Call Now
← Back to Blog
LABOR & EMPLOYMENT

Employee NDAs and AI Tools in 2026: What California Employers Need to Know

Nadine Deeb, Esq.By Nadine Deeb, Esq. · Published June 29, 2026 · Updated August 6, 2026 · Last legally reviewed August 6, 2026
Employee NDAs and AI tools — the 2026 employer compliance challenge

An employee is trying to move fast. A customer proposal is due by noon, a code issue needs troubleshooting, a manager wants a first draft of a termination memo, and a spreadsheet contains customer names, pricing, margins, and vendor terms. So the employee opens an AI tool and pastes in the information. No one meant to leak confidential information, waive trade-secret protection, or create a privacy problem — but that is exactly why employee NDAs need an AI-era refresh. In 2026, employers cannot treat confidentiality agreements as static paperwork signed on an employee’s first day. Generative AI tools, automated decision systems, chatbots, and AI-powered workplace software have changed how employees create, process, upload, and reuse information. A modern NDA should protect confidential information and trade secrets — but it must also avoid overreaching into unlawful noncompete territory, protected wage discussions, whistleblowing, labor rights, privacy rights, and AI-specific compliance obligations.

Key takeaways

  • AI has created new confidentiality risks that most existing NDAs never contemplated.
  • California NDAs must stay narrow and lawful — no de facto noncompetes, wage-discussion bans, or whistleblower blocks.
  • New 2026 rules (CPPA ADMT regulations, AB 2013) affect how AI touches employee and consumer data.
  • The fix is a coordinated set of NDA, AI-use policy, handbook, and vendor-review updates — not just adding “AI” to an old template.

Why AI Changes the NDA Conversation

Traditional employee NDAs were designed around familiar risks: an employee downloads a customer list, shares pricing with a competitor, copies source code, or discloses business plans after leaving. AI creates new risks. Employees may paste confidential information into public AI tools; AI vendors may store, process, or reuse prompts and outputs; confidential customer data may be uploaded without approval; trade secrets may be mixed into AI-generated summaries or code; AI outputs may include inaccurate, biased, or infringing content; managers may use AI tools for employment decisions without oversight; and company policies may restrict too much and violate employee rights. The result is a new legal challenge: employers need stronger confidentiality controls without drafting policies so broadly that they become unenforceable or unlawful.

Legal Framework: Employee NDAs Must Be Narrow, Lawful, and Practical

An employee NDA can protect legitimate business interests, including confidential information and trade secrets. But it cannot do everything.

1. California limits restraints on employee mobility. Business and Professions Code section 16600 provides that, except as provided in that chapter, every contract by which anyone is restrained from engaging in a lawful profession, trade or business of any kind is void to the extent of the restraint. In the employment context, the section directs courts to read that rule broadly and to void a noncompete provision “no matter how narrowly tailored” unless it satisfies an exception in the chapter. This matters because some confidentiality agreements are drafted so broadly that they function like a noncompete — for example, a clause preventing an employee from using general skills, experience, industry knowledge, or publicly available information after employment. Confidentiality clauses should protect true confidential information and trade secrets, not attempt to stop employees from working in their field.

2. NDAs cannot block lawful whistleblowing. Labor Code section 1102.5 prohibits an employer from making, adopting or enforcing a rule, regulation or policy that prevents an employee from disclosing information to a government or law-enforcement agency, to a person with authority over the employee, or to another employee with authority to investigate, discover or correct the violation or noncompliance. It also protects providing information to or testifying before a public body when the employee has reasonable cause to believe the information discloses a violation of law, regardless of whether making the disclosure is part of the employee’s job duties. An employee NDA should include clear carveouts for protected disclosures, whistleblowing, and legally protected reporting.

3. NDAs cannot prohibit wage discussions. Labor Code section 232 prohibits employers from requiring employees, as a condition of employment, to refrain from disclosing their wages; requiring an employee to sign a waiver or other document that purports to deny that right; or discharging, disciplining or otherwise discriminating against an employee for disclosing wages. A confidentiality agreement that defines compensation, wage information, or payroll discussions too broadly can create risk. Do not use an NDA to stop employees from discussing their own wages or exercising protected workplace rights.

4. Trade-secret agreements should include DTSA notice language. The federal Defend Trade Secrets Act includes a whistleblower-immunity notice provision. Under 18 U.S.C. section 1833(b), employers must provide notice of immunity in any agreement with an employee, contractor, or consultant that governs the use of trade secrets or confidential information, and the statute permits compliance by cross-reference to a policy document. The notice matters because, if an employer does not provide it, the employer may not recover exemplary damages or attorney fees under the DTSA in an action against that employee, contractor or consultant. The notice requirement applies to covered agreements entered into or updated after May 11, 2016. Employee NDAs, confidentiality agreements, contractor agreements, invention-assignment agreements, and AI-use policies should all be reviewed for DTSA notice compliance.

When did your employee NDA last get reviewed? If it predates ChatGPT and Copilot in your workplace, it may not cover how your team actually works. We can update it.

Book a Free Consultation →

How Laws Are Changing in 2026

The legal environment around AI, data, and employee information is moving quickly. Employers should not wait until a data leak, employee complaint, or customer audit to update policies.

California privacy and automated-decisionmaking rules. The California Privacy Protection Agency’s regulations covering CCPA updates, cybersecurity audits, risk assessments, and automated decisionmaking technology (ADMT) became effective January 1, 2026. Among other things, they implement consumers’ rights to access, and to opt out of, a business’s use of ADMT. Under those regulations, a consumer may have access and opt-out rights when a business uses ADMT for a significant decision, including in employment-related contexts, depending on the circumstances. If an employer uses AI or automated tools for hiring, promotion, discipline, productivity scoring, scheduling, compensation, or termination, it should review privacy notices, vendor contracts, employee disclosures, risk assessments, and internal controls.

California generative-AI training-data transparency. AB 2013 requires covered developers, on or before January 1, 2026 and before each subsequent public release of a covered generative-AI system or service or a substantial modification to it, to post specified documentation about the data used to train the system or service. Employers that develop or deploy generative AI should understand whether they are merely using third-party tools or developing covered systems — because employees may be placing company data into tools whose training-data, retention, and output practices affect confidentiality and compliance risk.

California AI Transparency Act. SB 942, the California AI Transparency Act, became operative on August 2, 2026, after AB 853 delayed the original January 1, 2026 operative date. The Act requires specified disclosure features for covered AI-generated image, video and audio content, including manifest and latent disclosures, and requires covered large generative-AI providers to offer a free AI-detection tool. Additional obligations for large online platforms begin in 2027. Even a business that is not itself a covered AI developer should have internal review rules for employees who create AI-generated images, video, audio, marketing, recruiting content, or public communications.

Companion-chatbot and AI-disclosure developments. California SB 243, approved in 2025, addresses companion chatbots and includes disclosure and minor-protection requirements. Businesses that deploy chatbots — especially consumer-facing, youth-facing, wellness, education, or companion-style tools — should monitor AI disclosure and safety obligations as part of a broader AI-governance program.

New laws, before they catch you off guard.

Monthly. New Arizona, California, and Texas business-law changes, the deadlines attached to them, and what they mean in practice. No spam — unsubscribe anytime.

By subscribing you agree to receive emails from Accord & Shield Legal, PLLC. This is general information, not legal advice.

Federal Enforcement Trends Employers Should Watch

AI does not excuse discrimination. Federal employment-discrimination laws, including Title VII and the ADA, apply when employers use AI systems in hiring and other workplace decisions. An AI screening or decision tool can create legal risk if its use results in unlawful disparate impact or disadvantages an applicant or employee because of disability without the employer satisfying its accommodation and other statutory obligations. An AI-use policy should not only restrict employee sharing of confidential information — it should also control how managers use AI in employment decisions.

Confidentiality rules can implicate labor rights. The National Labor Relations Board has scrutinized confidentiality and handbook rules that employees could reasonably read as restricting protected concerted activity. Employee NDAs and AI policies should avoid language that appears to prohibit employees from discussing working conditions, wages, workplace concerns, or protected concerted activity.

Noncompete enforcement has shifted at the federal level. The FTC finalized a nationwide Non-Compete Rule in 2024, but a federal court set the rule aside that August. The Commission later dismissed its appeals, and on February 12, 2026, removed the rule from the Code of Federal Regulations. The FTC’s Non-Compete Rule is not in effect and is not enforceable. Regardless of the federal picture, California employers must continue to comply with California’s strong restrictions on restraints of trade under Business and Professions Code section 16600.

What an AI-Era Employee NDA Should Cover

A modern employee NDA should be more than a generic confidentiality paragraph. It should work together with the company’s handbook, AI-use policy, information-security policy, invention-assignment agreement, BYOD policy, privacy notices, and vendor-management process.

1. Clear definition of confidential information. The NDA should define confidential information clearly and practically — customer and prospect lists, pricing and margin information, source code, product roadmaps, financial information, vendor terms, business strategy, nonpublic marketing plans, security credentials, internal policies, trade secrets, nonpublic customer data, and technical documentation. But the definition should not be so broad that it covers general skills, experience, publicly available information, wages, workplace complaints, or protected legal disclosures.

2. AI-specific restrictions. The NDA or AI-use policy should say whether employees may enter company information into AI tools and under what conditions — addressing public AI tools, company-approved AI tools, prompt content, uploading documents, customer data, source code, HR information, financial data, trade secrets, legal documents, confidential third-party information, AI-generated outputs, and review before external use.

3. Vendor-approved AI tools. Employers should distinguish between approved enterprise AI tools and unapproved public tools. Approval should consider vendor terms, retention practices, training-data use, security controls, audit rights, confidentiality, data-processing terms, privacy obligations, and access controls.

4. Human-review requirement. Employees should not treat AI output as automatically correct, legally safe, noninfringing, unbiased, or ready for customer use. A strong policy should require human review before AI output is used for customer communications, employment decisions, legal or compliance documents, financial statements, regulated advice, marketing claims, public content, code deployment, contract language, or reports involving confidential or personal information.

2026 Employee NDA and AI Policy Checklist

IssueWhat Employers Should Review
Confidential informationDoes the NDA clearly define protected information without overreaching?
Trade secretsDoes the agreement preserve trade-secret protection and include DTSA notice language?
AI toolsDoes the policy say which AI tools employees may use?
Prompt restrictionsAre employees barred from entering confidential, customer, HR, legal, or trade-secret information into unapproved AI tools?
Vendor reviewAre AI vendors reviewed for data retention, training use, confidentiality, and security?
Employee rightsDoes the NDA carve out whistleblowing, wage discussions, and protected activity?
Noncompete riskCould the confidentiality language operate like a restraint on employment?
Privacy noticesDo employee privacy notices address AI and automated decisionmaking where required?
ADMTAre AI tools used for significant employment decisions reviewed under CPPA rules?
IP ownershipDo agreements address AI-generated work product, employee-created materials, and company assets?
Output reviewIs human review required before using AI output externally or in employment decisions?
TrainingAre employees trained on what not to upload into AI tools?
Incident responseIs there a process if confidential information is accidentally entered into an AI tool?
Remote workDo policies address personal devices, browser extensions, plug-ins, and AI assistants?
Departing employeesAre exit procedures updated for AI accounts, downloads, prompts, and cloud tools?

The NDA Was Fine Until AI Changed the Workflow

A California company had a standard employee NDA. It protected customer lists, pricing, business plans, source code, and internal documents, and it had worked for years. Then employees started using AI tools. A sales employee pasted customer notes into a chatbot to draft a proposal. A developer used an AI coding assistant with proprietary code. A manager summarized performance reviews using an unapproved AI tool. A marketing employee generated public content based on confidential product plans. No one thought they were violating the NDA — the NDA never mentioned AI. The company discovered the issue only after a customer asked whether its data had been entered into third-party AI tools. Suddenly the company needed answers: Which tools were used? What data was uploaded? Did the vendor retain prompts? Were customer contracts violated? Was personal information involved? Could trade-secret protection be affected? The problem was not that the company lacked an NDA — it was that the NDA had not been updated for how employees actually work in 2026. The lesson: confidentiality protection must match the workflow.

How Accord & Shield Can Help

At Accord & Shield, we help businesses update employment, confidentiality, and technology policies for the AI era. Employers need to protect confidential information, trade secrets, customer data, source code, and intellectual property — but they also need policies that comply with California law and respect employee rights. We can help employers review and update employee NDAs; draft AI-use policies for employees and contractors; add DTSA whistleblower-immunity notice language; review confidentiality clauses for California noncompete risk; create carveouts for whistleblowing, wage discussions, and protected activity; update handbooks for AI and confidential-information controls; review vendor AI terms and data-processing risks; coordinate AI policies with privacy notices and CPPA obligations; develop manager rules for AI use in hiring, discipline, and termination; create incident-response procedures for accidental AI data disclosures; train teams on what not to upload into AI systems; and align contractor, consultant, and invention-assignment agreements with AI workflows. Our approach is practical — we do not simply add “AI” to an old confidentiality template. We look at how the business actually uses AI, where confidential information flows, what laws apply, and what policies employees can realistically follow. Our contracts and business formation practices support this work end to end. If your employees use ChatGPT, Claude, Gemini, Copilot, AI note-takers, AI recruiting tools, AI coding tools, or AI document systems, your NDA may already be outdated.

Frequently Asked Questions

Do employee NDAs need to mention AI tools?

In many cases, yes. If employees use generative AI, AI note-takers, AI coding tools, AI recruiting tools, or AI document platforms, the NDA or a related AI-use policy should explain what information may not be entered into AI systems and which tools are approved.

Can an employee enter confidential company information into ChatGPT or another AI tool?

Not unless the company has approved that use and reviewed the legal, privacy, confidentiality, and vendor-contract risks. Employers should create clear rules for public AI tools, enterprise AI tools, customer data, source code, HR information, and trade secrets.

Are employee NDAs enforceable in California?

Employee NDAs can be enforceable when properly drafted to protect legitimate confidential information and trade secrets. However, they should not function as unlawful noncompetes, restrict wage discussions, block whistleblowing, or interfere with protected employee rights.

What should a California employee NDA include in 2026?

A California employee NDA should include a clear definition of confidential information, trade-secret protections, DTSA notice language where appropriate, AI-use restrictions, employee-rights carveouts, return-of-property obligations, and provisions that avoid unlawful restraints on employment.

Can an NDA stop an employee from reporting illegal conduct?

No. California law protects certain whistleblower disclosures. NDAs should include carveouts for protected reporting to government agencies, law enforcement, regulators, and other legally protected channels.

Can an NDA prohibit employees from discussing wages?

No. California Labor Code section 232 protects employee wage discussions. Confidentiality agreements should not prohibit employees from disclosing or discussing their own wages.

What is the DTSA notice requirement?

The Defend Trade Secrets Act includes a whistleblower-immunity notice requirement for contracts with employees, contractors, or consultants that govern trade secrets or confidential information. Employers that fail to provide the notice may lose certain remedies in a DTSA action against that person.

How do California privacy rules affect workplace AI tools?

The CPPA's 2026 regulations address automated decisionmaking technology and related rights in certain contexts. Employers using AI for significant employment decisions should review privacy notices, vendor contracts, employee disclosures, risk assessments, and internal governance.

What are the biggest risks of employee AI use?

Major risks include confidential-information leakage, trade-secret exposure, customer-data misuse, inaccurate AI output, discrimination in employment decisions, intellectual-property issues, vendor data retention, and policies that unlawfully restrict employee rights.

How can Accord & Shield help with employee NDAs and AI policies?

Accord & Shield can review and update employee NDAs, draft AI-use policies, add lawful carveouts, protect trade secrets, review vendor terms, align policies with California law, and help employers create practical rules for employee use of AI tools.

This article is provided for general informational purposes only and does not constitute legal advice, employment advice, privacy advice, technology advice, or business advice. Reading this article or contacting Accord & Shield through this website does not create an attorney-client relationship. Laws governing employee confidentiality agreements, trade secrets, noncompetes, whistleblowing, labor rights, privacy, AI tools, automated decisionmaking, and workplace technology are changing quickly and may vary depending on the facts, industry, location, employer size, employee role, contract language, data involved, and tools used. You should consult qualified legal counsel before drafting, revising, enforcing, or relying on any employee NDA, confidentiality agreement, AI-use policy, handbook provision, trade-secret agreement, contractor agreement, or workplace technology policy. Accord & Shield does not guarantee any particular legal, business, employment, regulatory, dispute, or litigation outcome.

Let’s Talk

Need an NDA That Holds Up?

We’ll review the terms that actually matter — before you sign. Let’s talk.