Engineering and architecture
Can staff put client drawings into ChatGPT? Confidentiality risks
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Staff should not put client drawings into ChatGPT or similar public AI tools until two checks pass: the client contract permits that processing, and the firm's plan terms exclude uploads from model training. Without both, an upload may breach a confidentiality obligation. A short written staff policy and an approved business account close most of the gap.
Key takeaways
- Owning the instruments of service does not cancel a confidentiality promise made in the client contract.
- Consumer and business plans of the same AI product can treat uploads very differently, so the plan staff actually use is what counts.
- Security-sensitive facilities, unannounced projects and private residences carry the highest upload risk.
- Five plain rules that staff can remember prevent most accidental disclosures of client drawings.
- Consented, de-identified licensing differs from staff uploads in who decides, what leaves the firm and what record remains.
Is uploading a client drawing to an AI tool a confidentiality breach?#
Uploading a client drawing to an AI tool can be a confidentiality breach, depending on what the client contract says and what the tool's terms let the vendor do with the file. A drawing sent to a third-party service has left the firm's control, and many professional services agreements limit disclosure to people who need the information for the project.
The tool alone rarely settles the question. A plan that excludes content from training may still store the file, allow vendor staff to review content for abuse monitoring or process it in another country. Whether any of that conflicts with the contract is a reading of both documents, done with counsel for sensitive clients.
Two mistakes come up often: assuming that because the firm authored a drawing it may do anything with it, and assuming that deleting a chat deletes the upload. Retention depends on the vendor's terms, not on what the user sees on screen.
What to check in the client contract#
The client contract sets the outer limit, so check the signed agreement for each project rather than the firm's standard form. Older agreements were written before AI tools were common and may not mention them, which leaves the general confidentiality and third-party clauses to decide the question.
| Clause | What to look for | Why it matters |
|---|---|---|
| Confidentiality | The definition of confidential information and permitted disclosures | Drawings and models often fall inside the definition |
| Data handling or security | Rules on storage locations, encryption or approved systems | A public AI service may not be an approved system |
| Subcontractors and third parties | Whether outside service providers need approval | An AI vendor can count as a third party receiving project information |
| Instruments of service | Who owns the drawings and what license each party holds | Ownership and confidentiality are separate questions |
| Security-sensitive information | Limits on sharing facility layouts, systems or access points | Some project types bar any outside processing |
| AI-specific terms | Disclosure, approval or prohibition of AI use | Newer agreements may address AI directly |
What to check in the AI tool's terms#
The AI tool's terms decide what happens to a file after upload, and they often differ between consumer and business plans of the same product. Consumer versions of chat assistants may use conversations to improve models unless a setting or plan says otherwise, while business and enterprise plans commonly offer terms that exclude customer content from training.
Read the current terms for the plan your staff actually use, because vendors revise them. A setting chosen by one employee on a personal account does not bind the vendor the way a firm-level agreement does, and the firm cannot see or control that account.
The same checks apply to AI features built into software the firm already licenses, such as office suites, document management systems and PDF or design tools. Those features can run under separate AI terms or default settings, so an approved product does not automatically mean an approved AI feature.
- Training: whether uploads or prompts can be used to train or improve models.
- Retention: how long files and conversations are stored, and how deletion works.
- Access: whether vendor staff can view content and for what purposes.
- Location: where content is processed and stored.
- Administration: whether the firm can manage accounts, enforce settings and remove departing staff.
Which drawings carry the most risk?#
The drawings with the most risk are those whose disclosure could harm the client or the public, not simply those stamped confidential. Ranking project types gives staff a default answer before anyone has to read a contract.
File details travel too. PDF properties, file names and layer names can reveal a client or a site even when the visible sheet looks generic, so a cropped or renamed export is not automatically anonymous.
| Drawing type | Risk level | Default rule |
|---|---|---|
| Security-sensitive facilities, utilities and data centers | Highest | Never upload to outside AI tools |
| Unannounced or confidential developments | High | No uploads without written client approval |
| Private residences with owner details | High | No uploads; treat owner names and addresses as personal information |
| Consultant or client-provided backgrounds | Medium to high | Treat as the other party's material |
| Firm standard details with no project data | Lower | Allowed in approved tools under policy |
A five-rule staff policy for client drawings#
A five-rule staff policy works because people remember it under deadline pressure. A longer AI policy has its place, but these rules cover most of what goes wrong when client drawings meet public AI tools.
Keep the approved project list with each project manager, who knows the contract terms, and revisit it at each phase. Pair the rules with an easy way to ask, so staff check rather than guess.
- Rule 1: use only firm-approved AI tools on firm accounts, never personal accounts for project work.
- Rule 2: never upload client drawings, models or reports unless the project is on the approved list for AI processing.
- Rule 3: strip title blocks, client names, addresses and stamps before any approved upload.
- Rule 4: a named professional reviews any AI-assisted output before it reaches a client or a drawing set.
- Rule 5: report accidental uploads the same day so the firm can assess them and, where required, notify the client.
Uncontrolled uploads versus consented, de-identified licensing#
Uncontrolled uploads and consented data licensing differ in who decides, what leaves the firm and what record exists afterward. Both can involve project information reaching an AI company; only one is planned, approved and documented.
SourceX works in the second column. Under the SourceX five-step transaction, rights review and privacy preparation happen before the firm approves any release, and a SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. The opening assessment asks about systems and record types and never requests drawings.
| Question | Staff upload to a public tool | Consented, de-identified license |
|---|---|---|
| Who decides | An individual, often without asking | The firm's authorized signer, after a rights review |
| Client position | Unknown or not considered | Contracts reviewed; restricted projects carved out |
| Confidential details | Uploaded as they are | Client names, sites and personal details removed first |
| Use terms | The vendor's standard terms | A license defining permitted use, term and restrictions |
| Record kept | Usually none | A documented record of what was released and why |
Illustrative: a firm finds drawings in personal AI accounts#
Illustrative: a fictional architecture firm of about 70 people learns from an IT review that several designers have been pasting floor plans and code questions into personal chat accounts. One affected project is a private school whose agreement includes a security clause covering building layouts.
The principals open a no-blame reporting window, ask staff to list what they uploaded and to which tool, and have counsel review the school agreement for notice obligations. They buy a business plan whose terms exclude content from training, publish the five rules and create an approved project list.
The outcome is a clear record of past exposure, a contract-specific answer for the school project and a tool staff can use without guessing. Uploads of client drawings stop being an individual judgment call.
Frequently asked questions
What should we do if someone already uploaded client drawings?
Record what was uploaded, when, to which tool and under which account, then read the tool's deletion and retention terms. Review the affected client contract for notice obligations with counsel. Do not assume that deleting the conversation removed the file from the vendor's systems.
Are cropped details or screenshots safer than full sheets?
Somewhat, but not automatically. A cropped detail can still carry a project name, a distinctive condition or a client logo, and a security-sensitive layout stays sensitive in pieces. The contract question concerns the information, not the file size, so the same checks apply.
Can staff use AI tools on our own standard details?
Generally yes, where the details carry no project or client information and the tool is approved. Standard details, office templates and master specification sections are usually the safest material for testing AI tools inside a firm, because the firm controls them outright.
Do we need to tell clients we use AI tools?
It depends on the contract and the client. Some agreements now require disclosure or approval, and some public clients ask about AI use in proposals. Even where nothing requires it, many firms explain their policy up front because it answers the question before a client raises it.
Does a business AI plan solve the problem by itself?
No. An enterprise plan addresses training use and account administration, but it does not change what the client contract allows. Firms still need an approved project list, habits for removing identifying details and a named reviewer for AI-assisted output.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.