
NDA for AI Vendors: What to Include in Your Contract
TL;DR
- •Even with a reputable vendor, you must sign a Non-Disclosure Agreement (NDA) specifically tailored to the nuances of AI projects.
- •Clearly define what constitutes confidential information and explicitly state restrictions on data usage and storage.
- •Ensure your vendor understands how AI can inadvertently disclose information and obligate them to implement appropriate safeguards.
Implementing AI solutions often requires bringing in external experts. While these vendors can help your company achieve quick initial results, they also gain access to sensitive information. Your primary task is to ensure this data is robustly protected. This isn't just about reputation; it carries direct financial risks.
Why a Standard NDA Fails with AI Vendors
A typical NDA used for other projects may be insufficient when dealing with AI. This is because AI work has unique characteristics: models learn from data, can generate new content based on it, and the risk of data leaks increases due to technological complexity. A standard NDA doesn't account for the intricacies of working with Large Language Models (LLMs), which might retain parts of the data or "memorize" patterns.
Definition: LLMs (Large Language Models) are advanced AI models, like ChatGPT, that form the backbone of many AI tools. They are capable of understanding, generating, and processing human language.
Essential Clauses for Your AI Project NDA
To avoid unwelcome surprises, your NDA needs to be meticulously detailed and account for AI specifics. Here are the key sections to focus on:
1. Clear Definition of Confidential Information
Beyond standard categories like financial data or trade secrets, specify that confidential information also includes:
- Training data: All data you provide to train AI models. This can include text, images, audio, video, customer databases, internal documents, etc.
- Model outputs: Any results generated by the AI model during your project, even if they are intermediate.
- AI solution methodologies and architecture: Descriptions of how the AI system functions, which models are used, and how they are integrated and configured.
- Experiment progress and results: All findings obtained during the testing and refinement of the AI solution.
The more specific this section, the less room for maneuver the vendor will have in a disputed situation.
2. Restrictions on Data Use and Disclosure
This section must be particularly stringent. Ensure it includes the following:
- Usage solely for project purposes: Clearly state that confidential information may only be used for tasks defined in the Statement of Work. Prohibit the use of your data for training any other models (besides yours) or for the vendor's other projects.
- Prohibition of third-party transfer: Explicitly forbid the transfer of your data to any subcontractors without your written consent. If transfer is necessary (e.g., for using third-party AI services), require these third parties to also sign an NDA with similar terms.
- Anonymization and aggregation: If the vendor plans to use anonymized or aggregated data to improve their tools, this must be clearly agreed upon and permitted by you. Define anonymization criteria to prevent reverse identification.
3. Data Security Measures
Given that an AI vendor may handle large volumes of data, specific requirements for its storage and processing must be outlined:
- Storage location: Clearly define where your data will be stored (e.g., servers in Ukraine, EU, USA). Prohibit storage on personal devices or unauthorized cloud storage.
- Technical security measures: Require the implementation of standard security protocols: data encryption (both in transit and at rest), access control, and regular security audits.
- Data destruction: Upon project completion or contract termination, the vendor must guarantee the complete and irreversible destruction of all your confidential data, including copies. Demand written confirmation of this fact.
4. Liability for Breach
This section ensures compliance with the NDA terms. It should include:
- Penalties: Clearly defined penalties for each identified breach of confidentiality. These amounts should be significant enough to act as a deterrent.
- Damages: The right to claim compensation for actual damages caused by an NDA breach, even if they exceed the penalty amount.
- Right to terminate the agreement: The ability to immediately terminate the primary contract with the vendor upon discovering a confidentiality breach.
5. Risks of Using Public AI Services
Many AI vendors use publicly available LLMs like ChatGPT or Claude. It's crucial to understand that these services often store user-inputted information for further training of their models. This can lead to an unintentional leak of your confidential information. Therefore, your NDA should include a clause that:
- Prohibits the use of such services for processing confidential data without your explicit written consent.
- Requires the use of enterprise versions of AI services (e.g., ChatGPT Enterprise, Microsoft Azure OpenAI Service), which guarantee that your data will not be used for model training.
- Obligates the vendor to use specific AI model settings (e.g., chat history off mode), if technically possible.
Vendor Vetting: What Else Should You Do?
Beyond signing an NDA, conduct your own due diligence on the vendor:
- Reputation: Look for reviews, case studies, and check company registration details.
- Security protocols: Inquire about their internal security policies, standards, and certifications (if any).
- Technical expertise: Ensure the team understands the specifics of working with confidential data in the context of AI. Ask how they handle sensitive processes using test or anonymized data.
Step-by-Step Data Protection Plan with an AI Vendor
Here's an action plan to minimize risks when working with AI vendors:
-
Step 1: Diagnostics and Risk Analysis (Before Project Start)
- Task: Identify which data is confidential, its sensitivity level, and potential risks associated with transferring it to an AI vendor.
- Deadline: Before negotiations begin.
- Outcome: A list of sensitive data and an assessment of leakage risks.
-
Step 2: NDA Development and Agreement (Before Signing Main Contract)
- Task: Create an NDA that addresses all AI-specific issues, including the definition of confidential information, usage restrictions, security requirements, and liability. Consult a lawyer specializing in IT law and data protection.
- Deadline: Before signing any documents.
- Outcome: A tailored NDA, signed by both parties.
-
Step 3: Statement of Work (SOW) and Security Protocols (Before Data Transfer)
- Task: Clearly specify in the SOW exactly what data is being provided, in what format, and for what specific purposes. Define protocols for data transfer, storage, and processing (e.g., using test or anonymized data).
- Deadline: Before the first data transfer.
- Outcome: A detailed SOW incorporating security requirements.
-
Step 4: Monitoring and Audit (During the Project)
- Task: Regularly verify the vendor's compliance with the NDA and security protocols. This may include requesting reports on data usage, infrastructure audits (by agreement), and activity monitoring.
- Deadline: Weekly/monthly (depends on data volume and sensitivity).
- Outcome: Compliance reports, identification, and resolution of potential breaches.
-
Step 5: Data Destruction (After Project Completion)
- Task: Ensure all confidential data provided to the vendor, along with all copies and derivative materials, has been completely and irreversibly destroyed. Demand an official certificate of data destruction.
- Deadline: Immediately after project acceptance.
- Outcome: Confirmation of data destruction.
How this works on our side: We understand the importance of data protection. For sensitive processes during our sessions, we use test or anonymized data, and NDAs are available upon request. The code and automations created are the property of your company, run on your tools, and have no ties to us as a vendor. We guarantee a minimum of 3 working automations for your company's priority tasks, with a money-back guarantee if we don't achieve this. Payment is via company invoice with VAT; we provide all closing documents. https://course.aiadvisoryboard.me/corporate?utm_source=blog&utm_medium=article_body&utm_campaign=corporate
FAQ
Do I still need an NDA if we use enterprise versions of AI services?
Yes, you do. While enterprise AI services offer enhanced data protection, an NDA with your vendor is still essential. It governs the vendor's responsibility for negligence, accidental leaks, and ensures your data isn't used for purposes other than your project.
What if an AI vendor refuses to sign a tailored NDA?
If a vendor refuses to sign an NDA with appropriate AI-specific provisions, that's a significant red flag. They likely don't understand the specific risks or are unwilling to take responsibility. In such cases, it's advisable to seek another partner who values data security.
Can I require the AI vendor to report on my data usage?
Yes, not only can you, but it's highly recommended. Include clauses in your NDA that obligate the vendor to provide regular reports on how your data is used, stored, and processed. This helps you monitor the situation and ensure all agreements are met.
How can I verify that the vendor has indeed destroyed my data?
This is a complex issue, especially with AI models. Demand written confirmation of the destruction of all data and its copies. For particularly sensitive projects, consider conducting an independent audit or requiring logs that confirm the deletion of information from their systems.
Conclusion
Working with AI vendors offers tremendous opportunities for businesses but demands heightened attention to data protection. An NDA tailored to AI specifics is your reliable shield, allowing you to innovate with confidence. Do not overlook this step, as the consequences of a data leak can be severe. If you're still wondering where to begin with AI adoption, start with a free 30-minute diagnostic consultation with our experts. We'll analyze your real-world challenges and show you how AI can be applied without risking your data.

Implements AI agents in companies and teaches founders and their teams to work with them — through courses and corporate programs.
This article was prepared with AI assistance, based on Yaroslav Maxymovych's methodology and materials. Spotted an inaccuracy — let us know via the form below.
Your company's first 3 AI automations — in 2 weeks
A corporate AI-transition program: 4 live sessions with your team plus a video course for every employee. Up to 20 people for one fixed price. If it doesn't work — money back.
New case studies on AI adoption — in your inbox
Once a week: practical breakdowns of what companies automate with AI and what actually comes out of it.
No spam. Unsubscribe anytime.
Related Articles

AI Adoption Plan for a 50-Person Company: 30-Day Blueprint
Develop a realistic 30-day AI adoption plan for a 50-person company. Learn where to start, how to choose tasks, and measure results effectively.
Read more
AI Adoption: A 30-Day Plan for 50-Person Companies
Develop a 30-day AI adoption plan for your 50-person company. Learn how to choose initial tasks and train your team for quick wins.
Read more
How to Avoid Vendor Lock-in After AI Implementation
Learn how to avoid becoming dependent on external vendors after implementing AI solutions. Discover strategies for building in-house AI capabilities to maintain control and agility.
Read more