Skip to content

Leadership and readiness

Should you sign an NDA before discussing your data with an AI company?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

You should sign an NDA before sharing any samples, schemas or confidential deal context with an AI company, but you do not need one for a metadata-only fit check that names systems, record families and years of history. When you do sign, the NDA should bar training on samples, limit use to evaluation and require deletion.

Key takeaways

  • No NDA is needed for a metadata-only conversation about systems, record families and years of history.
  • Sign an NDA before sharing any sample, schema, field list or deal context such as a pending sale or shutdown.
  • A data-specific NDA must forbid training, fine-tuning or testing models on samples, not just disclosure.
  • Strike or narrow residuals clauses, which can let the recipient use whatever its people remember.
  • An NDA does not replace a privacy review: personal data needs de-identification and the right terms before it moves.

When do you need an NDA with an AI company?#

An NDA with an AI company is needed the moment anything beyond descriptive metadata will change hands. That includes sample records, even redacted ones, database schemas and field lists, documentation of internal processes, and confidential context such as a pending sale, a shutdown or a system retirement.

An NDA is not needed for a metadata-only conversation. Telling a buyer that your help desk holds many years of tickets linked to engineering issues, or that your dispatch system keeps job notes and callbacks, reveals little a competitor could use. Insisting on an NDA at that stage mostly slows a conversation that may not go anywhere.

A useful rule of thumb: if you would be uncomfortable seeing the information in a competitor's slide deck, sign first.

There is also a trade secret reason to sign before sharing process documents or playbooks. DOJ guidance describes trade secret protection as depending on reasonable measures, not absolute ones, and lists confidentiality agreements and need-to-know access among its examples. Handing over internal procedures with no confidentiality terms may make a later trade secret claim harder to support.

What can you share without an NDA, and what needs one?#

The line falls between describing your records and showing them. The table below sorts common items by whether confidentiality terms should come first.

What can you share without an NDA, and what needs one?
InformationNDA first?Notes
System names and record familiesNoEnough for a fit check
Approximate years of history and volumesNoRanges are fine; avoid customer counts
Known restrictions in general termsNoName categories, not specific customers
Field lists, schemas and data dictionariesYesThey reveal how you run the business
Redacted sample recordsYesAlso needs a de-identification review
Process documents and playbooksYesOften trade secret material
Pending sale, shutdown or migrationYesDeal context is sensitive in its own right
Your price expectations and deal termsYesKeep negotiating positions confidential

Mutual or one-way: which NDA fits a data discussion?#

A mutual NDA usually fits a data discussion, because both sides disclose something: you share records and context, and the buyer shares what it is building, the data it needs and how it evaluates samples. Many AI developers propose their own mutual form.

Mutual is fine as long as the obligations really are mutual. Read the buyer's form for one-sided carve-outs, such as broad exceptions for information the buyer independently develops, or a shorter confidentiality period for the supplier's information than for the buyer's.

Which NDA terms matter most for data?#

The NDA terms that matter most for data are the ones a standard form leaves out. Most templates were written for business plans and product roadmaps, not for records that can be copied into a training run.

  • Definition: confidential information expressly includes samples, schemas, unpublished metadata and anything derived from them.
  • Purpose limit: use is restricted to evaluating a potential license.
  • No model use: no training, fine-tuning, testing or benchmarking of any model on the samples.
  • No re-identification: no attempt to identify people or customers in de-identified records.
  • Recipients: named teams only, and no subcontractors or annotation vendors without written consent.
  • Return or destroy: deletion of all copies, including notebooks, logs and caches, with written confirmation.
  • No license granted: the NDA gives no rights to the data beyond evaluation.
  • Term and survival: confidentiality that lasts long enough, and for as long as trade secrets remain secret.
  • Compelled disclosure: notice before any disclosure required by law, where notice is permitted.

The residuals clause and other traps#

The residuals clause is the most dangerous term in a buyer's standard NDA. It lets the recipient use information retained in the unaided memory of its people, which in a data discussion can blur into the patterns and structure of your records. Strike it, or limit it so it never covers samples or data.

Two other traps are worth checking. An independent development exception is reasonable in principle, but for an AI developer it can be hard for you to disprove, so ask that it not apply to anything derived from your samples. A feedback clause can grant the buyer rights in suggestions you make; it should not reach your data or documentation.

Standard NDA versus a data-ready NDA#

A data-ready NDA differs from a standard form in a handful of clauses, and those clauses decide whether a sample stays a sample. Use the comparison below when marking up a buyer's paper or preparing your own.

Keep a disclosure log alongside the NDA. Record what was shared, when, with whom and in what form, so the return-or-destroy obligation can be checked against an actual list rather than memory.

Standard NDA versus a data-ready NDA
ClauseTypical standard formData-ready version
DefinitionBusiness, technical and financial informationAlso samples, schemas, metadata and anything derived from them
Permitted useEvaluating a business relationshipEvaluating a license only; no model training, testing or benchmarking
RecipientsEmployees, advisors and contractors with a need to knowNamed team; contractors and annotation vendors only with consent
ResidualsOften allows use of information retained in memoryDeleted, or excluded for samples and data
Return or destroyOn request, with exceptions for routine backupsAll copies, including notebooks, logs and caches, with written confirmation
Re-identificationUsually not addressedExpress ban on identifying people or customers

Illustrative: a consulting firm answers a sample request#

Illustrative: a fictional operations consulting firm is asked by an AI developer for redacted proposal sections and internal project review notes. The firm's general counsel receives the developer's mutual NDA the same day.

The form has a broad residuals clause, permits disclosure to contractors and says nothing about model use. The general counsel strikes the residuals clause, adds a no-training and no-benchmarking clause, limits recipients to the named evaluation team and requires an officer-signed deletion certificate after evaluation.

The developer accepts every change except the contractor restriction, and the parties settle on contractor access only with the firm's consent for each contractor. The firm then de-identifies a small set of documents, removing client names and engagement details, and shares them only after the managing partner approves the release.

How SourceX handles confidentiality before samples#

SourceX keeps the initial assessment to metadata, so no NDA is needed to find out whether a company is a fit. Samples move only later in the SourceX five-step transaction, after confidentiality terms are in place, de-identification is applied and the supplier approves the release.

Each release is recorded in the SourceX Evidence Packet, including permitted use and release authorization, so the terms attached to a sample are documented in the same way as the terms of a full license.

Frequently asked questions

Does an NDA stop an AI company from training on our sample?

Only if it says so. A standard NDA restricts disclosure, not model use, so add an express prohibition on training, fine-tuning, testing and benchmarking. Even then, an NDA is a contract you would have to enforce, so the strongest protection is to share as little as possible and only de-identified samples.

Should the NDA be with the intermediary, the buyer or both?

If an intermediary sits between you and the buyer, you generally want confidentiality terms with each party that will receive your information. Check that the intermediary's terms with the buyer are at least as protective as its terms with you, and ask to see them.

Can we use the AI company's standard NDA?

You can start from it, but review it as a data agreement rather than a routine form. Check the definition of confidential information, purpose limits, model use, residuals, recipients and deletion, and expect to negotiate those points.

Is an NDA enough to share records that contain personal data?

No. An NDA governs confidentiality between companies; it does not satisfy obligations to the people in the records. De-identify samples first, and have counsel check whether data processing terms or other safeguards are needed under the privacy laws that may apply.

How long should confidentiality last?

Long enough to cover the value of what you share. Many NDAs set a fixed term for ordinary information and keep trade secrets confidential for as long as they remain secret. Agree the term with counsel based on how sensitive the samples and context are.

What if the AI company refuses a no-training clause?

Treat that as a signal about how samples would be used. You can offer a written description of fields and record structure instead of real records, or keep the conversation to metadata until a full license with permitted use terms is negotiated. Sending real samples without the clause is a risk to weigh with counsel.

Sources

  • DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing examples such as limiting access on a need-to-know basis and requiring confidentiality agreements. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify