August 20, 2026
Filed First, Invented Second
Patent law rewards whoever files first. For most of its history, that rule assumed the two competing filers each did their own inventing. That assumption is getting harder to defend.
Imagine a research lead at a semiconductor startup, or a synthetic biology lab, or a battery materials company, traveling to a conference with a laptop and a phone. On it: the roadmap for a breakthrough the company plans to patent in six months. It doesn't need to be stolen in the traditional sense - no one has to break in, install malware, or bribe an employee. It only has to be copied.
Proximity is the new access
A device on an open conference or hotel network, or one imaged during a routine border inspection, can have its encrypted contents copied without the owner ever noticing. The adversary doesn't need to read it immediately. They archive it and wait - for a cryptanalytic advance, a leaked key, or simply enough computing power - and decrypt it on their own timeline.
This is the harvest-now-decrypt-later model, and it turns any conference, any airport lounge, any hotel bar into a potential collection point. The cost to the adversary is proximity and patience. Neither is in short supply.
Getting there first, without getting there first
Once the roadmap is decrypted, the incentive isn't just to read it - it's to act on it before the original inventor does. A well-resourced competitor, or a state-directed entity operating on a national timeline rather than a product timeline, can file a patent application on an idea it never actually conceived.
The effect on the original company is severe even if the stolen filing is eventually invalidated: blocked or contested claims, expensive litigation, delayed market entry, and a competitor able to manufacture a copy at a fraction of the R&D cost because it skipped the R. For deep-tech and defense-adjacent startups (semiconductors, advanced materials, quantum-resistant cryptography), that delay can be the difference between defining a market and chasing one.
And it scales. A single well-positioned adversary can target many executives and researchers across many companies at once, quietly building a queue of intelligence to exploit as decryption capacity allows.
A national competitiveness problem, not just a corporate one
This isn't only a private-sector concern. When breakthrough technology developed in the U.S. is harvested, decrypted, and reproduced elsewhere at a fraction of the cost, the effect is a transfer of competitive advantage that no export control or foreign investment review was ever positioned to catch, because nothing crossed a border except a traveler's own device.
For companies doing government-relevant or dual-use research, this closes a gap that trade policy doesn't reach: the intelligence didn't leave the country in a shipment or a filing. It left in someone's pocket, on a device that looked, to every existing control, perfectly ordinary.
The device was never the right place for it
The standard defenses, such as stronger device encryption, tighter mobile device management policy, more aggressive remote wipe, all share the same weakness: they assume the roadmap has to be on the device to be useful to its owner. It doesn't.
With mobile isolation software, the researcher's device never holds the file. It renders a pixel stream from a server that stays put. There's no local cache to image at a checkpoint, no encrypted archive to copy over a hotel network, nothing sitting in a device that can be harvested today and cracked open in three months. End the session, and there's nothing left behind to have ever been vulnerable.
The companies that protect their breakthroughs going forward won't be the ones with the toughest encryption standard. They'll be the ones that stopped putting the breakthrough on a device that leaves the building at all.
Recent articles
Security
August 18, 2026
The Signal Paradox
Signalgate exposed a real problem: audit and access control aren't the same thing. Here's how regulated organizations should think about secure messaging.
Security
August 13, 2026
If You're Not First, You're Last
Your endpoint security is running on a Talladega Nights quote.
Mobile
August 6, 2026
Your Baby’s Not Ugly. It Could Just Be Smarter.
Every MDM, MAM, and Conditional Access policy exists to protect data sitting on the device. Take the data off, and much of that sprawl disappears.
