Services AI Audit Guides Marketplace Blog Contact
Privacy

What happens to the data you send an AI provider.

Most businesses adopt AI tools faster than they read the terms attached to them. The answers are usually reassuring for paid business tiers and considerably less so for free consumer products — and the difference is where most accidental exposure happens.

The distinction that matters most

Consumer products

Free and personal tiers of AI assistants. Historically the default has been that conversations may be used to improve the service. Settings exist to change this, and most staff have never opened them.

Business and API tiers

Paid business plans and developer APIs generally commit not to train on customer data by default, with defined retention periods. This is the tier your business data belongs on.

The practical consequence: an employee pasting a client contract into a free consumer assistant is a different risk from your system calling a business API. The first is where real exposure occurs, and it is usually invisible to management until someone asks.

Questions worth asking any provider

1
Is my data used for training? For business tiers the answer should be no by default, not no if you find the right toggle.
2
How long is it retained, and where? Retention periods and geography both matter — some regulated data cannot leave a jurisdiction.
3
Who can access it? Provider staff access for abuse monitoring is common and usually reasonable; you should still know it exists.
4
What happens when I leave? Deletion terms, and whether they extend to backups.
5
Sub-processors? Providers often use other infrastructure companies. Your data may touch more organisations than the one you contracted with.
6
What certifications do they hold? Independent audits are not a guarantee, but their absence is informative.

The categories that need more than terms

For some material, a good contract is not sufficient, either legally or reputationally:

For these, running the model on your own infrastructure removes the question entirely rather than managing it. How that works in practice.

A policy most businesses should have and few do: a short written rule about what may and may not be pasted into external AI tools, and one approved tool for anything sensitive. The exposure almost never comes from a considered architectural decision. It comes from someone in a hurry with a document and a deadline.

Common questions

Do AI companies train on my business data?

On paid business tiers and APIs, generally no by default, with contractual commitments to that effect. On free consumer tiers the position has historically been different, and settings that change it are off the beaten path. Read the terms for the specific tier you are using — the difference between tiers of the same product is larger than the difference between providers.

Is it safe to use AI with client information?

It depends on your obligations to that client and on which tier you use. Many professional service firms can use business-tier AI tools for client work under appropriate terms; some cannot, either because of regulation or because of what they promised in their own engagement letters. Check your professional obligations before your provider's terms — yours are usually stricter.

What is the safest option for sensitive material?

Running the model on infrastructure you control, so the data never leaves. That removes the third-party question entirely, at the cost of maintaining the system yourself. For most businesses the sensible pattern is a split: sensitive work local, everything else on a business-tier cloud service.

How do I stop staff pasting confidential material into AI tools?

A written policy plus a sanctioned alternative. Prohibition alone fails, because the tools are genuinely useful and people under deadline will use them anyway. Giving staff an approved tool that handles sensitive material properly is far more effective than a rule they will quietly route around.

Keep reading
Running AI locally Local vs cloud, compared Private AI for law firms

AI that runs
on your terms.

Private AI systems in environments you control — your data never trains public models, and engagements are available under NDA.

Private AI systems Book a free audit