sits on its books. For most technology giants, part of the answer is patents. And here the story gets strange, because the accepted wisdom is that artificial intelligence has no patents worth having.
That wisdom has a good pedigree. The people who build these systems will tell you the moat is somewhere else. It is in the mountains of computing hardware, in the enormous piles of training data, and in the small number of researchers who know how to turn the first two into a working model. OpenAI seemed to agree in the most convincing way possible, by giving its best ideas away. The technique that taught ChatGPT to be helpful, and the research that showed how models predictably improve as they grow, went out into the world as free publications, not as patents. A company that hands its crown jewels to its competitors does not look like a company that patents.
Think of a patent as a no-trespassing sign staked on one specific method. It does not fence off a goal, like “make a chatbot that remembers you.” It fences off one particular way of reaching that goal, described in enough detail that anyone could rebuild it once the patent expires. If a competitor finds a genuinely different way to the same place, your sign does not stop them. This is why the distinction between patenting the goal and patenting the method matters so much, and why so much of this article turns on exactly which methods OpenAI bothered to fence. So we did the tedious thing. We read all sixty-nine patents OpenAI owns, one by one, and sorted them by what they actually cover. The point was not to admire the engineering. It was to answer the investor’s question in concrete terms. If you strip away the valuation and the user counts and the promises, and you look only at the property a court could enforce, what is there? The answer is a surprisingly clear map of the company’s own priorities, and it is not the map the hype would lead you to draw.
How we know this: reading the recipe, not the fine print
Before the map, one honest caveat about method, because it shapes everything that follows.
Every patent has two very different parts. There is the specification, which is the long descriptive section where the inventors explain what they built and why, almost like the introduction to a recipe. And there are the claims, which are the short, dense, lawyer-drafted lines at the end that define exactly what the patent can stop someone else from doing, the enforceable fine print. The specification is where a patent tells its story. The claims are where it draws its legal boundary, and that boundary is almost always much narrower than the story. The specification is the recipe introduction that says “this dish is a rich, comforting winter stew.” The claims are the enforceable line that says “we specifically protect the step of searing the beef before adding exactly these three root vegetables.” A rival can make a winter stew all day long. They just cannot copy that exact fenced step.
This article reads mostly from the specifications, because the specifications are what reveal intent, ambition, and product mapping. That is the right lens for our question, which is about what OpenAI is trying to protect and why. But it comes with a standing warning that we carry throughout: what a patent says about itself is not the same as what its claims would survive in court. Several of the filings you are about to meet describe grand capabilities in the specification while the enforceable claims underneath are narrow, contested, or flagged by patent reviewers as vulnerable. When that gap matters, we say so. When a claim is our inference rather than a settled fact, we say that too. A patent family is a group of filings that all protect the same underlying invention in different countries or forms, the way one book can have a hardback, a paperback, and a foreign edition. A priority date is the earliest date the family can point to, its place in line at the patent office. And an invention group, the word we use throughout, is a set of related patents OpenAI filed around one product area. Inside a group, some documents are really the same invention filed several times, which is exactly why sixty-nine patent families describe only about thirty-four to thirty-six distinct inventions.
With that established, here is the shape of what OpenAI owns.
The shape of it: three portfolios in one trench coat
The single most misleading thing you could do with OpenAI’s patents is treat them as one collection. They are three, and they come from three different places, with three different characters. Mix them together and you would conclude that OpenAI has been inventing hardware and databases and AI software steadily for the better part of a decade. Separate them and the real picture appears.
The first and by far the most important portfolio is the organic one: forty-nine patents OpenAI’s own people filed. This is the annotated product roadmap, the fence around ChatGPT and its siblings, and it is where almost the entire rest of this article lives. Its earliest priority date is mid-2022. Before that, OpenAI, as a filer of patents, did not exist.
The second portfolio arrived with a company. In 2024 OpenAI acquired Rain Neuromorphics, a chip startup with old ties to OpenAI’s founding circle, and sixteen hardware patents came stapled to the deal. These are not OpenAI’s inventions. They are a chipmaker’s inventions that OpenAI now owns, and they tell their own story of a hardware company that changed its mind, which we come to later.
The third portfolio also arrived with a company. Also in 2024, OpenAI bought Rockset, a startup that built a fast search-and-analytics database, and four database patents rode along. Again, bought, not filed. Imagine judging a chef by the contents of their kitchen after they bought out two neighboring restaurants. The pizza oven and the pasta extruder are now theirs, but they reveal the previous owners’ priorities, not the chef’s. Attributing all sixty-nine patents to OpenAI’s own strategy makes the same mistake. Only the forty-nine organic filings show what OpenAI itself decided was worth protecting.
Here is the segmentation at a glance.
| Portfolio | How it arrived | Count | Character | Earliest priority date |
|---|---|---|---|---|
| Organic OpenAI | Filed by OpenAI’s own people | 49 | Product-layer software; the annotated roadmap | Mid-2022 |
| Rain Neuromorphics | Acquired with the company (2024) | 16 | AI-chip hardware; two generations, one pivot | 2018 |
| Rockset | Acquired with the company (2024) | 4 | Real-time search-and-analytics database plumbing | 2018 |
The three rings
The easiest way to understand these 13 categories is that together they cover the entire system required to turn an AI model into a useful autonomous worker. Some categories give the AI intelligence, some give it memory and tools, some let it operate software, and others provide the infrastructure and hardware underneath everything.
Where the segmentation splits the portfolio by where the patents came from, the rings split it by what the patents do.
- Ring 1, what the AI directly does. It operates software, writes code, edits documents, creates media, and interacts through interfaces.
- Ring 2, what makes the AI a persistent agent. It remembers users, calls tools, coordinates with other agents, schedules work, and maintains state.
- Ring 3, what powers the system. Model training, safety systems, databases, chips, and computing infrastructure.
The central thesis is that OpenAI is protecting far more than a chatbot. It is assembling patents around an AI system that can understand a task, use software, call services, create artifacts, remember context, and keep working over time.
| Category | Group name (dossier) | Representative patents |
|---|---|---|
| Computer-use agents & overlay operator | Agents that use a computer | US11887367B1, US2025348183A1, US2025348196A1, WO2025235715A1 |
| Code generation & run-and-verify | Code, written and then run | US12498947B2, US12008341B2, EP4716883A1, US2024402999A1, WO2024242700A1 |
| Generative visual media | Making images and video | WO2025174789A1, US2025259361A1, US2025259362A1, US11922550B1, US11983806B1, US2025259423A1 |
| Serving the model as a product | Serving the model as a product | US12596764B1, US12400074B1, US12554519B2, US12591766B1, US12450198B2, US20260073295A1, WO2026059944A1 |
| Memory & personalization | Remembering you | US2025200361A1, WO2025128397A1, US12430518B2, US12443803B2 |
| Tool use, plugins & RAG | Plugging in the outside world | US11922144B1, US2024427571A1, US12547480B2 |
| Multi-agent orchestration & automations | Teams of agents working together | US12405822B1, US12346664B1, US2025373574A1, US12518109B1 |
| Text insertion & editing | Text, inserted and edited | US11886826B1, US11983488B1, WO2024191475A1 |
| Adaptive chat UI & rich output (Canvas) | The chat interface itself | US20260093899A1, WO2026072442A1, US12039431B1, US12051205B1, US12164548B1, US2025274411A1 |
| Compute-in-memory hardware (Rain) | The hardware they bought (Rain) | US2024160693A1, US12159683B2, US10430493B1 (plus 13 supporting) |
| Custom silicon packaging | The lone chip | US20260093634A1 |
| Model factory (training/scaling/safety) | The model factory | US12079587B1, US12073299B2, US12387007B2, US12406207B2, US2024362421A1, US2025348482A1 |
| Search & retrieval infra (Rockset) | The search plumbing they bought (Rockset) | US11030242B1, US11327962B1, US11860871B2, US12353480B2 |
Ring 1: what the AI directly does
Agents that use a computer
Formal category: Computer-use agents and the translucent overlay operator. This is the estate fencing how an agent learns interface actions from video and how it perceives a live screen and injects clicks and keystrokes into arbitrary apps with safety and coordinate correction.
These four patents cover the two hardest parts of building an AI that can operate a computer the way a person does, where the training data comes from and how the finished agent actually reaches out and clicks things.
- US11887367B1 - Using machine learning to train and use a model to perform automatic interface actions based on video and input datasets. Covers a way to teach a computer to use a keyboard and mouse without paying an army of people to label the training data by hand. The hard part is that a model needs examples of a screen paired with the exact clicks and key presses that caused each change, and hand-labeling thousands of hours of video that way is impossibly expensive. This patent gets around that with a three-stage pipeline. First it trains a small “labeler” model on a modest amount of hand-labeled video, and it lets that labeler peek at both past and future frames, which makes its guesses about “what action happened here” much more accurate. Then it turns the labeler loose on a huge pile of free, unlabeled internet video and tags every frame with a predicted action. Finally it trains a second, working model on all that auto-tagged video, and that second model can then operate a real interface on its own, clicking, typing, scrolling, and more, using only what it has seen so far because in live use the future has not happened yet. It relates to OpenAI’s computer-use agents, and it is the training-data foundation such an agent would sit on.
- US2025348183A1 - Overlay application and techniques for interfacing with a generative response engine. Covers a see-through overlay window that lets an AI drive the real programs on your machine rather than staying trapped inside a chat box or a browser tab. The overlay is a nearly invisible layer that floats over whatever application you have open. It takes a screenshot, sends it to an AI model, gets back an instruction such as “click here,” and then injects that click and any keystrokes into the real application underneath. It keeps the operating system’s attention on itself rather than on the target app, so it stays in control while still driving the app in the background. Around that it wraps two guardrails: a safety layer that reads the AI’s own written description of what it is about to do and blocks it if it looks dangerous, and a correction loop that crops the area around a proposed click, double-checks with a small validator model whether the click will actually land on the intended button, and adjusts the aim before acting. It relates to OpenAI’s Operator, and it fences both how such an agent clicks and how it is kept from doing something reckless.
- US2025348196A1 - Overlay application and techniques for interfacing with a generative response engine. Covers the same see-through overlay operator, described here as a coordinated platform of parts rather than a single tool. One part orchestrates everything, one part draws the overlay, one part talks to the operating system to track which application currently has focus, and one part actually injects the synthetic clicks and keystrokes. The platform also chooses how to control an app depending on how it is built, driving a web page through its underlying page structure and driving a natively drawn program through pure computer vision, meaning the model reads the screen the way a person would rather than through any special machine-only hookup. It checks proposed actions for safety, corrects the aim of clicks, and records a before-and-after snapshot of each action so the results can feed future training. It relates to OpenAI’s Operator, fencing the same capability a second way as an engineered platform, which broadens the protection around it.
- WO2025235715A1 - Overlay application and techniques for interfacing with a generative response engine. Covers the international version of the same overlay operator, with its framing leaning on two ideas. The first is that the operator can reach the AI model across several surfaces at once: a web page’s underlying structure, an application’s own programming interface (the built-in commands a program exposes for other software to call), and raw computer vision that simply reads the pixels on screen. The second is a screen-reading trick that slices any screenshot, whatever the display size, into fixed-size tiles the model can handle. It keeps the same click-correction loop, here extended to trickier inputs such as click-and-drags and modifier-key clicks, the same safety screening of the AI’s stated intent, and the same before-and-after training capture that waits for the screen to stop changing before recording the result. It relates to OpenAI’s Operator, extending the same protection beyond the United States.
Code, written and then run
Formal category: Code generation and the run-and-verify loop (Code Interpreter). This is the estate fencing a machine that not only writes code but executes it, selects the winner by mechanical test-pass rate, and feeds execution results back as self-generated training data.
These five patents fence the shift that made AI coding tools trustworthy, from a machine that merely writes code to one that runs its own code, checks whether it worked, and tries again when it did not.
- US12498947B2 - Interpreting computer code with a multimodal machine learning model. Covers the Code Interpreter, a model wired to a walled-off code interpreter (a safe sandbox where untrusted machine-written code can run without touching the real computer) so it can write code, run it, read the error, rewrite it, and retry until it works with no human in the loop, and it even fences the decision of whether to write code at all so a simple question gets a plain answer instead of a needless program. It is the group’s standout and its most defensible filing, the patent behind the moment a chatbot stopped merely talking and started doing real work like analyzing a spreadsheet or handing back a finished chart.
- US12008341B2 - Systems and methods for generating natural language using language models trained on computer code. Covers the granted United States version of the run-check-and-learn loop, and it runs the loop in reverse too, generating plain-English descriptions from code and pairing the two directions so each model teaches the other, an arrangement the inventors deliberately labeled “non-conventional and non-generic” to fend off a challenge that it is an obvious idea. It relates to Codex, and it is the enforceable, earliest-priority anchor of the group.
- EP4716883A1 - Systems and methods for generating code using language models trained on computer code. Covers the same pipeline that picks the best machine-written program by actually running each candidate and scoring it on how many automated tests it passes rather than on which code merely looks correct, then feeds those results back as fresh training data so the system improves on its own successes. It is the European filing of the Codex run-and-verify invention.
- US2024402999A1 - Systems and methods for generating code using language models trained on computer code. Covers a pending United States version of the same machinery, emphasizing a ranking that scores each candidate program by the model’s own confidence and a focused way of training the companion description model. It relates to Codex, and it is one more overlapping filing that thickens the fence around the run-and-verify method.
- WO2024242700A1 - Systems and methods for generating code using language models trained on computer code. Covers the international version of the disclosure, and it states the elegant core most plainly: the results of running the code do two jobs at once, picking the best program and becoming new training data, so the system teaches itself with no outside labels. It relates to Codex, extending the run-and-verify protection across many countries.
Making images and video
Formal category: Generative visual media: DALL-E and Sora. These are the visual generative engines: a describe-then-draw two-stage image pipeline and a diffusion-transformer video engine operating on spacetime patches.
These six patents stake out picture-making and movie-making, and they split into a DALL-E image line and a Sora video line that dominates the group.
- WO2025174789A1 - Generative video engine capable of outputting videos in a variety of durations, resolutions, and aspect ratios. Covers the Sora engine itself, a diffusion-transformer that slices a video into small blocks spanning both space and time, the spacetime patches, and processes all of them at once across many graphics chips with each chip aware of the others so the finished clip stays consistent instead of drifting, and it sets a video’s length and shape simply by arranging its noisy starting frames into the right count and grid. It is the group’s standout and technical heart, the machine that generates a minute of coherent video from a sentence.
- US2025259361A1 - Storyboard graphical user interface to a visual media generative response engine. Covers the Sora storyboard, a timeline where a creator drops prompts at specific moments so scenes change when intended, sitting on top of that same spacetime-patch engine. It relates to Sora, and it is the editing timeline that turns the tool from a one-shot prompt box into something you can direct scene by scene.
- US2025259362A1 - Prompt editor for use with a visual media generative response engine. Covers the Sora prompt editor and the routing behind it, deciding when you attach an image whether you want that exact picture to appear in the video or just want the video to borrow its look and feel, then sending the image down the matching path. It relates to Sora, fencing the front-end box and that intent decision a second way alongside its siblings.
- US11922550B1 - Systems and methods for hierarchical text-conditional image generation. Covers the DALL-E way of turning a sentence into a picture in two steps, first converting your words into a compact numeric summary of the intended image, then painting the image from that summary, with the text reader and image reader trained together so a caption and its photo end up described the same way. It relates to DALL-E, and it is the earliest anchor of OpenAI’s image line, the patent behind a typed sentence becoming a photorealistic picture on demand.
- US11983806B1 - Systems and methods for image generation with machine learning models. Covers editing inside a picture and extending it past its borders, erasing a region and asking the model to fill it back in to match its surroundings, or growing a square photo into a wide one, using a mask that straddles the edge so the model can see the existing image while it invents the extension. It relates to DALL-E’s edit, inpaint, and outpaint features.
- US2025259423A1 - Model image generation using recaptioned images. Covers a data-cleaning trick that rewrites the sloppy, scraped captions on training images into richer, more accurate ones, using a small tuned captioner rather than a full language model to keep costs down at web scale, because a generator that learns from better descriptions draws what you actually asked for. It relates to DALL-E’s image quality, the unglamorous groundwork beneath the visible product.
Text, inserted and edited
Formal category: Text insertion and instruction-driven editing. This is an AI writer that inserts text into the middle of a document conditioned on both sides, retains the document’s key facts across edits, and turns plain-English requests into concrete editing controls.
These three patents fence the machinery that let an AI write and rewrite inside an existing document, not just add to the end of one.
- US11886826B1 - Systems and methods for language model-based text insertion. Covers a writing assistant with three parts working together: it inserts text into the middle of a document by looking at both the words before the gap and the words after it so the new passage reads smoothly in both directions, it pulls out a document’s key facts (the who, what, where, when, and why) and holds them across many small edits so it does not reread the whole thing each time, and it turns a casual instruction like “make this friendlier” into concrete settings for tone, structure, and format. It is the group’s standout, the patent behind highlighting a sentence in ChatGPT and asking it to rewrite the sentence in place.
- US11983488B1 - Systems and methods for language model-based text editing. Covers the same technology framed as two separate systems, one that edits by following plain-English instructions while holding onto the document’s key facts across a run of edits, and one that inserts into a gap by reading both sides and letting the model choose exactly where to drop the new text. It relates to the iterative revision behavior inside ChatGPT, where a draft keeps improving across passes without the assistant losing track of the document.
- WO2024191475A1 - Systems and methods for language model-based text editing. Covers the international version of the same invention with one added wrinkle: it explicitly allows starting from an empty document, so you can hand the system nothing but an instruction and get a fresh draft from a blank page. It relates to AI-assisted writing in ChatGPT, extending the same protection to generating new writing from a single plain-English request.
The chat interface itself
Formal category: Adaptive chat UI and rich output surfaces (including Canvas). This is the chat surface itself: visual grounding into and out of images, model-emitted interactive widgets, reaction signals, and the Canvas collaborative editing pane.
These six patents fence the window you actually touch, the surface you point at, read, and react to, rather than the model that answers.
- US20260093899A1 - Collaboration on an asset using a generative response engine. Covers Canvas, the side-by-side editing pane, and the deepest engineering in the group: rewriting only the sentence you selected rather than regenerating the whole document, previewing the answer before the model finishes typing, keeping a reliable undo history of every edit, and a memory-saving trick that quietly sends only the current version of your document to the model instead of every past version. It is the group’s standout, the invention behind an AI that edits your document like a careful collaborator instead of retyping the whole thing every time.
- WO2026072442A1 - Selective interaction with a portion of content by a generative response engine. Covers the international sibling of the Canvas patent, foregrounding AI comments anchored to the exact line or phrase they refer to, the way a human reviewer leaves margin notes, alongside the same selective rewrites and memory-saving messages. It relates to Canvas, specifically its inline AI comments and suggestions.
- US12039431B1 - Systems and methods for interacting with a multimodal machine learning model. Covers letting you point instead of describe: you click, circle, or draw on an image and the AI knows which part you mean rather than making you type out “the small plant in the bottom-left corner,” and it can even offer ready-made questions tied to wherever you pointed. It relates to the point-and-ask behavior in ChatGPT’s image features.
- US12051205B1 - Systems and methods for interacting with a large language model. Covers the mirror direction, where the AI answers a question about an image by placing a visible marker right on the spot instead of writing a paragraph describing where to look, which matters enormously for anyone with low vision, and it lays a faint grid over the picture so the model has a coordinate frame and can even nudge the marker if it landed slightly off. It relates to visual pointing and screen interaction in ChatGPT’s vision features.
- US12164548B1 - Adaptive UI for rich output rendering of assistant messages. Covers teaching the model, through training rather than a one-off instruction, to answer with a real chart, table, map, or small working app when that fits better than a paragraph, and it fixes a subtle bug by handing a clicked table cell back with its meaning attached instead of a bare number. It relates to ChatGPT’s interactive rich message widgets.
- US2025274411A1 - User and model reactions with large language models. Covers lightweight reactions the model can both send and learn from, a thumbs-up, heart, or laugh, using them as cheap training feedback and even to decide whether to reply now or wait for you to keep typing. It relates to the reaction and feedback affordances in the ChatGPT interface.
Ring 2: what makes the AI a persistent agent
Serving the model as a product
Formal category: Serving the model as a product: APIs, caching, and chain-of-thought. This is the plumbing that turns a raw model into a callable, billable, stateful, tool-using, reasoning service.
These seven patents fence the machinery that sits in front of a model to make it a service people can call, pay for, and build on, not the intelligence itself.
- US12596764B1 - Prompt caching in generative response engines. Covers the machinery for reusing a model’s work on a repeated block of text, computing a fingerprint from the start of your prompt so matching prompts always land on the same machine and the saved work can be reused for the longest repeated stretch, extending the same trick to repeated images and audio, and, most aggressively, it claims the automatic fifty percent discount on cached input as protected subject matter. It is the group’s standout, the clearest case in the whole portfolio of OpenAI trying to patent a number on its own price sheet rather than just a speed-up.
- US12400074B1 - Stateful pretrained transformers in a generative response engine. Covers a way to make a normally forgetful model behave like a multi-step machine by pausing it mid-answer, swapping in a fresh set of instructions for the current stage, and then finishing, so a single chatbot can play several roles in one conversation, say search, then checkout, then payment, without cramming every rule into one bloated instruction sheet or leaking one stage’s rules into the next. It relates to OpenAI’s stateful-agent building patterns, and it is the group’s most conceptually distinctive filing.
- US12554519B2 - Virtual assistants API. Covers the Assistants API, which lets a developer save an assistant once under a permanent identity and reuse it rather than resending every instruction on each call, stores conversations as separate objects that different assistants can share, and turns a pile of files into a searchable collection in a single call. It relates to the Assistants API and its file-search and threads features.
- US12591766B1 - Application programming interface with generative response engine state management. Covers the Responses API, which moves an entire multi-step task onto the server by looping through tools on its own until the model signals it is done with a special “end turn” token, lets you resume a past conversation from a single identifier without replaying its history, and can force the model to emit a properly formatted tool call when one is required. It relates to the Responses API and its server-side tool-calling.
- US12450198B2 - Systems and methods for generation of metadata by an artificial intelligence model based on context. Covers a pipeline that reads a piece of content, including images, video, and audio, and generates a fitting title, thumbnail, or summary, then automatically trims and cleans the result to the exact size a spot in the interface needs. It relates to the automatic titling and summarization features layered on top of OpenAI’s multimodal models.
- US20260073295A1 - Generative response engine using chain-of-thought reasoning. Covers how a reasoning model generates private step-by-step thinking, uses it to produce the answer, then throws that thinking away so it neither reaches you nor clogs the model’s limited memory, while a cheaper second model writes the live “here is what I am thinking” summary you see on screen. It relates to how OpenAI’s reasoning models serve a hidden chain of thought behind a visible summary.
- WO2026059944A1 - Generative response engine using chain-of-thought reasoning. Covers the international version of that same hidden-thinking, visible-summary design, with added attention to how the summary appears on screen, as a collapsible panel with a reasoning-time indicator shown inline or side by side. It relates to the same reasoning-model serving behavior, filed for protection internationally.
Remembering you
Formal category: Memory and personalization. This is the per-user context machinery: an auto-curated notepad of facts, a settings-driven instruction store, and highlight-to-refine follow-ups.
These four patents fence the pieces that give ChatGPT a memory, so you stop reintroducing yourself at the start of every new conversation.
- US2025200361A1 - Selective learning of information for the generation of personalized responses by a generative response engine. Covers ChatGPT Memory, a size-capped, human-readable notepad of facts the assistant keeps about you across conversations, and its clever move is applying reinforcement learning (a training method where the model improves by being graded on its choices) to the single question of what is worth remembering, so you never have to say “remember this,” plus a background housekeeping process that merges duplicate notes and drops stale ones. It is the group’s standout, the actual machinery behind ChatGPT quietly remembering your name, your work, and your preferences.
- WO2025128397A1 - Selective learning of information for the generation of personalized responses by a generative response engine. Covers the international version of the same Memory invention, leaning harder on the privacy switches, requiring you to turn memory on and letting you turn it off for a single conversation, and describing how it can notice patterns that show up only across many chats. It relates to ChatGPT Memory as deployed internationally, including its on-off controls.
- US12430518B2 - Custom model instructions with language models. Covers Custom Instructions, the settings panel where you describe yourself once, and the careful machinery that reloads those preferences only at the right moments and checks whether they even matter for your current question before applying them, so a saved “I am a nurse” does not clutter an unrelated coding answer. It relates to ChatGPT Custom Instructions.
- US12443803B2 - Systems and methods for targeted interactions with computational models. Covers pointing at part of an earlier answer and following up on just that piece, where you highlight the text, type an instruction, and the system quietly stitches the two into one clean request behind the scenes, and it even works on a region of a generated image. It relates to the highlight-to-edit and follow-up interactions in ChatGPT.
Plugging in the outside world
Formal category: Tool use, plugins, and RAG integration. This is how a model safely discovers and calls live external services by reading a publisher-hosted manifest at a known URL and translating model requests into real web calls.
These three patents fence the moment a chatbot stopped being a closed box and could reach live information and take real actions on your behalf.
- US11922144B1 - Schema-based integration of external APIs with natural language applications. Covers the plugins arrangement where a company that runs an online service posts a small description file (a manifest) on its own website, at a predictable web address the AI already knows to check, and the AI reads that file, learns what the service can do, and calls it on the user’s behalf with no engineer wiring the two systems together, and it is memorable because it writes the literal web address .well-known/ai-plugin.json into the patent. It is the group’s standout, the filing that tried to fence the moment AI started using the live internet on your behalf.
- US2024427571A1 - Schema-based integration of external APIs with natural language applications. Covers the same underlying invention from a system angle, emphasizing that a single chat window can plug into many different live services at once, each discovered through its own publisher-hosted description file. It relates to ChatGPT Plugins and the function-calling convention, and it is a same-disclosure sibling of the standout.
- US12547480B2 - Schema-based integration of external APIs with natural language applications. Covers a more built-out, later version with a two-layer setup, a short description file that points to a fuller one, plus a check that confirms the file really lives on the publisher’s genuine domain so an impostor site cannot pose as a service your AI trusts. It relates to the maturing plugins and function-calling platform, the version that tries to make these connections trustworthy at scale.
Teams of agents working together
Formal category: Multi-agent orchestration and automations. This is a coordination layer that lets a team of agents share state and self-schedule work on an append-only ledger, plus a scheduler that gives a timeless model a sense of time.
These four patents fence the layer that lets a crew of AI agents work on a task together without tripping over each other, and lets them do things later on a schedule.
- US12405822B1 - Multi-agent interactions using a shared workspace. Covers a coordination layer for a team of AI agents built on a shared, append-only log (a running logbook where every action is written down as a new entry and nothing is ever erased), on top of which each agent reads the latest updates and decides for itself whether to stay quiet or add something, so there is no central boss and no two agents doing the same job at once, and each agent is sent only the messages from conversations it has joined to cut wasted computing. It is the group’s standout, the plumbing that lets a crew of specialized AIs work as a team without stepping on each other.
- US12346664B1 - Interactions with a generative response engine during a long running task. Covers letting you keep talking to an agent while it works, and it trains the agent to tell the difference between a question it truly cannot proceed without answering and one it can set aside and work around, plus a task outline held in a notepad so it does not lose its place on a long job. It relates to a long-running agent feature, the difference between handing a job to an assistant who vanishes for hours and one you can check in with and redirect.
- US2025373574A1 - Interactions between assistant-type agents. Covers the “have your people call my people” layer where your assistant talks directly to someone else’s assistant to arrange something, stepping in only for messages from another AI, honoring a per-account block list, and acting on its own only within permissions you have already approved. It relates to assistant-to-assistant coordination, and no shipped OpenAI product matches it yet, which makes it a bet on where the technology is going rather than a fence around anything you can use today.
- US12518109B1 - Language model automations. Covers giving a model that has no built-in sense of time a way to do things later, turning “remind me every morning” into a real scheduled task, converting your login into a longer-lived permission so it can act later as your stand-in, and using a second model to write the recurring messages in your own writing style so a daily task does not repeat the same stale line. It relates to a scheduled-tasks or automations feature, the difference between an assistant that only answers when you are watching and one that runs your recurring errands on schedule.
Ring 3: what powers the system
The model factory
Formal category: Model factory: training, scaling, and safety infrastructure. This is OpenAI’s toolkit for building, shrinking, and governing models: embeddings, speech, moderation, PII scrubbing, custom-assistant platform, and distillation.
These six patents fence the machinery behind the products rather than a single headline product, the tools for building, shrinking, and controlling models.
- US12079587B1 - Multi-task automatic speech recognition system. Covers Whisper, a single speech model that transcribes, translates, detects speech, and identifies languages all at once, steered by a short sequence of control tokens fed in at the start, trained on roughly 680,000 hours of audio cleaned up automatically from the internet, with clever tricks for feeding in long audio and recovering when its output goes off the rails. It is the group’s standout and the best-evidenced specification in the whole portfolio, packed with concrete numbers where most filings assert benefits vaguely.
- US12073299B2 - Systems and methods for using contrastive pre-training to generate text and code embeddings. Covers a way to turn text and code into the numeric fingerprints that let a search box understand meaning rather than match keywords, training the model by comparing examples against each other within a batch (which avoids a costly extra step) and starting from an already-trained generative model rather than from scratch. It relates to OpenAI’s embeddings service for semantic search and retrieval.
- US12387007B2 - Personally identifiable information scrubber with language models. Covers a scrubber that redacts personal information from text, using a big, careful “teacher” model to learn the hard, context-dependent difference between a public name in a news story and a private name in a medical record, then transferring that judgment to a smaller, cheaper “student” model that does the actual redacting at scale. It relates to OpenAI’s content and privacy safety tooling.
- US12406207B2 - Systems and methods for generating customized AI models. Covers the platform behind the GPTs builder and its store, a five-part recipe for building a custom assistant plus, tellingly, an automated evaluator model that checks each new user-made assistant for policy compliance before it goes live, safety at the scale of an app store with no human in the loop. It relates to the GPTs builder and the GPT Store.
- US2024362421A1 - Systems and methods for language model-based content classification. Covers the content-moderation model that flags sexual, hateful, violent, and self-harm material, built by a training loop that repeatedly cleans its own data and retunes until it stabilizes, and it even tries to catch the failure where a model fixates on a single loaded word. It relates to OpenAI’s moderation endpoint.
- US2025348482A1 - Generating a distilled generative response engine trained on distillation data generated with a language model program. Covers making AI web search fast and cheap by using a slow, elaborate assistant only to generate training examples, then teaching a small, fast model to reproduce them so it can answer in a blink instead of making you wait ten seconds. It relates to OpenAI’s search product, the fast, cited answers over live web results.
The search plumbing they bought (Rockset)
Formal category: Search and retrieval infrastructure: the Rockset estate. This is a four-patent acquired estate for a real-time search and analytics database, centered on a converged index that answers many query classes fast over messy, constantly-changing data.
These four patents did not come from OpenAI’s labs; they arrived when OpenAI bought Rockset in 2024, and they read like engine parts for a specialized real-time database.
- US11030242B1 - Indexing and querying semi-structured documents using a key-value store. Covers the converged index, which folds three different index types (an index being a lookup structure that makes searching fast, the way the tabs on a filing cabinet let you find a folder without reading every one) into a single storage layer so that many kinds of question can each be answered quickly over messy, constantly-changing data, without anyone defining a rigid structure in advance, and it updates only the fields that actually changed rather than rebuilding. It is the standout of this acquired estate, the quiet machinery that decides whether a search over a big, messy pile of data comes back in a blink or in a minute.
- US11327962B1 - Real-time analytical database system for querying data of transactional systems. Covers reusing the same three-index design to keep an analytical copy of a database fresh within seconds of a live system, applying only the changed entries from a change log. It relates to real-time analytics, and it is the standout’s closest sibling.
- US11860871B2 - Continuous delivery of database queries for applications based on named and versioned parameterized database queries. Covers storing each query as a named, versioned record exposed at its own web address, so applications run queries by calling a URL instead of embedding query code. It relates to the surrounding database machinery.
- US12353480B2 - Efficient execution of database queries on streaming data. Covers pre-summarizing streaming data as it arrives so that reports over high-volume streams come back fast without reprocessing the whole history. It relates to the same real-time analytics plumbing.
The hardware they bought (Rain)
Formal category: Compute-in-memory hardware: the Rain estate. This is a 16-patent acquired estate for compute-in-memory AI accelerators, spanning an abandoned analog-nanowire generation and a conventional digital SRAM generation, with three cleanly severable standouts.
These sixteen patents did not come from OpenAI’s labs either; they arrived with the 2024 acquisition of Rain Neuromorphics, and read as a set they tell the story of a chip startup that changed its mind about how to build an AI chip. The three severable standouts get full bullets; the thirteen supporting filings get short notes.
- US2024160693A1 - Error tolerant AI accelerators. Covers an AI chip that survives radiation by armoring only a tiny compressed copy of its learned values rather than the whole table, dropping the extra armored area from roughly 200 to 300 percent down to about 10 to 20 percent, then rebuilding the full table on demand when it senses trouble on a timer or a failed self-check. It is a clean, severable asset, a hardware fault-tolerance technique any accelerator maker serving satellites, space systems, defense, or medical imaging could license independent of any AI model.
- US12159683B2 - Methods for efficient 3D SRAM-based compute-in-memory. Covers stacking chip layers that talk to each other wirelessly through magnetic coupling, the same effect that charges a phone on a pad, instead of tiny wires drilled straight down, so the layers no longer have to line up perfectly during manufacturing. It is a severable building block, an alignment-tolerant die-to-die link that a chip-packaging house could license on its own.
- US10430493B1 - Systems and methods for efficient matrix multiplication. Covers the founding Rain idea, scattering special nanowires (wires thinner than a human hair, each wrapped in a material whose resistance you can set and that then remembers it) at random onto a grid of electrodes and letting that messy physical mesh do a neural network’s core math directly through physics, scaling with the chip in a way orderly grids cannot. It is the origin artifact of Rain’s whole thesis, the founding bet that a neural network could learn as raw circuit physics.
- US11450712B2 - Memristive device. Covers a nanowire whose insulating coat has small openings filled with programmable-resistance plugs, an early analog-hardware building block for sparse resistance networks.
- US11551091B2 - Learning in time varying, dissipative electrical networks. Covers computing learning adjustments locally inside a physical, changing electrical network, so the circuit trains itself without the usual backpropagation step.
- US11755890B2 - Local training of neural networks. Covers a hardware network with paired weight copies and polarity-switching neurons that learns from differences in activity rather than from computed gradients.
- US11922296B2 - Electrical networks using analytic loss gradients. Covers computing exact training adjustments for a hardware network by reusing symmetric pieces of the circuit’s own math, letting even lopsided circuits be programmed precisely.
- US12271439B2 - Flexible compute engine microarchitecture. Covers a compute-in-memory block that keeps all its multiply units busy whether it runs at lower or higher numeric precision, sharing hardware between the two modes.
- US12541690B2 - Training optimization for low memory footprint. Covers profiling candidate training techniques for a given model and picking the fastest one that fits within a fixed memory budget on a memory-based accelerator.
- US2021049504A1 - Analog system using equilibrium propagation for learning. Covers an analog network that uses the circuit’s own stored energy as the quantity being minimized, so learning emerges from the physics.
- US2024143541A1 - Compute in-memory architecture for continuous on-chip learning. Covers pairing each compute-in-memory block with a co-located update unit so weights can change on-chip during training with no off-chip data trips.
- US2024169203A1 - Fast target propagation for machine learning and electrical networks. Covers a feedback network that physically computes the math needed to train every hidden layer at once, an alternative to backpropagation.
- US2024403043A1 - Architecture for AI accelerator platform. Covers a system-on-chip where one general-purpose processor serves as both the control and the data path for its compute-in-memory engines.
- US2025028674A1 - Instruction set architecture for in-memory computing. Covers a compute tile with a custom processor instruction that remaps address ranges in sequence to orchestrate several compute-in-memory engines.
- US2025045224A1 - Tiled in-memory computing architecture. Covers a tile layout where data movers address the compute engines directly and route around the general-purpose processor, keeping it only for control and nonlinear steps.
- US2025117441A1 - Convolution operations with in-memory computing. Covers a tile where a compact processor is tightly coupled to the compute-in-memory engines, handling convolution reshaping and tuning each engine’s clock to how much work it faces.
The lone chip
Formal category: Custom silicon packaging: the lone chip. This is the single hardware patent OpenAI authored on its own: a multi-chiplet package that relays high-bandwidth-memory signals past the JEDEC distance limit using active logic bridges embedded in the substrate.
This group holds exactly one patent, and that is the point of it: the single hardware invention OpenAI made entirely on its own.
- US20260093634A1 - Non-adjacent connection of high-bandwidth memory chiplets, I/O chiplets, and compute chiplets through embedded logic bridges. Covers a way to wire memory that sits too far from the processor to talk to it under the normal industry rules, using tiny active relay chips buried in the package that catch the fading electrical signal, clean it up, and pass it along, so a processor can reach many more memory stacks than the standard allows (a chiplet being one of the small chip modules that combine into a single package, some doing the computing and others holding fast memory). It is the clearest hardware signal in the whole portfolio that OpenAI intends to design its own silicon, since a company content to buy its chips from others would not bother patenting how memory is physically arranged around a processor.
Cross-cutting: what the whole portfolio reveals
What OpenAI is not patenting: missing versus hidden
Now for the photo negative. Once you have seen what OpenAI fenced, the more revealing exercise is to notice what it did not, because the empty spaces map the strategy. But the empty spaces are not all the same kind of empty, and conflating them is the single easiest way to get this story wrong. There are two very different reasons a patent can be missing.
The first bucket is genuinely not patented, and it is enormous. There is no patent on the model’s architecture, none on how the model is trained, whether the initial pre-training or the reinforcement learning from human feedback that shapes its behavior, none on the evaluation methods, almost nothing on safety and alignment, nothing on real-time voice, nothing on the deep inference plumbing, and nothing on vector search. This is the science, and its absence is deliberate in two different ways. Some of it OpenAI keeps as a trade secret, and some of it OpenAI already published, which permanently bars a patent. A patent and a trade secret are opposite strategies for protecting an idea. A patent is a lock on the front door that everyone can see: you publish exactly how your invention works, and in exchange you get the right to stop others from using that method for about twenty years. A trade secret is the opposite bet: you never show anyone the room at all, and you are protected only for as long as nobody else figures it out. You patent what a rival could watch you do and copy. You keep secret what they cannot see from the outside. A model’s training recipe lives inside OpenAI’s own computers, so it can stay a secret. A product feature ships to millions of users, so it cannot, which is exactly why the products get patented and the science does not.
The one-line rule that explains the entire organic portfolio is this: OpenAI patents what a competitor can watch, and keeps secret what a competitor cannot. Every group in this article obeys it.
The second bucket is different, and it is a caution against over-reading the first. Some absences are not absences at all. They are patents that exist but that we cannot see yet. When you file a patent, it does not become public right away. It stays hidden for roughly eighteen months before it publishes. That delay is normal and universal, but it has a striking consequence here. Everything OpenAI has filed since roughly early 2025 is invisible to us today, and even the portfolio we can read is already a year and a half out of date. The map in this article is a photograph of where OpenAI was in the past, not where it is now.
So when we say OpenAI has not patented something, we mean one of two things, and the difference matters. Either it genuinely chose not to, which reveals strategy, or it may already have and we simply cannot see it yet, which reveals only the calendar. The science, the architecture and training and alignment, sits firmly in the first bucket, because OpenAI published enough of it to make its intentions clear. Newer product areas may sit in the second. We flag which is which throughout, and we resist the temptation to read every gap as a deliberate choice.
The tell: how these patents are written
Spend enough time inside these documents and you start to notice the seams, the small drafting habits that reveal how the portfolio was built and what its authors were worried about. Three tells stand out.
The first is a coined phrase. Across many of OpenAI’s patents, the model is never called GPT, or ChatGPT, or a large language model. It is called a “generative response engine.” OpenAI appears to have invented this house term precisely so its claims can describe what its product does without naming the product, which keeps the fence abstract and reusable across filings. Once you know to look for it, the phrase turns up everywhere, a small linguistic fingerprint left across the portfolio, and it is a clue that these filings were drafted as a coordinated set rather than one at a time.
The second tell is the legal dance around a rule that shapes all software patents. United States patent law says you cannot patent an abstract idea. You cannot own “the concept of a chatbot that remembers you.” You can only own a specific, concrete machine or method that achieves it. So software patents are written to sound as physical and specific as possible, reciting particular components, particular data structures, and particular steps, precisely to survive the challenge that they are merely claiming an abstract idea. OpenAI’s patents do this constantly, and their own reviewers flag, again and again, exactly which claims are most exposed to being struck down as too abstract.
The third tell is repetition, the same invention filed several ways, which is why sixty-nine families collapse to about thirty-four to thirty-six real inventions. That is not sloppiness. It is a deliberate strategy of overlapping fences, which we count as a strength in the next section.
Strengths
For all the caveats, this is not a weak portfolio for what it is trying to be. Its strengths are real and worth stating plainly.
It planted flags early on the ground that turned out to matter most. The computer-use training pipeline was filed in April 2023, well before anyone shipped a computer-use product, and the multi-agent coordination and anticipatory messaging patents stake out territory the industry is only now walking onto. Being first to the patent office on the agent land is a genuine advantage.
Its coverage tracks real products tightly. Because OpenAI patents what it ships, the fences sit on features that actually exist and actually make money, rather than on speculative research that may never leave the lab. A patent on a live feature is worth more than a patent on a maybe.
It builds in depth, not just breadth. The habit of filing the same invention several ways, as a United States patent, a pending application, and an international filing, means that if one filing falls to a challenge, the others may still stand. One loss does not sink a feature. That is what the overlapping fences buy.
And the acquisitions, whatever else they are, bought OpenAI something it could not otherwise have: older priority dates. The Rain and Rockset filings reach back to 2018, years before OpenAI filed anything of its own, which gives it a few early flags in hardware and search it could never have planted itself.
Weaknesses
The weaknesses are just as real, and an investor should weigh them honestly.
It is mostly a United States wall. The portfolio is heavily weighted toward United States filings, with thinner protection abroad, which means the fence is strongest in one market and weaker in the others where AI competition is intensifying.
Its patents make big promises with few measurements. Across group after group, the specifications assert efficiency gains, “fewer inferences,” “reduced computational resources,” without the benchmark data to back them, and patent reviewers flag this repeatedly as a vulnerability, because a claim you cannot support is a claim that can be narrowed or struck. Whisper, the one thoroughly evidenced filing, only underscores how thin the others are.
In several cases, OpenAI’s own past work is the closest prior art. Because the company published so much, its filings on text editing, on the Assistants API, and on image generation sometimes have to distinguish themselves from OpenAI’s own earlier publications, an awkward position that its reviewers name directly.
There is nothing before 2022 that OpenAI actually filed. The organic portfolio is young, and youth means fewer granted patents, less prosecution history, and less battle-tested protection.
And the biggest holes are the ones already mapped: no real fence around safety, around voice, or around vector search, three areas that are central to where the products are going.
The Anthropic mirror
It would be easy to read everything so far as a quirk of one unusual company. So we checked the mirror. OpenAI’s closest rival, Anthropic, has a patent portfolio too, and looking at it turns the OpenAI story from a quirk into a field-level truth.
Anthropic owns about seventeen patent families, and independent analysis confirms that it originally filed only about one of them itself. Nearly all the rest were acquired, and the patent-office assignee records name IBM on the oldest families, which carry priority dates from 2016 to 2021, years before Anthropic was founded in 2021, and titles that are unmistakably old IBM Research work. (Source: PatSnap portfolio analytics, 2026-07-20, with the acquired-versus-original split independently corroborated by Lumenci’s public Anthropic portfolio analysis, accessed 2026-07-20.) A company founded in 2021 cannot have originated a 2016 invention, so whatever those older families are, they are not homegrown. When a patent changes hands, it can move two ways. An assignment is a sale, where ownership transfers completely, the way selling your house makes the buyer the new owner. A license is permission to use, where the original owner keeps the property and simply lets someone else use it, the way renting lets you live somewhere you do not own. The distinction decides who actually controls the patent. The public assignee records point toward the older Anthropic families being fully owned rather than merely licensed, but confirming assignment versus license for certain requires a records check we flag in the closing checklist rather than assert here.
The punchline is the single family Anthropic did file itself. It is US12387036B1, priority March 20, 2024, granted August 12, 2025, and it covers a multimodal agent for operating a software interface, which is to say Anthropic’s computer-use feature, the one where Claude drives a computer, launched in October 2024. (Source: Google Patents, US12387036B1, accessed 2026-07-20.) Anthropic’s one homegrown patent is a product patent. So the rule generalizes cleanly. OpenAI patents its products and not its science, and files forty-nine of its own. Anthropic barely patents at all, and its single own filing is also a product. Two labs at opposite ends of patenting volume land on identical posture: the science stays unpatented.
There is one more thread worth pulling, because it connects to the citations. Both labs bought their pre-founding patent history rather than inventing it. OpenAI bought Rain and Rockset. Anthropic’s older estate traces to IBM. The company that the popular AI story wrote out of the picture turns out to sit quietly underneath both frontier labs, which is exactly where we go next.
Who OpenAI cites, and who cites OpenAI
Patents leave a paper trail, and the trail is its own kind of map. Every patent cites earlier ones, and those citations run in two directions that are easy to mix up, so let us fix them first. A backward citation is an earlier patent that OpenAI’s own filing had to tip its hat to, an acknowledgment of whose shoulders it is standing on. A forward citation is a later patent that tips its hat to OpenAI, a sign of who is now building on OpenAI’s work. Backward citations point at the past OpenAI came from. Forward citations point at the influence it is starting to have. The counts below come from a portfolio analytics tool, so lean on the ranking and the relative size rather than the exact figures. (Source: portfolio citation analytics, PatSnap, 2026-07-20.)
Look backward, at whom OpenAI cites, and the surprise is how old-guard the list is. OpenAI’s patents lean most on Microsoft, which they cite about ninety-six times, then IBM at about seventy-six, then Google at about seventy, followed by Amazon, Salesforce, Adobe, Intel, Oracle, Samsung, and Huawei. The self-styled disruptor’s paper trail runs straight through the incumbents of twentieth-century enterprise computing. The new company is built, on paper, on the old ones.
Two threads in that list are worth naming. Microsoft, OpenAI’s largest backer, sits on both sides of the graph, as OpenAI’s number-one prior-art source and, looking forward, as its number-two forward-citer, so the partnership is visible right there in the citations. And IBM, at number two backward, is the same IBM whose old patents make up nearly all of Anthropic’s estate. The company written out of the AI story sits underneath both frontier labs at once, cited seventy-six times by one and bought wholesale by the other.
Look forward, at who cites OpenAI, and you see influence beginning to compound. OpenAI cites itself the most, about twenty-five times, which is the fingerprint of a tightly interlinked portfolio drafted as one coordinated program rather than a scattering of unrelated filings. After itself come Microsoft and Google again, both sides of both rivalries. And then, notably, Baidu and ByteDance, two Chinese technology giants, both land in the top ten of companies building on OpenAI’s patents. Chinese labs are already reading and citing OpenAI’s filings, which is worth remembering the next time someone says patents do not matter in this field.
Is this a weapon? Monetization and litigation
So what is the portfolio for? A patent estate can serve three purposes. It can make money by licensing, renting the inventions out for fees. It can be a weapon, used to sue competitors and block them. Or it can be a shield, held mainly to protect the company’s own freedom to operate and to deter rivals from suing first. Which is this one?
The honest answer, as of July 2026, is that it looks like a shield. Three features point that way. The drafting is defensive, written to survive challenges rather than to reach aggressively across a rival’s product. The coverage tracks OpenAI’s own products, which is what you do to protect your freedom to build them, not to attack someone else’s. And the overlapping, layered filings are classic freedom-to-operate insurance, the kind of estate you hold so that if a competitor ever sues you, you have something to counter-sue with, which encourages both sides to cross-license and call it even rather than fight.
The evidence backs this up. There is no OpenAI-initiated patent lawsuit on record, and no offensive patent-licensing program. (Source: patent-litigation research, as of 2026-07-20.) OpenAI is in plenty of litigation, but it is about copyright, over the data used to train its models, not about patents, and it is mostly OpenAI defending rather than attacking. One honest caveat: our local dataset carries no litigation records, so this reading rests on the character of the portfolio plus a light check of the public record, not on a courtroom database. A defensive patent is a fire extinguisher, held in case you need it, mostly to keep others from burning you. An offensive patent is a matchbook, used to start something. Nothing about OpenAI’s estate today looks like a matchbook.
But here is the twist that ties back to the stock. A defensive shield built by a private company can become an offensive sword once that company goes public and faces shareholders who expect every asset to work. A product-tracking, tightly-drafted patent estate is a latent option. It is a shield today that could be picked up as a sword later, and the moment a company most often reconsiders how hard to wield its patents is right after it goes public. Keep that in mind as we close.
Outlook
What follows is informed speculation, clearly labeled as such, with each guess tied to a signal we can actually see. Nobody outside OpenAI knows its patent strategy, but the filings leave tracks.
The first signal is the 2024 burst of agent filings. The computer-use, multi-agent, and automation patents bunch together in 2024, which suggests OpenAI saw agents as the next defensible product layer well before the market did. Expect the agent fence to thicken.
The second signal is the anticipatory filings maturing into products. Assistant-to-assistant messaging and the full desktop-wide operator overlay are patented but not fully shipped. If those patents are honest signals, the products are coming, and the fence went up first.
The third signal is the one we cannot see: the roughly eighteen-month pipeline of filings that have not published yet. Everything OpenAI has filed since early 2025 is invisible, so the portfolio a year from now could look meaningfully different from the one in this article, and a surprise there could reveal a pivot before any product does.
The fourth signal is the IPO itself. A public company under pressure to show defensible assets, and answerable to shareholders, has more reason to both file more and assert more. The single biggest open question in this whole story is whether the frontier norm, that the labs do not patent their science, survives rising competition, an IPO, and the litigation that tends to follow money. What to watch, concretely: does OpenAI start asserting its patents against anyone, does the hidden pipeline reveal a move into hardware or into the science it has so far kept secret, and does going public change its calculus on disclosure versus secrecy.
A few superlatives
Before the close, the portfolio’s oddities and extremes, collected in one place.
The strangest thing OpenAI tried to patent is a price, the automatic fifty percent caching discount, claimed as protected subject matter. A close second is a web address, .well-known/ai-plugin.json, written literally into a filing. The earliest land grab is the computer-use training pipeline, filed in April 2023, roughly two years ahead of the product category. The best-evidenced specification, by a wide margin, is Whisper, the one filing packed with real numbers. And the most collision-prone patents, the ones sitting on the most crowded industry ground, are in the serving group, where everyone caches, meters, and routes, which is why those filings carry the most reviewer flags.
How it all works as one system
A computer-using agent could operate like this, and each step maps to a category:
- The model factory supplies the underlying intelligence.
- Serving infrastructure maintains the task and controls the model.
- Memory loads the user’s preferences and prior context.
- Search and retrieval bring in relevant facts.
- Tools connect the agent to external services.
- Computer use lets it operate applications that have no interface for machines.
- Code execution handles calculations, files, and programmable work.
- Text editing modifies documents precisely.
- Canvas and the adaptive interface present the work to the user.
- Generative media creates visual artifacts.
- Multi-agent orchestration divides the project among specialists.
- Automations let the work continue later.
- Rain and custom silicon could reduce the cost and latency of running the whole system.
So the portfolio’s strategic center is not any single model. It is the integrated architecture of an AI worker: perceive, remember, retrieve, reason, use tools, operate software, create and edit artifacts, verify results, coordinate with other agents, and keep working over time.
The takeaway
The company everyone said had no moat spent about three years quietly fencing the one layer a moat can actually hold. While the world watched the models, argued about their intelligence, and repeated that the real value was in compute and data and talent, OpenAI was at the patent office fencing the product layer, the parts of ChatGPT, Sora, and its agents that a competitor can see and copy. It left the science almost entirely unfenced, some of it kept as a secret and some of it given away years ago, and that combination is not an accident. It is a strategy you can state in one line: patent what a rival can watch, and keep secret what they cannot.
Read as a photo negative, the portfolio maps what OpenAI is afraid of losing. The dense fences sit exactly where competitors could imitate a shipped feature. The empty spaces sit where imitation is impossible because the method never leaves OpenAI’s own computers, or where the idea is already public and belongs to everyone. And the same posture holds across the frontier: Anthropic, in mirror image, filed exactly one patent of its own, and it too is a product.
For anyone weighing the stock as OpenAI moves toward a public listing reportedly targeted for around September 2026 at a valuation that has been discussed as high as a trillion dollars (as of 2026-07-20, and subject to change), the patents are one concrete, legible answer to the question the hype keeps dodging. What does this company actually own? On the patent side, it owns one product-tracking software estate it built in about three years, plus two older estates it bought, aimed today at defense. It is narrower than the mythology, more specific than the headlines, and more honest than either. And it is a shield that a newly public company, answering to shareholders, could one day decide to pick up as a sword. The models are what the world is watching. The patents are where OpenAI told us, quietly and in its own hand, what it thinks is worth keeping.
A note on sources, method, and what still needs checking
This article reads the sixty-nine patents through the analysis already built for them, plus two data sets provided directly and a round of dated web research. A few honest notes.
What the analysis reflects. Everything drawn from the patents describes what those patents say about themselves in their specifications, not what their legal claims would hold up in court. The narrow enforceable claims are usually much smaller than the ambitions described. Where that gap matters, we flagged it. One whole lane of analysis, a close reading of the enforceable claims themselves, has not been run, so treat every product mapping as “this is what the patent describes building,” not “this is what OpenAI could stop you from doing.”
The citation and Anthropic figures. The citation counts (Microsoft 96, IBM 76, Google 70, and the rest) and the Anthropic portfolio figures come from a portfolio analytics tool (PatSnap), captured 2026-07-20, not from the patents in our own database, which carry no citation columns. The exact universe behind the counts is not fully specified, so we leaned on the ranking and the relative sizes rather than the precise numbers. The Anthropic acquired-versus-original split is independently corroborated by Lumenci’s public analysis (accessed 2026-07-20). The specific “sixteen of seventeen families are IBM-origin” figure rests on the PatSnap assignee field and should be read as tool-sourced.
Moving facts. Valuation, IPO status, product launch dates, competitor ship dates, and litigation all carry an inline “as of 2026-07-20” because they change. The valuation (about 852 billion dollars) and IPO posture (confidential filing June 8, 2026) are reported figures, not audited ones.
Before publication, three checks remain. First, a United States Patent and Trademark Office Assignment Search on two or three of Anthropic’s older families would confirm whether IBM assigned or merely licensed them, and pin the exact IBM count, which would let the “sixteen of seventeen” figure move from footnote to body. Second, the exact scope behind the citation counts should be confirmed with the tool’s owner. Third, any product launch date used as a set-piece (Canvas, Plugins, Sora) should get a final source recheck close to publication, since links and dates drift.
