Guide7 min read

Is It Safe to Use AI to Review or Draft Contracts?

Pasting a raw contract into consumer AI isn't safe: you expose the parties, amounts and secret clauses at once, and you may breach a confidentiality clause.

By Pierre de ONYRI
Worried about your data? Anonymize it before AI

Short answer: pasting a raw contract into a consumer AI is not safe. A contract is one of the most sensitive documents a business has. It gathers, all at once, the names of the parties, their addresses, the amounts, the payment terms, and secret clauses. Pasting it into consumer ChatGPT exposes all of that in one shot. Worse: it can breach the contract's own confidentiality clause. And the AI can misread legal terms. There is a right way to do this, and it's simple.

Why a contract is a high-risk document

A contract is not ordinary text. It's a rare concentration of sensitive data in a single file. It holds the legal name and address of each party. It holds the amounts and payment terms. It often holds a confidentiality clause or an NDA. An NDA is a non-disclosure agreement: it forbids sharing the contents with third parties.

Here's the problem. When you paste the raw text into a consumer AI, you expose everything at once. Not line by line. The whole package leaves at the same moment. That's why a contract deserves more care than a routine email.

Some clauses also protect trade secrets. A trade secret is information with commercial value because it stays secret: a formula, a negotiated price, a client list. Lose it, and you lose the edge. More on that below.

Retention, training, trade secrets: what you expose

Start with training. On consumer versions of ChatGPT, your inputs may feed the models by default. You can opt out in settings. But opting out doesn't erase everything. Per OpenAI's Help Center, opting out does not delete past conversations. Nor does it remove data already used in a completed training run. Put plainly: a contract shared before you turned the setting off cannot be recalled.

Now the trade secret. Per the WIPO guide (the World Intellectual Property Organization), information only qualifies as a trade secret if three conditions are met. It must be secret — not generally known or readily accessible to people in the field. It must have commercial value because it is secret. And its holder must take reasonable steps to keep it secret: confidentiality agreements, controlled access, IT security.

Trade secret protection lasts for an unlimited time. But only while those three conditions hold. Once the information becomes known, published or readily accessible to people in the field, it can lose its protection. Voluntarily disclosing confidential clauses to a third-party AI service, with no confidentiality guarantee, undermines the 'reasonable steps' test. So you can jeopardise trade secret status (WIPO; the USPTO, the US patent office, takes the same line).

Finally, the contract can turn against you. Its own confidentiality clause often forbids sharing its contents with third parties. So uploading the file to an external AI can breach that clause. A UK law firm warns that using ChatGPT could lead to disclosing highly sensitive or confidential information that the tool might misuse (Harper James).

Two-part diagram: at top, a contract in the clear (names, amounts, a confidential clause in amber) travels to a consumer AI that keeps and exposes it; at bottom, the same contract anonymized shows only cobalt tokens, with a checkmark — the identifiers never leave the browser.
After the WIPO guide to trade secrets, Thomson Reuters' analysis of AI reliability in legal practice, and Harper James (drafting an NDA with ChatGPT).

The other risk: an AI that gets the law wrong

Confidentiality isn't the only issue. Reliability matters too. A consumer AI can misread legal terms. A UK law firm notes that an agreement drafted by ChatGPT may be generic, unclear, or unenforceable if challenged. It may omit essential provisions. For example, a data-protection clause required when the parties share personal data under the UK GDPR. And it may be misleading, inaccurate or outdated, because it doesn't reflect the latest case law or jurisdiction-specific rules (Harper James).

The gap with professional tools is stark. One legal-industry analysis puts public AI at roughly 60-70% accuracy in legal research. Systems built on curated legal databases reach 95%+. Worse, AI can fabricate case citations or inaccurate precedents that look authentic. That's why professional responsibility demands verifying AI outputs before you rely on them (Thomson Reuters).

One last point, and it's essential. Delegating judgment to an AI does not absolve the human of responsibility for accuracy. Every workflow that includes AI still needs a human to review and own the outcome. AI-generated contract analysis is a draft to verify. It is not legal advice (Thomson Reuters).

You assumeThe reality
“Pasting the contract just saves me time”You expose the parties, amounts and secret clauses at once
“It's confidential, so it's protected”Disclosing it to a third-party AI can cost you the trade secret
“Sending the contract bothers no one”Its own confidentiality clause may forbid it — you breach it
“The AI draft is ready to sign”It may be generic, omit clauses, or cite a fake precedent
A contract stacks a confidentiality risk and a reliability risk — both are handled before you send.

The fix: anonymize before you send

The good news: the confidentiality risk drops sharply at the source. The practical step is simple. Anonymise or redact the identifying elements of the contract before sending anything to a consumer AI. The names of the parties. The addresses. The amounts. The clauses that identify the deal. You can also use a contractually governed enterprise offering, where the provider commits not to retain or train on your data (Harper James; WIPO).

The logic is mechanical. The fewer identifying elements leave your organisation, the less you expose. And you better protect the trade secret's 'reasonable steps' test. One caveat: anonymisation is not foolproof, a residual risk can remain. But cutting at the source is still the most effective step. And for the underlying legal decisions, always confirm with a qualified professional.

  • Never send the raw contract to a consumer chat.
  • First mask the names, addresses, amounts and identifying clauses.
  • For regular use, prefer an enterprise offering with a contractual commitment.
  • Treat any AI output as a draft to be reviewed by a lawyer.
  1. 1Spot the identifying elements in the contract.
  2. 2Replace them with reversible tokens in the browser.
  3. 3Send only the anonymized text to the AI.
  4. 4Restore the real values in the reply, locally.

That's what ONYRI Sanitize is for. The engine detects the sensitive elements — names, addresses, amounts, identifying clauses — and replaces them with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI finds only tokens, never the real identities or figures. You keep the review help, without leaking what the contract protects — and without treating it as legal advice.

Frequently asked questions

Is it safe to use ChatGPT to review or draft a contract?
Not by pasting the raw contract into a consumer version. You expose the parties, amounts and secret clauses at once. By default those inputs may feed training, and opting out does not erase what was already shared. You may also breach the contract's confidentiality clause. Anonymise the identifying elements before sending, or use a contractually governed enterprise offering.
Can pasting a contract into AI cost me a trade secret?
Yes, it's a real risk. Per WIPO, information is only protected as a trade secret if its holder takes reasonable steps to keep it secret. Voluntarily disclosing confidential clauses to a third-party AI service, with no confidentiality guarantee, undermines that test and can jeopardise the protection.
Can I rely on an AI-drafted contract as legal advice?
No. A consumer AI can produce generic text, omit essential clauses, or cite a fake precedent. Its accuracy in legal research is far lower than professional tools. Treat the output as a draft to verify, and have the underlying decisions confirmed by a qualified professional.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next