An existing confidentiality clause or non-disclosure agreement doesn’t stop applying just because the tool someone used to draft, summarize or search a document happens to be AI — the obligation runs to the information, not to the method used to handle it.
Key takeaways
Treadstone Law’s explainer on the difference between the two instruments describes what each protects, not how: “A non-disclosure agreement (NDA) is a standalone contract whose sole or primary purpose is to protect confidential information. A confidentiality clause is a provision within a broader contract... that serves the same protective function as one section among many.” Both, the same page notes, “define what counts as confidential, who can access it, how it must be protected, and what happens if it is disclosed without permission.” (treadstonelaw.ca) None of that turns on which tool an employee used. Pasting a client’s financials into a chatbot is a disclosure in exactly the sense the clause already defines, provided the clause’s own definitions of “confidential information” and “disclosure” are broad enough to reach it — an assumption worth checking rather than making.
Canada’s Centre for Cyber Security names this as one of eight distinct risks of generative AI, under the heading “Privacy of data”: “Users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts. Threat actors could harvest this sensitive information to impersonate individuals or spread false information.” (cyber.gc.ca) Its own mitigation advice is direct: “Avoid providing PII or sensitive corporate data as part of the queries or prompts,” and “Do not share private information with AI tools unless you understand what they are doing with your data. Sharing data trains AI models to then be potentially exploited or sold.” An employee pasting a draft, NDA-covered document into a public AI tool to summarize it is precisely the scenario this guidance describes, and depending on that tool’s own terms, the content may be retained or used for further training well beyond the moment it was typed in.
The enforcement mechanics do not change because the third party handling the information was software. Treadstone Law’s page on NDA enforceability states that in Ontario, both an NDA and a confidentiality clause “are enforceable so long as they meet general contract requirements,” and that “if a breach occurs, the injured party can seek an injunction to stop further disclosure and claim damages.” (treadstonelaw.ca) An AI-mediated leak of confidential information is analyzed under exactly those same mechanics — the technology does not create a new cause of action, and it does not remove the old one either.
Treadstone Law’s own framing of what makes these clauses work is a drafting point, not a technology point: “Getting the language right — especially on what counts as ‘confidential’ — is the most important drafting task.” An older confidentiality clause drafted before generative AI tools existed may never have contemplated whether submitting information to a third-party AI service counts as a disclosure to a “third party” at all — that is worth an explicit review rather than an assumption in either direction. PIPEDA adds a second, statutory reason the same discipline applies regardless of who or what the third party is: Schedule 1’s accountability principle states that “an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing,” and “shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.” (laws-lois.justice.gc.ca, Schedule 1) That accountability does not lift merely because the third party is an AI vendor rather than a human subcontractor.
PIPEDA attaches a specific, dated consequence if that third-party processing goes wrong. Section 10.1 requires an organization to report to the Privacy Commissioner “any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual,” with the notification to the affected individual itself given “as soon as feasible after the organization determines that the breach has occurred.” (laws-lois.justice.gc.ca, PIPEDA s.10.1) That reporting duty runs to the organization that controls the information, not to whichever AI vendor’s servers the data happened to pass through — a breach on the vendor’s end is still the business’s own obligation to report, on the same clock as if it had happened on the business’s own network. Treadstone Law’s own explainer on this duty sets out what the report itself has to contain and when. (treadstonelaw.ca)
A law firm’s junior associate pastes a client’s draft settlement terms into a general-purpose AI tool to check the grammar, without checking whether that tool retains submitted prompts for training. If the firm’s engagement letter contains a standard confidentiality clause and the AI vendor’s own terms permit retaining submitted content, the firm has very plausibly caused an unauthorized disclosure under its own contract’s ordinary definition — the breach analysis in Ontario does not change because the third party was software rather than a person. Per Treadstone Law’s own framing of remedies, the available responses are the same injunction and damages the clause already contemplates; what differs is only how quickly the firm can establish what was disclosed and to whom, which is harder once the recipient is a vendor’s training pipeline rather than a named individual.
Related: the equitable protection that applies even without a signed clause, the broader policy backdrop this obligation sits inside, the same third-party-processing accountability applied to biometric data
Not automatically — it depends on how the NDA or clause defines “confidential information” and “disclosure.” A broadly worded clause will very likely reach it; the point is that the clause’s own wording, not the technology, decides the answer.
No. What applies is the ordinary combination of the existing contract (the NDA or clause) and, where personal information is involved, PIPEDA’s accountability rule for information handed to any third party for processing — AI tools are not treated as a special exception either way.
For accountability purposes, PIPEDA does not prohibit sending data to a foreign processor, but the organization stays accountable for it regardless, primarily through the contract with that vendor — the location does not remove the underlying confidentiality obligation.
That is a policy choice each organization has to make for itself, but the Cyber Centre’s own advice points toward a narrower rule than an outright ban: know what a specific tool does with submitted data before using it for anything sensitive, and treat not knowing what happens to a submission after it is sent as a reason not to submit it.
Reviewing whether a target’s AI tool use created undisclosed confidentiality exposure is worth its own checklist item.