NDA and AI Contractors: What Founders Must Include in the Agreement

NDA and AI Contractors: What Founders Must Include in the Agreement

8/6/202617 views5 min read

TL;DR

  • Standard NDAs must be supplemented with clauses prohibiting the use of company data for retraining general models.
  • Ownership of AI-generated code and algorithms must belong exclusively to the client, without any vendor lock-in.
  • Explicitly define data deletion requirements post-contract and liability for leaks via third-party AI platforms.

When engaging external experts for AI implementation, a standard Non-Disclosure Agreement (NDA) often fails to protect your interests. In the AI landscape, your data isn't just rows in a CRM; it is the fuel for models that might "accidentally" learn from your trade secrets and leak them to competitors.

Where the Risk Hides in AI Projects

Business owners are used to NDAs protecting them from a developer leaking project details to third parties. AI introduces a new risk: the contractor might use your live data to train their agents or test prompts in public chatbots.

If your customer databases or financial reports end up in a public model's "training set," extracting them becomes impossible. This creates serious legal risks of AI in business that must be addressed before signing the acceptance certificate.

Definition: LLM Training — the process where a neural network uses input data to improve its future responses. Without proper privacy settings, your data becomes part of the model's knowledge base, accessible to other users.

Checklist: What to Change in Your AI Contractor Agreement

Don't rely on verbal assurances of "working securely." Verify these 5 points:

  1. Training Prohibition (Opt-out): The contractor must use only API configurations where data is not used for vendor model training (e.g., OpenAI API instead of the free version of ChatGPT).
  2. Ownership of Prompts: The text commands that drive the AI are your intellectual property. They are the "recipe" for your automation.
  3. Data Anonymization: A requirement to use de-identified data during development and testing. No real customer databases should exist in the test environment.
  4. No Vendor Lock-in: Automation code and settings must reside in your cloud environment, not the contractor's account. You must be able to terminate the relationship and continue operations independently.
  5. Direct Liability for Sub-processors: AI contractors often use third-party services (Make, Zapier, Pinecone). They must guarantee these services also meet your security standards.

How is Intellectual Property Allocated?

A common trap occurs when a contractor claims that because the AI wrote the code, it is "unowned" or "belongs to the developer." For a founder, this is a liability. You are paying to acquire an asset. The contract must state that any work product (Human-written or AI-generated) is transferred to you in full.

It is also critical to understand how to prevent data leaks in ChatGPT if the contractor's team uses it for scripting. The owner should demand the use of corporate accounts with enhanced security.

| Security Parameter | Standard IT Contract | AI-Specific Contract | | :--- | :--- | :--- | | Data | Prohibition of transfer to 3rd parties | Prohibition of use for model training | | Tools | Use of licensed software | List of permitted/prohibited AI services | | Deliverable | Program code | Code + Prompts + Trained weights (if applicable) | | Post-Project | Return of property | Total deletion of data from AI request history |

Definition: Prompt Engineering — the process of creating specific instructions for AI. In a business context, this is an intellectual asset, as the accuracy of your automation depends entirely on the quality of the prompt.

How this works on our side: We understand founders' security concerns; therefore, all code and created automations are the property of the company; they run on the client's tools with no vendor lock-in. For sensitive processes during training, test or anonymized data is used, and an NDA is provided upon request. Every participant in our program personally launches their first micro-automation, understanding exactly where the data is stored. https://course.aiadvisoryboard.me/corporate?utm_source=blog&utm_medium=article_body&utm_campaign=corporate

FAQ

Can I use a standard NDA for AI projects?

You can, but it won't protect you from the primary risk — your data becoming part of a general AI model. Standard agreements typically don't account for the technical nuances of neural networks, so they must be supplemented with API security clauses.

Who owns the code if it was written by AI?

Under many jurisdictions, intellectual property arises from human creative effort. However, in your contractor agreement, you can explicitly state that all economic rights to any result (regardless of the method of creation) transfer to your company upon payment.

How do I verify that a contractor actually deleted my data?

You can request written confirmation or screenshots of deleted dialogue history. However, it is more reliable to structure the work so that data remains within your corporate accounts, to which the contractor has only temporary guest access.

Conclusion

AI security isn't about trust; it's about access architecture and clear legal language. Ensure your contractor doesn't just "know AI," but understands the difference between a public chat and a secure integration.

Tomorrow morning, ask your legal counsel or CTO: "In whose cloud and on whose accounts will our automations live after we settle the final invoice?" If the answer is "theirs" — change the terms immediately.

For companies

Your company's first 3 AI automations — in 2 weeks

A corporate AI-transition program: 4 live sessions with your team plus a video course for every employee. Up to 20 people for one fixed price. If it doesn't work — money back.

Working automations in 2 weeks
Up to 20 employees, one price
Money-back guarantee
See the program & priceIt's the program page, not a checkout — a 2-minute read
Newsletter

New case studies on AI adoption — in your inbox

Once a week: practical breakdowns of what companies automate with AI and what actually comes out of it.

No spam. Unsubscribe anytime.