Artificial intelligence is rapidly changing how businesses create documents, analyze information, communicate with customers, develop products, review contracts, write software, and make operational decisions. The same capabilities that make generative AI valuable, however, can also create new pathways through which confidential information escapes an organization’s control. An employee may paste an internal financial report into a public chatbot. A developer may use proprietary source code to obtain debugging assistance. A vendor may retain customer prompts to improve its models. An AI application connected to internal databases may reveal restricted information after receiving a malicious prompt. In each scenario, the business may discover that its traditional non-disclosure agreement was written for an earlier technological environment.
Conventional non-disclosure agreements generally assume that confidential information moves between identifiable people and organizations through relatively familiar channels. The agreement prohibits the receiving party from disclosing the information, limits its permitted use, and requires its return or destruction when the relationship ends. Generative AI complicates each of those assumptions. Information submitted to an AI system may pass through cloud infrastructure, application programming interfaces, logging systems, security tools, model providers, subcontractors, data repositories, embeddings, vector databases, and automated monitoring platforms. The person entering the information may not know where it is stored, how long it is retained, or whether it will be used to improve a model.
An effective AI-era NDA must therefore do more than declare information confidential. It must address how information is collected, processed, transmitted, retained, used, accessed, reproduced, and deleted throughout the AI lifecycle. It should work together with the company’s cybersecurity program, vendor agreements, data-processing terms, employment policies, incident-response plan, and internal AI governance procedures. The goal is not to prohibit productive AI use. The goal is to ensure that AI use occurs within clearly defined legal and technical boundaries.
AI data leakage occurs when confidential, proprietary, regulated, or otherwise restricted information becomes accessible to an unauthorized person, system, model, or process. The disclosure may be intentional, accidental, or technically indirect. It may occur when information is entered into an AI tool, when an AI provider retains the information, when a model generates an output containing restricted material, or when an attacker manipulates an AI application into revealing information from a connected system.
The most visible form of leakage occurs when employees place confidential information into an externally hosted generative AI platform. Prompts may contain customer records, contract terms, trade secrets, pricing information, employee data, legal advice, source code, acquisition plans, or nonpublic financial information. Even when a provider represents that customer data will not be used for general model training, the information may still be temporarily retained for abuse monitoring, troubleshooting, legal compliance, system administration, or other operational purposes. A business must therefore evaluate the complete data-handling environment rather than relying on a simplified promise that its information will not be used to “train the model.”
Leakage can also occur through AI outputs. An application may retrieve information from an internal knowledge base and reveal it to a user who lacks permission to see the underlying source document. A customer-service chatbot may disclose information belonging to another customer. A coding assistant may reproduce confidential code or credentials that were included in its context. An AI agent with access to email, cloud storage, or business software may retrieve and transmit more information than the user intended.
The OWASP Top 10 for Large Language Model Applications identifies prompt injection and sensitive-information disclosure as leading risks in generative AI applications. Prompt injection occurs when instructions supplied directly by a user or indirectly through external content cause the AI system to disregard its intended restrictions. Sensitive-information disclosure can involve personally identifiable information, financial records, health information, credentials, confidential business information, legal documents, proprietary models, or source code.⁴ These risks demonstrate why confidentiality cannot be managed exclusively through contract language. The NDA must be supported by access controls, system architecture, testing, monitoring, and incident-response procedures.
A traditional NDA may prohibit disclosure to a “third party” without explaining whether an AI provider, cloud host, application developer, or model subcontractor constitutes a third party. It may permit use of confidential information for a broad “business purpose” without identifying whether model training, fine-tuning, evaluation, analytics, or product improvement falls within that purpose. It may require information to be returned or destroyed without addressing backup copies, prompt logs, embeddings, derived datasets, model weights, or information that has been incorporated into a machine-learning system.
These gaps can produce disputes over interpretation. A vendor may argue that submitting information to its model was merely part of providing the contracted service. A customer may contend that any use beyond generating the requested output violated the agreement. A provider may claim that de-identified, aggregated, or “derived” information is outside the definition of confidential information. The customer may respond that the derived information reveals commercially sensitive patterns, business volume, customer behavior, or operational strategy.
The Federal Trade Commission has warned that companies offering AI models must honor their privacy and confidentiality commitments. The FTC has specifically recognized the tension between an AI provider’s interest in obtaining additional data and its contractual or public commitments to protect customer information. The agency has also stated that representations concerning model training and data use may create enforceable obligations, regardless of whether those representations appear in a formal contract, privacy policy, promotional material, online marketplace, or other communication.⁵
Accordingly, businesses should not rely on general confidentiality language or marketing statements. The agreement should precisely define the information covered, the purposes for which it may be used, the systems through which it may be processed, the parties that may access it, and the technical and organizational measures that must protect it.
An AI-focused NDA should define confidential information broadly enough to encompass both traditional business information and information created or transformed through AI processing. The definition may cover prompts, uploaded files, training data, retrieval sources, customer records, employee information, system instructions, model configurations, source code, credentials, embeddings, vector representations, outputs, evaluations, feedback, usage metadata, analytics, and information inferred from the customer’s use of the service.
Usage data desserves particular attention. An AI provider may be able to infer a company’s business volume, geographic expansion, product-development priorities, customer concerns, transaction activity, staffing needs, or strategic direction from the frequency and nature of its AI requests. Even when the actual prompt content is not retained, metadata concerning those requests may have independent commercial value. The NDA should therefore distinguish technical telemetry reasonably required to operate and secure the service from information used for advertising, benchmarking, competitive analysis, product development, or other secondary purposes.
The definition should also address combinations and transformations of information. Confidential information should not lose protection merely because it has been summarized, reformatted, tokenized, embedded, translated, analyzed, or incorporated into an output. A financial projection remains sensitive when summarized by an AI model. Proprietary code remains sensitive when converted into an explanation or pseudocode. Customer information remains regulated when extracted from a document and placed into a structured dataset.
At the same time, the definition should preserve customary exclusions for information that becomes public without breach, was already lawfully known to the recipient, is received lawfully from an unrestricted third party, or is independently developed without use of the disclosing party’s information. The party relying on an exclusion should bear the burden of proving that it applies through contemporaneous records. This is particularly important where the recipient operates models trained on large datasets and may otherwise argue that similar information emerged from a different source.
The NDA should state that confidential information may be used only to perform specifically identified services for the disclosing party. Broad permission to use information for “business purposes,” “service improvement,” or “research and development” may authorize more activity than the customer intends.
For an AI service, the agreement should distinguish between processing necessary to generate the customer’s requested output and processing that benefits the provider more generally. The provider may need to transmit prompts through its systems, maintain limited security logs, investigate abuse, or create temporary processing copies. Those activities can be described and permitted. Training a general-purpose model, fine-tuning a model for other customers, creating commercial datasets, developing unrelated products, or using customer interactions to evaluate market demand should require separate and express authorization.
The contract should also address human review. Some providers allow personnel or contractors to review prompts and responses for quality assurance, safety evaluation, abuse investigation, or technical support. If human access is permitted, the agreement should identify the permissible circumstances, restrict access to personnel with a legitimate need, require confidentiality obligations, and maintain auditable records of access.
A purpose limitation becomes especially important where an AI vendor changes its services or terms over time. The agreement should provide that new uses of customer information require advance written notice and, where appropriate, affirmative written consent. A provider should not be able to transform a limited service relationship into a broad data license merely by revising an online policy. The FTC has cautioned that quietly changing terms to authorize materially different data uses may create consumer-protection concerns.⁵
One of the central provisions in an AI NDA should address whether customer information may be used to train, retrain, fine-tune, evaluate, test, benchmark, or otherwise improve an AI model. A statement that data will not be used for “training” may be too narrow if it does not cover related practices.
The agreement should specify whether the restriction applies to foundation models, customer-specific models, classifiers, safety systems, retrieval models, ranking systems, and other machine-learning components. It should also apply to prompts, attachments, outputs, corrections, ratings, feedback, usage patterns, and inferred information. Otherwise, the provider may refrain from training on the original document while still using the customer’s corrections or outputs as evaluation data.
The parties should decide whether customer-specific improvement is permitted. In some arrangements, the customer may want the model to learn from its terminology, documents, or prior interactions. That type of personalization can be valuable, but it should occur within a segregated environment and solely for the customer’s benefit. The agreement should state who owns the resulting model, configuration, adapter, fine-tuning dataset, or other improvement and what happens to those materials when the relationship ends.
Where training is prohibited, the restriction should extend to the provider’s affiliates and subprocessors. It should also prohibit indirect workarounds, such as using customer data to generate synthetic training data or using customer outputs to evaluate a generally available product. The FTC has indicated that confidentiality commitments concerning AI data use apply to both direct use and attempts to accomplish the same result through alternative methods.⁵
Many AI vendors do not operate every part of their service. A business may contract with an application developer that sends information to a separate foundation-model provider, hosts data with a cloud provider, uses third-party monitoring tools, and relies on contractors for support. The customer’s confidential information may therefore be handled by several entities that are not named in the primary agreement.
The NDA should require the vendor to identify material subprocessors and model providers before receiving confidential information. The customer should receive notice of material changes and, in higher-risk arrangements, an opportunity to object. Each subprocessor should be bound by written obligations at least as protective as those imposed on the primary vendor. The primary vendor should remain responsible for its subprocessors rather than requiring the customer to pursue an unfamiliar third party.
The contract should also address where information will be stored and processed. Geographic location can affect regulatory obligations, government-access risks, litigation procedures, and the practical ability to enforce contractual remedies. A representation that data will remain in the United States, for example, should apply to backups, logs, support access, and disaster-recovery environments rather than merely the primary application database.
Secure deployment guidance issued by the NSA, CISA, and international partners emphasizes the importance of evaluating externally developed AI systems, protecting deployment environments, controlling access, monitoring system activity, securing model and data components, and preparing for incidents.³ An NDA should incorporate those operational realities by requiring the vendor to maintain an appropriate security program rather than treating confidentiality as a purely legal promise.
A confidentiality obligation without minimum security requirements may leave the recipient free to decide what safeguards are reasonable. For low-risk information, that flexibility may be acceptable. For trade secrets, personal information, regulated data, or mission-critical business information, the agreement should establish measurable requirements.
The security provisions should require administrative, technical, and physical safeguards appropriate to the sensitivity of the information. Relevant controls may include encryption during transmission and storage, multifactor authentication, role-based access, least-privilege permissions, logging, vulnerability management, secure software development, network segmentation, employee training, backup protection, data-loss prevention, and periodic risk assessments.
The NIST Cybersecurity Framework 2.0 organizes cybersecurity risk management around governance, identification, protection, detection, response, and recovery.² The NIST Generative AI Profile applies risk-management concepts specifically to generative AI and addresses issues such as data privacy, information security, human oversight, supply-chain risk, testing, monitoring, and incident management.¹ An agreement need not reproduce these frameworks word for word, but it can require a security program reasonably aligned with recognized standards.
Security language should avoid unsupported promises of absolute protection. No system can guarantee that a breach will never occur. A more workable standard requires safeguards that are reasonable and appropriate to the nature of the information, foreseeable threats, the vendor’s role, and the consequences of unauthorized disclosure. For especially sensitive deployments, the customer may require documented compliance with a specific framework, independent testing, penetration assessments, or relevant certifications.
An AI system may comply with its written NDA obligations while still exposing information because of poor application design. A chatbot connected to internal documents, for example, may retrieve confidential material in response to a cleverly constructed prompt. An AI agent may have permission to search an entire email account when it needs access to only one folder. A system may rely on the model itself to decide whether a user is authorized to receive particular information.
The agreement should require access controls to be enforced outside the language model. A model should not receive information that the requesting user is not authorized to access. Retrieval systems should filter source materials based on the user’s identity and permissions before those materials enter the model’s context. AI agents should receive only the minimum tools and privileges necessary for the assigned task.
Prompt injection should be addressed through testing, input handling, isolation of trusted instructions, output validation, monitoring, and limitations on autonomous actions. OWASP recognizes that prompt injections may be direct or indirect and may arise from content contained in websites, documents, emails, or other materials processed by the system.⁴ A malicious instruction hidden in an uploaded document can therefore affect an AI application even when the human user never sees it.
The NDA or related security addendum should require the provider to test for reasonably foreseeable disclosure paths and remediate material vulnerabilities. Where the AI system can take actions, access external systems, or retrieve confidential records, the agreement should also require appropriate approval steps, transaction limits, and mechanisms to stop or reverse unauthorized activity.
Confidentiality agreements play an important role in trade-secret protection because federal and state law generally require the owner to take reasonable measures to preserve secrecy. Under the federal Defend Trade Secrets Act, protected information must derive economic value from not being generally known and must be subject to reasonable measures to keep it secret.⁶ Michigan’s Uniform Trade Secrets Act similarly protects information that has economic value from secrecy and is subject to reasonable efforts to maintain that secrecy.⁷
An NDA is evidence of reasonable measures, but it is not conclusive by itself. A company that signs confidentiality agreements while allowing unrestricted use of public AI tools may have difficulty explaining how it protected the information. Courts evaluating trade-secret claims may consider access restrictions, employee policies, document markings, vendor controls, monitoring, training, and the organization’s response to known risks.
Businesses should therefore integrate AI restrictions into their trade-secret program. Employees and contractors should understand which AI tools are approved, which categories of information may be entered, and when authorization is required. Highly sensitive information should be technologically blocked from unapproved services where feasible. Access to internal AI systems should correspond to business need, and departures or role changes should trigger prompt access reviews.
The agreement should preserve the availability of injunctive relief for actual or threatened misappropriation. Monetary damages may be inadequate when a trade secret has been placed into an external model or disseminated through an AI system. The federal statute and Michigan law permit courts to enjoin misappropriation and award damages under appropriate circumstances.⁶ ⁷ Contract language recognizing irreparable harm can support an application for equitable relief, although the ultimate decision remains with the court.
Many AI leaks begin without malicious intent. An employee may use an unauthorized chatbot because it produces faster results. A contractor may upload customer information to an AI transcription service. A manager may create meeting summaries through a personal account. These practices are sometimes described as “shadow AI” because the tools operate outside the organization’s approved technology and security processes.
Employee and contractor NDAs should expressly address AI-assisted use and disclosure. The agreement should state that entering confidential information into an unauthorized AI system constitutes a prohibited disclosure or use, even when the employee does not intend to publish the information. It should require compliance with the company’s AI, information-security, records-management, and acceptable-use policies as amended from time to time.
Policies should be practical rather than purely prohibitory. Employees need approved alternatives for common tasks such as summarization, drafting, translation, coding, and research. If every AI tool is banned while employees remain under pressure to increase productivity, unauthorized use is likely to continue. An effective program classifies information, approves tools based on risk, and gives employees clear examples of permitted and prohibited conduct.
Employment-related confidentiality agreements must also account for statutory whistleblower protections. The Defend Trade Secrets Act provides immunity for certain confidential disclosures of trade secrets to government officials or attorneys for reporting or investigating suspected legal violations, as well as disclosures made in sealed court filings. Employers must provide notice of that immunity in agreements governing trade secrets or confidential information if they wish to preserve eligibility for certain exemplary damages and attorney-fee remedies. The statute defines employees for this purpose to include contractors and consultants.⁶
An NDA does not replace privacy, cybersecurity, or breach-notification laws. When AI systems process personal information, the parties must determine which laws apply, which party owns or controls the information, and which party must investigate and report an incident.
Michigan’s Identity Theft Protection Act requires notice in specified circumstances when certain unencrypted and unredacted personal information is accessed and acquired by an unauthorized person, unless the person or agency determines that the breach is not likely to cause substantial loss, injury, or identity theft. Required notice must be provided without unreasonable delay. A service provider maintaining information it does not own or license may also be required to notify the owner or licensor of the information.⁸ Contractual incident-notification provisions should allow the customer enough time to evaluate these obligations.
Sector-specific rules may impose additional requirements. Financial institutions covered by the FTC Safeguards Rule must develop, implement, and maintain an information-security program containing administrative, technical, and physical safeguards. Covered institutions are also responsible for taking steps to ensure that relevant service providers protect customer information.⁹ Health-care covered entities and business associates subject to the HIPAA Security Rule must protect the confidentiality, integrity, and availability of electronic protected health information through appropriate safeguards.¹⁰
The NDA should identify categories of regulated information that may not be processed unless the vendor has agreed to the required contractual and security obligations. A general confidentiality clause is not a substitute for a business associate agreement, data-processing agreement, financial-services security provision, or other legally required instrument.
The agreement should define a security incident broadly enough to include unauthorized access, disclosure, acquisition, alteration, loss, or use of confidential information. It should also cover incidents affecting prompts, outputs, model configurations, embeddings, logs, connected systems, credentials, and relevant subprocessors.
Notification should occur promptly after discovery rather than only after the vendor completes its investigation or conclusively determines that legal notice is required. A customer may face regulatory, contractual, litigation, insurance, and public-relations deadlines that cannot be managed if the vendor delays disclosure. The notice should describe what occurred, when it occurred, the information and systems affected, containment measures, known recipients, and the steps being taken to investigate and remediate the incident.
The vendor should preserve relevant evidence, including logs, access records, system configurations, prompts, outputs, and forensic materials. It should cooperate with the customer’s investigation and provide periodic updates. The parties should determine who controls communications with affected individuals, regulators, insurers, law enforcement, and the public.
AI incidents may be difficult to investigate because model behavior can be nondeterministic and because relevant information may exist across several providers. Contracts should therefore require adequate logging and traceability. At the same time, logs themselves may contain confidential information and must be protected accordingly. The solution is not unlimited retention, but a documented retention period that balances security, investigation, privacy, and deletion obligations.
Traditional NDAs often require the recipient to return or destroy confidential information at the end of the relationship. In an AI environment, deletion is more complicated. Information may exist in active databases, backups, security logs, vector stores, embeddings, caches, support tickets, fine-tuning datasets, and model components.
The agreement should specify which systems are subject to deletion, the time allowed for completion, and the limited circumstances in which information may be retained. Backup copies may be permitted to remain until overwritten through the recipient’s ordinary retention cycle, provided they are not restored or used except for disaster recovery and remain protected by the agreement.
If customer information was used to train or fine-tune a model, the parties must determine whether meaningful deletion is technically possible. Removing a source file does not necessarily remove its influence from a trained model. The agreement should not promise deletion from model weights unless the provider can actually perform and verify that process. A customer that requires complete reversibility may need an architecture that relies on retrieval from segregated databases rather than incorporation of the information into model parameters.
The recipient should provide written certification of deletion upon request. For high-risk information, the customer may seek supporting evidence or an independent verification process. The agreement should also clarify that termination of the commercial relationship does not end the confidentiality obligation for retained information or trade secrets.
A business cannot evaluate AI confidentiality risk solely from a vendor’s public description of its service. The customer may need information concerning data flows, retention periods, subprocessors, security controls, training practices, access logs, testing results, and incident history.
Audit rights should be proportionate to the risk. A vendor serving many customers may reasonably resist unrestricted on-site inspections. The parties can instead rely on current independent assessments, security reports, certifications, questionnaires, penetration-test summaries, and targeted follow-up requests. More intrusive audit rights may be appropriate after a material incident, a significant system change, or credible evidence of noncompliance.
The agreement should require the vendor to notify the customer if a material representation becomes inaccurate. A security report issued before the vendor added a new model provider or agentic feature may no longer describe the relevant environment. The vendor should also disclose material changes that expand data use, introduce new subprocessors, change retention practices, or connect the AI system to additional customer resources.
Contractual verification should include performance as well as documentation. A policy stating that customer data is segregated offers limited protection if access controls are misconfigured. Testing, monitoring, and incident exercises help establish whether the controls function as represented. NIST’s AI and cybersecurity frameworks emphasize ongoing governance and risk management rather than a one-time review at the beginning of the relationship. ¹ ²
AI agreements often contain broad limitations of liability that apply to nearly every claim, including confidentiality breaches and security incidents. A customer should evaluate whether the proposed cap reflects the potential harm from disclosure of trade secrets, personal information, credentials, or regulated records.
The parties may negotiate separate liability treatment for breaches of confidentiality, violations of data-use restrictions, security incidents, infringement, gross negligence, willful misconduct, or violations of law. The appropriate allocation depends on bargaining power, the sensitivity of the information, insurance coverage, the vendor’s role, and the availability of alternative providers.
Indemnification may address third-party claims, regulatory investigations, notice costs, forensic expenses, credit monitoring, or claims arising from the vendor’s unauthorized use of information. The provision should clearly identify covered claims, control of the defense, settlement authority, cooperation duties, and exclusions.
The agreement should also preserve equitable remedies. Once a trade secret or privileged document has been exposed through an AI system, damages may not fully restore the disclosing party’s position. Prompt injunctive relief may be necessary to stop further processing, disable access, preserve evidence, or prevent additional distribution.
Contract remedies should complement, not replace, insurance and incident planning. Businesses should examine whether their cyber, technology-errors-and-omissions, professional-liability, or other policies address incidents involving AI systems, unauthorized model training, privacy violations, and vendor failures.
Businesses frequently use AI to summarize legal documents, draft communications, analyze disputes, or organize evidence. These activities can involve attorney-client communications, attorney work product, litigation strategy, personal information, and materials subject to protective orders.
Submitting privileged information to an external AI provider can create arguments concerning waiver if the disclosure is inconsistent with maintaining confidentiality. The analysis may depend on the provider’s terms, the security of the system, the purpose of the disclosure, the user’s authority, and the precautions taken. Legal departments and law firms should therefore use approved enterprise systems governed by appropriate confidentiality and data-use restrictions rather than consumer accounts with uncertain terms.
An AI NDA should state that the provider receives no authority to waive privilege, disclose protected materials, or use them for any purpose beyond the contracted service. The provider should notify the customer of legal demands where permitted, provide an opportunity to seek protective relief, and disclose only the information legally required.
Confidentiality protections should also address inadvertent outputs. An AI-generated summary or draft may repeat privileged information and may be copied into an unprotected location. Access restrictions, document labeling, human review, and records-management procedures should apply to AI outputs just as they apply to the source materials.
The strongest NDA will fail if it is disconnected from the organization’s daily operations. Contracting, cybersecurity, privacy, legal, procurement, human resources, and business teams should coordinate their AI governance efforts.
Before adopting a tool, the organization should identify the intended use, the information involved, the systems the AI can access, the people who will use it, and the consequences of an error or disclosure. Higher-risk uses should receive greater technical and legal review. Tools that merely assist with public marketing language do not present the same risk as agents connected to customer databases, financial systems, medical records, or litigation files.
The organization should maintain an inventory of approved AI systems and responsible owners. Contracts, data flows, security reviews, model providers, retention practices, and renewal dates should be documented. Employees should receive recurring training that reflects actual business activities rather than abstract warnings.
Monitoring should focus on identifying risky behavior while respecting legitimate privacy and employment considerations. Technical controls may restrict uploads of sensitive information, block unapproved AI services, detect credentials or personal information, and preserve evidence of potential incidents. The organization should also create a practical process through which employees can request approval for new tools or report accidental disclosures without fear that every mistake will automatically result in punishment.
AI governance is an ongoing process. Models, vendors, features, and legal requirements change rapidly. Contract terms that were adequate when a tool generated text may become insufficient after the vendor adds persistent memory, external connectors, autonomous agents, or customer-specific training. Periodic review is therefore essential.
Artificial intelligence has not made non-disclosure agreements obsolete. It has made precise confidentiality agreements more important. Businesses must now account for information flows that extend beyond direct person-to-person disclosure and into models, APIs, cloud systems, logs, embeddings, agents, subprocessors, and automated decision-making environments.
An effective AI NDA should clearly define protected information, restrict use to a specific purpose, prohibit unauthorized training and secondary use, regulate subprocessors, require appropriate security, address prompt injection and excessive access, establish incident-response obligations, and provide workable deletion and verification rights. It should also preserve trade-secret protections, recognize lawful whistleblower disclosures, allocate liability, and coordinate with applicable privacy and cybersecurity laws.
Most importantly, the agreement must operate as part of a broader governance program. A signed NDA cannot compensate for unrestricted employee use, inadequate access controls, poorly configured AI applications, or a lack of incident planning. The businesses best positioned to benefit from AI will be those that treat confidentiality as a combined legal, technical, and operational responsibility.
This article is provided for general informational purposes and does not constitute legal advice. The appropriate contractual and security provisions will depend on the nature of the information, the AI system, the parties’ industries, applicable laws, and the specific risks of the proposed use.
Contact Tishkoff
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).
Sources:
1- Chloe Autio, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts, National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, July 26, 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
2- Cherilyn Pascoe, Stephen Quinn, and Karen Scarfone, National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, February 26, 2024. https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
3- National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, and International Partners, Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems, U/OO/143395-24, Version 1.0, April 2024. https://media.defense.gov/2024/apr/15/2003439257/-1/-1/0/csi-deploying-ai-systems-securely.pdf
4- OWASP Foundation, OWASP Top 10 for LLM Applications 2025, released November 18, 2024. https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-v2025.pdf
5- Federal Trade Commission, Office of Technology, AI Companies: Uphold Your Privacy and Confidentiality Commitments, January 9, 2024. https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/01/ai-companies-uphold-your-privacy-confidentiality-commitments
6- Defend Trade Secrets Act of 2016, 18 U.S.C. §§ 1833(b), 1836, and 1839. https://www.congress.gov/114/plaws/publ153/PLAW-114publ153.pdf
7- Michigan Uniform Trade Secrets Act, MCL 445.1901 through MCL 445.1910. h www.legislature.mi.gov/Laws/MCL?objectName=mcl-445-1901ttps://
8- Michigan Identity Theft Protection Act, MCL 445.61 through MCL 445.79d, including the security-breach notification requirements of MCL 445.72. https://law.justia.com/codes/michigan/chapter-445/statute-act-452-of-2004/
9- Federal Trade Commission, Standards for Safeguarding Customer Information, 16 C.F.R. Part 314. https://www.ftc.gov/sites/default/files/documents/federal_register_notices/standards-safeguarding-customer-information-16-cfr-part-314/020523standardsforsafeguardingcustomerinformation.pdf
10- Health Insurance Portability and Accountability Act Security Rule, 45 C.F.R. Part 160 and Part 164, Subparts A and C. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
