Is it safe to put a CIM into ChatGPT? A guide for COOs and CCOs

An inner form sits within layered boundaries, suggesting controlled access to confidential information.

An associate has a 90-page CIM open, a screening memo due tomorrow morning, and a ChatGPT tab one click away. Dragging the PDF in would save an hour. Before anyone does that, someone at the firm has to have answered whether it's allowed. Usually that person is the COO or CCO.

The short answer

On a personal account (ChatGPT Free, Plus, or Pro, or Claude Free, Pro, or Max), don't. On a business plan your firm has approved, used within your NDA terms and your compliance policy, it can be done responsibly. Paying for Plus doesn't turn a personal account into a business one. A business plan changes the vendor's defaults and gives you a contract. Whether you can put a particular CIM into that tool still depends on the NDA you signed to get it.

Once a tool is approved, the work itself looks like our walkthrough on drafting a screening memo from a CIM.

Three questions that get mixed together

"Is it safe?" covers three separate questions, and most articles answer only the first.

  1. Will the vendor train its models on our document? On business plans, vendors say no by default. On personal plans, it depends on a setting.
  2. Will the vendor keep it, and who can see it? Every plan keeps data for some period, and the rules differ by plan.
  3. Does sending it break our NDA or our compliance program? This has nothing to do with the first two. A vendor that never trains on your data can still be a party your NDA doesn't allow you to share with.

For a COO or CCO, the third question usually matters most.

Personal accounts vs. business plans

This is what the vendors say about their own products, as of October 2026. Vendor terms change often. We couldn't load OpenAI's help center directly, so confirm the ChatGPT details we cite from it on OpenAI's site.

Personal accountsBusiness plans
PlansChatGPT Free, Plus, Pro. Claude Free, Pro, Max.ChatGPT Business (formerly Team) and Enterprise. Claude Team and Enterprise. Microsoft 365 Copilot.
Training on your chatsChatGPT: may be used unless the user opts out, per OpenAI's help center. Claude: the user chooses, and flagged or rated chats can still be used (Anthropic).Off by default at OpenAI, Anthropic, and Microsoft. Anthropic's exception: chats a user rates or reports.
ContractConsumer terms, accepted by one person.Business terms and a data processing agreement signed by the firm.
RetentionSet by the vendor. Claude keeps chats 30 days after deletion with training off, and de-identified data up to five years with it on (Anthropic).Admins set policy. ChatGPT Enterprise allows a minimum of 90 days (OpenAI). Claude Enterprise allows a minimum of 30 days, with indefinite as the default (Anthropic). Copilot uses Microsoft Purview.
Records for an examThe firm can't search, retain, or export anything.Audit and eDiscovery tools on enterprise tiers, such as the ChatGPT Enterprise Compliance API and Purview for Copilot.

Temporary Chat isn't a compliance control either. OpenAI's help center says temporary chats aren't used for training, but OpenAI may keep a copy for up to 30 days for safety review.

Deleting a chat hasn't always meant it was gone. In May 2025, a federal court in the New York Times copyright case ordered OpenAI to preserve ChatGPT output logs. A later order ended that obligation going forward from late September 2025, but logs already preserved stayed accessible, Engadget reported.

Copilot follows your file permissions. Microsoft says Copilot only shows a user data they already have permission to see, and that Copilot has opted out of the human-review abuse monitoring available in Azure OpenAI. If your SharePoint permissions are loose, Copilot will reflect that. We compare the three tools in more depth in Claude vs. ChatGPT vs. Copilot for investment firms.

What your NDA says about AI tools

A CIM arrives under an NDA, and that NDA is a contract. Securities law doesn't decide whether you can upload it. The NDA's own language does.

Most NDAs were written before generative AI and assume human recipients. In a June 2026 National Law Review article, Darrow Everett argues that entering a counterparty's confidential information into an AI tool may breach an NDA even when the NDA says nothing about AI, because the information leaves the permitted circle and becomes subject to terms the discloser never agreed to. The firm also warns that a model trained on confidential data can't be untrained.

That is law-firm commentary. We found no court decision on whether an AI vendor counts as a third party, or as a permitted Representative, under an NDA. Until a court rules, it depends on your NDA's language and your tool's contract.

  • If the NDA lets you share with Representatives and service providers bound by confidentiality, a business plan with a data processing agreement and no-training terms gives you an argument. Have counsel confirm it.
  • If the NDA is silent, the safer path is written consent from the seller or the banker. It's a short email.
  • If the NDA bans AI tools, don't use them on that deal.
  • A personal account, with no confidentiality contract at all, is the weakest position you can be in.

Is a CIM material nonpublic information?

People often say "CIMs are MNPI." That's imprecise. A CIM for a private company is confidential under your NDA. It becomes material nonpublic information (MNPI) in the securities-law sense when it bears on publicly traded securities: a borrower with public debt, a public parent, or a carve-out from a public company. Many compliance teams treat all deal information as restricted anyway.

Start with the law. Section 204A of the Advisers Act requires every investment adviser, registered or not, to maintain and enforce written policies reasonably designed to prevent misuse of MNPI, as described in a 2022 SEC staff risk alert. In that alert, staff criticized advisers whose diligence on alternative-data vendors was ad hoc and undocumented. The alert doesn't mention AI. Our read is that examiners will apply the same logic to an AI vendor: check it, document it, and check it again.

ACA Group notes that private credit advisers routinely receive nonpublic borrower information, and that a recurring exam finding is missing documentation of when MNPI arrived and how restrictions were applied. Proskauer raises the reverse risk: an adviser that doesn't know whether MNPI went into a model's training data could face questions under Section 204A.

Information barriers are where AI tools need the most care. A shared workspace, shared project files, chat memory, or a connector that reads every folder can let information cross a wall that your policies say is closed. We haven't seen legal commentary on this yet, so test it before rollout.

What the SEC has and hasn't said

There is no AI-specific SEC rule for advisers. The SEC proposed a rule on predictive data analytics in 2023, aimed at conflicts of interest in advice, and withdrew it in June 2025. Existing rules still apply, including fiduciary duty, Section 204A, the compliance program rule, recordkeeping, and Regulation S-P.

The Division of Examinations' fiscal 2026 priorities, released in November 2025, say staff will assess whether firms have adequate policies to monitor or supervise their use of AI. They also name AI-related cyber risks, data loss prevention, oversight of third-party vendors, and private credit. The document says it is not a rule, and it doesn't mention MNPI or deal documents in AI tools, so don't let anyone tell you the SEC has flagged CIMs in ChatGPT.

Regulation S-P is law. The 2024 amendments require registered advisers to have a written incident response program that includes oversight of service providers, and to notify affected customers within 30 days of learning of unauthorized access to sensitive customer information. Reg S-P covers personal information about individuals, so a CIM about a company usually falls outside it. If a CIM includes personal data on owners or guarantors, ask counsel whether your AI vendor becomes a service provider for it.

Recordkeeping

Rule 204-2, the books-and-records rule, predates AI chat. How it applies is still law-firm interpretation.

  • Skadden reads AI-generated content that is never sent as likely not a written communication that must be kept. Content you send to clients or counterparties likely is, if the subject matter is covered.
  • Cooley says AI notes and summaries fall within the rule's definition of a record, and that unsent content can still be required under other provisions. It recommends deciding by category in advance.
  • Morrison Foerster recommends capturing AI output used in client communications or advice, and auditing AI logs periodically.

No rule says to keep every prompt. But if a prompt or output turns out to be a record, a personal account gives the firm no way to retain, search, or produce it. Exempt reporting advisers and family offices may fall outside some of these rules, so confirm your status with counsel.

A checklist before you approve a tool

  • The tool is on a business or enterprise plan the firm controls. Personal accounts are banned for deal material.
  • A signed data processing agreement confirms no training on inputs or outputs, confidentiality, a subprocessor list, breach notice, and deletion at termination.
  • You know the training exceptions, such as chats a user rates or reports, and have turned feedback off org-wide where the plan allows it.
  • Retention is set to match your records policy and your NDA return-and-destroy obligations.
  • You know who at the vendor can see content, and when.
  • You have read the vendor's security report (for example, a SOC 2 Type 2 report), not only its marketing page.
  • Permissions, shared projects, memory, and connectors can't carry information across deal teams or information barriers.
  • Your data classification says what may go in: public, internal, confidential (CIMs), and restricted or MNPI.
  • Deal checklists include a step to read each NDA for AI or third-party limits, and to get written consent when it's silent.
  • You have decided, by category, which AI outputs are records, and you can preserve them under a litigation hold.
  • A person reviews any AI output before it informs an investment decision.
  • The AI policy sits in your compliance manual, staff are trained on it, and vendor diligence is documented and repeated on a schedule.

Why a ban doesn't solve it

In 2023, Bloomberg reported that Samsung banned staff from using generative AI tools after a leak. Engineers had reportedly pasted confidential source code into ChatGPT. We know of no public enforcement case involving an investment firm putting a CIM or MNPI into a public AI tool.

Banning AI has its own cost. Debevoise argues that blanket bans push people toward unapproved tools, much like off-channel messaging. Give the associate with the CIM an approved tool and a clear rule. We wrote about that step in from AI seats to AI workflows.

How we handle it at Giantfish

These questions come up on every engagement we run. We only use the accounts, files, and tools a client approves, and that boundary goes into the statement of work. Workflows run in the firm's own AI account under its existing controls. We set clients up on business plans whose terms keep their data out of model training by default. We follow the client's MNPI policies, and every output is a draft a person reviews. Files shared with us are deleted at handoff, and we confirm it in writing.

Read more about how we handle security and compliance.

This is general information, not legal advice. Check your own NDA terms and compliance policy with counsel.

Sources

Regulators:

Vendors:

Law firms and commentary:

Press: