Menu

  1. Sep 22, 2026

    OM Confidentiality and AI: What an NDA Means When a Model Reads Your Deal Documents

Every firm evaluating AI on its deal flow asks the same first question: is the platform secure. That is the wrong first question. OM confidentiality is not a security property. It is a list. A confidentiality agreement names who may receive the document and the single purpose for which they may use it, and an AI platform that is not on that list is an unauthorized recipient whether or not a byte ever leaks. The breach is the handoff, not the leak. A firm can run a flawlessly secured tool and still be in default on four hundred agreements it signed without reading.

Key Takeaways

  • A confidentiality agreement restricts recipients and purpose. Security controls address neither. A platform can be encrypted, audited, and certified, and still be a person to whom the agreement never permitted disclosure.

  • The law firm Stephenson Harwood concluded in June 2026 that where an NDA's permitted recipients do not contemplate an AI provider or its sub-processors, "the mere act of uploading the information may itself constitute a disclosure," exposing the receiving party even when nothing is compromised.

  • Most CRE confidentiality legends carry no service-provider carve-out at all. A publicly posted brokerage legend furnishes the memorandum "solely for the purpose of a review by a prospective purchaser" and bars use "for any other purpose or made available to any other person."

  • The purpose clause fails before the disclosure clause does. Extracted OM data that survives into a firm's comps database serves a purpose the agreement never granted, and it no longer looks like the document, so nobody catches it.

  • In United States v. Heppner (S.D.N.Y., February 2026), Judge Jed Rakoff held that documents a defendant created with a consumer AI assistant were covered by neither attorney-client privilege nor work product.

What does an OM confidentiality agreement prohibit?

Two things, and neither is a security standard. It prohibits disclosure of the memorandum and its contents to anyone outside a named set of recipients, and it prohibits use of the information for any purpose other than evaluating the specific acquisition. Everything else in the document, including the disclaimers on accuracy, is subordinate to those two restrictions.

Read the operative language from a brokerage's publicly posted confidentiality agreement: the information "is confidential and furnished solely for the purpose of a review by a prospective purchaser of the Property. It is not to be used for any other purpose or made available to any other person without the written consent of Seller" or the broker. One purpose, zero permitted third parties, in a single sentence.

Negotiated agreements do better. They define Representatives, or Related Parties, as the recipient's officers, employees, attorneys, accountants, financial advisors, consultants, and lenders who need to know for the stated purpose and agree to be bound. That list is a closed set of human professional categories, drafted to solve a 1995 problem: keeping a seller's rent roll from a competitor while letting the buyer's lawyer read it.

The International Bar Association put it plainly in April 2026: confidentiality clauses "typically restrict disclosure of confidential information to identifiable human third parties and may not contemplate AI platforms." The list was not wrong. It was written before the question existed.

Is uploading an OM to an AI platform a disclosure?

Often yes, and the answer does not depend on whether anything went wrong. Uploading transmits a copy of the document to infrastructure operated by a party that did not sign the agreement, and may involve storage, cross-border transfer, and access by sub-processors the firm has never seen. Under most confidentiality language, that transmission is the disclosure.

This inverts the usual risk instinct. Ordinary confidentiality risk is about outcomes: did the information reach someone it should not have. Contractual confidentiality risk is about acts: did you hand it to someone the contract did not name. Stephenson Harwood's June 2026 note on confidential information, NDAs and AI states the distinction outright: "the fact that an AI platform is secure does not, of itself, mean that its use is permitted under an NDA."

Courts have begun treating the upload as the disclosing act. In United States v. Heppner, decided in February 2026 and analyzed by the Harvard Law Review, Judge Jed Rakoff held that reports a defendant generated with a consumer AI assistant were not privileged, because the provider's consumer terms permitted retention, human review, and disclosure under legal process. That holding concerns privilege, not NDAs. The transferable logic is narrower and still uncomfortable: the terms of service under which a document is processed decide whether the law still treats it as confidential.

Question

Security review answers

Confidentiality agreement answers

Is the data encrypted in transit and at rest?

Yes

Not asked

Is the vendor SOC 2 Type 2 certified?

Yes

Not asked

Did an unauthorized party obtain the file?

No

Not asked

Is the provider a permitted recipient under the agreement?

Not asked

The entire question

Is this use within the stated purpose?

Not asked

The entire question

Can the firm prove which tools touched the file?

Sometimes

Required in a dispute

Two columns, almost no overlap. A firm that completed the left one and never opened the right has answered a question nobody asked. It is the same error as the objection to connecting AI to the deal inbox, a scoping problem dressed as a trust problem, and as granting an agent permissions inherited from a person rather than sized to a task.

Why is the purpose clause a bigger problem than the disclosure clause?

Because a firm can fix disclosure with procurement and still breach purpose by accident every single day. The disclosure restriction is violated at the moment of upload, which is visible. The purpose restriction is violated later, quietly, when data extracted from a document the firm passed on survives inside the firm's own systems and gets used on unrelated deals.

Work the arithmetic on a mid-sized acquisitions shop. Stated inputs: 600 inbound offering memorandums a year, 22 structured fields extracted per OM into the comps table, 45 deals pursued past first look.

Input

Value

Inbound OMs received under a confidentiality legend

600

Structured fields extracted per OM

22

Extracted data points retained

13,200

Deals pursued past first look

45

OMs where the stated purpose has concluded

555

Retained data points tied to a concluded purpose

12,210

The agreement authorized one purpose: evaluating that acquisition. For 555 of those documents the evaluation ended in a pass. The extracted rent, tenant names, in-place cap rate, and asking price remain as the firm's market intelligence. That is a different purpose, and the most commercially attractive byproduct of running AI on deal flow, which is why nobody looks at it directly.

Detection compounds the problem. A PDF in a folder looks like a confidential document. A row in a comps table looks like data the firm owns. Once extraction strips the document's identity, the obligation attached to it goes invisible downstream. That is the argument for a chain of custody on AI-extracted data carrying the source document and its terms forward into every field.

What should a firm verify before a deal document reaches a model?

Four things, in order, and none of them is model accuracy. Whether the agreement permits disclosure to service providers. Whether the provider's terms make it a permissible one. Whether the extracted output is scoped to the stated purpose and expires with it. Whether the firm can reconstruct, later, which tool touched which document under which terms.

Check

What defeats it

Does the agreement have a service-provider or Representatives carve-out?

A legend with no carve-out at all, which is the common case on inbound OMs

Do the provider's terms prohibit training on inputs?

A no-training promise that covers public models but permits internal evaluation sets

Is retention zero, or only training opt-out?

Treating the two as one control. Opting out of training does not stop storage

Are sub-processors disclosed and bound to the same terms?

A clean top-level agreement over a sub-processor chain the firm has never seen

Does extracted data expire when the evaluation ends?

Nothing. Almost no firm builds this, which is why the purpose clause is the exposure

Can the firm evidence all of the above in a dispute?

No logging of which documents went to which tool on which date

Training opt-out and zero retention are separate controls, and they get conflated constantly. Training opt-out means the provider will not use inputs to improve its models. Zero retention means it does not persist the input after returning a response. A firm can hold the first and still have confidential OMs sitting on a third party's storage for a contractual retention window.

The American Bar Association reached the general version of this in Formal Opinion 512, issued July 29, 2024, which put the burden of understanding how a tool handles inputs on the professional using it, not the vendor selling it. The broker did not vet your stack. The seller has never heard of it. The obligation sits with the firm that clicked accept.

How should the confidentiality agreement itself change?

By naming AI processing expressly, in both directions. Buyers should negotiate for a Representatives definition that includes approved AI service providers engaged for the stated purpose and bound to equivalent terms. Sellers and brokers should stop relying on silence, and instead permit AI use on defined conditions rather than pretending the question will not come up.

Stephenson Harwood's drafting list is the practical version: make AI use the receiving party's own risk without limiting its liability, restrict processing to closed environments that do not train on inputs, limit which categories may be processed, and treat confidential information contained in an AI output as the disclosing party's. That last item closes the comps-database gap, and buy-side firms will resist it.

The asymmetry favors sellers right now. A buyer who asks for an AI carve-out is disclosing that it runs documents through tools, and brokers have long memories. A buyer who does not ask is not compliant. It is silent, which is the worse position when someone asks in writing.

Frequently Asked Questions

Does an NDA prohibit using AI on an offering memorandum?

Usually it does not say. Most CRE confidentiality agreements restrict disclosure to a closed list of human recipient categories and permit one purpose, and neither contemplates an AI platform. Silence is not permission. Where the platform is not a permitted recipient, uploading the document can itself be the disclosure.

Is an AI vendor a "Representative" under a confidentiality agreement?

Only if the definition covers it. Representatives clauses name officers, employees, attorneys, accountants, advisors, consultants, and lenders who need to know and agree to be bound. A provider processing documents on its own infrastructure does not obviously sit inside that list without express drafting.

Can a firm keep data extracted from an OM after passing on the deal?

That is a purpose question, not a disclosure question. If the information was furnished solely to evaluate that acquisition, retaining the extracted fields as market intelligence serves a different purpose. The data stops looking confidential once it is a row in a table, which is why it goes unexamined.

Does a SOC 2 certification satisfy an NDA?

No. A SOC 2 report addresses whether security and availability controls operated effectively. A confidentiality agreement addresses who may receive the information and what it may be used for. A provider can hold every certification available and still be a party the agreement never authorized.

Conclusion

The confidentiality question gets postponed because it is legal rather than technical, and because the firms most eager to run AI on deal flow are least eager to hear that their signed agreements never contemplated it. Postponing does not shrink the exposure. It makes it undocumented, which is the version hardest to defend when a seller's counsel asks in writing what happened to their rent roll.

The discipline is small. Read the permitted-recipient clause before the security questionnaire. Treat training opt-out and retention as two controls. Make extracted data carry the terms of the document it came from. Ask for the AI carve-out at signature, where the firm has negotiating power, instead of finding the gap at upload, where it has none. Confidentiality was always a list of names. The list now has to include the machines.

Get Started

Every deal in your inbox, screened automatically.

Get Started

Every deal in your inbox, screened automatically.