Yes, if it’s worded to cover it — and you may be exposed even without an NDA at all.
Short answer
Yes, an NDA or confidentiality clause can stop you putting protected material into an AI tool — but only if its definition of a prohibited disclosure is broad enough to capture a hosted AI system. And separately, putting someone else’s confidential information into a public AI tool can itself be the unauthorized disclosure, NDA or not.
A confidentiality clause or a standalone NDA does the same underlying job: it defines what counts as confidential, who can access it, how it must be protected, and what happens if it is disclosed without permission. Whether pasting information into an AI chatbot counts as a breach comes down to how that definition is drafted — many confidentiality clauses restrict disclosure “to any third party,” and a hosted AI service that stores, logs, or could train on what you enter is a reasonable candidate for that label.
This is a drafting question, not a settled one: an older NDA written before generative AI tools were common may not contemplate this scenario at all, which is itself the risk — the clause doesn’t need to mention AI by name to bind you, but a vague one leaves real room to argue either way.
Canadian courts don’t require a signed document before they’ll protect confidential information. As the general doctrine puts it, “in Ontario (and across Canada), courts have long recognized a cause of action for breach of confidence” for information that “has commercial value because it is not generally known or readily ascertainable.” That cause of action turns on how the information was received and used, not on whether paper was signed.
The mechanism that actually creates the exposure is a practical one: Canada’s Cyber Centre warns that “users may unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts.” Feeding a client’s confidential file into a public AI tool to summarize it can be the disclosure itself — whatever your NDA does or doesn’t say.
Read the NDA’s actual definitions of “disclosure” and “third party” before assuming an AI tool is or isn’t covered, rather than guessing from the spirit of the agreement. And check the AI vendor’s own terms for whether it retains, logs, or trains on what you submit — that answer often matters more than what your own NDA says.
Once confidential material goes in, the next question is often who actually owns the resulting prompt or output, and if something goes wrong, who is liable if the tool copies someone else’s work. Vendor data-handling terms are exactly what Treadstone’s AI Due Diligence reviews check before you commit to a tool.
See what to check before confidential material ever reaches the tool.