Most non-disclosure agreements sitting in your files right now were drafted before generative AI became a routine part of the modern workplace. At the time, the biggest confidentiality risks involved a rogue employee forwarding documents to a competitor or a vendor sharing proprietary data with an unauthorized subcontractor. The standard NDA language — “the receiving party shall not disclose confidential information to any third party” — was built for that world. It worked well enough when disclosure meant a human being handing information to another human being. But that world has changed, and the language hasn’t kept up.

Today, employees across every industry are pasting sensitive data into AI-powered tools like ChatGPT, Claude, Gemini, and dozens of specialized platforms. They’re feeding in financial projections, draft contracts, source code, customer lists, and strategic plans. In many cases, they’re doing it not out of carelessness but out of a genuine desire to work more efficiently. The problem is that when confidential information enters an AI tool, it may be processed, stored, and potentially used to train future models. That raises a question your NDA almost certainly doesn’t answer: has the receiving party just “disclosed” your confidential information to a “third party”?

The Ambiguity at the Heart of the Standard NDA

The honest answer is that it’s not clear. Traditional NDA language was never drafted with this scenario in mind. The prohibition on disclosure to “third parties” assumes a familiar cast of characters — competitors, partners, subcontractors, the press. An AI platform doesn’t fit neatly into any of those categories. It’s not a person. It’s not an organization in the traditional sense. It’s a tool, but it’s a tool operated by a company that may retain, process, and learn from everything entered into it.

Consider what happens when an employee at the receiving party pastes a section of your proprietary business plan into an AI chatbot to generate a summary. Has the receiving party “disclosed” the information? One could argue yes — the data has been transmitted to a server owned and operated by a third-party technology company. But one could also argue no — the employee was simply using a productivity tool, much like running a spell-check or using a search engine. The NDA doesn’t say, because the people who drafted it never imagined the question.

This ambiguity is not academic. When your confidentiality protection depends on winning an argument about what “disclosure” means in the context of a technology that didn’t exist when the agreement was signed, you have a real and present problem. Litigation over NDA breaches is already expensive, slow, and uncertain. Adding a layer of novel technological interpretation to that process only makes things worse. And if you’re the disclosing party, the damage is done long before any court weighs in on whether the breach technically occurred.

Why “Reasonable Safeguards” Aren’t Enough

Some practitioners take comfort in the fact that most NDAs require the receiving party to use “reasonable safeguards” or “commercially reasonable measures” to protect confidential information. The theory is that allowing employees to paste sensitive data into AI tools without guardrails would fail that standard. That may be true, but it’s a thin reed to lean on. What counts as “reasonable” changes over time and varies by industry, and there’s a strong argument that using widely adopted AI tools — tools used by millions of professionals — is itself reasonable conduct. Courts haven’t provided clear guidance yet, and waiting for them to do so is a strategy that favors the party that already has your information.

The better approach is not to rely on general standards that require interpretation. It’s to address the risk directly.

The Fix: Targeted Provisions That Close the Gap

The good news is that updating your NDAs to account for generative AI doesn’t require reinventing the agreement. A few targeted provisions can close the gap while preserving the structure and intent of the original document.

First, broaden the definition of disclosure. The definition should explicitly cover the input of confidential information into AI tools, machine learning models, large language models, and similar technologies. This removes the ambiguity about whether feeding data into an AI platform constitutes “disclosure” under the agreement. It doesn’t matter whether the AI is characterized as a “third party” or a “tool” — the act of inputting the data is itself captured.

Second, address AI inputs directly. Consider adding a provision that specifically prohibits the receiving party from entering, uploading, or otherwise inputting confidential information into any generative AI tool, large language model, or automated processing system without the prior written consent of the disclosing party. This is clear, enforceable, and leaves no room for the argument that using AI was simply a form of internal processing.

Third, clarify ownership of derivative outputs. When confidential information is used as an input for an AI tool, the resulting outputs — summaries, analyses, code, reports — may constitute derivative works or contain embedded elements of the original confidential data. Your NDA should address who owns those outputs and whether they are themselves subject to the confidentiality obligations of the agreement. Without this provision, you risk a scenario in which the receiving party argues that the AI-generated output is “new” information, not subject to the NDA, even though it was built entirely from your proprietary data.

The Cost of Doing Nothing

Every day that your NDAs remain silent on generative AI is a day that your confidential information is potentially exposed to risks that the agreement was never designed to address. The receiving party’s employees are almost certainly using AI tools already. The question is not whether your confidential data will encounter generative AI — it’s whether your agreement has anything meaningful to say about it when it does.

Updating your NDAs is not a heavy lift. It doesn’t require starting from scratch or renegotiating the fundamental terms of the relationship. It requires a careful review of the existing language and the addition of a few well-drafted provisions that bring the agreement into alignment with how people actually work today.

If you haven’t looked at your NDAs through this lens, it’s worth taking a few minutes to do so. The gap between what your NDA says and what it needs to say may be smaller than you think — but ignoring it doesn’t make it go away.

Leave a Reply

Your email address will not be published. Required fields are marked *

Contact Us

FIll out the form below and we will cantact you as soon as possible