The Anthropic IP Plugin: Open-Source Blueprint for IP Work in EPC/EU Practice
In May 2026 Anthropic released claude-for-legal/ip-legal, an open-source plugin for IP work. What it solves cleanly, what it deliberately does not solve, and which design patterns transfer to a German or European practice, without importing the US-centric content.
Article published on 16 May 2026
Key insight: The plugin shows what an AI workflow for IP practice can look like when duty of evidence and human review are wired into the system rather than left to the practitioner. The design patterns (see below) are transferable; the individual workflows ("skills") are not. The legal content is US-centric; the plugin's own CLAUDE.md advises EU users against adopting it unchanged. Claim drafting is explicitly excluded. The plugin is open source (GitHub) and positioned as a reference implementation, not a finished product.
What the plugin does
Twelve skills (structured workflows), one scheduled agent (an automated monitoring task that runs on a timer), and five MCP servers (interfaces to external data sources such as patent databases). The skills are not single-shot prompts but multi-step conversations with built-in checkpoints where the model pauses and asks before continuing. The first skill (cold-start-interview) builds a practice profile once, which all other skills read as background: a prose file holding jurisdiction, enforcement strategy, approval rules, standard templates, portfolio.
All twelve skills at a glance
| Skill | Function | EPC/EU relevance |
|---|---|---|
cold-start-interview | 10- to 15-minute interview, writes the practice profile | High: onboarding logic is language-agnostic |
cease-desist | Draft outgoing C&D or triage incoming | Medium: structure yes, US threat framing (declaratory judgment) no |
takedown | DMCA §512 notices and counter-notices | Low: DSA Art. 16 is the EU counterpart, separate logic |
clearance | Trademark knockout and confusion analysis | Medium: structure yes, Polaroid/DuPont no, instead CJEU line Canon/Sabel/Lloyd |
fto-triage | Freedom-to-operate as structured first pass | High: plugin recognises DE-specific features (Schneidmesser/Kunststoffrohrteil, bifurcated proceedings) |
invention-intake | Triage disclosure as PURSUE/INVESTIGATE/DECLINE | Low: § 102(b) US grace period breaks EP novelty (Art. 54) |
infringement-triage | Four-mode triage of infringement claim | Medium: mode-router pattern is portable |
ip-clause-review | IP clauses in agreements with severity 🔴/🟠/🟡/🟢 | High: redline granularity, AI authorship module (DABUS) |
oss-review | Open-source license compliance, deployment-first | High: near jurisdiction-neutral; the BUSL/SSPL/Elastic block fills a real gap in German-language material |
portfolio | Register and deadline tracking, five modes (init/report/add/update/audit) | Medium: EUIPO yes, DPMA annuities and EPC renewal fees missing |
matter-workspace | Isolate matters, cross-matter context off by default | High: direct match to the German BORA duty of confidentiality |
customize | Edit the practice profile without touching YAML | High: UX pattern for any config UI |
Eight transferable design patterns
The following patterns can be lifted from the plugin and applied in any practice, without adopting US law.
- Practice profile as plain text. The plugin stores the firm's configuration not in a technical format but as readable prose: jurisdiction, enforcement strategy, approval rules, portfolio. Users can edit the profile directly, and Claude reads it as context. For an EU firm: DPMA/EPO/EUIPO focus, preferred claim wording.
- Origin tag on every statement. Every factual statement carries a tag marking its source:
[verify](factual claim to confirm),[review](legal judgment call),[model knowledge — verify](default for non-sourced statements),[settled — last confirmed YYYY-MM-DD], plus tool-specific tags only when the citation literally appeared in that tool in this session. In the EPC context:[Juris],[Beck Online],[Dejure],[DPMAregister],[EPO Register],[CURIA]. The prompt library of this app has absorbed this discipline; the tools FTO, Opposition, Scope of Protection now carry it.Verbatim from the plugin CLAUDE.md
"Do not promote a tag to a more trustworthy tier because the citation 'seems right.' The tag describes provenance, not confidence."
"[model knowledge — verify] — everything else. This is the default. If you didn't retrieve it, it's model knowledge, no matter how confident you are."
- No silent gap-filling. When the model has known doubts about a citation (pending appeal, partially overruled, vacated), it picks one of three options: (a) supplement and flag, (b) name the doubt but not use it for the argument, (c) stop and ask. Option (b) names the doubt without using it for the argument.
Verbatim from the plugin CLAUDE.md
"Flag-but-don't-use. If you are aware of information that would change whether a rule applies or is in force — pending litigation, rescission proposals, effective-date delays, superseding amendments, enforcement moratoria — surface it as a flagged caveat tagged [model knowledge — verify] even though you must not use it to change your analysis."
"Silence about known doubt is as misleading as confident assertion."
- Decision tree at the end of every skill. The model does not recommend; it lays out five options (Draft the X, Escalate, Get more facts, Watch and wait, Something else) and the user picks.
- Risk floor across skills. A risk flagged as 🔴 cannot silently become "acceptable" in a later step. Downgrade only with an explicit reason.
Verbatim from the plugin CLAUDE.md
"A 🔴 finding upstream cannot become 'advisable' downstream without the downstream skill stating: 'Upstream rated this [X]. I'm lowering it to [Y] because [reason].' Silent demotion is a contradiction a reviewing lawyer cannot see."
- Review checklist above every output. Every deliverable begins with a block showing at a glance: which sources were used, what was fully read, where the model is uncertain, and what the reviewing attorney should check first.
- Smallest possible changes in contracts. In contract review: single word before phrase before sentence before entire clause. An AI tends to rewrite whole clauses; the plugin counteracts that.
Verbatim from the ip-clause-review skill
"Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals 'we threw out your drafting' — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal 'we have specific asks' and are faster to read, understand, and accept."
- Automated deadline monitoring that only reports. The
ip-renewal-watcherchecks the portfolio weekly and reports upcoming deadlines. It does not pay, does not renew and does not contact clients. When nothing is due it posts an "all clear" so the team knows the monitoring is running.Verbatim from the ip-renewal-watcher agent
"If nothing is due in the next 90 days and nothing is in grace, post a short all-clear — so the team knows the agent ran, the register isn't stale, and the sync (if any) succeeded. Silent passes look identical to a broken cron job."
A concrete example: fto-triage as walkthrough
The FTO skill draws a clear line between triage (a structured first pass) and opinion (claim construction, file-wrapper review, validity assessment). It produces claim charts (comparisons of patent claims against product features), element by element. The equivalence doctrine is flagged separately; indirect infringement is marked as attorney work.
A missed risk cannot be undone (the product is on the market); an overly cautious flag can be revised after deeper analysis. The skill calibrates its threshold accordingly. This logic has been folded into the FTO prompt of the app.
Verbatim from the fto-triage skill
"Under-flagging a blocking patent is a one-way door — a product launched, a deposition a year later, treble damages on the table. Over-flagging is a two-way door — the attorney narrows the list in a read-through. Stay on the two-way door side. Always."
"This is not a freedom-to-operate opinion. A formal FTO opinion requires a comprehensive search, full claim construction, and element-by-element infringement analysis by registered patent counsel. Patent infringement is strict liability; willful infringement triples damages. A 'no obvious blocking patents' result means the triage didn't find one — it does not mean the product is clear."
What does not transfer
The plugin's own CLAUDE.md warns EU users explicitly:
"Applying US doctrine here would give you a wrong answer that looks right."
- Takedown procedures: the
takedownskill is based on US law (DMCA §512). In the EU the DSA Art. 16 mechanism applies with its own logic. The skill would need a complete rewrite. - Trademark confusion analysis: the
clearanceskill uses US factors (Polaroid/DuPont). For DE/EP the framework is § 14 MarkenG / Art. 9 EUTMR under the CJEU's interaction doctrine (Canon, Sabel, Lloyd). Different factors, different weighting. - Confidentiality marking: the plugin sets a US privilege header on every document ("PRIVILEGED — ATTORNEY WORK PRODUCT"). That header does not exist in DE/EP practice. The plugin's
CLAUDE.mdrecommends EU users replace it withCONFIDENTIAL — INTERNAL LEGAL ANALYSIS — NOT A SUBSTITUTE FOR EXTERNAL COUNSEL ADVICE. - Patentability and novelty: the
invention-intakeskill checks under US law (Alice test, one-year grace period for own prior publications). Under the EPC different standards apply: the COMVIK approach (Art. 52 EPC, technical effect) and the near-absolute novelty bar (Art. 54 EPC, no comparable grace period). - Wilful infringement: the FTO skill warns of treble damages for knowing patent infringement, a US concept. Irrelevant for DE/EP; damages follow an elective method (§ 139 PatG).
Confidentiality: tool locality is not enough
The plugin runs under Claude in Anthropic's cloud. The model sees every input. That the plugin file itself is installed locally changes nothing (the same observation as in the MCP article). For real client material you need either a cloud instance that meets the applicable professional-confidentiality requirements, or a locally hosted language model as backend.*
Significance for patent practice
The eight design patterns above are the transferable core. Anyone adopting them has done the more demanding part; populating the legal content for EPC/EU takes time but raises no architectural questions.
What the plugin deliberately does not do: patent claim drafting is explicitly excluded. That gap is covered by the prompt tools of this app: Claim Brainstorming, Patent Description Generator, Office Action Response, Opposition Analysis, Scope of Protection. Plugin and prompt library complement each other.
Sources
- Anthropic,
claude-for-legal/ip-legal(commit 4d55f53, May 2026) - Plugin
CLAUDE.mdwith discipline rules and EU caveat - Regulation (EU) 2022/2065 (Digital Services Act), esp. Art. 16 notice-and-action
- Cross-reference: MCP · Connecting AI Models to Patent Data
- Cross-reference: Duty of Evidence for AI Answers
- Cross-reference: Prompt Engineering for Local LLMs
* Processing of confidential content is subject to professional-confidentiality requirements (BRAK, epi guidelines, § 203 StGB and their equivalents). These can be met by a locally hosted model or, in individual cases, by a trustworthy or self-hosted cloud instance. This does not constitute legal advice.