Guides

    Your Copilot Licence Doesn't Cover Your Client's NDA

    The most common answer to the AI-confidentiality question is 'we have an enterprise licence.' It answers the wrong contract.

    Published 2026-07-13

    The short answer

    Enterprise AI terms — ChatGPT Enterprise, Microsoft Copilot, Claude for Enterprise — are agreements between your firm and the AI vendor. Your NDA is an agreement between your firm and your client. The vendor's promise not to train on your data does not grant your client's permission to send their confidential data to that vendor. Only two things close the gap: the client's authorization, or an architecture where the model never receives the confidential values at all.

    What enterprise AI terms actually promise

    Enterprise AI agreements are real security upgrades — the kind that would be required to satisfy an NDA and the confidential-data protections and laws around it. But note the scope up front: what follows is true for enterprise AI with a signed BAA, proper memory and retention management, and (in some cases) a compliance-grade API. It is not true for individual plans or free AI, which offer none of it. With that caveat, here is what a genuine enterprise agreement delivers:

    • No-training commitments — your prompts and files are not used to train the vendor's models.
    • Retention and residency controls — shorter or zero retention windows, regional processing options.
    • Admin and audit tooling — SSO, usage visibility, workspace controls. Note the gap: regulated work typically requires audit records retained for at least 7 years, and standard enterprise-AI tooling does not provide that by default — you have to add the retention and audit layer yourself.
    • Processor paperwork — DPAs, and in healthcare contexts BAAs, that make the vendor a lawful processor of data you send it.

    Every item on that list governs the same relationship: you and the vendor. That is exactly why it cannot answer the confidentiality question, which lives in a different relationship entirely.

    Two contracts, two questions

    Enterprise AI terms (you ↔ vendor)NDA (you ↔ client)
    Question it answersWhat will the vendor do with data you send it?Who are you allowed to send the client's data to in the first place?
    Who grants permissionThe vendor commits to you.The client commits — and only the client can authorize a new recipient.
    Effect of a no-training clauseReduces the risk that transmitted data is reused or exposed.None. The disclosure occurred at transmission; the clause changes what happens after.
    Who can waive itYou can accept the vendor's standard terms yourself — as long as you understand the clauses and can certify that all residency, retention and use of the data is legal.Nobody but the client. Your firm cannot consent on the client's behalf.

    Put plainly: a promise made to you by the AI vendor cannot substitute for a permission that only your client can give. A standard NDA forbids disclosure of confidential information to third parties without consent. An AI vendor is a third party. An enterprise agreement makes that third party better-behaved and contractually constrained — but the data was still disclosed to it, and the client never agreed to that.

    Why this matters more for consultants than for anyone else

    For a company using AI on its own data, well-orchestrated enterprise terms settle the question — the data owner and the AI customer are the same party. Consultants, HEOR teams, regulatory writers and biostatisticians are in the opposite position: nearly everything valuable they touch is someone else's confidential information, held under an NDA or engagement terms. The firm's AI licence was negotiated by the firm, for the firm. The client was never at that table.

    This is also why "our IT department approved Copilot" doesn't end the analysis. IT approval establishes that the tool meets your firm's security bar. The NDA question — may this client's data leave your custody for that vendor? — is a matter of the client's contract, engagement by engagement.

    When enterprise AI is enough

    • Nothing confidential goes in. Public information, general knowledge, fully synthetic examples — no client permission needed.
    • The client authorized it. Some clients will approve a named enterprise deployment, sometimes with conditions (region, retention, scope). Get it in writing and keep it with the engagement records. And even when authorized, if the data is not cloaked you should go as far as possible to protect it — a leak doesn't only breach laws and contractual agreements, it tarnishes your reputation and the client relationship your career is built on.
    • The engagement terms already permit it. Modern MSAs sometimes allow processing in approved third-party systems meeting defined safeguards. If yours does, document that the AI deployment meets them.

    Outside those cases, there are only two honest resolutions: ask the client — which many firms avoid, because the answer may be no, or slow, or conditional — or change the architecture so the question disappears: cloak every confidential value on your own computer before the text is transmitted, so the model never receives the client's information at all. No disclosure, nothing to consent to, and an audit trail to prove it afterwards.

    If you work in pharma or another regulated industry and you're weighing whether to let AI run on your data without secret protection, consider asking for cloaks on that data instead. A marginal ~5% loss in efficiency protects your data and your secrets — and keeps everyone legally compliant.

    In sum

    "Enterprise AI terms protect the firm from the vendor; they do not authorize the firm to disclose client-confidential information to the vendor — that authorization can only come from the client, or be made unnecessary by never transmitting the confidential values."

    Frequently asked questions

    Is ChatGPT Enterprise safe for client confidential data?

    It is safer than consumer ChatGPT — enterprise terms include no-training commitments, retention controls and admin oversight. But 'safe' and 'authorized' are different questions. Sending a client's confidential data to any third-party AI service is a disclosure under a standard NDA, and the client's permission — not the vendor's terms — is what makes a disclosure authorized.

    Does Microsoft 365 Copilot's commercial data protection satisfy an NDA?

    No. Copilot's commercial data protection is a commitment from Microsoft to your organization about how prompts are handled. Your NDA is a commitment from your organization to your client about who may receive their information. Microsoft's promise cannot grant your client's consent.

    When is enterprise AI enough on its own?

    Three common cases: the input contains no client-confidential information; the client has authorized use of that specific AI system — which is compulsory in writing in a signed contract (an MSA or the NDA itself), with no conflicting clause between the NDA and MSA that would prevent the use; or your engagement terms expressly permit processing in approved third-party systems and the AI deployment meets those terms. Outside those cases, an enterprise licence reduces vendor risk without resolving the client obligation.

    What is the difference between a DPA, a BAA, and an NDA in this context?

    A DPA (data processing agreement) and a BAA (business associate agreement) govern how a vendor processes data you send it — they sit between you and the vendor and address privacy law. An NDA sits between you and your client and addresses confidentiality. A vendor-side DPA or BAA can make the vendor a compliant processor; it cannot make your transmission to that vendor an authorized disclosure under the client's NDA.

    How can consultants use AI without triggering the client-consent problem at all?

    By ensuring the model never receives the confidential values. If every confidential value is replaced with a semantic cloak on the consultant's own computer before the text is transmitted, no client-confidential information is disclosed to the AI vendor — so there is nothing for the client to consent to. That is an architectural resolution rather than a contractual one.

    This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary — review your own agreements with qualified counsel before relying on any framework described here.

    Work with AI on data you can't share with it.

    Untraceable cloaks confidential values on your computer before any AI model sees the text — the model never receives the secret at all.