gaash.ai

Authority & Mentions · 9 min read · July 15, 2026

From NDA to AI Citation: How to Make Confidential Work Visible Without Breaking Confidentiality

Your best reference projects are locked behind an NDA, which means no AI engine will ever mention them. When ChatGPT, Perplexity, or Google's AI Overviews are asked who can solve a given problem, they cite the expertise they can actually read — not the strongest project you're forbidden to name. The way around this isn't a loophole in the NDA; it's disciplined anonymization: mechanics instead of client names, ranges instead of exact figures, patterns instead of single cases.

The consulting paradox: your best work is the work no one can see

In few industries is the gap between real competence and visible competence as wide as in management consulting. Your most convincing work — the post-merger integration that actually worked, the insolvency you averted, the sales model you rebuilt from scratch — sits under confidentiality. The client won't be named, often because simply having hired a consultant is treated internally as an admission of weakness. So the website falls back on filler: strategic excellence, sustainable transformation, a partnership approach.

For generative AI systems, that's a real problem. A language model cites what it can read and verify. Ask ChatGPT who can help with a restructuring in mechanical engineering, and it looks for concrete signals: specific situations, numbers, methods, named approaches. Vague phrases give it nothing to work with. The consultants who get cited aren't necessarily the best ones — they're the ones who made their substance legible to a machine.

The fix isn't a gray area, and it isn't a breach of confidentiality — it's a craft: separating the transferable core of an engagement from whatever identifies the client. Large firms like McKinsey, BCG, and Roland Berger have built entire publishing operations around exactly this distinction. Most mid-sized consultancies have simply never done it deliberately for their own visibility.

What an AI model reads in a case study — and what it skips

A generative model judges a case description on verifiability and specificity. 'We significantly improved a client's efficiency' is worthless — it fits every consultancy on earth. 'At an automotive supplier with several hundred employees across multiple plants, we cut order-processing lead time by more than half by redrawing the handoff between sales and production planning' is citable, without the client's name ever appearing.

The difference is what's sometimes called case mechanics: the starting situation, the concrete intervention, the measurable result, the transferable principle. None of those four elements gives away a trade secret. Together, they describe your method — and that's exactly what a language model is checking for when it decides whether to surface you as an answer.

Run this test on every reference you write: could a competitor identify the client from this text alone? If yes, you're giving away substance you don't need to. If no, you can usually say more without any risk. Most consultancies get both sides wrong at once — too vague to be convincing, and occasionally still too specific for the NDA.

{}

The anonymization ladder: five steps from names to patterns

Confidentiality isn't binary — think of it as a ladder. Step one is the named client with a logo and a quote, the ideal outcome worth actively asking for, since a release line at project close costs nothing. Step two is industry and size without a name: 'a listed chemicals group.' Step three replaces anything identifying with a range: 'revenue in the mid nine figures.'

Step four is the aggregated case: combine several similar engagements into one composite, so no single client is reconstructable, and the pattern becomes statistically more convincing than any one example. Step five is the pure principle: 'In most succession situations we've advised on, the handover doesn't fail on price — it fails on the outgoing owner's unresolved role after the handoff date.' That's maximally anonymous and still highly citable, because it names a verifiable pattern.

The skill is picking the highest step the NDA actually allows for each reference. Many consultancies default to the vaguest option out of caution — but most contracts permit steps two and three without issue. You just have to read the contract instead of assuming silence is safer.

Read the NDA before you decide to stay silent

The most common mistake is pre-emptive self-censorship. Consultants assume 'confidential' means 'unmentionable.' In practice, most confidentiality agreements restrict passing on specific information tied to the client — not the fact that an engagement happened in a given industry, and certainly not a description of your own method.

Go through your active NDAs and sort them into three buckets: what's flatly off-limits (name, figures, specific strategic decisions); what's permitted once anonymized (industry, problem type, rough scale of results); and what's yours regardless (your frameworks, your approach, your judgment). That third bucket is your most valuable, most underused asset for AI visibility.

Build the ask into project close. A short question at the end of an engagement — 'Can we reference this anonymized, in ranges, as a case study?' — gets a yes surprisingly often, and sometimes even permission to name the client outright. The best time to ask is the moment of success, not a cold email two years later.

Turning an anonymized case into something an AI can cite

An anonymized case doesn't do much good buried in a paragraph on a subpage. Generative systems favor structures that map cleanly onto a question. Package each case as a question-and-answer unit: 'How do you restructure a manufacturing firm facing an acute liquidity crunch?' followed by your concrete, anonymized answer — approach and rough scale of result included.

That structure pulls double duty. It mirrors how people actually query AI systems, and it lets the model lift your case directly as an answer. Add the four mechanics elements in a clear sequence, and where you can, a timeframe ('within nine months'). Concrete timing measurably increases how credible the claim reads.

Write for the standalone, quotable line too. Something like 'In our experience, restructurings rarely fail on missing cost levers — they fail on approaching the house bank too late' is exactly the kind of compressed insight a language model will lift verbatim and attribute to you. Seed a few of these deliberately through your writing.

Anonymizing numbers without giving anything away

Numbers are your most convincing and most sensitive material. An exact revenue figure can make a client identifiable, especially in a narrow industry. The fix is relative figures and ranges instead of absolute values. 'Cut the reject rate by roughly a third' gives nothing away, and it's more convincing than a raw number anyway, because it shows the leverage of the work.

Where an absolute figure is unavoidable, use an order of magnitude: 'a double-digit million sum in freed-up working capital' instead of a specific euro amount. Ranges like this are fully usable by AI systems and worthless to a competitor trying to re-identify the client. Also check for compounding: industry plus region plus size plus timing can expose a single client even when each detail alone is harmless.

A practical test: feed your anonymized case description into an AI system yourself and ask which company it might be describing. If the model guesses correctly, your anonymization is too thin. If it can't guess but still grasps what you achieved, you've found the right balance.

The aggregated case: your strongest GEO asset

The most elegant answer to the confidentiality problem is aggregation. Instead of telling one story, you fold your experience across many similar engagements into a single pattern. 'Across a dozen succession-planning engagements with family businesses, the conflict has consistently centered on operational control, not ownership percentage.' No single client is identifiable, and the statement is more statistically solid than any one case would be.

For a generative system, aggregated patterns like that are gold — they read as genuine field experience, they're phrased in a verifiable way, and they answer the question behind the question. Nobody asks an AI 'who advised company X' — they ask 'why do family business successions typically fail.' Whoever answers that pattern question becomes the cited source, with no client name required.

Aggregation has a second advantage: it's NDA-safe by construction. If no individual case can be reconstructed, there's nothing left to violate. Build two or three of these composite cases for every practice area you have, and update them as new engagements close. Your citable material grows while your confidentiality obligations stay untouched.

From NDA archive to visible authority in 90 days

Don't start from a blank page — start from your archive. Pull the ten engagements from the last few years you're proudest of. For each one, work out the highest anonymization step the contract actually allows, extract the four mechanics elements, and write it up as a question-and-answer unit. That's an afternoon of focused work per case, and it hands you ten citable building blocks immediately.

In parallel, build three aggregated composite cases for your core practice areas. Combine those with your standalone insight lines into a guidance section that answers questions directly instead of listing services. Add a short methodology page describing your approach — that's entirely yours to publish, with no NDA in the way.

Then wire the process into how you run projects: every engagement close ends with the reference conversation and the extraction of that case's mechanics into your archive. After 90 days, the empty stretch of boilerplate is gone, replaced by a growing, AI-readable record of your competence — and you start getting named when someone asks an AI who to hire in your field.

Common questions

Does describing an anonymized case on my website violate the NDA?

Usually not, as long as no individual client can be reconstructed from it. Most NDAs restrict passing on information attributable to the client, not a description of your own method or an anonymized pattern. Check your specific contract, watch for the risk of combining industry, size, region, and timing into an identifying fingerprint, and when in doubt, move up an anonymization step or use an aggregated composite case where no single engagement is recognizable.

Why isn't my existing, generically worded reference copy enough for AI visibility?

Because generative systems weight verifiability and specificity. Phrases like 'strategic excellence' or 'sustainable transformation' fit every consultancy and give a model no signal to cite you as a concrete answer. A text becomes citable only through case mechanics — the starting situation, the concrete intervention, the measurable result in ranges, and a transferable principle. None of that reveals a secret; it describes your method, which is exactly what the model is looking for.

How do I convince a client to let me use them as a named reference?

Ask at the moment of success, not years later. Build the reference question into project close and offer tiered options: full naming, industry mention only, or fully anonymized use with figures in ranges. Many clients agree to anonymized use immediately, and some agree to being named outright, because a successful project reflects well on them too. The key is always offering the low-friction anonymous option as a fallback.

Share