Proposal work is full of confidential information: client names, pricing, technical detail, references, sometimes privileged or regulated data. Generative AI makes it trivially easy to paste that information into a tool that was never approved, on terms nobody read. The result is a data leak that happens by habit rather than malice – and one the firm remains responsible for.
This guide covers how to use AI in bids without exposing confidential client data: classifying what you have, choosing approved tools, minimizing what leaves, and having an incident plan before you need one.
The risk is not that AI is uniquely dangerous. It is that copying and pasting is frictionless, and the default tools are the wrong ones.
The nature of the risk
Three properties make AI-assisted data exposure different from a traditional software risk:
- It leaves your perimeter. The moment text is pasted into a browser tool, your access controls stop applying; you cannot audit or recall it.
- The terms differ by tier. Consumer tiers of common AI tools may use inputs to improve models by default; business and enterprise tiers generally do not. The screen looks the same.
- You remain responsible. The client gave their information to you. Your confidentiality obligations did not transfer to a website.
A 2025 Harmonic Security analysis reportedly found sensitive data in 26.4% of file uploads to AI tools. The risk is common, not hypothetical. It is also avoidable, because the exposure happens at a decision point – which tool, which data – that a short policy can govern.
What the professional bodies say
Two developments show where the standard is heading:
- The American Bar Association’s Formal Opinion 512 (July 2024) treats confidentiality and competence obligations as applying to a lawyer’s use of generative AI; boilerplate engagement language is not enough.
- The ICMCI Code of Responsible Use of AI in Management Consulting (June 2026) treats entering confidential client data into AI systems without safeguards as a conduct violation, regardless of the contract.
For any firm handling confidential client information, the direction is clear: AI use is governed by existing duties, not exempt from them. Contractual silence is not permission.
Classify before you upload
Before any document touches an AI tool, assign it a tier and apply a rule.
| Tier | Examples | Rule |
|---|---|---|
| Public | Published marketing, public standards, your own website copy | Usable within the approved tool |
| Internal | Internal templates, non-confidential drafts | Approved tool only; no client identifiers |
| Confidential | Client names, pricing, technical detail, references | Redact identifiers; approved tool with no-training terms |
| Regulated | Personal, financial, health or privileged data | Do not enter without documented approval and controls |
The classification is what turns a vague instruction (“be careful with AI”) into a decision a busy person can actually make.
Choose the right tool, and read the terms
The difference between safe and unsafe is the tier, not the brand.
- Use a business or enterprise tier with a no-training commitment and a data-processing agreement.
- Read the terms for your exact plan, not the marketing page. “Not used for training” and “not stored” are different promises; several enterprise tiers still retain content for a period for abuse monitoring.
- Name one approved tool so the default choice is the right one, and make it easy to use.
- Prohibit consumer tiers for confidential work – and offer the approved alternative, or people will route around the policy.
A blanket ban that leaves no approved path usually fails: the work pressure does not disappear, so use moves to personal accounts where the firm has no visibility at all.
Minimize what leaves
Even with an approved tool, reduce the data before it goes in.
- Redact direct identifiers – names, emails, exact addresses.
- Check for re-identification. A rare job title, an exact deal size or a date plus a location can identify a person even without a name.
- Minimize context. Send only what the task needs.
- Separate client workspaces so one engagement’s content never carries into another’s.
- Avoid pasting regulated data unless you have documented approval and controls.
Minimization is a data-protection principle as well as a security one, and it shrinks the compliance surface of everything you do with AI.
Handle retention, deletion and incidents
Know what happens to the data after the task, and plan for the day something goes wrong.
- Know the retention window for your tier, including abuse-monitoring logs.
- Confirm the deletion path before you rely on it.
- Write a short incident checklist now: stop processing, preserve a record, identify what was exposed, check the vendor’s deletion path, notify the accountable owner, and assess whether client notice is required.
- Rehearse it once on a low-stakes document so the steps are familiar under pressure.
An incident handled with a written process is survivable; one improvised is not.
A data-handling checklist for a bid
Before a bid starts, confirm:
- The approved tool and tier are in place, with no-training terms confirmed for that plan.
- Every input is classified: public, internal, confidential or regulated.
- Identifiers are redacted, and re-identification risk is checked.
- Client workspaces are separated, with no shared history between engagements.
- The retention window is understood, including abuse-monitoring logs.
- The incident checklist is written and someone knows the steps.
Run it before the first prompt, not after the first problem. Run this once per bid, and the exposure risk drops sharply. It takes minutes and prevents the exposures that are hardest to defend. Print it, work it, and keep the record with the bid file so you can show exactly how data was handled if a client ever asks.
Common mistakes
- Treating contractual silence as permission. Silence on AI is unresolved, not consent.
- Assuming a business tier is automatically safe. The tier is necessary, not sufficient; check the training and retention terms.
- Confusing “not trained on” with “not stored.” They are separate settings.
- Banning without an approved alternative. It drives use underground.
- No incident plan. Improvising during a data event multiplies the damage.
Frequently asked questions
Is it safe to put client data into an AI tool?
Only with the right controls: an approved business or enterprise tier with no-training terms, a data-processing agreement, redaction of identifiers, separated workspaces, and an internal policy. Consumer tiers and contractual silence are not safe defaults.
Can I paste an RFP into ChatGPT or Claude?
Treat the whole bid under a defined policy. Client-issued solicitation text is often lower risk than your or your client’s confidential data, but never use a consumer tier for confidential or regulated material, and never enter client identifiers without documented approval.
Does an enterprise AI tier protect client data?
It reframes the vendor as a processor with a data-processing agreement and usually a no-training commitment, which covers most of the mechanics. But you still retain confidentiality duties, retention still applies for some periods, and you must configure and use it correctly.
What should an AI policy cover for bids?
Which tools are approved, which data tiers may and may not be entered, how identifiers are handled, who to ask when unsure, and who reviews the list. Half a page is enough for most firms. See AI Proposal Governance.
What do you do if confidential data is exposed?
Stop processing, preserve an internal record, identify what was exposed, follow the vendor’s deletion path, notify your accountable owner, and assess whether client notice is required. Write the checklist before an incident, not during one.
How do you decide which tool is safe for a bid?
Match the tool tier to the data tier. Confidential work requires an approved business or enterprise tier with confirmed no-training terms; regulated data requires documented approval and controls. Consumer tiers are never appropriate for confidential client data.
Do we need a data-processing agreement with AI vendors?
For any tool processing client personal data, yes – a data-processing agreement plus a no-training commitment is the baseline for a processor relationship. Without one, you may not be able to satisfy your own obligations to the client.
Next step
Protect the bid before you speed it up. Classify your data, name an approved tool, minimize what leaves, and write the incident checklist now. Download the AI Proposal Governance Checklist to set your tool and data rules, and see The Human-Verified Workflow for AI Proposals for how verification fits alongside data protection.
Sources
- American Bar Association, Formal Opinion 512 (July 2024): confidentiality and competence duties applied to generative AI use.
- ICMCI, Code of Responsible Use of AI in Management Consulting (June 2026): entering confidential client data into AI systems without safeguards as a conduct violation.
- Harmonic Security analysis (November 2025): sensitive data in 26.4% of file uploads to AI tools.
- Vendor documentation on tier-level training and retention defaults (OpenAI, Anthropic, Google): consumer vs. business/enterprise data handling.
Numbers are cited from their sources and dated. Where a source is a vendor claim, it is identified as such. This article is not legal advice; confirm obligations with qualified counsel.