Data Security for AI Tools in M&A

Protecting deal information when AI systems process confidential documents

Updated August 2026 · 6 min read · Deal Room Intelligence Series

Deal documents are among the most sensitive material a firm ever handles — unannounced transactions, undisclosed financials, employee data, counterparty terms under NDA. Sending them to an AI system introduces a specific set of exposures, and the one that causes real damage is rarely a breach. It is a perfectly functioning system doing exactly what its terms permit, in ways nobody read closely.

Six exposures, ranked by how often they actually bite

ExposureWhat goes wrongControl
Training on your contentDeal terms influence a model other firms useContractual prohibition, not a policy page
Undisclosed subprocessorsContent reaches parties you never assessedNamed list, with change notification
Retention past needDocuments persist long after closeStated period and a deletion mechanism
Logging and support accessContent in debug logs and support toolingAsk specifically; it is rarely volunteered
Cross-border transferProcessing in a jurisdiction your NDA does not permitRegion pinning, contractually
Internal over-accessYour own team reads what they should notPer-room access control and audit

Note that only one of these is a breach in the ordinary sense. The rest are the system operating as designed under terms nobody negotiated — which is why a SOC 2 report, useful as it is, does not answer most of this list.

The training question, asked properly

“Do you train on customer data?” almost always receives “no, not by default.” That answer is doing a lot of work in three words, and the operative one is default — a default is a setting, and settings change without your signature.

Ask instead:

Subprocessors — the question nobody asks

When you send a document to an AI due diligence tool, more parties see it than the vendor. Typically: the foundation model provider, a cloud host, an observability or logging platform, possibly an OCR service, and the vendor's own support tooling.

Each is a party your NDA never contemplated. Ask for the named list, and for notice before it changes. A vendor who cannot produce one has not mapped their own data flow, which is a more serious finding than any single name on the list would have been.

Retention, and why “we keep it for you” is a liability

Deal documents stop being needed the moment the transaction closes or dies. Every day they persist afterwards is exposure with no offsetting value.

Vendors frequently frame indefinite retention as a feature — your history, always available. For deal material that is a liability, because the documents remain discoverable, breachable, and subject to whatever the NDA said about return or destruction. Ask for a stated retention period, a deletion mechanism you can trigger, and confirmation of what deletion actually means for backups.

The regulatory floor has risen, on a documented timeline

This is no longer only a commercial-risk question. The governance surface hardened fast and on the record:

For a firm handling deal documents, the confidentiality duty in the last item is the immediate one: putting client material into a system whose terms permit training or undisclosed onward transfer is a professional problem before it is a security problem.

Internal exposure, which firms consistently under-manage

External controls get the attention; the more common incident is internal. An AI tool that indexes a whole data room and answers questions across it can quietly become the most effective way for someone inside your firm to read material they were walled off from.

Three controls worth insisting on:

A procurement checklist

  1. Contractual prohibition on training, flowing down to subprocessors and the model provider.
  2. Named subprocessor list with change notification.
  3. Stated retention period, client-triggered deletion, and a clear answer on backups.
  4. Encryption at rest and in transit — and ask specifically whether document text is encrypted in the database, not merely on the disk.
  5. Region pinning where your NDAs or data-protection obligations require it.
  6. Per-room isolation, role-based access, clean-team support.
  7. Read-level audit logging.
  8. SOC 2 Type II if available — and note what it does not cover, which is most of items 1, 2 and 3.
  9. A signed DPA where personal data is in scope.
  10. Breach notification timelines that are compatible with your own obligations to clients.

The trade-off worth naming

Every control above adds friction, and the strictest configuration — no retention, no logging, no cross-document indexing — also removes capabilities you may be buying the tool for. Cross-document analysis requires holding documents together. Reproducibility requires retaining run records.

The workable position is not maximum restriction. It is scoped retention with real isolation: keep what is needed to reconstruct a decision, isolate it per engagement, delete it on a schedule you set, and log who read it. That preserves the audit trail you need for defensibility while removing the standing exposure that serves nobody.

Bottom line

The realistic risk is not a dramatic breach. It is a training clause with a carve-out, a subprocessor nobody enumerated, and documents sitting in a system two years after the deal died.

Get the training prohibition in the contract, get the subprocessor list in writing, set a retention period, and log reads as well as writes. Then check that your access controls are enforced server-side — because the person most likely to see something they should not is already inside your firm.

Sources

  1. NIST AI Risk Management Framework (AI RMF 1.0), published 26 January 2023. nist.gov/itl/ai-risk-management-framework
  2. Regulation (EU) 2024/1689 (EU AI Act), Article 99; applies from 2 August 2025. artificialintelligenceact.eu/article/99
  3. ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512: Generative Artificial Intelligence Tools, 29 July 2024. americanbar.org

Nothing here is legal advice. We cite only sources we have retrieved and read — see our methodology.

Review how we handle deal documents →

Anweshna Portal
Anweshna Demo