Choose a color

Can You Use AI Under a Client NDA? What Freelancers Need to Check

Client-Safe AI By Empowering Trends September 27, 2026 5 min read

Most NDAs freelancers sign were drafted before ChatGPT existed, and clients rarely think to update them once AI enters the workflow. That doesn’t mean the agreement stays silent on the question. Standard confidentiality language usually restricts disclosure to any “third party,” and a language model — even a consumer one you’re chatting with for thirty seconds — counts as a third party under most reasonable readings of that clause.

The gap isn’t in the law. It’s in awareness. A client who wrote “do not share confidential information with any third party” in 2022 wasn’t picturing an AI chatbot, but the sentence still applies to one. Pasting their internal roadmap into an AI tool to get help rewriting it is disclosure, whether or not the client anticipated that specific scenario.

This puts freelancers in an odd spot: technically bound by a clause nobody discussed, using a tool that’s become part of ordinary work. The fix isn’t to ignore the NDA and hope. It’s to read what you actually signed, and, where it’s unclear, ask before you paste.

Before you use AI on any project under NDA, go back to the contract and look for four specific things.

Confidentiality scope. What counts as confidential — everything the client shares, or only material marked as such? A broad definition (“all information disclosed in connection with this engagement”) sweeps in far more than a narrow one.

Third-party disclosure. This is the clause that usually catches AI use, even when the contract never mentions AI by name. Look at the actual wording: some NDAs list exceptions, subcontractors for instance, that a strict reading wouldn’t extend to a chatbot.

Data processing. Newer contracts sometimes address this directly — where data can be processed, whether it can leave a certain jurisdiction, whether cloud tools are permitted at all. Older ones usually don’t, which is its own kind of answer.

Ownership of work product. If the contract assigns all IP in the deliverable to the client, that’s usually fine for AI-assisted work. But some agreements go further and restrict the tools or methods used to produce the deliverable, which is worth knowing before you build a workflow around a tool the contract might not permit.

A short conversation at the start of a project avoids a much longer one later. Four questions cover most of what matters.

Are you comfortable with me using AI tools as part of this project? Some clients say yes without hesitation. Others have policies you don’t know about yet — a healthcare client, for instance, may have compliance requirements that make this an easy no.

Is there any information in this project I should treat as more sensitive than the rest? Not every document in a project is equally confidential. A client might be fine with AI touching public-facing copy but not financial projections.

Do you have a preference for which AI tools I use, or ones to avoid? Some companies have already vetted specific tools internally and have opinions about others.

Would you like this noted anywhere in our agreement? Getting the answer in writing, even briefly, protects you both if the question ever comes up again.

Most NDAs won’t mention AI at all, which leaves you interpreting intent rather than reading a rule. Three options, roughly in order of how much friction they add to your workflow.

Ask in writing.

A two-line email — “I use AI tools like Claude or ChatGPT for drafting and editing; wanted to check this is fine for our project before I start” — takes a client thirty seconds to answer and closes the ambiguity for good.

Use AI only on the non-confidential parts.

You can draft a blog post outline with AI while keeping the client’s actual financial data, internal strategy, or unreleased product details out of any prompt entirely. This splits the work rather than avoiding AI altogether.

Use a local AI tool that doesn’t send data to an external server.

This sidesteps the third-party disclosure question because nothing leaves your machine, though it comes with its own tradeoffs in capability and setup time. Local AI vs Cloud AI: A Plain-English Privacy Comparison covers what you’d be giving up.

Silence in a contract isn’t permission. It’s just silence. Treat it that way.

Keep it short and specific. Clients respond faster to a two-paragraph email than a legal memo.

Subject: Quick check on AI tools for [Project Name]

Hi [Client Name],

Before I get started, I wanted to flag that I use AI tools (mainly Claude and ChatGPT) for parts of my workflow — things like drafting, editing, and research. I don’t paste anything confidential or identifying into these tools without checking with you first, but wanted to confirm you’re comfortable with AI being part of the process in general.

Let me know if you’d rather I avoid it entirely, or if there’s anything specific you’d want kept out of AI tools altogether. Happy to work around whatever you prefer.

Thanks, [Your Name]

This does two things at once: it discloses your practice honestly, and it puts the decision in the client’s hands before any ambiguity becomes a problem. Most clients say yes and appreciate being asked.

Everything above is a starting point for a conversation, not a substitute for reading your specific contract or talking to a lawyer about it. NDA language varies enormously between clients, industries, and countries, and a clause that’s harmless in one agreement might be a real constraint in another.

If a project involves genuinely sensitive material — healthcare data, financial records, anything under a regulatory framework like HIPAA or GDPR — the cost of an hour with a lawyer who reviews contracts is small compared to the cost of a confidentiality breach. For lower-stakes projects, asking the client directly is usually enough. The point isn’t to be paranoid about every NDA you sign. It’s to actually read the ones you’ve already signed before you build AI into a workflow that clause might not anticipate.