Back to blog

August 19, 2026 · 5 min read

Can You Upload an NDA to ChatGPT Without Legal Risk?

ChatGPT can review your NDA in seconds. But confidentiality exposure, privilege risk, and AI interpretation errors can follow. Here's what you need to know.

Can You Upload an NDA to ChatGPT Without Legal Risk?

💡 Key Takeaways

  • Yes, you can technically upload an NDA to ChatGPT. But before you do, you must understand its risks and limitations.

  • When you share any private information with ChatGPT, you risk losing confidentiality and privilege. And since ChatGPT isn’t a lawyer, you will be liable for any mistakes or misinterpretations made by the AI.

  • Before uploading any NDA to an AI tool, ask if you can share that exact information to an external SaaS vendor under your current security policy.

  • Premium-tier enterprise tools do lower these risks, but don’t eliminate them entirely.

  • The solution isn’t to ban AI entirely. Instead, you should build a robust AI-NDA review workflow and use legal AI tools in place of general LLMs.


If you’re running operations, managing a business, or working for a mid-sized firm, you’ve probably done this more than once. An NDA lands in your inbox, you need to unblock a deal, and you don’t have time for a legal review. So you upload it into ChatGPT. You ask it to cut through the legalese, draft a quick summary, and flag any weird clauses.

It’s fast, it’s free, and it gets the NDA off your desk so you can keep things moving.

Businesses are readily using AI for drafting and reviewing non-disclosure agreements, and for good reasons. (We wrote How Are Businesses Using AI for NDAs in 2026 so you can get the complete picture.)

But what about the ad-hoc AI use, especially by non-legal teams? Generative AI is a useful shortcut , but is it safe to just upload an NDA into ChatGPT? Well, the answer depends on 3 things:

  • What you’ve decided to share with ChatGPT
  • Which variant of ChatGPT (or any general LLM) you’re using
  • Whether you had any human oversight in this process

Let us understand these factors and how they affect accuracy, legal risk, and attorney-client privilege.

Can You Upload an NDA to ChatGPT at All

Technically, yes. Uploading an NDA to ChatGPT is not automatically unlawful or a breach of confidentiality. People are doing it every day for summarisation, clause review, and understanding what they are about to sign. A Thomson Reuters study from 2025 found that 77% legal professionals regularly use AI for document review, while 74% use it for document summarisation.

But, whether you can technically do it and whether it creates legal exposure are different questions.

Okay, then I will never upload any information on ChatGPT. That should work, right?

A blanket no is not the right answer, because you still need to work with NDAs more efficiently. So, you need to understand where the actual risk sits. The risk is real, but it is contextual, not categorical. Let us see how.

What Makes Uploading an NDA Risky?

The first question on everyone’s mind is “Will ChatGPT store my information?” That is a reasonable question – and we’ll answer it here – but it is not the only risk.

Three things create risk when private information enters an AI system: Confidentiality exposure, AI interpretation risk, and privilege exposure.

1. Confidentiality Exposure

Many NDAs define disclosure broadly. So, when you submit an NDA to a third-party AI system, this may technically constitute disclosure to that system, regardless of whether the data is retained for training. Not only does the storage matter, but the processing does too.

2. AI Interpretation Risk

ChatGPT isn’t a lawyer – it is an LLM. It produces summaries and clause explanations based on pattern matching, not legal judgment. So, it can miss the clause that quietly changes what the agreement allows. If you acted on that summary — approved a deal, signed an agreement, made a commercial decision — the inaccuracy creates real downstream exposure. The LLM vendor disclaims, while you absorb the risk. You cannot claim that ‘the AI lied.’ The AI did what it does, and you relied on a pattern match as if it were a legal opinion.

For the specific clauses where AI review most consistently creates hidden risk, read 7 NDA Clauses AI Gets Wrong Every Time.

3. Privilege Exposure

Privilege exposure is a hidden risk, i.e., most businesses do not map it. Attorney-client privilege protects confidential communications between a client and their lawyer.

When those communications, or documents connected to live legal matters, enter a third-party AI system, the privilege analysis becomes complicated. You waive the privilege because of the processing architecture, not because you deliberately disclosed information.

In a traditional review workflow, human lawyers look at documents on a secure, closed local database. There is no external AI, no third-party cloud processing, and no model training. Because the data never leaves that secure bubble, there is zero doubt that privilege was preserved. But, by introducing complex AI processing architecture, you introduce a new risk: you now have to prove to a judge exactly where the data went, who (or what) had access to it, and whether that exposure legally destroyed your attorney-client privilege.

A useful question to ask before uploading any NDA to an AI tool is this: Would I email this exact information to an external SaaS/tech vendor under our current security policy?

If the answer is no — or uncertain — the AI upload deserves the same scrutiny.


Does Every NDA Upload Pose the Same Level of Risk?

No, because not all NDAs are the same.

A public NDA template with standard confidentiality language is very different from a signed acquisition NDA containing commercially sensitive deal terms and pricing information.

AI tools cannot tell the difference, they see text as text. So, the level of risk depends on what the document contains.

Here’s a risk framework to help you think before you share an NDA with a third-party tool like ChatGPT.

Risk Level NDA Type(s) AI Environment Redaction Required Human Review Required
GREEN (Lower risk) Public templates, anonymised summaries, clause explanations Consumer-grade or enterprise AI Recommended Always before acting on output
YELLOW (Requires care) Unsigned commercial NDAs, vendor agreements, employment confidentiality Enterprise AI preferred Yes — remove identifying and commercial terms Legal review before decisions
RED (Do not use consumer-grade AI) M&A NDAs, litigation-sensitive material, privileged strategy, trade secrets Human-led review only N/A; Do not upload Full human review,  no AI

You can use this risk framework (or design one of your own) to make deliberate decisions about which NDA materials can enter AI systems and which cannot. Keep in mind that these decisions should be made in advance, not at the eleventh hour when someone is trying to move fast on a deal.

But I’m Using ChatGPT Enterprise. So, That Changes the Risk Level, Right?

Yes, it does make things less risky. But, be cautious: while upgraded tools like ChatGPT Enterprise lower your privacy risks, they don't eliminate them entirely.

Let us first look at the differences between consumer-grade ChatGPT and Enterprise ChatGPT, from a legal and operational standpoint.

Factor Consumer ChatGPT Enterprise AI with Contractual Protections
Data retention Configurable but limited contractual protections Zero-retention contractually guaranteed
Training restriction Opt-out available — not the same as no retention No training — contractually enforced
Confidentiality obligation None to the organisation Contractual confidentiality obligations
Data isolation Not guaranteed Tenant isolation standard
Audit trail Limited Logging and auditability available
Professional defensibility Limited Defensible with documented workflow

Now, here are two examples of how you can still be exposed to risk.

1) Your secret information is still in someone else’s hands

Imagine a CFO secretly buying out a competitor. He copies the top-secret merger contract into ChatGPT Enterprise to draft a press release. Sure, the AI won't use that data to train itself, but the second they hit enter, that market-moving secret leaves the company's network and sits on OpenAI's servers.

If an investor later sues the company, the opposing legal team can now subpoena OpenAI directly for those server logs, triggering a  courtroom battle over whether uploading that contract legally destroyed their attorney-client privilege. It proves that while Enterprise AI puts your data in a high-security vault (instead of an accessible cloud storage), your secrets are still ultimately in someone else's hands.

2) No training doesn’t mean no retention (unless explicitly stated)

When an AI company promises, "We won't use your data to train our AI," most people think that means their data is completely invisible and safe. It's not. Just because an AI isn't learning from your data doesn't mean it isn't saving it, looking at it, or sharing it.

"No training" just means the AI won't memorize your words to get smarter. It does not mean the company deletes your text the moment you hit enter. Most companies still keep "logs" (history files) of everything you type for months just in case they need to review it later.

With Enterprise ChatGPT, OpenAI contractually binds itself to a "no-peek" policy for model training, i.e., your data is never used to train public models. However, human eyes can still theoretically access it under strict conditions.

For example, OpenAI engineers can access workspace data solely to fix technical bugs, handle platform abuse, or recover data with your explicit corporate permission. Plus, if OpenAI is served with a legally binding subpoena, warrant, or court order by a government entity, they are legally obligated to halt their 30-day automatic deletion cycle and preserve your data for law enforcement.

Now, you may think, “My data is encrypted when it is stored.” Just because a message is encrypted (so hackers can't intercept it mid-air) does not mean it stays confidential once it lands. If the AI company holds the keys to unscramble that data on their servers, it isn't truly private.

Why a Blanket AI Ban is Not The Solution

Many organisations have formally told their staff not to upload confidential information into AI tools. Most of those organisations have employees who are doing it anyway, and  for the same reason businesses started using AI in the first place. It saves time on routine tasks – work that needs to get done.

The problem with a blanket ban is that it removes the organisation's visibility over what is happening without stopping what is happening. That shadow AI governance is a worse position than controlled adoption with clear rules.

When AI bans fail, an unofficial hierarchy of acceptable risk emerges. Employees use AI for drafting and summaries but avoid it for highly sensitive negotiations. Nobody defined that boundary, and individuals made their own judgments based on their own risk tolerance. That is not a policy, it's just managed inconsistency.

So, who are the organisations that have reduced their exposure? They are the ones that defined upload boundaries clearly enough that staff know what they can do and what they cannot — and why.

What a Safer NDA Review Workflow Actually Looks Like

The businesses reviewing NDAs safely with AI in 2026 are those who have simply established clear rules around what can be uploaded and where.

They defined upload boundaries so the team has a clear shared understanding of what NDA materials can go into AI tools and which cannot. They kept humans in the loop on anything that matters, using AI for summarisation and issue spotting, but requiring human approval steps for anything the business will eventually act on.

Finally, they used AI environments with contractual protections (like Enterprise ChatGPT) for sensitive work, reducing their risk.

To create your own safe NDA workflow, follow these steps:

  1. Classify the NDA before opening any AI tool using the Green, Yellow, or Red tiers.
  2. Redact commercially sensitive terms and identifying information for Yellow materials before upload.
  3. Use AI for issue spotting and clause summarisation, not for final legal interpretation.
  4. Require human review checkpoints before any decision is made or document is signed.
  5. Keep Red materials in human-led review workflows entirely.

Risk prevention is also a major reason why many SMEs are moving sensitive NDA workflows into legal-specific AI environments rather than relying on enterprise general-purpose chat tools.

Platforms like Evatt AI are built specifically around this operational distinction — structured NDA review workflows with contractual data protections, human review checkpoints, and source-traceable outputs. Evatt AI isn’t a replacement for your decision process, but acts as a more controlled environment for the review process.

Conclusion: Time to Move Beyond Pasting NDAs in a Chatbox

At the end of the day, managing NDAs, reviewing contracts, and handling sensitive corporate data requires more than just typing casual prompts into a generic consumer chatbot.

The legal and operational stakes for you are simply too high for a tool that wasn't built for absolute confidentiality first. Forward-thinking legal teams and SMEs are completely shifting away from standard generative platforms and moving their critical workflows into structured, dedicated legal AI environments—spaces purpose-built to defend privilege, enforce strict data isolation, and handle complex documents safely.

If you are ready to take the next step, try Evatt AI for free today. You don’t need any mandatory sales calls or weeks of demo. Just start using the product, built for real legal work.