For pharma teams
So are your vendors. The useful question is not whether AI is being used on your work — it is whether confidential values and secrets leave, and whether anyone can show afterwards what happened. Those are two separate problems, and they have two separate solutions.
This is an ordinary operational fact, not a scandal. In most organisations, some portion of confidential work already passes through a model — a summary here, a rewritten paragraph there — and the policy says otherwise. Prohibition does not stop it. It moves it somewhere with no record, which is the worse of the two exposures, because it is invisible. A ban produces silence, and silence is not the same as absence.
Today a consultancy working on your data has two realistic options: refuse to use AI, or use it and not mention it. The second is what mostly happens. You carry the exposure without knowing it exists.
There is a third: use it under a governed workflow, and disclose, with a record behind the disclosure — making sure your secrets stay inside your client-vendor environment. A vendor offering that is not a risk you have to manage — it is the only vendor whose AI use you can actually see.
The vendors who disclose are not your problem — when they properly strip your confidential data and secrets, and keep advanced audits of what was sent. The ones who say nothing are. A firm that volunteers a conformance record has told you exactly what it did. Silence from the rest is not evidence that they did less.
This is getting more urgent, not less. Use of MCP — the connector standard that lets an AI model reach directly into the systems it is pointed at — is spreading like wildfire, and a model wired into a document store or a clinical database can read patient data and secrets with no protection layer in between. Make sure the consultants and regulated experts working on your data are using the right tool for a job this complex.
Pasted into whatever was open, outside any residency control, any retention control, and any record. The organisation's own policy has no visibility into it.
When someone asks what was exposed, the honest answer is that nobody knows. There is no log of what was submitted, so the question cannot be answered — not slowly, not at all.
A no-training commitment binds the AI vendor to your organisation. It says nothing about a partner's or a client's confidentiality obligations, and those are the obligations that bite.
What an enterprise AI licence does and does not cover →Frontier providers now embed watermarks in generated text, and detection tooling is arriving. Whether a deliverable was AI-assisted is becoming a matter of record rather than a matter of policy.
AI watermarking and your deliverables →Eleven things any AI workflow touching your confidential work should be able to demonstrate. They are written to be vendor-neutral and any tool can conform. Use them to ask better questions of whoever you are evaluating, us included.
Please read first
These are technical requirements, offered freely to help make AI use in regulated work safer. They are not legal advice and they are not contract language. Have your own counsel decide how any requirement here should be expressed in your agreements.
Internal use, on your own confidential data. No third-party consent question.
The open specification for what an auditable AI record has to contain — usable as your own internal standard, whatever tooling you pick.
Subprocessors, residency by region, retention, encryption and key custody, in the form a security review asks for.
Run it against a document your team actually works on, rather than a demo dataset.
What to ask of the consultancies and CROs working on your data.
What your confidentiality agreements already forbid your vendors from doing — usually without anyone having read them with AI in mind.
What your vendors’ enterprise AI licence does and does not cover for you. Usually less than the vendor believes.
A conformance target you can point a consultancy or CRO at, rather than writing your own from scratch.
I was a global director of health economics inside pharma, running a small team with exactly this problem. Then a vice president at a CRO for five years, on the receiving end of sponsor data and subcontracting work out. I have sat on all three sides of this transaction — the sponsor, the vendor, and now the tooling. Untraceable is the thing I wanted in the first two seats and could not buy.
— Gabriel Tremblay, founder, Untraceable AI
If it is useful, take the requirements and use them — with us or without us. If you want to see what conformance looks like in practice, read the Protocol or ask for a walkthrough.