Ref AI-02 · Confidentiality · 18 min read · Updated July 2026

Can You Upload a CIM to ChatGPT? A Private Equity Decision Tree

Before uploading a CIM to ChatGPT or another AI tool, clear the NDA, firm-approval, product, retention, data-classification, access, and review gates.

The short answer: only if every approval, document, product, data, and review gate clears.

If you are using an unapproved personal or consumer account, the practical answer is no. If you do not know whether the exact product, workspace, connected feature, or document is approved, stop and escalate.

An enterprise plan may provide stronger contractual, administrative, retention, and security controls. It does not rewrite the NDA, grant permission on behalf of the data owner, remove every subprocessor, classify the content, or perform the human review.

The mistake is asking one question:

“Does this AI provider train on my data?”

That is necessary but incomplete.

No training, no retention, no disclosure, and permission to process are four different questions.

Treat the AI provider like a deal adviser

Private equity already has a framework for giving confidential material to a third party.

In Tamara Sakovska’s The Private Equity Toolkit, the seller releases a CIM after an NDA, then provides deeper data-room materials as the process advances. The NDA can make the recipient responsible for breaches by advisers and financing sources. Sensitive customer, supplier, employee, and commercial material may be withheld or more tightly restricted.

An AI system is not automatically identical to a human adviser as a legal matter. The analogy is operational:

  • Who receives the information?
  • On whose behalf?
  • Under which agreement?
  • For which permitted purpose?
  • Through which systems and subprocessors?
  • With what access, retention, deletion, and audit controls?
  • Who is responsible if the workflow exceeds the permission?

Do not call the upload “internal” merely because an employee initiated it.

The decision tree

Decision tree for uploading a CIM to an AI toolThe decision starts with data classification, then checks document restrictions, firm approval, the exact product configuration, permitted data types, minimization, and review controls. Any unknown or failed gate routes to stop and escalate.STARTWhat data are you about to send?Is it public, synthetic, or approved for this use?Classification is about the content, not the filename.YESProceed in policyStill verify outputsand log sources.NODo the NDA, VDR rules, and process terms permit it?Check AI use and third-party processing, not just confidentiality.Did the firm approve the exact product and feature?Plan, workspace, connected app, and retention settings all matter.Are every data type and recipient permitted?Check PII, trade secrets, privilege, MNPI, sharing, and subprocessors.Can you minimize, redact, cite, log, and review?Send the minimum necessary and preserve page-level traceability.Proceed inside the approved workflowApproval enables processing. It does not waive verification.ANY NO OR UNKNOWNStopDo not upload.Escalate to legal,compliance, IT, orthe data owner.
Exhibit 1No training, no retention, no disclosure, and permission to process are four different questions. A pass on one does not answer the others.

Gate 1: What is the material?

Start with the content, not the filename.

Classification Examples Default workflow
Public Filed financials, company website, published research Use only within firm policy; cite and verify
Synthetic A deliberately fictional deal with no recoverable client content Good for testing; still follow product rules
Anonymized / aggregated Minimum necessary facts with identifiers and sensitive detail removed Confirm re-identification risk and approval
Deal-confidential Teaser, CIM, VDR export, management deck, lender term sheet Require document permission and approved environment
Restricted Customer list, employee data, privileged material, trade secrets, sensitive contracts Escalate; a broad tool approval may not cover the data

A CIM may contain confidential business information without every page being MNPI. It may also contain personal data, trade secrets, or material nonpublic information depending on the transaction. Do not use a generic label as a substitute for reviewing the actual content.

Gate 2: What do the deal documents permit?

Check:

  • NDA definitions of confidential information and representatives;
  • permitted use;
  • third-party disclosure and adviser provisions;
  • VDR terms and click-through notices;
  • process letters and seller instructions;
  • restrictions on copying, downloading, data extraction, or automated processing;
  • privilege and common-interest provisions;
  • return or destruction obligations; and
  • governing-law or data-residency constraints.

An NDA that allows disclosure to “advisers” does not automatically mean every software provider, connected app, or model endpoint is covered. That conclusion belongs to the people who interpret and administer the agreement.

Gate 3: Did the firm approve this exact environment?

“We have ChatGPT” is not specific enough.

Approval should resolve:

  • product name and plan;
  • named workspace or tenant;
  • user identity and role;
  • web app, desktop app, mobile app, or API;
  • model and region where relevant;
  • connected cloud drives and third-party actions;
  • custom GPT, project, library, or shared workspace;
  • browsing, code execution, retrieval, and agent features;
  • logging and compliance APIs;
  • admin settings; and
  • the permitted data classifications and use cases.

An approved drafting workflow for public marketing copy does not automatically authorize a CIM upload. An approved enterprise workspace does not automatically authorize every connector.

Gate 4: What do the provider’s current terms actually say?

As of July 2026, OpenAI states that it does not use inputs or outputs from ChatGPT Enterprise, Business, Edu, Healthcare, Teachers, or its API platform to train or improve its models by default. It also describes encryption and configurable retention for qualifying organizations.

That answers part of the training and security analysis. It does not answer the whole decision.

OpenAI’s separate chat and file retention documentation says:

  • chats are generally saved until the user deletes them;
  • deleted chats are scheduled for deletion within 30 days, subject to stated exceptions;
  • temporary chats are scheduled for deletion within 30 days;
  • files may be saved separately to Library;
  • files attached to a project or custom GPT can remain until that project or GPT is deleted; and
  • workspace and enterprise retention settings can differ.

Policies and product features change. Verify the current first-party documents and the firm’s negotiated agreement for the exact environment. Do the same for any other provider named in the workflow.

Gate 5: Which data types are inside the file?

A single deck can contain:

  • customer identities and contracts;
  • pricing and rebate terms;
  • personally identifiable employee data;
  • healthcare or other regulated information;
  • trade secrets and product roadmaps;
  • export-controlled information;
  • privileged legal analysis;
  • lender materials;
  • sensitive cyber architecture;
  • management compensation;
  • material nonpublic information; and
  • seller-created projections and adjustments.

The strictest included category may determine the permitted workflow.

The SEC’s 2024 amendments to Regulation S-P require covered institutions, including covered registered investment advisers, to maintain incident-response policies and address service-provider handling of customer information. That does not mean every PE entity or CIM falls within the rule. Entity, data, and use-case scope matter. It does show why “the vendor says enterprise” is not a complete control analysis.

Gate 6: Can you minimize the disclosure?

Ask what the task actually requires.

Instead of uploading the entire CIM:

  • use the public teaser;
  • send only the relevant pages;
  • remove names, addresses, and personal data;
  • aggregate customer rows;
  • replace values with synthetic numbers;
  • extract a schema locally and send the minimum fields;
  • use a firm-controlled retrieval layer; or
  • build the workflow on UpLevered’s fully synthetic house case.

The objective is not to make confidential material look anonymous. It is to reduce the data path to the minimum necessary content that the approved workflow permits.

Confidentiality also means learning the shape of a recurring problem without carrying a client’s names, files, templates, assumptions, or results forward.

Gate 7: Can the output be traced and reviewed?

If the approved use is extraction or synthesis, require:

  • document and page citations;
  • stable input and output versions;
  • the exact product and model version;
  • prompt or workflow logs where policy permits;
  • a record of connected tools and actions;
  • a separate as-reported layer;
  • deterministic tie-outs;
  • reviewer corrections;
  • unresolved-item labels; and
  • an accountable owner.

FINRA’s 2026 GenAI oversight guidance highlights formal approval, testing, logs, model-version tracking, monitoring, and human review for member firms. It also flags risks from agents acting outside intended authority, handling sensitive data, and producing hard-to-audit multi-step outcomes. Applicability depends on the firm, but the workflow controls are broadly useful.

Worked example: three uses of the same deal material

Exhibit A

Northwind Managed Services: Public, approved, and restricted paths

Assume the team wants to identify investment risks and draft diligence questions for synthetic Northwind Managed Services.

Path A: Public or synthetic teaser

The team uses a fictional teaser with no recoverable client content in an approved tool.

  • Document gate: passes.
  • Firm approval: passes.
  • Data types: no restricted data.
  • Use: extract stated facts and draft questions.
  • Control: citations, source labels, and human review.

Result: proceed within policy.

Path B: Confidential CIM in an approved enterprise workspace

The real CIM is covered by an NDA. Counsel and compliance confirm the use is permitted in the firm’s named enterprise workspace. The configured contract and settings meet the firm’s training, retention, access, logging, and deletion requirements.

  • Document gate: passes with stated conditions.
  • Firm approval: passes for the exact workspace and feature.
  • Data types: permitted for this workflow.
  • Use: populate the Evidence Ledger, not generate an autonomous recommendation.
  • Control: minimum pages, page-level citations, logs, tie-outs, reviewer acceptance.

Result: proceed inside the defined workflow. Approval does not waive verification.

Path C: Customer-level schedule in a connected personal drive

The analyst wants to attach a raw customer export through an unapproved connector. The file includes customer identities, pricing, and contract terms.

  • Document gate: unknown.
  • Firm approval: fails.
  • Product and connector: not approved.
  • Data types: restricted commercial information.
  • Use: unnecessary for the first-pass question.

Result: do not upload. Escalate and redesign the task using approved, minimized, or synthetic inputs.

If the CIM was already uploaded

Do not quietly delete the chat and assume the problem disappeared.

Take the following steps, subject to firm policy:

  1. Stop further processing, sharing, downloading, or forwarding.
  2. Preserve the facts needed for the response: user, date, account, workspace, plan, feature, model, connector, recipients, and files.
  3. Notify the required legal, compliance, privacy, information-security, or data owner promptly.
  4. Follow the firm’s incident, breach, and contractual-notice process.
  5. Use the provider’s available deletion and admin controls as directed.
  6. Determine retention, Library, project, custom-tool, shared-workspace, and backup implications.
  7. Record the response and remediation.

Deleting may be one response step. It is not a substitute for escalation or fact preservation. OpenAI’s current documentation, for example, describes deletion windows and exceptions rather than instantaneous removal from every system.

Common mistakes

CIM confidentiality traps

TrapWhat goes wrongHow to catch itFix
No training means approvedThe team treats one provider commitment as permission to process the document.Ask separately about document permission, firm approval, retention, subprocessors, access, deletion, and data types.Clear every gate for the exact environment and workflow.
Enterprise means internalThird-party processing and connected services disappear from the risk description.Map every system, connector, subprocessor, user, and recipient in the data path.Describe the environment accurately and rely on the negotiated controls, not the label.
The whole CIM is necessaryA narrow question sends hundreds of pages and multiple sensitive data types.Write the minimum fields or pages required before selecting the input.Redact, aggregate, extract locally, or substitute synthetic material.
Approval covers every featureA user adds a connector, shared project, custom tool, or agent that was never reviewed.Compare the actual feature path with the approved product inventory.Approve the exact plan, workspace, feature, data class, and action scope.
Delete and stay quietAn accidental upload is removed without preserving facts or following incident policy.Ask whether the right owner can determine what happened, where the data went, and what remains.Stop, preserve facts, escalate, then execute the directed response.

Pre-upload checklist

Before any deal document enters an AI workflow

  • Classification: I know whether the content is public, synthetic, anonymized, deal-confidential, or restricted.
  • Documents: The NDA, VDR terms, process letter, engagement terms, and permitted-use language have been checked.
  • Approval: The firm approved the exact product, plan, workspace, app, connector, feature, user group, and use case.
  • Contract: Current terms address training, retention, access, sharing, subprocessors, residency, deletion, and auditability.
  • Data types: Customer, employee, personal, privileged, trade-secret, regulated, and MNPI considerations are resolved.
  • Minimization: The workflow sends only the fields or pages necessary for the task.
  • Control: Inputs, outputs, sources, model versions, and human review are logged as required.
  • Authority: The AI cannot send, share, edit, or act beyond the approved scope without review.
  • Escalation: A named owner handles any no, unknown, incident, or exception.
  • Verification: Approval to process is not being confused with confidence in the output.

Sources and methodology

This decision tree combines private-equity transaction practice, current provider documentation, and cross-sector governance standards. It does not interpret any specific agreement.

Revision History

Revision History

  1. : Original publication. Added the eight-gate decision tree, product-policy distinctions, synthetic worked example, accidental-upload response, and pre-upload checklist.

Frequently asked questions

Can I upload a confidential CIM to ChatGPT?

Only if the document restrictions, firm policy, exact product and workspace, contractual terms, retention settings, data types, access controls, and required review process all permit it. If any gate is unknown, do not upload and escalate to the appropriate legal, compliance, IT, or data owner.

Does ChatGPT Enterprise train on uploaded CIMs?

OpenAI states that it does not use ChatGPT Enterprise, Business, Edu, Healthcare, Teachers, or API inputs and outputs for model training by default. That does not by itself establish permission to upload a CIM or answer retention, subprocessor, access, residency, sharing, deletion, or NDA questions.

Is deleting a chat enough after an accidental CIM upload?

Do not assume deletion resolves the issue. Stop further processing, preserve the relevant facts, identify the account, workspace, product feature, recipients, and files involved, and follow the firm’s incident and escalation process. Provider retention and backup rules may continue to apply after deletion.

Does every CIM contain MNPI?

Not necessarily. A CIM can contain confidential business information and may contain material nonpublic information, personal data, trade secrets, or privileged material depending on the deal and recipient. Classification must be based on the actual content and governing restrictions.

Can I use a synthetic CIM with an AI tool?

Synthetic or properly anonymized material is often a lower-risk way to test a workflow, but firm policy and product rules still apply. The synthetic case must not reproduce confidential names, files, templates, assumptions, or results in a way that exposes the original source.

Continue through the workflow

The safe default is simple: if the permission or the environment is unclear, stop. A fast answer is not worth creating a disclosure problem.

Stay sharp. Subscribe to Deal Flow Bullet.

PE workflows, current AI controls, and deal analysis for middle-market practitioners. Free, every two weeks.