Primer

IP and Regulatory Due Diligence for Medical Device Investments A Working Primer for Investment Banks, Private Equity, and Venture Capital in Life Sciences

Executive Brief
Since April 2025, patent eligibility law for AI-enabled inventions has shifted twice in quick succession: the Federal Circuit’s Recentive decision closed off patents that merely apply generic machine learning to a new clinical dataset, while the USPTO’s Desjardins decision opened a narrower path for claims that genuinely improve how a model itself operates. The two are not reconciled, and examiners are now leaning harder on written description requirements as a result. Separately, the FDA has finalized its framework for how AI-enabled devices update after clearance and overhauled its quality system requirements for the first time since 1996.
This primer translates those shifts into a practical due diligence framework — covering patent portfolio strength, design patent exposure, FDA regulatory files, trade secret practices, litigation risk, and AI-specific technical diligence — built for use before an investment, an exit, or a public offering. It closes with a red-flags checklist for fast triage on live deals.

Contents
Why This Primer, and Why Now 1
Part One: The Current State of Patent Eligibility for AI Medical Devices 2
The Baseline 2
Recentive: The Federal Circuit Draws a Hard Line 2
Desjardins: The USPTO Answers Back, Partially 2
The Section 112 Shift: Where Rejections Are Actually Moving 3
Part Two: A Due Diligence Framework 4
Patent Portfolio Audit 4
Design Patent Review 5
FDA Regulatory File Review 5
Trade Secret Review 6
Litigation, IPR, and Enforcement Exposure 6
AI-Specific Technical and Data Diligence 7
Part Three: How This Framework Maps to the Three Moments That Matter 8
Part Four: Red Flags at a Glance 10
Part Five: A Brief Word on Timing 12
A Closing Thought 12
Final Reminder 12

Why This Primer, and Why Now
You already know why intellectual property due diligence matters. Nobody needs to tell an investment committee that a medical device company’s valuation lives or dies on the strength of what it actually owns, versus what its pitch deck implies it owns. That part of the conversation is settled, and this primer won’t rehash it.
What has changed, and what makes this a useful moment to revisit your diligence checklist, is the ground underneath medical device IP itself. Over the past eighteen months, patent eligibility law for AI-enabled inventions has moved more than it has in the prior decade combined, the FDA has finalized a genuinely new framework for how AI-enabled devices get updated after clearance, and the FDA’s quality system requirements have just gone through the most significant overhaul since 1996. A portfolio that looked strong in 2023 may rest on claims drafted for a legal environment that no longer exists. A regulatory file that looked complete eighteen months ago may be missing a document type that didn’t exist yet when it was filed.
This primer does two things. First, it gives you a working-level refresher on the current state of patent eligibility law for AI medical devices — specifically the Alice framework and the two decisions from the last year and a half that every AI patent portfolio now has to be read against. Second, and this is really the point of the document, it lays out a practical due diligence framework built around that current landscape — one you can use, or hand to whoever runs technical diligence on your deals, before an investment, an exit, or a public offering.

Part One: The Current State of Patent Eligibility for AI Medical Devices
You know Alice. A brief refresher on where things stand today, and then two recent developments that matter more for valuation purposes than most diligence checklists currently account for.
The Baseline
Alice Corp. v. CLS Bank International, 573 U.S. 208 (2014), built on Mayo Collaborative Services v. Prometheus Laboratories, Inc., 566 U.S. 66 (2012), to create the two-step framework that still governs subject matter eligibility under 35 U.S.C. § 101. Step one asks whether a claim is directed to an abstract idea, a law of nature, or a natural phenomenon — courts have long treated “analyze data, reach a conclusion” as abstract on its face, which puts machine learning claims at structural risk almost by default. Step two asks whether the claim adds an inventive concept sufficient to transform that abstract idea into something eligible. Generic computer implementation has never been enough to clear step two, and it still isn’t.
Recentive: The Federal Circuit Draws a Hard Line
On April 18, 2025, the Federal Circuit issued its first precedential decision squarely addressing Alice as applied to machine learning: Recentive Analytics, Inc. v. Fox Corp., 134 F.4th 1205 (Fed. Cir. 2025). The patents at issue covered using machine learning to generate television scheduling and network maps. The court framed the case as one of first impression — whether claims that do no more than apply existing machine learning methods to a new kind of data are eligible at all — and answered no.
Two points from the opinion matter disproportionately for diligence purposes. First, the court rejected the argument that applying a known ML technique to a genuinely novel dataset creates eligibility on its own; a new data environment is not, by itself, a technical improvement. Second, the court rejected the argument that outperforming human speed or accuracy confers eligibility. Combined, these holdings put a large category of “we applied ML to a new clinical problem” patents on materially weaker footing than they occupied before April 2025 — including patents that were drafted, and in some cases already issued, well before anyone could have written around Recentive.
Desjardins: The USPTO Answers Back, Partially
Five months later, the USPTO’s Appeals Review Panel decided Ex parte Desjardins, Appeal No. 2024-000567 (PTAB ARP Sept. 26, 2025), reversing a PTAB rejection of a Google machine learning training patent. The panel found the claims eligible at step two because they disclosed a genuine improvement to how the model itself operates — reduced memory use, reduced system complexity, resistance to “catastrophic forgetting” during training — leaning on Enfish, LLC v. Microsoft Corp., 822 F.3d 1327, 1339 (Fed. Cir. 2016), for the proposition that software can make real, non-abstract improvements to computer function. The USPTO designated Desjardins precedential on November 4, 2025, and folded it into the Manual of Patent Examining Procedure in December 2025, directing examiners to look for concrete, disclosed technical benefits in AI-related applications rather than defaulting to abstract-idea rejections.
The diligence-relevant point: Recentive and Desjardins are not reconciled. One is a binding Federal Circuit decision; the other is USPTO guidance that binds examiners and the PTAB but not the courts. A portfolio built to clear the Desjardins standard alone — real, but modest, disclosed model-level improvements — may still be vulnerable if it’s ever tested in front of the Federal Circuit under Recentive’s stricter reading. When you’re evaluating a target’s portfolio, the operative question isn’t “would this survive at the USPTO,” it’s “would this survive litigation,” and those are no longer guaranteed to be the same question for AI claims.
The Section 112 Shift: Where Rejections Are Actually Moving
One more development worth flagging, because it’s recent enough that a lot of standard diligence templates haven’t caught up to it yet. The Desjardins panel stated directly that Sections 102, 103, and 112 — not 101 — are the appropriate tools for keeping patent scope in check, and prosecution data since the precedential designation shows examiners taking that instruction seriously. Section 112 written description rejections have grown meaningfully relative to Section 101 rejections, both broadly and specifically within AI-related filings, since Desjardins became precedential in November 2025.
Practically, this means a growing share of the risk in an AI medical device patent isn’t “is this eligible subject matter” anymore — it’s “did the specification actually prove the applicant possessed the claimed implementation.” Specifications that describe clinical outcomes in detail (sensitivity, specificity, lead time) without describing model architecture, training methodology, or data flow in comparable detail are now more exposed than they were two years ago, independent of whether the claims would clear Alice. This is a specific, checkable thing in diligence, and it’s covered in the framework below.

Part Two: A Due Diligence Framework
You already know the categories that belong in an IP diligence checklist. What follows is organized around what's changed, and around the three moments where this work actually gets used: before you invest, before you exit, and before a company goes public.
Patent Portfolio Audit
Chain of title and inventorship. Confirm every named inventor actually assigned their rights to the company, in writing, before the relevant filing. This sounds basic; it is also the single most common deal-breaker diligence finds, particularly at companies that used contractors, academic collaborators, or founders who moved between entities before the current company existed. An unassigned inventor can hold up a deal or an exit entirely.
Claim quality against the current eligibility landscape. Pull the prosecution history on every AI-related claim and ask, specifically: does this claim describe a change to the model, the training process, or the computation — the kind of disclosure Desjardins protects — or does it describe a known ML technique applied to a new clinical dataset, the kind of claim Recentive rejected? Portfolios prosecuted before April 2025 were not drafted with Recentive in mind, by definition, and deserve a fresh read rather than an assumption that issuance equals validity.
Section 112 exposure. For issued patents and pending applications alike, check whether the specification discloses real mechanism — architecture, data flow, training methodology, loss function — or whether it primarily describes clinical outcomes. Given the current examiner posture, weak written description is now a live risk for both pending applications (rejection risk) and issued patents (validity risk in litigation or an IPR).
Freedom to operate. Separate from whether the target's own patents are strong, confirm whether the target's product actually practices technology covered by someone else's patent. This is a standard diligence item, worth reiterating here only because AI-specific freedom-to-operate searches are still a less mature practice than traditional device or drug FTO work, and the search itself requires someone who knows how to read ML patent claims, not just device claims.
Claim-to-product mapping. This is worth stating plainly because it gets skipped more often than it should: confirm that the patents in the portfolio actually cover the product being bought, sold, or taken public, not just a product in the same general space. A company can hold genuinely valid, well-drafted patents that read on an earlier prototype, a different model architecture, or a feature the company has since redesigned around — and none of that protects the commercial product you're valuing today. This requires someone to sit down with the current product's actual technical specification and walk it claim-by-claim against the issued patents and pending applications, element by element, the same exercise a defendant's litigation counsel would run if the company ever asserted these patents against a competitor. If nobody has done that exercise recently, a patent count on a cap table slide can be quietly misleading — the number of patents tells you very little if the claims don't actually read on the thing being sold.
Maintenance and deadlines. Confirm maintenance fees are current, confirm PCT national phase deadlines (30 to 31 months from earliest priority) haven't been missed on any pending international filings, and confirm the portfolio's foreign filing footprint actually matches where the company manufactures, sells, or expects to compete.
Continuation and pipeline strategy. Ask whether the company has continuation applications pending that could extend or broaden claim coverage as the product evolves, particularly relevant if the company's PCCP (see below) describes planned future model updates that aren't reflected in the current claim set.
Design Patent Review
If the target holds design patents on device housings, control interfaces, or other ornamental features, revisit them in light of LKQ Corp. v. GM Global Technology Operations LLC, 102 F.4th 1280 (Fed. Cir. 2024) (en banc). The Federal Circuit's May 2024 decision eliminated the rigid Rosen-Durling obviousness test for design patents and replaced it with the same flexible, multi-reference Graham factors used for utility patents. Design patents that would have been difficult to invalidate before May 2024 may be considerably easier to challenge now. If a company's competitive moat leans on design patent protection for its device's appearance, that assumption is worth specific, current re-testing rather than reliance on the fact that the patent issued or survived an earlier validity challenge.
FDA Regulatory File Review
Clearance basis and predicate analysis. Confirm the specific pathway — 510(k), De Novo, or PMA — and, for 510(k) clearances, confirm the predicate device relied on is still valid and hasn't itself been subject to a recall or safety action that could cast doubt on the comparison.
PCCP scope, if one exists. If the device has an authorized Predetermined Change Control Plan, read it closely. It should tell you, in specific terms, what future model changes the company is authorized to make without a new submission — which is directly relevant to both the product roadmap and, per the discussion above, the specificity of the company's related patent disclosures. A PCCP that's vague or narrowly scoped may signal future regulatory friction as the product evolves; a PCCP that's detailed and well-matched to the company's actual technical roadmap is a genuine asset, and one that's easy to overlook if your diligence template predates the PCCP framework, which was only finalized in December 2024.
Quality system status. Confirm where the company stands on the transition to the FDA's Quality Management System Regulation, effective February 2, 2026, which incorporates ISO 13485:2016 by reference. A company that's already ISO 13485-certified should be in reasonably good shape; a company still operating under the legacy Quality System Regulation framework without a clear transition plan is carrying more near-term regulatory risk than its clearance status alone would suggest.
Adverse events, complaints, and recalls. Standard diligence territory, worth flagging here only because AI-enabled devices generate a different flavor of complaint than traditional devices — model drift, unexpected performance degradation in subpopulations underrepresented in training data — and a diligence team unfamiliar with AI-specific device issues may not know what pattern to look for in a complaint file.
Trade Secret Review
Is there an actual program, or a policy document nobody follows? Ask to see the company's confidentiality agreements with employees, contractors, and vendors, its access controls around training data and model weights, and its exit procedures for departing technical staff. A company that treats its model weights, training data composition, or data pipeline as a trade secret needs to be able to show it actually behaved that way — restricted access, consistent NDAs, no unmarked public disclosures — because "reasonable steps to maintain secrecy" is the legal test, and it's a factual question courts will scrutinize closely if the secret is ever litigated.
Piecemeal disclosure risk. Review the company's conference presentations, marketing materials, job postings, and investor materials from before your involvement for technical detail that may have already undermined trade secret claims the company is currently relying on. This is backward-looking diligence — you're checking whether the secret is still a secret, not whether the company intended to protect it.
The overlap with patent and FDA disclosure. Confirm someone at the company is actually coordinating what goes into patent applications, what goes into FDA submissions, and what stays confidential. Given that patent applications generally publish 18 months after filing regardless of outcome, and that FDA submission content can become accessible through FOIA under some circumstances, a company that hasn't thought through this overlap may have inadvertently disclosed something it still believes is a trade secret.
Litigation, IPR, and Enforcement Exposure
Check for pending or resolved litigation involving the target's patents, including inter partes review (IPR) proceedings at the PTAB, which have become a standard tool for challenging patent validity outside of district court litigation. A patent that has already survived an IPR challenge is meaningfully stronger evidence of validity than one that has simply never been tested. Conversely, a pending IPR against a target's core patent is a live risk that should be reflected in valuation, not treated as background noise.
AI-Specific Technical and Data Diligence
This is the category most likely to be underdeveloped in a diligence template built before AI-enabled devices became common, so it's worth listing out explicitly.
Training data provenance and licensing. Confirm the company actually has the rights to the data used to train its models — patient data use consistent with consent and applicable privacy law, properly licensed third-party datasets, no unresolved questions about data sourced from academic collaborators or prior employers of the technical team.
Third-party model dependencies. If the company's device is built on top of a third-party foundation model or licensed ML framework, confirm the license terms actually permit the company's commercial use, including in a regulated medical context, and confirm what happens to the company's product if that license terminates or that third-party model is deprecated.
Model weight and architecture ownership. Confirm the model itself — not just the patent claims describing it — is clearly owned by the company, properly documented, and not entangled with a co-development agreement, academic collaboration, or prior employer's IP in a way that could cloud title later.

Part Three: How This Framework Maps to the Three Moments That Matter
Before you invest. The priority is forward-looking risk: is the patent strategy built for the post-Recentive, post-Desjardins landscape, or for the world as it existed before April 2025? Is the regulatory pathway and PCCP scope realistic for the product roadmap you're underwriting? Is the trade secret program real enough to protect the value that isn't in the patents?
Before you exit. The priority shifts to defensibility under scrutiny: would this portfolio hold up if the acquirer's own counsel ran the same audit described above, or if a competitor challenged the core patents through an IPR the moment the deal closed? Clean up what you can before a buyer's diligence team finds it themselves.
Before going public. The priority is completeness and disclosure accuracy: has every material IP and regulatory risk identified in the categories above been appropriately reflected in the company's public disclosures? This is the one place in this framework where the work genuinely crosses into securities law territory — accurate and complete risk factor disclosure is a securities law question, not an IP law question, and it needs a securities specialist's direct involvement, not just an IP attorney's input filtered through someone else. Flag this diligence framework's findings to that specialist; don't ask this framework to answer that question on its own.

Part Four: Red Flags at a Glance
The framework above is meant to be worked through in full on any deal where medical device IP is material to valuation. In practice, deal teams also need a fast way to triage — a short list of findings that should stop the process and trigger a deeper look before anyone signs anything. A few of those, specific to the current landscape:
A core patent portfolio consisting mainly of claims describing a known machine learning technique applied to a new clinical dataset or population, with no disclosed change to the model, training process, or computation. This is close to the exact fact pattern Recentive rejected, and a portfolio built this way carries real invalidity risk regardless of issuance date.
A patent portfolio that hasn't been mapped claim-by-claim against the actual current product. A large, impressive-looking patent count is not evidence of coverage on its own — it's evidence that patents exist. Coverage has to be checked directly, and a portfolio that protects an earlier version of the product, or a feature no longer in commercial use, functions much closer to no protection at all than the patent count would suggest.
Issued AI-related patents with specifications that read like marketing copy — describing clinical performance in detail while saying little about architecture, training methodology, or data flow. This is precisely the profile examiners are now flagging under Section 112, and the same weakness that gets an application rejected pre-issuance becomes a validity vulnerability post-issuance.
A trade secret program that exists on paper but not in practice — no consistent NDAs, no access controls around training data or model weights, technical detail freely discussed in marketing materials, conference talks, or investor decks without review. If the company can't show it took reasonable steps to keep the information secret, courts are unlikely to find that it was legally a trade secret at all, whatever the company believed internally.
An inventorship or assignment gap — a named inventor, particularly a former employee, academic collaborator, or contractor, who never signed a written assignment of rights to the company. This is quietly common and can be difficult or impossible to fix retroactively if the person is no longer cooperative.
A PCCP that doesn't match the product roadmap the company is presenting to you, or no PCCP at all for a device with an actively evolving model — meaning every meaningful future update may require a fresh FDA submission the company hasn't budgeted or planned for.
Reliance on a third-party foundation model or licensed ML component with license terms that don't clearly cover commercial use in a regulated medical context, or that permit the licensor to terminate or materially change the terms unilaterally.
Any of these findings, standing alone, doesn't necessarily kill a deal. What it should do is move the underlying risk from "assumed handled" to "priced and negotiated," whether that shows up in valuation, in representations and warranties, or in an escrow holdback tied to specific remediation.

Part Five: A Brief Word on Timing
One operational note that's easy to lose in a long checklist: this diligence is cheapest and most useful when it happens early, not when it happens under deal pressure in the final two weeks before signing. A patent portfolio audit run at the term sheet stage can shape valuation and deal structure. The same audit run three days before closing can only tell you what you're stuck with. If you're building a repeatable process across a portfolio of life sciences deals rather than running diligence once, the highest-leverage change most teams can make is simply moving this work earlier in the timeline, not making it more thorough.

A Closing Thought
None of this replaces the judgment of a deal team that knows the specific company, the specific therapeutic area, and the specific competitive landscape better than any general framework can. What changed over the last eighteen months is the legal terrain underneath a category of assets a lot of life sciences investors now hold or are actively evaluating, and a diligence checklist is only useful if it’s current. This one is offered in that spirit — as a working tool to run against a specific deal, not as a substitute for the counsel who will actually need to dig into that deal’s specifics. Questions on any of the items above are the kind of thing IP counsel with medical device and FDA experience fields regularly, and that’s true whether or not this particular document is in front of them.

Final Reminder
This primer is for informational purposes only. It is not legal, financial, or securities advice. The law in this area — particularly the AI patent eligibility landscape — has moved substantially in the last eighteen months and may move again. Before relying on any of the items in this framework for an actual transaction, confirm current guidance with counsel who practices in this specific area, and bring in a securities specialist for any question touching public disclosure obligations.