IBM Patents an AI System That Rewrites Data Security Rules During Live Collaboration
Most data-security tools set rules once and forget them. IBM is patenting an AI that watches what data gets shared during a live meeting, updates its rules based on feedback, and adjusts in real time as the context changes.
What IBM's self-adjusting data security actually does
You're in a video call with colleagues from three different departments, and someone shares a file that contains both public marketing copy and private salary figures. Your company's current security software treats that file the same way every time, no matter who's in the room or what the conversation is about.
IBM's new patent describes an AI system designed to change that. The AI studies a record of how your organization's data has been used historically, then sorts each piece of data into security categories. When a group meeting or collaboration session starts, the AI checks the context: who's attending, what kind of session it is, and what data is being shared. It then enforces the right rules for that moment, not a blanket rule written months ago.
When people flag that a rule was too strict or too loose, the system takes that feedback and reclassifies the data for next time. It's meant to be a loop that gets more accurate the more it's used.
… causing the AI model to enforce security measures associated with the first classifications during a first collaboration event of a plurality of user devices, wherein the AI model determines and incorporates contextual information into the enforcement of the security measures …
Translation: The AI actively applies safety rules during a shared work session while factoring in the surrounding situation.
How the AI classifies data and enforces rules in context
The system starts by pointing an AI model at a database that logs how user data has historically been accessed and shared. From that history, the AI generates initial classifications for each type of data, essentially tagging it with a sensitivity level and an associated set of rules.
During a live collaboration event (think: a shared document session, a video call, a co-editing environment), the AI monitors what data is being touched and pulls in contextual information, details about who the participants are, what devices they're using, and what kind of session is taking place. That context shifts which rules actually get applied. A file that's freely shareable inside one team might be restricted when an outside contractor joins the same call.
The enforcement step is where the patent's claims are most specific. The AI doesn't just check a static permission list; it factors context directly into the decision for each event, and it can update its behavior mid-session based on that context.
After the event, feedback from users or administrators feeds back into the system. If a restriction was flagged as too aggressive, or data that should have been locked down slipped through, the AI updates its classifications. The old label is replaced with a revised one, and that revised classification becomes the baseline for the next session.
In response to receiving feedback associated with the enforcement of the security measures, the first classifications of the user data are updated to second classifications of the user data …
Translation: After getting user reactions to how it handled security, the system changes how it categorizes the data.
What this means for companies sharing sensitive data in meetings
Enterprise security teams spend a lot of time writing and rewriting data-access policies as organizations change. A system that learns from real-world usage and adjusts its own rules could reduce that manual overhead, particularly for large companies where who-needs-what-data changes constantly.
For everyday users, the pitch is that fewer legitimate requests get blocked and fewer sensitive files get accidentally exposed, because the rules reflect the actual situation rather than a policy written for an average case. IBM has been filing around AI-driven enterprise security for some time, and this patent fits a pattern of trying to replace static, rule-based controls with systems that respond to context. How well the feedback loop works in practice, and whether users can game it, are questions the patent doesn't answer.
IBM's 57th filing we've tracked since May in our AI safety guardrails watch follows one that locks developer access and one that double-checks AI advice, showing how the company keeps tightening its controls over AI behavior.
The design's central bet is that user feedback is a reliable signal for improving security classifications. That's a real tradeoff: any system that loosens restrictions in response to complaints is also a system that a persistent or frustrated user can gradually weaken, even without meaning to. The patent doesn't describe guardrails that prevent classification drift in the wrong direction.
There's also a cost on the other side of the ledger. Security rules that shift based on context are harder to audit than static ones. If a regulator or an internal compliance team asks why a particular file was accessible during a particular meeting, the answer might be a complex chain of contextual factors that's difficult to reconstruct.
The core idea, making security rules sensitive to real-time context, is worth pursuing. But the feedback mechanism is the part that needs the most scrutiny before you'd want to trust it with genuinely sensitive data.
There are more where this came from
We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.
The drawings
5 drawing sheets from US 2026/0300539 A1 · click any drawing to enlarge
Want this weekly breakdown for a company we don't cover? Patentlyze Pro →
Be the first to weigh in