AI (Artificial Intelligence)Camryn A. ConroyInsight

Before You Prompt: How AI Can Breach Your NDA

By October 1st, 2026No Comments

This article originally appeared as a Gavel to Gavel guest column in the Journal Record on September 30, 2026.

By Phillips Murrrah attorney Camryn A. Conroy

Camryn A. Conroy

Camryn A. Conroy

Artificial intelligence (AI) has transformed the legal profession. From drafting emails to summarizing complex documents, AI tools offer undeniable efficiency. But for individuals and businesses bound by nondisclosure agreements (NDAs), that convenience may create significant legal risk.

Entering confidential information into a public generative AI platform may constitute an unauthorized disclosure, and in many cases, a breach of an NDA, for three reasons.

First, most NDAs prohibit disclosure to third parties except on a need-to-know basis or as otherwise expressly permitted. Public AI platforms are operated by external companies. When a user enters confidential information into ChatGPT, Claude, Gemini, or a similar system, the information is transmitted outside the user’s organization and shared with a third-party service provider. Even if the disclosure is inadvertent or intended only to obtain assistance from the AI tool, the information has been provided to an entity that is not a party to the NDA.

Second, many NDAs require recipients of confidential information to return or destroy that information on request or upon termination of the parties’ relationship. After confidential information is submitted to a third-party AI platform, compliance with these obligations becomes difficult, if not impossible. Users generally cannot retrieve every copy of submitted information or certify its destruction. Some providers have historically used prompts to improve or train models, further complicating these obligations.

Third, AI providers are not parties to the NDA and are not bound by its confidentiality terms. An NDA requires the receiving party to protect information through agreed safeguards and restrictions. These protections do not automatically extend to AI vendors.

Recent litigation reinforces these concerns. In United States v. Heppner, Judge Rakoff of the Southern District of New York held that communications between a criminal defendant and Anthropic’s Claude were protected by neither attorney-client privilege nor the work-product doctrine. The court emphasized that the privilege exists between the client and their attorney, and that because Claude is not an attorney, communications with Claude could not fall under the purview of the privilege. Additionally, such communications were neither intended to be, nor in fact, kept confidential. The opinion further noted that Anthropic’s privacy policies authorized the collection and potential disclosure of user data, undermining any reasonable expectation of confidentiality.

While Heppner addressed privilege rather than NDAs specifically, the lesson is the same: information shared with a public AI chatbot is often treated as information shared with a third party and may not be afforded any reasonable expectation of confidential treatment. The Southern District of New York has signaled that users should not assume their AI conversations remain confidential.

The question is no longer whether AI can make you more productive. The question is whether using it could violate your confidentiality obligations. Before you type a single word, understand your NDA, read the platform’s privacy policy, and know exactly how the provider may store, use, share, or retain the information you enter.


About the author:

Camryn A. Conroy is an attorney at the law firm of Phillips Murrah who represents clients in a wide range of commercial and business matters.

CONTACT: caconroy@phillipsmurrah.com | 405.606.4735


Visit Phillips Murrah on social media:

Instagram Logo facebook Icon LinkedIn Logo Threads icon Twitter icon