
NDA and AI Contractors: What Founders Must Include in the Agreement
TL;DR
- •Standard NDAs must be supplemented with clauses prohibiting the use of company data for retraining general models.
- •Ownership of AI-generated code and algorithms must belong exclusively to the client, without any vendor lock-in.
- •Explicitly define data deletion requirements post-contract and liability for leaks via third-party AI platforms.
When engaging external experts for AI implementation, a standard Non-Disclosure Agreement (NDA) often fails to protect your interests. In the AI landscape, your data isn't just rows in a CRM; it is the fuel for models that might "accidentally" learn from your trade secrets and leak them to competitors.
Where the Risk Hides in AI Projects
Business owners are used to NDAs protecting them from a developer leaking project details to third parties. AI introduces a new risk: the contractor might use your live data to train their agents or test prompts in public chatbots.
If your customer databases or financial reports end up in a public model's "training set," extracting them becomes impossible. This creates serious legal risks of AI in business that must be addressed before signing the acceptance certificate.
Definition: LLM Training — the process where a neural network uses input data to improve its future responses. Without proper privacy settings, your data becomes part of the model's knowledge base, accessible to other users.
Checklist: What to Change in Your AI Contractor Agreement
Don't rely on verbal assurances of "working securely." Verify these 5 points:
- ✅ Training Prohibition (Opt-out): The contractor must use only API configurations where data is not used for vendor model training (e.g., OpenAI API instead of the free version of ChatGPT).
- ✅ Ownership of Prompts: The text commands that drive the AI are your intellectual property. They are the "recipe" for your automation.
- ✅ Data Anonymization: A requirement to use de-identified data during development and testing. No real customer databases should exist in the test environment.
- ✅ No Vendor Lock-in: Automation code and settings must reside in your cloud environment, not the contractor's account. You must be able to terminate the relationship and continue operations independently.
- ✅ Direct Liability for Sub-processors: AI contractors often use third-party services (Make, Zapier, Pinecone). They must guarantee these services also meet your security standards.
How is Intellectual Property Allocated?
A common trap occurs when a contractor claims that because the AI wrote the code, it is "unowned" or "belongs to the developer." For a founder, this is a liability. You are paying to acquire an asset. The contract must state that any work product (Human-written or AI-generated) is transferred to you in full.
It is also critical to understand how to prevent data leaks in ChatGPT if the contractor's team uses it for scripting. The owner should demand the use of corporate accounts with enhanced security.
| Security Parameter | Standard IT Contract | AI-Specific Contract |
|---|---|---|
| Data | Prohibition of transfer to 3rd parties | Prohibition of use for model training |
| Tools | Use of licensed software | List of permitted/prohibited AI services |
| Deliverable | Program code | Code + Prompts + Trained weights (if applicable) |
| Post-Project | Return of property | Total deletion of data from AI request history |
Definition: Prompt Engineering — the process of creating specific instructions for AI. In a business context, this is an intellectual asset, as the accuracy of your automation depends entirely on the quality of the prompt.
How this works on our side: We understand founders' security concerns; therefore, all code and created automations are the property of the company; they run on the client's tools with no vendor lock-in. For sensitive processes during training, test or anonymized data is used, and an NDA is provided upon request. Every participant in our program personally launches their first micro-automation, understanding exactly where the data is stored. https://course.aiadvisoryboard.me/corporate?utm_source=blog&utm_medium=article_body&utm_campaign=corporate
FAQ
Can I use a standard NDA for AI projects?
You can, but it won't protect you from the primary risk — your data becoming part of a general AI model. Standard agreements typically don't account for the technical nuances of neural networks, so they must be supplemented with API security clauses.
Who owns the code if it was written by AI?
Under many jurisdictions, intellectual property arises from human creative effort. However, in your contractor agreement, you can explicitly state that all economic rights to any result (regardless of the method of creation) transfer to your company upon payment.
How do I verify that a contractor actually deleted my data?
You can request written confirmation or screenshots of deleted dialogue history. However, it is more reliable to structure the work so that data remains within your corporate accounts, to which the contractor has only temporary guest access.
Conclusion
AI security isn't about trust; it's about access architecture and clear legal language. Ensure your contractor doesn't just "know AI," but understands the difference between a public chat and a secure integration.
Tomorrow morning, ask your legal counsel or CTO: "In whose cloud and on whose accounts will our automations live after we settle the final invoice?" If the answer is "theirs" — change the terms immediately.
Read with AI
Open this article in your assistant — it will summarize it and help apply it to your company.
Show the prompt
Read the article https://aiadvisoryboard.me/blog/nda-ai-contractor-clauses-founder-guide.md and summarize the key points. Then ask me about my company (industry, team size, what takes the most time) and explain which ideas from the article apply to us and where to start.

Implements AI agents in companies and teaches founders and their teams to work with them — through courses and corporate programs.
This article was prepared with AI assistance, based on Yaroslav Maxymovych's methodology and materials. Spotted an inaccuracy — let us know via the form below.
Your company's first 3 AI automations — in 2 weeks
A corporate AI-transition program: 4 live sessions with your team plus a video course for every employee. Up to 20 people for one fixed price. If it doesn't work — money back.
New case studies on AI adoption — in your inbox
Once a week: practical breakdowns of what companies automate with AI and what actually comes out of it.
No spam. Unsubscribe anytime.
Related Articles

The Founder's Weekly Ritual That Keeps AI Adoption Alive
Without weekly oversight, even successful AI adoption fades into routine. Founders can sustain momentum with just 15 minutes per week—tracking three simple metrics and defining one new automation…
Read more
Company AI Usage Policy: What It Should Include and How to Implement It
How to create an AI usage policy for your company: what to include, how to prevent data leaks, who is responsible, and how to implement it without consultants. Practical steps for business owners.
Read more
AI in Marketing for a 3-Person Team: First Steps and What to Delegate
Learn how to successfully implement AI in marketing for a 3-person team. First steps, delegation strategies, and measuring impact.
Read more