Article
Pipe dreams
A pitch deck said two patents stood issued. The public record said both had expired. What changed is not that somebody finally checked -- it is what checking now costs.
provenance -- what it takes for a fact to stay true, and what asking the record now costs · 2026-08-08 · 5 sources
One slide in a seed-stage pitch deck announced, in the confident typography such documents favour, "2 Patents Issued." The two patent numbers appeared beneath the claim, inside a screenshot -- an image of text rather than text, the least examinable format short of omitting the numbers altogether. Nothing sinister in that; decks are assembled from whatever is to hand. But it meant the numbers could not be copied, only read, and a number that must be retyped is a number that will not be looked up.
Here is the odd part. A patent is a public fact. It has a number, a registry, a legal status, and an office of the United States government whose entire job is to answer questions about it. That is precisely why it goes unchecked. The claim wears the costume of the checkable, and the costume does the work the checking would have done. Diligence, as practised, samples: it reads the science hard, argues the market, and waves through the slide with the government-issue numbers on it, because surely those, of all things, are what they say they are. Usually they are. The trouble is the word usually, and the fix, it turns out, is not vigilance but design.
The walk
What happened to this deck was not cleverness. It was a sequence of small, unglamorous steps, and the steps are the story.
First the two numbers were extracted from the screenshot -- lifted out of the image and back into text, where they could be worked with again. Then came the only question that matters in this business: whom do you ask? Not a search engine, which returns what has been written about a thing. Not a database that mirrors a database. You ask the record's owner. The numbers went to the patent office's own registry, and the registry answered as registries do, flatly and without adjectives: both patents had expired.
A second, independent source, asked the same question, gave the same answer. Then the finding went where it belonged -- into a written flag for the screening committee that had asked for the read, phrased as a question rather than a verdict. Companies do not, as a rule, knowingly raise money on dead patents. The likeliest explanations are mundane: a lapsed fee, a slide nobody updated, a founder who genuinely does not know. A flag says: before money moves, someone should ask which.
How a patent dies explains the staleness. A granted United States patent must be maintained -- fees fall due at three and a half, seven and a half, and eleven and a half years, and if a fee goes unpaid the right lapses.135 U.S.C. 41(b) and 37 CFR 1.362: maintenance fees on utility patents are due at 3 years 6 months, 7 years 6 months, and 11 years 6 months from grant; 35 U.S.C. 41(b)(2) provides that the patent expires on failure to pay, subject to the six-month grace period.Primary No letter of condolence arrives. No press release announces the death. The slide that announced the patent at grant is still sitting in the deck template years later, still true-looking, answering to nobody.
What the asking costs
The interesting economics are not in the catch but in the asking. Two questions put to two public registries: this was always possible. A patent attorney would have found it in an afternoon, for an afternoon of a patent attorney's fees. The reason such checks happen rarely is not ignorance but price -- against a deck making forty claims, the afternoon multiplies into a bill nobody at screening stage will pay.
That price has now collapsed. The machinery that did the asking here sits on
2,658 callable tools over the primary scientific record -- trial registries, drug
labels, adverse-event ledgers, patent offices, sequence archives, the
literature.2ToolUniverse, an open-source registry of callable scientific tools over primary biomedical, chemical, regulatory, and literature databases. Tool count from the local installation: tu status, version 1.1.11, reporting "tools loaded: 2658", read 2026-08-08. The count is a property of the installed catalogue, not of any single upstream database. (Primary, local census) Beside them sits a census of 17,762 raw endpoints across
84 systems, from securities filings to census tables, each one driveable
directly.3Internal API-surface census, queried 2026-08-08: 17,762 endpoints across 84 systems (SELECT count(*) FROM endpoint; SELECT count(*) FROM system;). Systems include the SEC's EDGAR full-text and submissions APIs, the USPTO Open Data Portal, and the US Census Bureau data API, each driven against its own published schema. (Primary, local census) The numbers are large, and it would be a mistake to be
impressed. A count of pipes is a fact about plumbing. None
of those 2,658 tools is a source, and none will ever be cited in anything we
publish: a tool is transport, and the authority is the registry at the far end
of it. The counts matter for one reason only. They set the marginal price of
asking the record's owner a question, and that price is now close to zero. The
forty-claim deck no longer costs forty afternoons. It costs minutes. The checking that was always theoretically
possible becomes the checking that actually happens.
The universe in question
The registry of tools deserves its own paragraph, because its history makes the essay's point better than the essay does. It is called ToolUniverse, an open-source project from Marinka Zitnik's laboratory at Harvard Medical School, released under the Apache licence.4Gao S, Zhu R, Sui P, et al. "Democratizing AI scientists using ToolUniverse." arXiv:2509.23426, submitted 2025-09-27. States the registry offers "more than 600 machine learning models, datasets, APIs, and scientific packages," and draws the analogy verbatim: "Like HTTP standardizes client-server communication, ToolUniverse defines an interaction protocol that governs how AI models issue tool requests and receive responses." Code at github.com/mims-harvard/ToolUniverse, Apache License 2.0, from the Zitnik Lab, Department of Biomedical Informatics, Harvard Medical School. Preprint, not yet peer-reviewed.Primary It did not begin as an ecosystem or a thesis. It began, in March 2025, as the toolbox of a single agent -- TxAgent, built for therapeutic reasoning -- and at birth it held 211 tools.5Gao S, Zhu R, Kong Z, Noori A, Su X, Ginder C, Tsiligkaridis T, Zitnik M. "TxAgent: An AI Agent for Therapeutic Reasoning Across a Universe of Tools." arXiv:2503.10970, submitted 2025-03-14. The abstract states the toolbox "consolidates 211 tools from trusted sources"; the paper introduces ToolGen, "a multi-agent tool construction system that generates tools from API documentation." Preprint, not yet peer-reviewed.Primary Six months later the toolbox was promoted to the headline: a second paper, "Democratizing AI scientists using ToolUniverse," recast it as shared infrastructure, by then offering "more than 600" models, datasets, APIs and scientific packages, with an analogy the authors chose carefully -- as HTTP governs how browsers and servers converse, this protocol governs how an AI scientist finds a tool and calls it.4Gao S, Zhu R, Sui P, et al. "Democratizing AI scientists using ToolUniverse." arXiv:2509.23426, submitted 2025-09-27. States the registry offers "more than 600 machine learning models, datasets, APIs, and scientific packages," and draws the analogy verbatim: "Like HTTP standardizes client-server communication, ToolUniverse defines an interaction protocol that governs how AI models issue tool requests and receive responses." Code at github.com/mims-harvard/ToolUniverse, Apache License 2.0, from the Zitnik Lab, Department of Biomedical Informatics, Harvard Medical School. Preprint, not yet peer-reviewed.Primary The copy running in this shop, asked directly, answers 2,658.
So which count is correct? All three -- each of the artifact that states it, on the date it stated it. The founding paper's 211, the second paper's 600-odd, and today's 2,658 are not a contradiction; they are a growth curve read at three timestamps, and anyone quoting one of them owes the reader the artifact and the date. A project built to pin numbers to their sources cannot itself be described honestly any other way, which is either an irony or a proof of concept, depending on your mood.
One more detail from its history, the best one: the original 211 tool wrappers were not written by hand. A multi-agent system read the underlying databases' own API documentation and wrote the specifications.5Gao S, Zhu R, Kong Z, Noori A, Su X, Ginder C, Tsiligkaridis T, Zitnik M. "TxAgent: An AI Agent for Therapeutic Reasoning Across a Universe of Tools." arXiv:2503.10970, submitted 2025-03-14. The abstract states the toolbox "consolidates 211 tools from trusted sources"; the paper introduces ToolGen, "a multi-agent tool construction system that generates tools from API documentation." Preprint, not yet peer-reviewed.Primary The plumbing was laid by the same kind of agent that now runs through it. What we add on our side is the part no registry can supply -- the discipline that decides what a delivered answer is worth.
The discipline
Cheap asking is necessary and insufficient. A pipe delivers an answer; something else must hold it, and hold it honest. Our system stores every claim as an atom carrying three things: the verbatim line from its source, a durable identifier for where that line lives, and a timestamp for when it was read. An atom missing any of the three fails to parse -- the sentence is not permitted to exist unaccompanied. The check is structural, not vigilant: no reviewer decides whether a claim deserves its provenance, because a claim without provenance cannot be stored at all. This sounds bureaucratic and is, in the way a chain of custody is bureaucratic: the tedium is the point. A fact that arrives without its papers is a rumour with good formatting, whatever pipe it arrived through.
The same principle runs through everything we publish, and the examples are worth listing because each one retires a way of being wrong. The source count shown on each essay is not typed by an author; it is counted from the endnotes at build time, so the number on the page and the notes beneath it cannot disagree -- a typed count can lie, a derived count cannot. A page that cites a data file which does not exist will not build; the error is loud and arrives before publication, not after. The front page keeps no list of reports of its own: it asks the index, so a report withdrawn from the index vanishes from the front page in the same breath, with no second copy left behind to go stale. None of this requires anyone to remember anything, which is the design working as intended. Once a fact is collected, the ways it could quietly drift from its source have been removed one by one -- not because the people involved are careful, though they try to be, but because the paths to being wrong are closed at the door.
The last stage is neither pipe nor parser. A human read the reports and hand-checked roughly twenty claims in each against their sources before anything was sent. And the machine's findings went to the committee as flags, not conclusions, because a system that surfaces gaps between a deck and the public record cannot weigh whether a gap is fatal or fixable. That judgment stayed with the people whose judgment it was. The division of labour is the design: the machine asks every question, the human samples the answers, the committee decides. Remove any of the three and the other two are worth less.
The turn
It would be pleasant to leave the story there, with the discipline pointed outward at other people's slides. Pointed inward, it is less flattering and more instructive. Run against our own records, the same machinery has caught our decay: a grant figure that was wrong by a transposed digit, carried for months through documents that all agreed with one another, until someone read the executed contract again; a patent status our own files described as pending after the registry had recorded its withdrawal. Nobody lied. Nothing was fabricated. The files simply went stale while agreeing with each other -- and internal agreement, it turns out, is exactly what staleness looks like from the inside. Every copy confirms every other copy, and all of them are wrong together. The check that catches this class of error is not a reviewer, who can only compare the copies. It is a fresh question put to the record's owner. And the repair follows the same rule as the catch: the correction is made at the source and flows outward to every copy, and the query that found the error once stands ready to find it again.
What a reader may now demand
The deck's slide was probably true once, at grant, in whatever year the template was made. The lesson is not that decks lie; most do not. It is that documents age and the world does not, and the gap between them widens quietly, fee by unpaid fee, until someone asks. For decades the asking was expensive enough that politeness stood in for verification. It no longer is.
So the standard a reader can hold any document to has changed shape. The old question was whether a claim is cited. The new one is stricter: can each number in this document be re-pulled, today, from the record that owns it? A citation is a claim about the past -- this was true when I wrote it down. Provenance is a standing invitation: ask again. The pipes did not create that standard. They merely removed the last respectable excuse for not meeting it.
Sources
Footnotes
-
35 U.S.C. 41(b) and 37 CFR 1.362: maintenance fees on utility patents are due at 3 years 6 months, 7 years 6 months, and 11 years 6 months from grant; 35 U.S.C. 41(b)(2) provides that the patent expires on failure to pay, subject to the six-month grace period. (Primary) ↩
-
ToolUniverse, an open-source registry of callable scientific tools over primary biomedical, chemical, regulatory, and literature databases. Tool count from the local installation:
tu status, version 1.1.11, reporting "tools loaded: 2658", read 2026-08-08. The count is a property of the installed catalogue, not of any single upstream database. (Primary, local census) ↩ -
Internal API-surface census, queried 2026-08-08: 17,762 endpoints across 84 systems (
SELECT count(*) FROM endpoint; SELECT count(*) FROM system;). Systems include the SEC's EDGAR full-text and submissions APIs, the USPTO Open Data Portal, and the US Census Bureau data API, each driven against its own published schema. (Primary, local census) ↩ -
Gao S, Zhu R, Sui P, et al. "Democratizing AI scientists using ToolUniverse." arXiv:2509.23426, submitted 2025-09-27. States the registry offers "more than 600 machine learning models, datasets, APIs, and scientific packages," and draws the analogy verbatim: "Like HTTP standardizes client-server communication, ToolUniverse defines an interaction protocol that governs how AI models issue tool requests and receive responses." Code at github.com/mims-harvard/ToolUniverse, Apache License 2.0, from the Zitnik Lab, Department of Biomedical Informatics, Harvard Medical School. Preprint, not yet peer-reviewed. (Primary) ↩ ↩2
-
Gao S, Zhu R, Kong Z, Noori A, Su X, Ginder C, Tsiligkaridis T, Zitnik M. "TxAgent: An AI Agent for Therapeutic Reasoning Across a Universe of Tools." arXiv:2503.10970, submitted 2025-03-14. The abstract states the toolbox "consolidates 211 tools from trusted sources"; the paper introduces ToolGen, "a multi-agent tool construction system that generates tools from API documentation." Preprint, not yet peer-reviewed. (Primary) ↩ ↩2