DECODED: Confidentiality, AI and You
Are you unknowingly violating confidentiality agreements?
This is Decoded: AI tools for getting straight answers from complex investment documents.
Every time you upload a quarterly report to ChatGPT, you may be violating a confidentiality agreement.
How can you continue to leverage AI and remain a good little LP?
Let’s break down some basics of how AI works, where the risks are, and what you can do to get the data you want while maintaining the confidentiality required by your subscription agreement.
Confidentiality, Third Parties, and Data Sharing
Confidentiality Clauses
Most subscription agreements include a confidentiality clause. These clauses are written to prevent harm resulting from information shared with “third parties” who might use that information against the GP; not to limit the necessary and benign use of information for practical analysis.
By signing the subscription agreement, the parties are legally obligated to honor the terms of that agreement - whether or not the document was read, the terms appear unfair, or any other number of excuses. If it was signed, it was agreed.
Who is a “Third Party”?
A third party is - in the most literal sense - any entity other than you. Many third parties are benign and necessary: Adobe, Excel, Gmail, your CPA, and your attorney are not scraping and nefariously using data. This is in line with the intent of confidentiality.
Other third parties such as disgruntled investors and competitors may be motivated to collect and use confidential information in a way that is damaging. Information intentionally or unintentionally shared is clearly not in line with your confidentiality obligations. This is what we want to avoid.
When sharing, consider not only who the third party is, but how the third party is maintaining your obligation to confidentiality.
AI and Data Sharing
The power of AI comes from indexing all of the world’s known information - including what users feed it. Data sharing is a feature by default.
But not all AI bots are the same: some share data and others do not. The following outlines the data sharing defaults for free consumer accounts*.
*Enterprise solutions for all tools may prevent data sharing, but this is not a practical solution for most individual users.
Paid versions typically provide expanded useage limits, not confidentiality layers.
Check the fine print of your AI tool, subscription, and settings for details on data sharing.
IMPORTANT NOTE
Using AI feedback features immediately and irrevocably shares all of the chat’s information (the documents, the prompts, literally everything) - regardless of the tool, settings, or permissions.
Traceability
Source information can be released into the universe of the internet, but does it matter?
Every time a user uploads information to an AI tool (other than the exceptions noted above), that information is added to the world’s database of knowledge. That is a very small drop in a very big ocean.
But no matter how small the leak, sharing data is NOT compliant with the intent of confidentiality.
Now that the information is out, can it be found?
AI itself operates within a black box that is difficult to understand and predict, so knowing how and what information may be revealed is nearly impossible to calculate. Given the vastness of the internet, the chances that the particular details of a deal will be revealed via a routine use of AI seem extremely remote.
Despite the remote possibility of discovery, again, this is NOT compliant with the intent of confidentiality.
Can the offending party be identified?
It is not possible to track AI source data back to the user who provided it due to privacy and encryption used by AI tools. However, the investors in a deal are known to the GP, and if the leaked information is somehow unique, that could potentially be tracked back to an individual.
Even if the risk of being caught is slim to none, this is still not in alignment with intent.
Should I be worried about using AI?
This is a very long line of circumstances: if confidential information is shared + if it is discovered + if the data provided by the offending party is somehow unique from that provided to all other investors = a possible problem for the LP.
But, no matter how remote the risk, releasing information to an unsecured space is NOT compliant with the intent and obligation to maintain confidentiality.
Keeping it Confidential
It is possible to meet the intent of confidentiality if AI is used correctly.
The Easiest Solution
Use NotebookLM + never give feedback.
The underlying model for NotebookLM is web-based, but the source information you upload remains within your NotebookLM account; it is not used to train Google's models or shared elsewhere.
REMINDER: use of the feedback buttons will automatically and irrevocably share the entire chat: all the documents, prompts, etc. To maintain confidentiality, don’t use the feedback function.
Not Secure
ChatGPT, Gemini, and Claude share by default and are not secure.
ChatGPT and Gemini release information from uploaded sources. This cannot be changed or undone.
Claude does the same if the user has opted in to model training - which many users did without realizing it when Anthropic introduced the choice in late 2025.
If you are really committed to one of these AI bots, you can anonymize the data and still get the answers you want. But, that requires manual redaction and other time-intensive work that would probably be better spent just reading the documents yourself.
REMINDER: paid does not ensure privacy. Check the fine print of your AI tool, subscription, and settings for details on data sharing.
Bottom Line
The Pandora’s box of the internet and AI is open; the world is not going back. However, it’s important to understand where and how information may be shared and act accordingly.
Will proprietary data get shared? Possibly.
Will it be discovered? Maybe.
Will the leak source be tracked down? Unlikely.
Do you have a responsibility to maintain confidentiality? Absolutely.
Can you control how and where information is shared? Definitely.
Can we use AI and maintain confidentiality? Yes - if used conscientiously.
Your Turn
What tools are you using and how are you approaching confidentiality?



