Guides

    AI, confidentiality and regulated work.

    Ten guides on the question the general AI-safety literature keeps leaving open: what to do when the input itself is confidential. Each one is self-contained — start wherever your problem is.

    Does Using AI Break Your NDA?

    Law-firm guidance ends with “use a secure, enterprise-grade AI tool.” This is the framework for what that actually requires — clause by clause.

    Read the guide →

    Your Copilot Licence Doesn’t Cover Your Client’s NDA

    The most common answer to the AI-confidentiality question is “we have an enterprise licence.” It answers the wrong contract.

    Read the guide →

    De-identification Is Not Confidentiality

    Health privacy has a de-identification standard. NDA-bound information has none — and treating the two as interchangeable is how confidential data ends up in AI models.

    Read the guide →

    What Does Redaction Cost You?

    Every guide says de-identify before you prompt. Almost none say what it costs your output. Here is the measured answer — method by method.

    Read the guide →

    Semantic Cloaking, Explained

    A worked definition of the technique behind Untraceable — and how it differs from every other way of hiding data from an AI.

    Read the guide →

    The Governance Gap Is a Data Problem

    Executives name governance and compliance as their top AI agent concerns. Their staff, meanwhile, are pasting confidential documents into tools nobody approved. That gap does not close with a stricter policy.

    Read the guide →

    AI Watermarking and Your Deliverables

    Text produced with frontier AI is becoming machine-detectable, and the parties who can run that check are the ones you answer to. The mark is not the problem. Work that cannot be explained is.

    Read the guide →

    AI for HEOR: What You Can and Can’t Put in a Prompt

    The field’s guidance says use AI carefully, keep humans in the loop, and be ready to defend it at HTA. Here is the piece it leaves open: what to do when the input itself is confidential.

    Read the guide →

    Canada’s Blind Spot: PIPEDA, Law 25 and Generative AI

    Most “AI compliance” writing is US-centric. Canadian consultants operate under PIPEDA and, in Quebec, Law 25 — which bear directly on sending client data to an AI model.

    Read the guide →

    AI Use Policy Template for Consulting Firms

    A one-page, permissioned policy — free to copy and adapt. Built around the question that actually matters: which data can go into which tool.

    Read the guide →