Call Now
← Back to Blog
LABOR & EMPLOYMENT

Why Employee NDAs and ChatGPT Don’t Always Mix

Nadine Deeb, Esq.By Nadine Deeb, Esq. · Published June 5, 2026 · Updated July 2026
Split illustration of an employee non-disclosure agreement with a shield and padlock on one side and a glowing AI neural network labeled ChatGPT on the other, connected by a cracked red arrow symbolizing confidentiality risk

Employee NDAs were not written for a workplace where employees can paste sensitive information into a chatbot and get a polished answer seconds later. That is the problem.

Looking for the implementation side — the policy, training, and enforcement checklist? See our companion guide: Employee AI Use Policy & NDA: 2026 Checklist.

Generative AI tools like ChatGPT can help employees draft emails, summarize documents, brainstorm strategy, clean up code, analyze spreadsheets, and speed up routine work. But they also create a new confidentiality risk: employees may disclose company information to third-party AI systems without realizing they have done anything wrong.

An NDA may prohibit disclosure of confidential information. But if the company has no AI policy, no training, no approved tool list, and no rules for prompts, employees may not understand that entering customer data, source code, financials, contracts, HR information, business plans, or trade secrets into an AI tool may violate company policy, client obligations, or trade secret protections.

Bottom line: NDAs still matter, but they are not enough. Employers need AI-specific confidentiality rules.

Legal update note: This article is current as of July 2026 and provides general information for U.S. employers. Employee NDAs, confidentiality policies, AI-use policies, trade secret protections, labor-law rights, privacy rules, intellectual-property ownership, employment agreements, and vendor terms vary by jurisdiction, industry, tool, and facts. This article is not legal advice. Employers should consult counsel before implementing or enforcing NDA, AI, confidentiality, monitoring, data-use, or employee discipline policies.

Key Takeaways for Employers

  • An NDA does not equal an AI policy. Confidentiality language written before generative AI may not clearly prohibit prompt-based disclosures.
  • Prompt inputs can be disclosures. Employees may disclose trade secrets or confidential information by pasting them into AI tools.
  • Tool settings matter. Business and enterprise AI products may treat data differently than consumer tools, but employers must verify the terms and settings.
  • Trade secret protection requires reasonable measures. If employees freely upload trade secrets into unapproved tools, the company may weaken its position later.
  • Overbroad confidentiality rules can create labor-law risk. NDA and AI policies should not unlawfully restrict employees from discussing wages, benefits, or working conditions.
  • AI output creates separate IP risk. AI-generated text, code, images, inventions, or strategy may raise copyright, patent, ownership, and originality issues.
  • The fix is policy plus training. Employers need clear rules, approved tools, data classifications, prompt restrictions, and manager training.

Why a Standard Employee NDA May Not Be Enough

A traditional employee NDA usually says the employee cannot disclose or misuse confidential information. That is useful, but it may not answer modern AI questions like:

  • Can employees paste customer contracts into ChatGPT for summarization?
  • Can engineers paste proprietary source code into an AI coding assistant?
  • Can HR use AI to rewrite employee discipline notes?
  • Can sales teams upload customer lists to generate outreach copy?
  • Can finance employees use AI to analyze unreleased revenue numbers?
  • Can managers use AI to draft layoff communications?
  • Can employees use personal AI accounts for company work?
  • Can employees use AI output in company deliverables?

If the NDA does not address AI tools, employees may assume the answer is yes — especially if the company informally encourages AI productivity. The company may later say, “You disclosed confidential information.” The employee may respond, “No one told me using ChatGPT counted as disclosure.” That is why employers should update confidentiality programs for AI use.

What Counts as Confidential Information in an AI Prompt?

Employees may not realize how much sensitive information appears in everyday prompts. Examples may include customer names, client contracts, pricing terms, source code, product roadmaps, financial projections, board materials, investor updates, unreleased marketing plans, litigation strategy, employee discipline records, medical or leave information, payroll data, personal information, vendor terms, acquisition targets, trade secrets, internal policies, security procedures, and technical specifications.

Even a prompt that seems harmless can reveal sensitive context. For example:

“Summarize this customer complaint and draft a response explaining why our unreleased product feature failed during beta testing.”

That single prompt may disclose customer information, product problems, unreleased roadmap details, and internal strategy.

Trade Secret Risk: Reasonable Measures Matter

Trade secret protection depends in part on whether the company took reasonable steps to keep the information secret. If an employer allows employees to paste confidential code, formulas, customer lists, pricing strategy, or product plans into unapproved AI tools, the company may face hard questions later:

  • Was the information actually treated as secret?
  • Were employees trained not to disclose it?
  • Were AI tools approved or restricted?
  • Did the company monitor or enforce its policy?
  • Did the NDA mention AI tools?
  • Did the company classify confidential information?
  • Did vendor terms protect uploaded data?

The federal Defend Trade Secrets Act also contains an employee whistleblower-immunity framework, and employers who want to preserve certain remedies must provide notice of that immunity in contracts or agreements with employees that govern the use of trade secrets or confidential information. Congressional materials discussing the DTSA explain that the immunity covers certain disclosures to government officials or attorneys in connection with reporting or investigating suspected violations of law.

Employer takeaway: update NDA and confidentiality language carefully. Protect trade secrets without overreaching into legally protected disclosures.

If employees use AI, your NDA needs an AI checkup. We can review your NDAs, confidentiality agreements, employee handbook, AI-use policy, invention-assignment agreements, and vendor terms to help protect trade secrets and reduce AI disclosure risk.

Book an AI NDA Review →

Not All AI Tools Treat Data the Same Way

One reason employers struggle with ChatGPT policies is that “AI tool” is not one thing. Different products may have different rules for training on prompts, retaining data, deleting data, human review, enterprise controls, audit logs, account ownership, user permissions, shared links, workspace visibility, API data handling, data residency, security certifications, and contractual confidentiality.

OpenAI, for example, states in its business data privacy documentation that it does not train on organization data by default for products such as ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, and its API platform, and explains that business-data handling and training settings differ from consumer data-use settings. That is useful — but employers should not stop there. Terms, settings, and retention options should be verified for each product the company approves.

A policy should distinguish between:

  • approved enterprise tools;
  • approved API uses;
  • personal AI accounts;
  • free consumer tools;
  • browser extensions;
  • AI meeting assistants and note takers;
  • AI coding tools;
  • AI document-review tools;
  • AI image tools; and
  • unapproved third-party AI applications.

Practical rule: employees should not put confidential company, customer, employee, or client information into any AI tool unless the company has approved that tool for that category of data.

NDAs Cannot Ignore Employee Rights

Employers also need to be careful not to overcorrect. A confidentiality policy that says “employees may never discuss company information with anyone” can create labor-law problems.

The National Labor Relations Board explains that employees have the right to act together with co-workers about wages, benefits, and other terms and conditions of employment, and employers may not discipline, discharge, or threaten employees for protected concerted activity. That matters for NDAs and AI policies.

Employers can prohibit employees from uploading trade secrets, customer data, source code, personal information, and confidential business plans into AI tools. But policies should not be drafted so broadly that employees could reasonably read them to prohibit discussions about wages, schedules, harassment, discrimination, safety, benefits, or working conditions. A strong policy protects confidential business information while preserving employee rights — the same balancing act we cover in our article on social media monitoring policies.

New laws, before they catch you off guard.

Monthly. New Arizona, California, and Texas business-law changes, the deadlines attached to them, and what they mean in practice. No spam — unsubscribe anytime.

By subscribing you agree to receive emails from Accord & Shield Legal, PLLC. This is general information, not legal advice.

AI Output Creates Separate IP Issues

Confidentiality is only one piece of the problem. AI use can also raise intellectual-property issues.

Copyright

The U.S. Copyright Office has issued registration guidance addressing works containing AI-generated material. Its guidance emphasizes that copyright protection depends on human authorship and that applicants may need to disclose AI-generated material in registration applications.

For employers, this matters when employees use AI to create marketing copy, website content, software code, images, training materials, proposals, reports, product documentation, client deliverables, or internal templates. Employers should decide when AI-generated output can be used, how it must be reviewed, and whether disclosure or human editing is required.

Patent and Inventorship

The USPTO has issued inventorship guidance on AI-assisted inventions, emphasizing that AI systems are tools and that inventorship remains focused on human contributions under U.S. patent law. For companies developing products, software, processes, or technical inventions, employees should not assume AI use has no effect on invention records.

Employers should update invention-assignment procedures to capture whether AI tools were used, what prompts were entered, what outputs were generated, what human contributions were made, whether confidential information was used, and whether third-party tool terms affect ownership or confidentiality.

What an AI-Updated NDA Should Address

An updated NDA or confidentiality agreement should not simply say “do not use ChatGPT.” That may be too blunt, too narrow, or outdated quickly. Instead, employers should consider language addressing:

  • approved and prohibited AI tools;
  • confidential information in prompts;
  • customer and client data;
  • employee personal information;
  • trade secrets and source code;
  • business plans and financial information;
  • litigation or legal strategy;
  • healthcare, biometric, or other sensitive data;
  • use of personal AI accounts;
  • AI-generated output review;
  • ownership of work product and invention assignment;
  • reporting accidental disclosures;
  • preservation of employee whistleblower rights;
  • protected concerted activity carveouts;
  • return or deletion of information;
  • monitoring and audit rights; and
  • discipline for violations.

The agreement should be paired with an AI policy. The NDA creates obligations. The policy tells employees what to do day-to-day. And because a poorly drafted NDA can fail entirely, it is worth reviewing the NDA mistakes that make them unenforceable at the same time.

What an AI Use Policy Should Say

Employers should give employees practical rules they can follow. A good AI workplace policy should address at least these points.

1. Approved Tools

List which tools employees may use for work. If the company approves only enterprise accounts, say so. If personal accounts are prohibited, say so. If certain departments have approved tools and others do not, say so.

2. Prohibited Inputs

Tell employees what they may not enter into AI tools. Common prohibited inputs include trade secrets, source code, customer data, client documents, employee personal information, health or leave information, payroll data, financial projections, passwords or credentials, confidential contracts, unreleased product information, legal advice or litigation strategy, merger, acquisition, or financing materials, and regulated data.

3. Human Review

Require employees to review AI output before using it. AI output may be inaccurate, biased, incomplete, outdated, or inconsistent with company policy. Employees should not treat AI output as approved legal, HR, financial, technical, or business advice.

4. Client and Customer Restrictions

If the company handles client or customer data, the AI policy should address contractual restrictions. Some customer contracts may prohibit uploading customer information to third-party tools. Some clients may require consent before AI tools are used on their materials.

5. IP and Work Product

The policy should explain whether employees may use AI output in company work product and what review or disclosure is required.

6. Incident Reporting

Employees should know what to do if they accidentally paste confidential information into an unapproved AI tool. The policy should require prompt reporting to a designated person or team, such as Legal, HR, IT, or Security.

7. Discipline and Enforcement

The company should explain that violations may lead to discipline, but enforcement should be consistent and legally reviewed when protected activity may be involved.

Build a practical AI policy employees can actually follow. A one-sentence rule saying “do not disclose confidential information” is not enough for generative AI. We can help draft an AI-use policy, update employee NDAs, revise handbook language, and align confidentiality rules with trade secret, labor-law, IP, and vendor-risk requirements.

Draft an AI Workplace Policy →

Practical Examples for Employees

Policies work better when employees see examples.

Usually Lower Risk

Depending on the tool and company policy, lower-risk uses may include drafting a generic meeting agenda, brainstorming non-confidential blog topics, rewriting a public job posting, summarizing publicly available information, creating a generic checklist, improving grammar in non-confidential text, or drafting a template without company-specific details.

Higher Risk

Higher-risk uses may include uploading a customer contract, pasting source code, summarizing employee medical information, drafting discipline based on personnel records, analyzing unreleased financial results, pasting board materials, entering litigation strategy, uploading a client’s confidential documents, using AI to screen applicants without review, or creating customer deliverables from AI output without human review. (Using AI in hiring carries its own regulatory obligations — see our guide to AI hiring rules in California and Texas.)

Red Flags That Your NDA Is Outdated

Your NDA or confidentiality program may need updating if:

  • it does not mention AI tools;
  • employees use personal AI accounts for work;
  • managers encourage AI use without policy guidance;
  • source code or customer data is being pasted into AI tools;
  • the company has no approved-tool list;
  • employees do not know whether prompts are confidential;
  • vendor terms have not been reviewed;
  • there is no incident reporting process;
  • invention-assignment agreements do not address AI-assisted work;
  • confidentiality language lacks DTSA whistleblower-immunity notice language;
  • policies do not preserve employee rights to discuss working conditions; or
  • no one owns AI governance internally.

Employer Checklist: Fixing the NDA / ChatGPT Gap

Employers should consider these steps.

1. Inventory AI Use

Find out what tools employees actually use — ChatGPT, Claude, Gemini, Microsoft Copilot, GitHub Copilot, AI note takers, transcription tools, design tools, HR tools, sales tools, browser extensions, and personal AI accounts.

2. Classify Data

Identify which data may never be entered into AI tools, which data may be used only in approved enterprise tools, and which data is safe for general productivity use.

3. Review Vendor Terms

Before approving a tool, review training use, retention, deletion, confidentiality, security, audit rights, data location, access controls, user permissions, incident response, indemnity, IP terms, and contract termination rights.

4. Update NDAs and Confidentiality Agreements

Add AI-specific language while preserving trade secret whistleblower immunity and employee labor-law rights.

5. Update the Employee Handbook

Add or revise policies on AI use, confidentiality, data security, acceptable use, intellectual property, invention assignment, workplace monitoring, discipline, incident reporting, and protected employee rights.

6. Train Employees and Managers

Training should explain what tools are approved, what data is prohibited, how prompts can disclose confidential information, how to review AI output, when to escalate questions, what to do after accidental disclosure, and what rights employees still have.

Final Takeaway

Employee NDAs still matter. But they were not designed to carry the entire weight of workplace AI governance. Generative AI creates new ways for employees to disclose confidential information, weaken trade secret protections, create IP uncertainty, and trigger labor-law or privacy issues. Most employees are not trying to cause harm. They are trying to work faster.

That is why employers need clear rules. A strong AI confidentiality program should include updated NDAs, trade secret protections, DTSA notice language where appropriate, labor-law carveouts, approved AI tool lists, prohibited-input rules, vendor-term review, data classification, employee training, incident reporting, and human review of AI output.

Do not wait for an accidental prompt disclosure to find out your NDA is outdated.

Protect confidential information before it enters the prompt.

If employees are using AI tools, your confidentiality program needs to catch up.

Book an AI NDA Review

This article is general information from Accord & Shield Legal, PLLC and is not legal advice. Reading it does not create an attorney-client relationship. For guidance on your specific situation, please consult a qualified attorney.

Frequently Asked Questions About Employee NDAs and ChatGPT

Can employees put confidential information into ChatGPT?

Not unless the employer has approved the tool and the category of information for that use. Employees should not enter trade secrets, customer data, employee personal information, source code, or confidential business information into unapproved AI tools.

Does an employee NDA automatically prohibit ChatGPT use?

Not always clearly. An NDA may prohibit disclosure of confidential information, but it may not explain whether AI prompts count as disclosures or which tools are approved. Employers should update NDAs and policies for AI use.

Is ChatGPT Business or Enterprise safer than a personal account?

Business and enterprise tools may offer stronger data controls than personal accounts. OpenAI states that it does not train on organization data by default for certain business and enterprise products. Employers should still review the specific product terms, settings, retention options, and data controls.

Can employees use AI to summarize customer contracts?

Only if company policy, customer contracts, confidentiality obligations, and vendor terms allow it. Many employers should prohibit uploading customer contracts to unapproved AI tools.

Can employers ban all AI use?

Employers can restrict workplace use of AI tools, but a total ban may be hard to enforce if employees already use AI informally. Many employers prefer an approved-use policy that distinguishes low-risk uses from prohibited inputs.

Do AI policies need labor-law carveouts?

Yes. Confidentiality and AI policies should not be drafted so broadly that employees could reasonably read them to prohibit protected discussions about wages, benefits, or working conditions.

Do AI tools create copyright issues?

Yes. AI-generated content may raise copyright and authorship questions. Employers should require human review and decide when AI-generated material may be used in company work product.

What should employers do first?

Start by inventorying AI tools, identifying high-risk data, reviewing vendor terms, updating NDAs and policies, and training employees on what they can and cannot put into AI prompts.

Let’s Talk

Protecting Your Confidential Information?

We’ll help you put the right NDAs and policies in place. Let’s talk.