The situation
A buy-side mandate is two weeks from signing. The virtual data room holds 300 customer contracts, an employee census with names and salaries, and a management forecast. A junior associate is asked for a change-of-control summary by morning. They download a batch of contracts, open ChatGPT on a personal account, and upload them with the request. The summary is good. The contracts, the forecast figures in the cover email, and the census tab they forgot to remove are now with a third party that is not a party to the NDA.
Nothing about this looks reckless to the associate. It looks like diligence done faster. For the firm, it raises three separate questions: the contract, securities law, and privacy law.
What the rules actually say
The NDA
Every NDA is different, so the answer starts with the one your client signed. Structurally, many confidentiality agreements do three things that matter here:
- Limit who may receive evaluation material, usually to named categories of Representatives such as directors, officers, employees and professional advisors, with the recipient responsible for their compliance.
- Limit use to evaluating or negotiating the transaction.
- Require return or destruction of the material if the deal does not proceed, often with a certificate.
A generative AI provider is rarely a listed Representative. Its terms may permit retention, sub-processing and, on some consumer accounts, model training, which can sit awkwardly with a use restriction and a destruction covenant. Some newer NDAs address AI tools expressly. If yours is silent, treat that as a question to raise, not a permission.
Securities law, when the target is public
In Ontario, section 76 of the Securities Act prohibits a person in a special relationship with an issuer from informing anyone of an undisclosed material fact or material change, other than in the necessary course of business. Subsection 76(3) applies a similar rule to a person considering a take-over bid or merger, and the definition of special relationship in subsection 76(5) reaches advisors engaged in professional activity for those parties.
National Policy 51-201 describes necessary course of business as a mixed question of law and fact, and lists legal counsel, financial advisors and parties to negotiations as the kinds of recipients it generally covers. It also states that a confidentiality agreement does not create a separate exception. We are not aware of regulator guidance on whether submitting undisclosed information to an AI service counts as informing another person. That uncertainty is the reason to keep it out of unvetted tools and to ask securities counsel before relying on any tool.
Privacy law
Data rooms often contain personal information. PIPEDA section 7.2 allows parties to a prospective business transaction to share it without consent only if the recipient has agreed to use it solely for purposes related to the transaction, to protect it with safeguards suited to its sensitivity, and to return or destroy it if the deal does not proceed. Quebec's private sector act has a comparable rule in section 18.4. Uploading an employee census to a personal AI account is hard to square with those promises. See our PIPEDA overview.
For lawyers, all of this sits on top of the professional duty of confidentiality covered in our guide to what the Law Society of Ontario says about generative AI.
Why policies and bans fall short
Deal work runs on deadlines, and the associate at midnight is not rereading the NDA. Data room controls such as watermarks and download limits govern the data room, not what happens after a document is opened on a laptop with a browser tab next to it. A firm-wide ban on AI tools pushes the same work into personal accounts, where the firm sees nothing. LayerX reported in 2025 that 71% of generative AI connections use personal, non-corporate accounts.
The disclosure is also irreversible. Once evaluation material is submitted, it cannot be recalled, and the firm may have to tell the disclosing party under the NDA's notice clause. Buyers are asking the same question of their targets, as our post on AI controls in technical diligence explains.
What a practical control looks like
- Read every NDA for AI. Check the Representatives definition, the use restriction, the destruction clause, and any AI language. When your client is the disclosing party, consider proposing an express AI clause.
- Name the sanctioned tool. Decide which AI tool may process evaluation material, under which contract terms on retention, training and confidentiality, and confirm it can honour a destruction obligation.
- Classify deal data. Undisclosed material facts, personal information from the data room, and customer contract terms should never go into an unapproved tool. Teach abstracted prompts that describe the clause, not the counterparty.
- Brief the deal team at kick-off. Five minutes on what the NDA and the privacy agreement allow, with the reason behind each rule.
- Set an incident path. If material reaches an unapproved tool, the deal lead is told the same day, the firm reviews the NDA notice clause, and a privacy assessment starts.
- Keep a record you can rely on when you sign a destruction certificate or answer a client's questions.
Sanitized Ai is a browser extension that supports steps 3 to 6 at the moment of risk. When someone is about to submit deal terms, client names and identifiers, financial data or personal information to an AI assistant, it redacts or blocks the sensitive content before submission and explains in plain language what was flagged and why. That is education at the prompt, not a memo after the fact, and it keeps deal data from becoming subject to a provider's terms.
Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) without seeing prompt content. That record can help show the firm took reasonable safeguards when a client or disclosing party asks, though it is not a substitute for advice from securities or privacy counsel. See how it fits law firms.