For pharma teams

    Your people are already using AI on confidential material.

    So are your vendors. The useful question is not whether AI is being used on your work — it is whether confidential values and secrets leave, and whether anyone can show afterwards what happened. Those are two separate problems, and they have two separate solutions.

    This is an ordinary operational fact, not a scandal. In most organisations, some portion of confidential work already passes through a model — a summary here, a rewritten paragraph there — and the policy says otherwise. Prohibition does not stop it. It moves it somewhere with no record, which is the worse of the two exposures, because it is invisible. A ban produces silence, and silence is not the same as absence.

    The third option nobody offers you

    Today a consultancy working on your data has two realistic options: refuse to use AI, or use it and not mention it. The second is what mostly happens. You carry the exposure without knowing it exists.

    There is a third: use it under a governed workflow, and disclose, with a record behind the disclosure — making sure your secrets stay inside your client-vendor environment. A vendor offering that is not a risk you have to manage — it is the only vendor whose AI use you can actually see.

    The vendors who disclose are not your problem — when they properly strip your confidential data and secrets, and keep advanced audits of what was sent. The ones who say nothing are. A firm that volunteers a conformance record has told you exactly what it did. Silence from the rest is not evidence that they did less.

    This is getting more urgent, not less. Use of MCP — the connector standard that lets an AI model reach directly into the systems it is pointed at — is spreading like wildfire, and a model wired into a document store or a clinical database can read patient data and secrets with no protection layer in between. Make sure the consultants and regulated experts working on your data are using the right tool for a job this complex.

    What this costs you today

    Confidential values in consumer tools

    Pasted into whatever was open, outside any residency control, any retention control, and any record. The organisation's own policy has no visibility into it.

    No way to scope an incident

    When someone asks what was exposed, the honest answer is that nobody knows. There is no log of what was submitted, so the question cannot be answered — not slowly, not at all.

    An enterprise licence that covers the wrong party

    A no-training commitment binds the AI vendor to your organisation. It says nothing about a partner's or a client's confidentiality obligations, and those are the obligations that bite.

    What an enterprise AI licence does and does not cover →

    AI involvement is becoming visible anyway

    Frontier providers now embed watermarks in generated text, and detection tooling is arriving. Whether a deliverable was AI-assisted is becoming a matter of record rather than a matter of policy.

    AI watermarking and your deliverables →

    What to require instead

    Eleven things any AI workflow touching your confidential work should be able to demonstrate. They are written to be vendor-neutral and any tool can conform. Use them to ask better questions of whoever you are evaluating, us included.

    Please read first

    These are technical requirements, offered freely to help make AI use in regulated work safer. They are not legal advice and they are not contract language. Have your own counsel decide how any requirement here should be expressed in your agreements.

    No confidential value is transmitted
    Confidential values are removed before any model receives the text — and this is a property of the architecture, not a policy commitment or a promise not to train. Ask where the removal happens. If the answer is “on our servers”, the values still left the building.
    Key custody stays with you
    Whatever maps substituted values back to real ones must remain in your own environment. A vendor holding that map can reverse your data, whatever their policy says. This is not the general question of who manages infrastructure encryption keys — it is specifically the map that reverses the substitution, which is the only key that can undo the protection.
    Verification before transmission, not after
    An automated check that attempts to reconstruct real values from the outgoing payload, and that blocks the submission when it succeeds. The threshold should be stated and defensible; the defensible one is zero. And no text should reach a model without such a check having run at all — an unchecked path is the failure, whatever the threshold on the checked one. A check that runs after the data has gone is a report, not a control.
    A per-document record
    Model and version, parameters, what was sent, what came back, which substitutions were in effect, the verification result and the human review — written at the time. A record reconstructed after a question is asked is worth far less than one that predates it.
    A record you can actually share
    The conformance record must be producible without disclosing confidential values, so it can go to a partner, a sponsor or a reviewer without a redaction exercise first.
    Named subprocessors
    Which models, which providers, which regions. “Enterprise-grade AI” is not an answer to this question.
    Inference residency, not just storage residency
    Where the model runs, disclosed per model. These two are routinely conflated and they are not the same control — data can rest in one region and be reasoned about in another.
    Stated retention
    What is retained, for how long, and what is never retained. Confirm it at the platform layer, not only in the application’s own settings.
    Provenance preserved, not defeated
    The vendor must not strip, obscure or degrade provider watermarks. A tool offering to make AI output undetectable is telling you what it optimises for.
    Human oversight captured
    Who reviewed the output and what they changed. This is the element most guidance in regulated fields actually asks for, and the one most tooling omits.
    Exit terms for the records
    What happens to the audit trail if you stop using the tool. A record you lose on termination is not a record.

    Where to go next

    For your own team

    Internal use, on your own confidential data. No third-party consent question.

    For work you outsource

    What to ask of the consultancies and CROs working on your data.

    Why this exists

    I was a global director of health economics inside pharma, running a small team with exactly this problem. Then a vice president at a CRO for five years, on the receiving end of sponsor data and subcontracting work out. I have sat on all three sides of this transaction — the sponsor, the vendor, and now the tooling. Untraceable is the thing I wanted in the first two seats and could not buy.

    Gabriel Tremblay, founder, Untraceable AI

    If it is useful, take the requirements and use them — with us or without us. If you want to see what conformance looks like in practice, read the Protocol or ask for a walkthrough.