50% off AVE Pro through August 15

Read your NDA before you upload the footage to an AI editor

Most AI video editors work by uploading your media to their servers. That is a third-party disclosure, and a growing number of client contracts now say so explicitly.

An editor at a sunlit desk reviews interview footage on a monitor, with the source drive plugged into the laptop beside them.

There is a question most editors have never had to ask before, and now have to ask on almost every job.

Where does the footage go?

For twenty years the answer was boring. Footage went onto a drive, into an NLE, and out as a file. The only meaningful copies were the ones you made. The question was so uninteresting that no contract bothered to address it.

That assumption quietly stopped being true.

The default changed while nobody announced it

Most of the AI video tools that got popular in the last two years are cloud services. That is not a criticism of how they are built. It is a description of how they work.

You select a file. The file uploads. Analysis happens on their infrastructure. Results come back.

This applies to transcript-first editors, to auto-clipping tools, and to browser-based editors. It also increasingly applies to features bolted onto desktop software, where the application runs locally but the AI feature calls a remote endpoint with your media attached.

The user-facing experience is a progress bar. The legal event is a disclosure to a third party.

Those are not the same thing, and the gap between them is where the problem lives.

What your contracts are starting to say

The legal profession noticed before most editors did.

Law firms now routinely advise clients that uploading confidential material to an AI service can breach an existing confidentiality agreement, because the information is processed on systems operated by a third party and may be stored, transferred across borders, or retained. Stephenson Harwood’s note on confidential information, NDAs and AI makes the point directly: the confidentiality provisions were written before anyone considered whether an AI platform counts as disclosure. Most of the time, they do not carve out an exception for it.

The practical consequence is that NDAs are being rewritten. Carta’s guidance on AI clauses in NDAs reflects what is now common drafting: explicit language prohibiting either party from inputting confidential information into generative AI or machine learning systems without prior written consent.

If you edit for other people, you will start seeing this language. Some of you already have.

Read it carefully, because the clauses are usually broader than editors expect. They tend to cover:

  • the media itself;
  • transcripts derived from the media;
  • filenames, folder structures, and project metadata;
  • any tool that “processes” the material, not only tools that “publish” it.

That last point catches people. A tool that only generates captions is still processing the material.

Metadata is the part everyone forgets

Even when the video never leaves, the surrounding information often does.

Project names. Client names. Camera card folder structures. Filenames like ACME_Q3_LAYOFFS_CEO_TAKE4.mov.

An editor who is careful about the media and casual about the metadata has still leaked the story. In several categories of work, the filename is the sensitive part.

This is worth checking explicitly for any tool you use. Not “does it upload my video,” but “what does it send, and when.”

Where this actually bites

This is not a theoretical concern for a small number of paranoid people. It is a routine constraint in ordinary categories of work.

Unreleased product. Anything shot before launch. Hardware, packaging, UI, pricing, roadmap slides visible in a screen recording.

Internal communications. All-hands recordings, restructuring announcements, training material, incident reviews.

Client and agency work. Where you are not the owner of the footage and the owner never agreed to a third-party processor.

Research and interviews. Where participants consented to a specific use, and that consent did not include a vendor’s servers.

Legal, medical, and regulated content. Where the constraint is not a preference but a statute.

Major studios have already moved on this and increasingly require on-premise or locally processed tooling for pre-release content. The rest of the industry usually follows studio security practice a few years later, and there is no obvious reason this will be the exception.

The question is not whether a vendor is trustworthy. It is whether you were entitled to make that choice on your client’s behalf.

”It is encrypted” is a different claim

Vendor security pages are generally accurate and generally answer a narrower question than the one you have.

Encryption in transit and at rest protects the material from third parties who are not the vendor. It says nothing about whether disclosure to the vendor was permitted in the first place.

Similarly, “we do not train on your data” is a real and meaningful commitment. It is also a commitment about one particular use, made by a company whose policy can change, that may be inherited by an acquirer, and that does not retroactively make the upload contractually permitted.

Both statements can be entirely true and entirely beside the point.

The useful questions are narrower:

  1. Does my media leave this machine at all?
  2. If it does, which specific action sends it?
  3. Can I do the core work without that action?
  4. Is the boundary visible in the interface, or do I have to read a support article to find it?

A tool that can answer those clearly is easier to defend in a conversation with a client than one that answers them well but invisibly.

Local is no longer the slow option

The reason cloud AI became the default is that it was, for a while, the only thing that worked. Running useful models required hardware most people did not have.

On a Mac in 2026, that is no longer the situation.

Apple Silicon runs speech and vision models fast enough for production use. Whisper-class transcription through Apple’s MLX framework will process a one-hour interview in a few minutes on an M4-class machine, entirely on device. Visual tagging, semantic search, caption generation, and scene description are all workable locally.

The tradeoff has genuinely shifted. Local analysis is no longer a compromise you accept for privacy. For a lot of footage-understanding work, it is simply the faster path, because there is no upload.

Three hours of ProRes does not need to cross the internet twice to tell you which twelve seconds you wanted.

The honest version of the tradeoff

Local-first does not mean nothing may ever leave.

Some tasks genuinely need an external service. Generating a shot that does not exist requires a generation provider. A frontier model may reason about a complicated brief better than anything you can run locally. Those are real capabilities and pretending otherwise helps nobody.

The distinction that matters is whether the boundary is a decision or a default.

A decision looks like this: you choose a provider, you know what is being sent, you do it for a specific project where you have the rights, and you can decline without losing the ability to edit.

A default looks like this: opening the application and importing footage means the footage is now somewhere else.

It is also worth saying that some tools in this space get this right. Jumper, for example, keeps footage local and passes only metadata to a connected agent. Credit where it is due. The category is not uniformly careless, and you should evaluate each tool on what it actually does rather than on where it sits in a marketing taxonomy.

What to check before the next job

A short, unglamorous checklist that will cover most situations:

  • Ask the client directly whether AI processing is permitted, and get the answer in writing. This conversation is much cheaper before the project than after.
  • Read the confidentiality clause for the words “artificial intelligence,” “machine learning,” “third-party processor,” or “automated processing.”
  • For each tool in your pipeline, identify which specific features transmit media, and whether transcription is one of them.
  • Check whether metadata and filenames travel separately from the media.
  • Keep sensitive projects on tools where the local path is complete, so that declining an external feature does not mean declining to work.
  • Write down what you did. If it ever matters, it will matter a year later when nobody remembers.

None of this requires becoming a lawyer. It requires knowing which of your tools upload, and being able to say so.

Where AVE sits

AVE is a local-first AI video editor for Mac, built around this boundary rather than around an apology for it.

Project files, imported media, transcription, visual analysis, timeline execution, and export stay on your Mac. The Local AI engine and starter analysis models ship with the app, so footage understanding works before you connect anything. External assistants, API providers, and generation services are connections you add deliberately, for the projects where they are appropriate.

That is the whole design argument. Not that external AI is bad, but that it should be something you turn on rather than something you fail to turn off.

You can read how the local-first workflow is defined, review the security and download details, or see how this compares to cloud transcript editors like Descript.

And if your next project is under an NDA that was signed before any of this existed, the safest assumption is the old one: the footage stays where you put it.