On 30 June 2026 the United States Patent and Trademark Office granted Mistral AI a patent titled "Code implemented tool calls". The application was filed on 4 March 2026. That is 118 days from filing to grant, in a system where the average utility application waits somewhere north of two years.

The number is US 12,670,045 B1. The named inventor is Gabriel Vergnaud, of Paris. The assignee is Mistral AI SAS, the company that has spent three years positioning itself as the open-weights alternative to the American labs. Of all of that, the detail worth your attention is the trailing letter.

What I can verify, and what I can't

I could not retrieve the claim text. The Official Gazette entry served me an empty page, and I am not going to characterise a patent's scope from its title. Anyone telling you Mistral has patented the practice of letting an agent write code to call its tools is guessing, and so would I be. Titles are filing-cabinet labels. Claims are the property line, and I haven't seen them.

What I can verify is the calendar, and the calendar is the argument.

Under the USPTO's kind codes, a B1 is a utility patent granted with no pre-grant publication. B2 is the ordinary case: the application published at eighteen months, the world could read it, then it granted. B1 means the world never read it. That happens when the applicant files a nonpublication request, and it also happens when a grant simply beats the eighteen-month publication clock. At 118 days, this one would have beaten it either way. The distinction matters to Mistral's lawyers. It makes no difference at all to everybody else, because the effect on the public is identical: the first time anyone outside the applicant and one examiner could read this document, it was already enforceable.

The window that never opened

This is where it stops being a curiosity about one French company and starts being a structural point about software patents in the agent era.

The America Invents Act gave the public a cheap way to interfere with a bad patent before it exists. Under 35 U.S.C. 122(e), a third party can hand the examiner prior art, with a short description of why it matters, for a nominal fee. It is the only mechanism in the system that costs a normal person less than a house. And it has a deadline: before the earlier of the notice of allowance, or the later of six months after the application publishes and the first rejection of any claim.

Read that against a B1. There was no publication, so the six-month clock never started. The only remaining boundary is the notice of allowance, and to file against a notice of allowance you must first know the application exists, which requires the publication that did not happen. The window did not close early on this one. It never opened.

Near as I can tell, that is not an exploit. It is the ordinary interaction of two rules that were written a decade apart and have never had to cope with a field where the entire state of the art is eighteen months old.

The prior art nobody got the chance to file

Whatever US 12,670,045 claims, the neighbourhood is crowded. Having a model emit executable code rather than a structured function call was published as CodeAct by Xingyao Wang and colleagues in February 2024, with the argument stated plainly: code as a unified action space, so the agent gets loops, conditionals and composition for free. By late 2025 Anthropic was pitching the same pattern over MCP on token economics, and Cloudflare had shipped Code Mode, which converts MCP tools into a TypeScript API and hands the model two functions instead of two hundred. By March 2026, when this application was filed, "write code, don't call tools" was closer to house style than to an idea.

Here is the uncomfortable part. All of that lives in arXiv preprints, engineering blogs and GitHub repositories. It is the worst-indexed corpus in the world from an examiner's chair, and it is where roughly all agent prior art now lives. The USPTO clearly knows: it ran an Automated Search Pilot Program from October 2025 to April 2026, using AI to surface relevant documents before formal examination. I don't have a clean read on how well it worked. What I can say is that when machine search is the only search that stands a chance, removing the humans who would have volunteered the references is a strange trade.

The strongest case against this read

Three serious objections, and I don't think any of them is a strawman.

The first is that fast is good. Pendency of two years plus is the actual scandal in the American patent system, and a 118-day grant is what happens when a well-drafted application lands with an examiner who finds it allowable on first action. Punishing speed to preserve a comment period is the tail wagging the dog. That objection is correct on its own terms, and I'd sign most of it. My disagreement is narrow: I'm not arguing against speed, I'm arguing that one of the two public checks on examination quality is wired to a publication event, so accelerating the grant silently deletes it. Fix the wiring, keep the speed.

The second objection is that Mistral is close to the last company you'd expect to swing this thing. It ships weights under Apache 2.0, and Apache 2.0 carries an express patent grant with a retaliation clause in section 3. Mistral also turned up in the Open Invention Network community in June 2026, eight days before this patent issued, and OIN membership means signing a patent non-aggression cross-licence. That is a real constraint, publicly made, and it deserves more credit than it usually gets.

It also has edges. The OIN covenant runs to the Linux System definition, an enumerated list of packages in Tables 0 to 13, not to software in general. Apache 2.0's grant is narrower than people assume: it covers claims necessarily infringed by the contribution itself, and unlike the copyright grant it does not carry sublicensing rights. Neither instrument obviously reaches a competitor's proprietary agent runtime, which is the only place a patent like this would ever be worth asserting. Good intentions are not the question. Scope is, and scope is written down.

The third objection is that the system already has a cure. If the claims are invalid over CodeAct, file for inter partes review or ex parte reexamination and kill them. True, and here is the price list: roughly $9,000 to petition and another $14,000 if the board institutes, with all-in costs commonly quoted between $300,000 and $700,000. That is a rounding error for Google and a company-ending number for the four people maintaining an open-source agent framework. Validity is not really the variable. Who can afford to prove it is.

The wrong instrument, and the right one

The reflex when a patent like this surfaces is to shout the prior art at each other in public. That reflex is late by construction: by the time a B1 is visible, the only forum that accepts prior art cheaply has already closed, and the expensive forums do not read forums.

The instrument that actually matches the problem is boring and available. OIN maintains the Linux System definition by nomination, and it has an open call for the next table. If the agent stack, meaning the runtimes, the tool-call middleware, the MCP servers and the code-execution sandboxes, is not inside that definition, then the non-aggression covenants that the open-weights companies keep signing do not cover the layer where the fighting will happen. Nominating it is a form letter. Nobody appears to have sent one.

The bet

My read is that US 12,670,045 will never be asserted against anyone, and that this will be entirely beside the point, because the thing worth watching was never this patent. It was the discovery that a technique the entire agent industry adopted in public, in eighteen months, can be enclosed in four months by a filing nobody is entitled to see. That asymmetry does not require a lawsuit to matter. It only requires a second company to notice it works.

Three things would resolve this, and all three are checkable. First: whether continuations appear in this family over the next twelve months. A single defensive grant and a growing continuation chain are different animals, and the file wrapper will say which this is. Second: whether the count of B1 grants assigned to AI labs rises through 2027 relative to B2s. If the four-month unpublished grant becomes a pattern rather than an artefact, that is the tell. Third: whether anyone nominates agent infrastructure into the OIN Linux System definition before the next table closes.

I'd take the under on the third. I would be pleased to be wrong, and it is the only one of the three that any reader of this piece can change.