M&A boutiques, corporate law firms and deal advisors

M&A boutiques: can the deal team put data room documents and diligence summaries into AI?

Sources verified Sanitized Ai Team

The short answer

Only into a tool the firm has vetted, and only if the NDA, the client and the law allow it. Evaluation material is usually shared under an NDA that limits who may receive it and what it may be used for, personal information in the data room is often shared under a privacy law exception tied to the transaction, and a public company deal may involve undisclosed material facts. Pasting that material into a personal AI account can fall outside all three.

The situation

A buy-side mandate is two weeks from signing. The virtual data room holds 300 customer contracts, an employee census with names and salaries, and a management forecast. A junior associate is asked for a change-of-control summary by morning. They download a batch of contracts, open ChatGPT on a personal account, and upload them with the request. The summary is good. The contracts, the forecast figures in the cover email, and the census tab they forgot to remove are now with a third party that is not a party to the NDA.

Nothing about this looks reckless to the associate. It looks like diligence done faster. For the firm, it raises three separate questions: the contract, securities law, and privacy law.

What the rules actually say

The NDA

Every NDA is different, so the answer starts with the one your client signed. Structurally, many confidentiality agreements do three things that matter here:

  • Limit who may receive evaluation material, usually to named categories of Representatives such as directors, officers, employees and professional advisors, with the recipient responsible for their compliance.
  • Limit use to evaluating or negotiating the transaction.
  • Require return or destruction of the material if the deal does not proceed, often with a certificate.

A generative AI provider is rarely a listed Representative. Its terms may permit retention, sub-processing and, on some consumer accounts, model training, which can sit awkwardly with a use restriction and a destruction covenant. Some newer NDAs address AI tools expressly. If yours is silent, treat that as a question to raise, not a permission.

Securities law, when the target is public

In Ontario, section 76 of the Securities Act prohibits a person in a special relationship with an issuer from informing anyone of an undisclosed material fact or material change, other than in the necessary course of business. Subsection 76(3) applies a similar rule to a person considering a take-over bid or merger, and the definition of special relationship in subsection 76(5) reaches advisors engaged in professional activity for those parties.

National Policy 51-201 describes necessary course of business as a mixed question of law and fact, and lists legal counsel, financial advisors and parties to negotiations as the kinds of recipients it generally covers. It also states that a confidentiality agreement does not create a separate exception. We are not aware of regulator guidance on whether submitting undisclosed information to an AI service counts as informing another person. That uncertainty is the reason to keep it out of unvetted tools and to ask securities counsel before relying on any tool.

Privacy law

Data rooms often contain personal information. PIPEDA section 7.2 allows parties to a prospective business transaction to share it without consent only if the recipient has agreed to use it solely for purposes related to the transaction, to protect it with safeguards suited to its sensitivity, and to return or destroy it if the deal does not proceed. Quebec's private sector act has a comparable rule in section 18.4. Uploading an employee census to a personal AI account is hard to square with those promises. See our PIPEDA overview.

For lawyers, all of this sits on top of the professional duty of confidentiality covered in our guide to what the Law Society of Ontario says about generative AI.

Why policies and bans fall short

Deal work runs on deadlines, and the associate at midnight is not rereading the NDA. Data room controls such as watermarks and download limits govern the data room, not what happens after a document is opened on a laptop with a browser tab next to it. A firm-wide ban on AI tools pushes the same work into personal accounts, where the firm sees nothing. LayerX reported in 2025 that 71% of generative AI connections use personal, non-corporate accounts.

The disclosure is also irreversible. Once evaluation material is submitted, it cannot be recalled, and the firm may have to tell the disclosing party under the NDA's notice clause. Buyers are asking the same question of their targets, as our post on AI controls in technical diligence explains.

What a practical control looks like

  1. Read every NDA for AI. Check the Representatives definition, the use restriction, the destruction clause, and any AI language. When your client is the disclosing party, consider proposing an express AI clause.
  2. Name the sanctioned tool. Decide which AI tool may process evaluation material, under which contract terms on retention, training and confidentiality, and confirm it can honour a destruction obligation.
  3. Classify deal data. Undisclosed material facts, personal information from the data room, and customer contract terms should never go into an unapproved tool. Teach abstracted prompts that describe the clause, not the counterparty.
  4. Brief the deal team at kick-off. Five minutes on what the NDA and the privacy agreement allow, with the reason behind each rule.
  5. Set an incident path. If material reaches an unapproved tool, the deal lead is told the same day, the firm reviews the NDA notice clause, and a privacy assessment starts.
  6. Keep a record you can rely on when you sign a destruction certificate or answer a client's questions.

Sanitized Ai is a browser extension that supports steps 3 to 6 at the moment of risk. When someone is about to submit deal terms, client names and identifiers, financial data or personal information to an AI assistant, it redacts or blocks the sensitive content before submission and explains in plain language what was flagged and why. That is education at the prompt, not a memo after the fact, and it keeps deal data from becoming subject to a provider's terms.

Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without seeing prompt content. That record can help show the firm took reasonable safeguards when a client or disclosing party asks, though it is not a substitute for advice from securities or privacy counsel. See how it fits law firms.

Frequently asked questions

Is an AI provider one of our Representatives under a typical NDA?

Usually not by name. Many NDAs define Representatives as directors, officers, employees, and professional advisors or financing sources, and require that each recipient be told about the NDA and be bound by confidentiality. Read the definition in your actual agreement, and ask the disclosing party if it is silent on AI tools.

If the AI tool promises confidentiality, does that settle the securities question?

No. National Policy 51-201 states that there is no exception to the tipping prohibition for disclosures made under a confidentiality agreement. The only exception is disclosure in the necessary course of business, which is a question of law and fact for each case. Ask securities counsel before any undisclosed material fact goes into an AI tool.

Can we use the AI features built into our virtual data room?

Possibly. The questions are the same: what the provider's terms allow it to do with the content, whether the disclosing party has agreed to that use, and whether it fits the NDA and the privacy agreement. A built-in feature is not automatically inside the NDA.

Does this apply to the sell side as well?

Yes. Sell-side teams hold the client's own confidential information, and often personal information about employees and customers, while they build the data room and draft disclosure schedules. The duty of confidentiality to the client applies to every tool that material passes through.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading