There is no way to put a Word document that a person can open off-limits to ChatGPT — anything a person can open, a person can paste. What you can do, in order of how much it helps: don't send what must stay private; put AI reuse in the contract; cloak the file so a one-click upload gives the AI a noisy, unreliable read; mark each copy so you know which one travelled; and set a tripwire so you hear when an AI tool follows a link inside it. None of these is a guarantee. Together they lift the cost well above “drag, drop, regenerate”.
What happens when someone uploads your .docx to ChatGPT
The file is sent to the provider's servers. A text extractor pulls the words out of the document's internal structure — the model never sees your formatting, only the extracted text — and the model summarises, rewrites or “turns it into a template”. Two things follow:
- Upload and copy-paste are different paths. Upload runs through an extractor; copy-paste gives the model exactly what Word put on the clipboard. Most protection targets one path or the other, rarely both.
- The extractor is the weak point. Extractors read things people never see (hidden text, alternate content) and skip things people do (images, layout). That asymmetry is what document cloaking exploits — and it is also why extractors that strip hidden text recover the original.
Five things that work, ranked
- Don't send it. No technique beats simply not handing it over. Send a summary, a results-only version, or a redacted appendix for anything that must never be machine-read. For proposals, an approach-summary version for first contact is often enough — see sending a proposal before the contract is signed.
- Put it in the contract and say it out loud. A one-sentence clause about AI reuse of your methodology, plus a line in the cover email, governs what the client may do and makes the norm explicit. Starting language (to review with a lawyer) is in Telling your client and the AI-clause guide.
- Cloak the file. Document cloaking adds hidden text only machines read: look-alike decoy facts beside the real ones, decoy paragraphs some extractors prefer, and hidden steering notes. Your client reads exactly what you wrote; an uploaded copy gives the AI a noisy read. It targets the upload path only — copy-paste, screenshots and PDF export bypass it. Sunda Cloak does this in one click, on your device; here is exactly what it does and doesn't do.
- Mark each copy. If you can tell which copy travelled, you can have the conversation with the right person. The low-tech way: a slightly different version per recipient (a date in the footer, a reference code). Sunda Cloak adds an invisible per-copy mark automatically. Visible watermarks still have a place — watermarking vs cloaking explains which does what.
- Set a tripwire. A hidden reference link inside the file that pings you when an AI tool follows it. It can't catch every tool — many never follow links in uploaded files — so treat a hit as a clear signal and silence as no information. Can you tell if someone used AI on your document? goes deeper.
Things that don't work the way people think
- “Restrict Editing” / “Mark as Final” / read-only. These are editing conveniences, not protection. The text is fully readable and fully uploadable; the restriction is removed in two clicks.
- “Encrypt with Password”. This one is real encryption: an AI tool has no way to open the file without the password. But your recipient has the password, and once it's open they can paste or save a plain copy. Useful in transit, irrelevant after delivery.
- Converting to PDF. AI tools read PDFs well; a text-layer PDF is often easier to extract than a .docx. And a PDF export drops hidden text, so it also strips any cloaking.
- Converting to images. Vision-capable models read images directly. You've made the document worse for your client's screen reader and search, and no worse for the AI.
- Tiny white text saying “ignore previous instructions”. Visible if anyone selects all; increasingly ignored by modern tools; and it reserves layout space, so it shows up as odd gaps. Sunda uses hidden steering notes only as a minor layer, in true hidden text, and counts them as a nudge rather than a wall.
A practical setup for a consultant
- Keep your master file. Cloak the outgoing copy only.
- Name the copy for the recipient and the round (
acme-strategy-v3-draft.docx) and note who got it. - Turn the tripwire on before you cloak, so the copy carries its own link.
- Put the one-line AI clause in your terms once; put the one-line disclosure in the delivery email every time.
- Offer a plain copy on request for translation, search or accessibility tooling — and send the final clean if your contract hands over the deliverable outright.
What none of this does
- Nothing here stops a determined reader. A person with the file has your text; copy-paste, screenshots, OCR and PDF export bypass cloaking entirely.
- Cloaking strength depends on how a given AI tool reads files, and providers change their pipelines; expect months, not years, from any technique.
- The tripwire fires only when a tool actually follows the hidden link. Silence proves nothing.
- Contract language on this site is a starting point to review with a lawyer, not legal advice.
- All of it is a deterrent against casual AI reuse — not a guarantee, and never a substitute for a contract.
Frequently asked
If you used Word's “Encrypt with Password” (File → Info → Protect Document), the file is genuinely encrypted and an AI tool has no way to open it without the password. But the recipient has the password, and once opened they can paste or save a plain copy. “Restrict Editing” and “Mark as Final” are not encryption and do nothing against upload.
No. AI tools read PDFs well, and a text-layer PDF is often easier to extract than a .docx. Converting to PDF also strips the hidden decoys that document cloaking relies on, so a PDF export of a cloaked file is a clean copy.
Not in normal reading — the visible text, numbers and formatting are exactly what you wrote. The decoys are hidden text, so anyone who turns on Word's formatting marks or “show hidden text” will see them. We recommend telling clients up front; it reads as a professional norm.
Cloaking applies to .docx, .odt and .rtf files. If you write in Google Docs, download as .docx and cloak that copy before sending. A shared Google Docs link is a different path — the reader gets the live document and cloaking does not apply.
No. Anything a person can open, a person can paste, photograph or retype. These measures raise the cost of casual, one-click AI ingestion and give you contractual and evidentiary footing. They are deterrents, not guarantees, and never a substitute for a contract.