Most businesses adopt AI tools faster than they read the terms attached to them. The answers are usually reassuring for paid business tiers and considerably less so for free consumer products — and the difference is where most accidental exposure happens.
Free and personal tiers of AI assistants. Historically the default has been that conversations may be used to improve the service. Settings exist to change this, and most staff have never opened them.
Paid business plans and developer APIs generally commit not to train on customer data by default, with defined retention periods. This is the tier your business data belongs on.
The practical consequence: an employee pasting a client contract into a free consumer assistant is a different risk from your system calling a business API. The first is where real exposure occurs, and it is usually invisible to management until someone asks.
For some material, a good contract is not sufficient, either legally or reputationally:
For these, running the model on your own infrastructure removes the question entirely rather than managing it. How that works in practice.
On paid business tiers and APIs, generally no by default, with contractual commitments to that effect. On free consumer tiers the position has historically been different, and settings that change it are off the beaten path. Read the terms for the specific tier you are using — the difference between tiers of the same product is larger than the difference between providers.
It depends on your obligations to that client and on which tier you use. Many professional service firms can use business-tier AI tools for client work under appropriate terms; some cannot, either because of regulation or because of what they promised in their own engagement letters. Check your professional obligations before your provider's terms — yours are usually stricter.
Running the model on infrastructure you control, so the data never leaves. That removes the third-party question entirely, at the cost of maintaining the system yourself. For most businesses the sensible pattern is a split: sensitive work local, everything else on a business-tier cloud service.
A written policy plus a sanctioned alternative. Prohibition alone fails, because the tools are genuinely useful and people under deadline will use them anyway. Giving staff an approved tool that handles sensitive material properly is far more effective than a rule they will quietly route around.
Private AI systems in environments you control — your data never trains public models, and engagements are available under NDA.