Skip to content
AI & legal work

Does putting client work into AI breach your NDA — and what it costs even when it does not

The question is usually asked as a yes or no, and the yes or no is the least interesting part of it. Whether one paste breaches one NDA turns on four or five words in that NDA. What happens to the information afterwards does not turn on the NDA at all — it turns on whether the company now holding the text owes anybody a duty to keep it. That is the part nobody can apologise their way out of.

9 min readPublished How we write these

The short version

  • Usually yes on the contract, if the NDA limits disclosure to named recipients — a hosted AI tool is a third party, and typing into it is a disclosure whether or not the agreement mentions AI.
  • The larger harm is to the owner, not to you. A trade secret exists only while the owner takes reasonable measures under 18 U.S.C. § 1839(3)(A); the USPTO puts it flatly — if one element ceases to exist, the trade secret ceases to exist.
  • The plan tier changes the legal answer. Consumer plans may train on input and retain it for years; the same vendors exclude commercial and API customers from training by published terms.
  • Disclosure under an obligation of confidence is not disclosure to the world. Material sent to a vendor bound by written confidentiality and a no-training term generally keeps its secrecy.

Two questions get collapsed into one here, and they have different answers, different remedies and different half-lives. Separating them is most of the work.

Breaching the NDA is the recoverable half

A breach of an NDA is a contract claim. The counterparty identifies the term, the breach and a loss, and gets what the agreement gave them — damages, an injunction, an indemnity, sometimes costs. It is unpleasant, negotiable, and it concludes.

The other half does not conclude. Trade secret protection is a status, not a grant, and it holds only while three conditions hold together. Under 18 U.S.C. § 1839(3) the information must derive independent economic value from not being generally known or readily ascertainable by proper means, and the owner must have taken reasonable measures to keep it secret. The USPTO states the consequence in one line: if any one element ceases to exist, the trade secret ceases to exist.

So the exposure is lopsided. Your breach costs you money. The client's loss of status costs them the asset — against competitors, against former staff, against everyone who had nothing to do with the paste.

The contract claim and the statutory claim are not the same instrument

The NDA

  • Binds only who signed it
  • Remedies are whatever it drafted
  • Expires on the date it names

Both

  • Triggered by the same paste
  • Turn on what counts as disclosure
  • Defeated by consent given in advance

Trade secret law

  • Reaches anyone acquiring by improper means
  • Exemplary damages and fees where wilful
  • Lasts only while the secret does
The middle column is the part people miss. The NDA is not only the source of the contract claim; it is also the main evidence that the owner took reasonable measures.

Most NDAs already cover this without using the word AI

People search an old agreement for "artificial intelligence", find nothing, and conclude it is silent. It rarely is. Four ordinary clauses do the work between them.

  • Disclosure to third parties. A vendor is a third party. Pasting sends the client's text to a company the client never chose.
  • The purpose limitation. Use is permitted only for the defined Purpose. Improving somebody else's product is not the Purpose.
  • Permitted recipients. Share with employees, advisers and sometimes subcontractors, if they are bound by equivalent written obligations. This clause decides the answer.
  • The standard of care. Many NDAs require the care you use for your own confidential material. A personal chat account rarely clears that floor.

Read the permitted-recipients clause twice. Where it extends to service providers bound by obligations no less protective, a business-tier tool under no-training terms may already sit inside the fence. Where it names only employees and advisers, it does not, and care about the tool will not fix that. What else changes with the direction of flow is in the guide to mutual and one-way NDAs.

The plan tier is the fact that flips the answer

The same assistant, under the same brand name, is two different contracts depending on how you signed in. The vendors publish the split themselves, and it is consistent enough to build a rule around.

  • Anthropic's consumer terms cover Free, Pro and Max: chats may be used for training unless the user opts out, with five-year retention for those who do not. The commercial terms — Claude for Work, Government and Education, and API use including through Bedrock and Vertex AI — are expressly excluded.
  • OpenAI's developer documentation states that API data is not used for training unless the customer opts in, and that abuse-monitoring logs are held for a limited window unless longer retention is required by law. Approved customers can obtain zero data retention.
  • Google's Gemini Apps privacy hub says a subset of consumer chats are read by human reviewers, and that chats already selected for review are held separately for up to three years, surviving deletion of the conversation.

Neither the clause nor the tier decides on its own

Who may the NDA be disclosed to?

Which contract is the tool on?

Personal login, consumer terms

Commercial terms, no training

Staff and advisers only

Breach, and loss

Outside the permitted list, to a vendor owing the owner nothing. The only cell where both problems land at once.

Breach, secrecy intact

Not allowed by the clause, but made under terms keeping the material out of training. A conversation, not a catastrophe.

Service providers bound equivalently

Condition never met

The carve-out attaches only where the provider is bound in writing. A personal account is bound by nothing.

Inside the fence

A permitted recipient, under terms forbidding training. The only combination needing no disclosure to the client at all.

A generous NDA does not licence a personal account, because the carve-out is conditional on the provider being bound. A business subscription does not widen a clause listing only employees.

Non-disclosure agreement template

Full text, free to read and copy, with the permitted-recipients, purpose and survival clauses drafted in the order an AI dispute actually tests them.

Open

Reasonable measures is a question about the owner, not about you

This is the prong that decides whether the information is still a trade secret, and it asks what the owner did. Courts treat it as a fact question. In Samuel Sherbrooke Corporate, LTD v. Mayer (No. 24-2173, 4th Cir., 18 November 2025) the Fourth Circuit held that at the pleading stage, an allegation that the person signed a confidentiality provision is on its own enough to plead reasonable measures.

Read the good news in that. Disclosure made under an obligation of confidence is not disclosure to the world. Where material moves from you to a vendor under commercial terms that forbid training and bind the vendor to confidentiality, the chain of confidence is unbroken and the secret survives the trip. Trade secret law does not punish disclosure; it punishes disclosure that leaves the information unprotected.

The reverse does the damage. Information handed over on terms permitting it to improve a product, retained for years and read by reviewers has left the owner's control by a route the owner never sanctioned. Whether a court calls that a failure of reasonable measures or a loss of secrecy hardly matters — trade secret status is a condition, not a certificate, and it does not come back.

Deleting the conversation does not undo it

Three things govern how long the text survives, and only the first is yours: the delete button, the vendor's retention schedule, and any legal hold above both. Vendor documentation is candid that its own windows yield to law — OpenAI holds abuse-monitoring logs unless longer retention is legally required.

That caveat is not theoretical. In The New York Times Company v. Microsoft Corporation (No. 1:23-cv-11195, S.D.N.Y.), the magistrate judge on 13 May 2025 directed OpenAI to preserve and segregate output log data that would otherwise have been deleted, setting aside its concerns about user deletion requests. The order was later narrowed by stipulation, but the mechanism is permanent: a vendor in litigation cannot honour its own deletion promise.

Where a pasted paragraph actually lives

  1. The paste

    It has left your machine

    From here the text is governed by a contract you did not negotiate.

  2. You delete

    The chat, not the copies

    Copies pulled for review or abuse monitoring run on their own schedules.

  3. Retention window

    Days on commercial terms, years on consumer

    The published tiers differ by orders of magnitude. Read the plan you are on.

  4. Legal hold

    Neither clock runs

    A preservation order overrides the retention policy and your deletion request together.

The only step in the sequence you control is the first one. That is the argument for deciding before the paste rather than after it.

What an AI clause in a mutual NDA should actually say

Two ways to draft this badly. A blanket ban is unworkable — search, spelling, mail and meeting notes all contain models now, so a clause forbidding all machine-learning processing is breached by both sides on day one. A clause asking the parties to use AI responsibly decides nothing.

Seven lines that make an AI clause operative

  • Restrict by behaviour, not by label: services that train on or retain customer input, rather than "artificial intelligence" at large.
  • Put the tier in the clause: use permitted only on terms excluding customer content from training, producible on request.
  • Extend permitted recipients to service providers bound in writing to no less protective obligations, the recipient staying liable.
  • Require deletion on request and on termination, and acknowledge its limits. Backups, abuse monitoring and legal holds are real.
  • Say what happens to output: whether material generated from Confidential Information is itself Confidential Information.
  • Carve trade secrets out of the survival period, so that obligation runs as long as the information qualifies.
  • Add a notification trigger — a duty to report any disclosure outside the permitted set within a stated number of days.

That last line is genuinely contested. Some courts have treated the expiry of an NDA's confidentiality obligation as the moment the owner stopped taking reasonable measures, ending trade secret protection with it; more recent decisions treat expiry as one fact for a jury. Splitting the term is cheap insurance, and belongs in the confidentiality clause of your service agreement too.

One more clause applies where the agreement is with a worker. 18 U.S.C. § 1833(b)(3) requires notice of the whistleblower immunity in any agreement governing trade secrets, and an employer who omits it may not be awarded exemplary damages or attorney fees against that person. Contractors count as employees here, so the notice belongs in an independent contractor agreement too — and the vendor terms behind all of it read like any other SaaS agreement: training, retention, sub-processors.

If it has already happened

The order matters here, because the obvious first move destroys the evidence you need for the second.

  1. 1

    Record it before you delete it

    Write down what was pasted, into which account and tier, on what date. Deleting first destroys the only description of the exposure, and what left is the first thing the client asks.

  2. 2

    Close the training route

    Turn off model training in the account settings, then delete the conversation. That generally stops future use, but anything already pulled for human review sits on a schedule you cannot reach.

  3. 3

    Read the notification clause before drafting the email

    Most NDAs name who must be told, in what form and within how many days. A report made outside the contractual route is sometimes treated as no report at all.

  4. 4

    Tell them what you know, not what you hope

    The client needs the tier, the published terms, the retention position and the steps taken. "It was not used for training" is only useful if you can point at the paragraph saying so.

  5. 5

    Fix the clause, not only the incident

    The same paste happens again unless something changes. An approved-tools rule and a permitted-recipients carve-out cost less than the second apology — the internal version is in the guide to an AI use policy.

The honest answer is narrower than either confident one

Using AI on confidential work is not inherently a breach, and not inherently safe. It is a disclosure, and disclosure is what NDAs and trade secret law were built to regulate. What decides the outcome is whether the recipient is bound to keep it — a question about the plan you signed into and the clause you signed up to, both knowable in the ninety seconds before the paste rather than the six months after.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Does putting client data into ChatGPT violate an NDA?

Usually yes, where the NDA limits disclosure to a defined list of recipients. A hosted assistant is a third party, and pasting sends the material to it. The exception is a permitted-recipients clause extending to service providers bound by equivalent written obligations, which a business-tier account under no-training terms can satisfy and a personal login cannot.

Does uploading a document to an AI tool destroy trade secret protection?

Not automatically. Trade secret status survives disclosure made under an obligation of confidence, so a vendor bound by written confidentiality that does not train on customer content generally keeps the chain intact. What endangers the status is disclosure on terms allowing the material to be used to improve a product, retained for years, or read by reviewers owing the owner nothing.

Is a paid subscription enough, or does it have to be an enterprise plan?

The distinction that matters is contractual, not the price. Vendors draw the line between consumer terms and commercial terms, and a paid consumer plan can still fall on the consumer side. Check which set of terms governs your account and whether they exclude your content from training, then keep a copy of the page you relied on.

What should an AI clause in a mutual NDA say?

Restrict disclosure to services that train on or retain input, rather than banning AI generally. Require that permitted tools run on terms excluding customer content from training, extend the permitted-recipients definition to bound service providers, require deletion on termination while acknowledging backup and legal-hold limits, and give trade secrets a longer survival period than general confidential information.

Does an NDA that predates generative AI still apply to it?

Yes. Confidentiality clauses are written around disclosure and permitted use, not around named technologies, so they catch a tool invented after signature without needing amendment. An explicit AI clause is worth adding at renewal because it removes an argument and sets the tier requirement, not because the old agreement was silent on the point.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week