Usually, yes — pasting client-confidential information into a public AI chatbot is a disclosure to an unauthorized third party, which is exactly what a standard NDA forbids. Enterprise AI terms protect you from the vendor, not from your client. Whether AI use is compliant depends on one question: what does the model actually receive?
The scale of the problem
Consultants and regulated-industry experts are already using AI on client work — mostly without telling anyone. The data is unambiguous:
57% of employees who use AI at work conceal it from their employer, and 48% have uploaded company information into public AI tools.
Source: KPMG & University of Melbourne, “Trust, Attitudes and Use of AI: A Global Study 2025” (n ≈ 48,000 across 47 countries)
Breaches involving shadow AI cost an average of $670,000 more than other breaches, and shadow AI is now a factor in 1 in 5 breaches.
Source: IBM Cost of a Data Breach Report 2025, Ponemon Institute (n = 604 organizations)
Every one of those hidden prompts is tested against a document most consultants have signed and few have re-read: the NDA.
What a standard NDA actually forbids
NDAs differ, but four clauses appear in nearly all of them — and each one bears directly on AI use:
| Standard clause | What it typically says | What it means for AI |
|---|---|---|
| Definition of Confidential Information | Broadly defined: business plans, financials, technical data, unpublished results, client lists — usually 'in any form.' | The definition almost never depends on whether a name is attached. A pricing model with the names removed is still Confidential Information. |
| Non-disclosure to third parties | The receiving party shall not disclose Confidential Information to any third party without prior written consent. | An AI provider is a third party. Transmitting confidential text to its servers is a disclosure — at the moment of transmission, regardless of retention or training policies. |
| Permitted use / purpose limitation | Confidential Information may be used solely for the engagement's purpose. | Even where disclosure could be argued away, processing client data in an unapproved external system frequently exceeds the permitted purpose. |
| Required safeguards | The receiving party shall protect Confidential Information with at least reasonable care. | Pasting client data into a free consumer chatbot on a personal device is very hard to defend as 'reasonable care.' |
Why “we have Copilot” doesn't answer the question
The most common objection is that the firm already licenses an enterprise AI — ChatGPT Enterprise, Microsoft Copilot, Claude for Enterprise — with contractual commitments not to train on customer data. Those commitments matter, but they answer the wrong question.
Enterprise AI terms are an agreement between you and the AI vendor. Your NDA is an agreement between you and your client. The vendor's promise not to train on your prompts does not grant you your client's permission to send their confidential data to that vendor in the first place. Unless the client authorized that specific disclosure — in the NDA, in the engagement letter, or in writing — the enterprise licence changes who holds the data, not whether you were allowed to send it.
The three routes — a decision framework
Every way of using AI on client work falls into one of three architectures:
| Route | What the model receives | NDA posture |
|---|---|---|
| 1 · Public AI | The raw confidential text, sent to a consumer service on consumer terms. | Unauthorized third-party disclosure under a standard NDA. The $670K shadow-AI premium lives here. |
| 2 · Enterprise AI | The raw confidential text, sent to a vendor under enterprise terms (no-training commitments, retention controls). | Reduced vendor risk, but still a disclosure to a third party. Requires client authorization to be clearly compliant — and there is always the risk of a leak. |
| 3 · Cloaked input | Text in which every confidential value has been replaced with a semantic marker before leaving your computer. The model never receives the secret. | No confidential value is disclosed, because none is transmitted. The NDA question dissolves rather than being argued around. |
Routes 1 and 2 manage disclosure with promises — the vendor's promises. Route 3 removes the disclosure. That is the architectural difference: a contractual protection asks your client to trust a third party; an architectural protection means there is nothing for the third party to be trusted with.
A practical decision tree
- Is any part of the input confidential under your NDA? If no — public or enterprise AI is fine. Be honest here: strategy, pricing, unpublished results and identities are confidential even with names removed.
- Has the client authorized disclosure to this specific AI system? If yes, in writing, it is most likely compliant when leak mitigation is strongly in place: a signed BAA, audit trails retained for 7 years (in regulated industries), and continued respect for HIPAA and other confidentiality laws. Keep the authorization with the engagement records.
- Can the confidential values be removed before the text reaches the model? If removal is complete and verifiable, no disclosure occurs. Crude redaction achieves this at the cost of the output (the model cannot reason about [REDACTED]); semantic cloaking achieves it while preserving the meaning the model needs.
- Can you evidence it afterwards? An auditable record of what was cloaked and what was submitted turns "we were careful" into something you can hand to the client's compliance team. An AI compliance system without an audit trail should not be trusted, and is unlikely to be convincing evidence to auditors or HIPAA officers.
The bottom line
The NDA question is not "which AI vendor do you trust?" — it is "what does the model receive?" If the model receives the confidential value, you need your client's permission, whoever the vendor is. If the model never receives it, there is no disclosure to permit. That is the standard consultants should hold any AI tool to — including ours.
Frequently asked questions
Is it a breach of NDA to paste client information into ChatGPT?
Under most standard NDAs, yes. Sending client-confidential information to a public AI service transmits it to a third party the client never authorized, which is precisely what a non-disclosure clause forbids. The breach happens at the moment of disclosure — whether or not the AI provider stores or trains on the data.
Does ChatGPT Enterprise or Microsoft Copilot make AI use NDA-compliant?
Not by itself. Enterprise terms are an agreement between your firm and the AI vendor: they reduce the risk that the vendor misuses your data. Your NDA is a separate agreement between your firm and your client. Unless the client authorized disclosure to that vendor, sending their confidential data to an enterprise AI service can still be an unauthorized disclosure — with better safeguards, but a disclosure nonetheless.
What can consultants safely put into AI tools?
Information that is not confidential (public data, your own general knowledge, fully synthetic examples), information the client has authorized for the specific tool, or text from which the confidential values have been removed before it reaches the model. The last route only satisfies the NDA if the removal is complete and verifiable — and it only stays useful if the AI can still reason about what remains.
Does anonymizing or redacting client data make it safe for AI?
Only partly. Redaction that strips names may still disclose confidential business information — pricing, strategy, unpublished results are confidential in themselves, not because a name is attached. And heavy redaction destroys the context the AI needs, degrading output quality sharply. This is the gap cloaking addresses: confidential values are replaced with semantic markers on your computer, so the model never receives them but can still reason about the document.
What should an AI clause in an NDA actually say?
Modern NDAs increasingly address AI directly: whether confidential information may be processed by AI systems at all, which deployment classes are permitted (public, enterprise, or architectures where the model never receives confidential values), and what audit evidence the disclosing party can request. If your NDAs are silent on AI, the general non-disclosure clause still governs — silence is not permission. Our recommendation when you adjust your NDA: don't let your secrets leak when you can get the power of AI without sharing them. Allow your data to be cloaked, but restrict any dumping of your raw data into online AI tools.
This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary — review your own agreements with qualified counsel before relying on any framework described here.
Work with AI on data you can't share with it.
Untraceable cloaks confidential values on your computer before any AI model sees the text — the model never receives the secret at all.