For many companies, non-disclosure agreements have become routine. The core terms are often familiar: define confidential information, limit use and disclosure, require reasonable safeguards, and return or destroy materials when the relationship ends. While the details still matter, the basic framework for NDAs has remained fairly consistent for years.
What has changed is the way confidential information is created, stored, and shared. As businesses increasingly rely on cloud platforms, remote work environments, collaboration tools, and artificial intelligence technologies, companies are paying closer attention to issues such as unauthorized uploads of confidential information to AI tools, use of personal devices and email accounts, cybersecurity obligations, access controls, and incident reporting requirements. As a result, many modern NDAs retain the traditional confidentiality framework while adding provisions designed to address evolving technology and data-security risks.
AI Provisions in Unexpected Places
Artificial intelligence is one of the most significant drivers of this shift. Increasingly, companies are seeing NDA provisions that address whether confidential information may be used with AI tools, machine learning systems, or automated analytics platforms. In some cases, these provisions are obvious. In others, they may be embedded in broader language about data processing, service providers, model improvement, aggregated data, or “training” rights.
These clauses can have significant ramifications. If not carefully reviewed, a company may inadvertently permit its sensitive business information, product plans, customer data, technical materials, or other confidential information to be used to train or improve AI systems. Even where the NDA is otherwise standard, AI-related language can affect how information is stored, processed, reused, and potentially exposed.
What Companies Should Watch For
Companies should pay particular attention to provisions that permit a recipient to use confidential information for product improvement, analytics, benchmarking, model development, or training purposes. The issue is not always whether AI tools can be used at all. In many cases, AI tools are useful and appropriate. The key question is whether the NDA clearly limits how confidential information may be used, whether it may be incorporated into any model or training dataset, and whether the disclosing party retains appropriate control over its information.
A well-drafted NDA should address these issues directly. Depending on the circumstances, companies may want explicit language prohibiting the use of confidential information to train public or generalized AI models, restricting disclosure to AI vendors unless appropriate safeguards are in place, and confirming that confidential information may only be used for the specific business purpose contemplated by the NDA.
As AI tools become more integrated into everyday business workflows, NDA review should evolve as well. Companies should not assume that traditional confidentiality provisions adequately address AI-related risks.
Foundry Law Group helps startups, technology companies, and growing businesses navigate these changing contract risks. If your company is reviewing NDAs or updating its form confidentiality agreements for AI-related issues, we can help identify the key provisions to watch for and tailor language that protects your business.