Employees who paste confidential information covered by non-disclosure agreements into consumer AI tools are inadvertently triggering widespread NDA violations, and standard contract language has not caught up to the risk. The practice is routine-surveys show more than half of employees have fed company data into public AI platforms-yet most NDAs were drafted before these tools existed, leaving both disclosing and receiving parties exposed.
Standard NDAs restrict disclosure of confidential information to employees and authorized representatives with a need to know. When an employee runs a counterparty's proprietary data through a consumer large language model, that information leaves the receiving party's environment and is processed on a third party's servers. The AI provider is neither an employee nor an authorized representative under the typical agreement.
Terms of service for consumer-tier AI tools often reserve the right to use inputs for model training. Even when opt-out settings exist, many employees have not configured their accounts to prevent training use. The result: confidential information can be absorbed into a product the receiving party does not control.
The return-or-destroy gap
Most NDAs include a return-or-destroy clause that requires the receiving party to delete all confidential information at the end of the relationship and certify compliance in writing. A receiving party whose employees have fed that information into an AI tool cannot honestly make that certification. While it can delete local chat histories, it cannot reach the provider's server logs, cached prompts, backups, or sub-processor systems. Once data has been used for training, certification becomes difficult or impossible to support.
Enterprise platforms that contractually commit to zero data retention and no training on inputs may close this gap, provided the receiving party can document which platform was used and its terms. Consumer tools offer no such assurance, leaving the receiving party signing a certificate it has no way to verify.
Scale and two-way exposure
The volume of potentially compromised information is significant. Multiple recent surveys put the share of employees who have pasted confidential company data into a public AI tool above 50%, and many organizations still lack a governing policy. If even a fraction of that activity involves information received under an NDA, the exposure across the economy is large.
Every company sits on both sides of these agreements. The same employees feeding a counterparty's confidential data into AI tools are likely doing the same with their own company's information, creating risk in both directions. For legal teams, this is not a hypothetical-it is a current, unmeasured liability.
Drafting fixes are straightforward
NDAs going forward should address AI use directly. At minimum, they should state whether the receiving party may process confidential information through AI tools at all. If permitted, the agreement should distinguish between enterprise platforms with contractual zero-retention and no-training commitments-which may be acceptable-and consumer tools, which generally are not. The NDA can also require disclosure upon request of which AI tools were used with the information.
The return-or-destroy obligation should extend, on a reasonable-efforts basis, to the AI provider's environment, and the destruction certification should qualify what cannot be reached. Emerging agentic AI systems, where the tool receives information and acts on systems containing it, magnify every problem and need specific attention. This is the same exercise NDA drafting has always required: identifying channels through which confidential information can leave the receiving party's control and closing them. AI is simply a channel that did not exist when most current NDAs were written.
Why this matters for legal professionals
In-house counsel and law firm attorneys drafting or litigating NDAs are carrying a risk that standard forms do not address. The disclosing party's information is less protected than it assumes, and the receiving party may be in breach without knowing it. Updating template language to account for AI tools is a low-effort, high-impact fix. For more on how AI intersects with contract analysis and compliance obligations, see AI for Legal. Until language catches up, companies are relying on agreements that were not built for the way employees now work.
Your membership also unlocks: