Microsoft · Filed Mar 25, 2025 · Published Oct 1, 2026 · verified — real USPTO data

Microsoft Patents a Method to Shield Sensitive Data While Running AI Models

When an AI model processes your medical records or financial data, every layer of that model touches something private. Microsoft has filed a patent for a system that figures out which layers of an AI need heavy security protection and automatically routes each one to the right piece of hardware.

An artificial intelligence model is partitioned and distributed across multiple hardware security domains for enhanced data protection. Drawing from patent filing US 2026/0300489 A1.
An artificial intelligence model is partitioned and distributed across multiple hardware security domains for enhanced data protection.
See all 12 drawings from this filing ↓
Publication number US 2026/0300489 A1
Applicant Microsoft Technology Licensing, LLC
Filing date Mar 25, 2025
Publication date Oct 1, 2026
Inventors Aditya Vasanth CHALLAPALLY
CPC classification 726/22
Grant likelihood Medium
Examiner POUDEL, SAMIKSHYA NMN (Art Unit 2436)
Status Response to Non-Final Office Action Entered and Forwarded to Examiner (Sep 21, 2026)
Document 20 claims

How Microsoft splits an AI's brain by data sensitivity

A doctor's office runs an AI that reads patient scans. The AI has dozens of internal steps, and only some of them actually touch raw patient data. The rest work on patterns so abstract that the original information is unrecoverable.

Microsoft's system looks at each step inside an AI model and asks: does this step handle truly sensitive input, or has the data been transformed enough that it's safe to run on less-guarded hardware? It then splits the model into groups of steps, called partitions, and assigns each group to the right computing hardware based on its security needs.

The goal is efficiency without sacrificing protection. Instead of running everything through expensive, heavily guarded hardware, you only do that for the parts of the AI that actually need it. The less sensitive layers can run on faster or cheaper components, and the whole system is matched automatically rather than by hand.

From the filing · CLAIM 1
… partitioning the neural network architecture into a partitioned neural network architecture that includes partitions comprising one or more layers of the neural network architecture based on the security requirements of each of the layers to be operated on selected hardware components from among the computing hardware components …

Translation: The system splits the AI model into pieces matched to the security level of each hardware part.

How the system maps layers and assigns security hardware

The system starts by building a map of the neural network, a diagram of every layer in the AI model, how they connect, and how data flows from one to the next. It notes which layers feed into which, and which layers depend on the output of earlier ones.

Next, it checks what computing hardware is available and sorts those components by their security domain (think of a security domain as a walled zone of hardware that has specific protections against snooping or tampering, enforced by physical chips, firmware, or both).

Then it applies rules to each layer to decide how sensitive that layer's work is:

  • Layers close to the input that receive raw sensitive data get the highest security classification.
  • Layers that produce abstract features (like edge patterns in an image or statistical signals) get a lower classification, because you can't reverse-engineer the original data from them.
  • The layer type and its position relative to the input layer both factor into that judgment.

Finally, the system partitions the model, grouping consecutive layers with similar security needs together, and assigns each group to a hardware component whose security level matches or exceeds what that group requires. The AI then runs across these partitioned components simultaneously or in sequence.

From the filing · THE ABSTRACT
Each partition includes a subset of the layers of the neural network architecture and each partition has different security requirements based on whether the layers in the partition are receiving sensitive input data or operating on data from which features of the sensitive input data can be reconstructed.

Translation: Different parts of the AI get different security based on how close they are to sensitive user data.

What this means for AI running on sensitive data

AI is moving into hospitals, banks, and government agencies, places where the data being processed is regulated and genuinely sensitive. Right now, the common answer is to run the entire AI inside a secure enclave, which is slow and expensive. Microsoft's approach, if it works as described, means only the parts of the model that need heavy protection get it, while the rest run normally. That could make privacy-preserving AI meaningfully faster and cheaper to deploy.

Claim 1 covers the whole pipeline: mapping the network, reading available hardware, classifying each layer's security needs, and partitioning accordingly. That's a broad functional claim. If granted, it could give Microsoft a foundational position over automated, hardware-aware security partitioning for AI models, covering a wide range of enterprise AI deployments.

Microsoft's 13th filing we've tracked since August in our on-device AI privacy watchlist follows work on catching data leaks and shrinking AI models.

Editorial take

Claim 1 is written broadly. It doesn't require a specific type of AI model, a specific hardware platform, or a specific security standard. It covers the general act of analyzing a neural network's layers, reading the hardware available, and splitting the model by security requirements. That breadth is the interesting thing here.

A claim this wide, if granted, could touch almost any system that automatically partitions an AI model for deployment across mixed-security hardware. That's a significant portion of where enterprise AI is heading, especially as companies try to run large models partly on-device and partly in the cloud.

Microsoft's interest in confidential computing shows up across its Azure infrastructure work, and this patent fits that thread. The practical question is whether prior art in trusted execution environments and model segmentation will narrow the claim during examination. The concept is sensible; the grant likelihood depends on how the examiner reads the existing landscape.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

12 drawing sheets from US 2026/0300489 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.
Reader comments

Be the first to weigh in

Start the discussion

Real name or a handle, either is fine. Comments are read by a person before they appear, so allow a little time. Keep it about the filing.