Is It Safe to Put
Company Data Into AI?
The honest answer is that it depends entirely on which tool, on which plan, and on what you paste. Here is how to tell the difference, and what to do about the fact that your staff are already doing it.
Quick Take
A consumer account and a business account from the same vendor can behave completely differently with your data. Check which one your people are using before anything else. Then write one page saying what may be sent where, because a ban does not stop the behaviour, it just moves it somewhere you cannot see. If the material is genuinely confidential - client files, unreleased work, anything covered by an NDA - there are ways to use AI without it leaving your network at all.
What Actually Happens to What You Paste
Four things vary between tools, and they are the four worth establishing before you worry about anything else.
Whether it trains the model
Consumer tiers have historically used conversations to improve the service. Business and enterprise tiers generally contract not to. This is the single largest difference between the free account someone signed up for and the paid one your business controls, and it is why the first question is always which account people are actually using.
How long it is kept
Retention periods differ, and "deleted" sometimes means removed from your view rather than removed from the provider's systems immediately. If you have a retention policy for other systems, this needs to fit inside it.
Where it is processed
Which country the processing happens in matters for UK and EU data protection obligations, and some vendors let you pin it while others do not.
Who else can see it
Staff at the provider for abuse monitoring, sub-processors, and anybody in your own business the tool has been connected to. That last one catches people out: connect an assistant to a shared drive and it will cheerfully summarise documents the person asking was never meant to read.
Where personal data is involved anywhere in that chain, the Information Commissioner's Office guidance on AI and data protection is the reference that governs it in the UK.1 The National Cyber Security Centre publishes the corresponding security guidance for organisations building or deploying AI systems.2
Three Questions for Any Vendor
Ask them in writing. The answers, or the difficulty of getting them, tell you most of what you need.
- ✔ Is our content used to train your models, on the plan we are actually on? The plan qualifier matters. A "no" that applies only to enterprise tiers is a "yes" for the person using a personal login.
- ✔ Where is it processed and how long is it kept? Ask for the retention period in days and the processing location by country.
- ✔ Who can access it, including your staff and your suppliers? Get the sub-processor list. Every serious vendor has one ready.
A fourth is worth asking if the tool will be connected to your systems rather than used in a browser: what can it reach, and does it respect the permissions the user already has? Retrofitting that answer after a rollout is considerably harder than establishing it before one.
Your Staff Are Already Doing This
Someone in your business has pasted a customer email, a supplier contract or a spreadsheet into a free AI tool in the last month. In most companies we look at, several people have. They did it to get their work done faster, which is what you pay them for, and nobody had told them not to.
Treat it as initiative without a rule. A ban is the intuitive response and the least effective one: it moves the behaviour onto personal phones and personal accounts, where you have no visibility and no contract. What works is a short written rule plus one sanctioned tool that is good enough that people do not need to go looking.
The rule fits on one page: what may never be sent to any external tool, what may be sent to approved tools, which tools are approved and who approves new ones, and what to do when something goes wrong. If you want a fuller version with a file-by-file classification, our AI governance policy guide publishes the complete template we use with clients, including the copy-paste document.
When the Data Must Not Leave the Building
Sometimes the answer to "can we send this to a cloud AI service" is simply no. Client files under professional privilege, unreleased commercial material, personal data you have no lawful basis to share with a processor, anything a customer contract explicitly forbids.
That does not rule AI out. Open-weight models now run acceptably on hardware you can own, which keeps the data inside your network entirely. There are real trade-offs - capability, speed, and somebody has to look after it - and we have written the full comparison, including hardware requirements and what each approach genuinely costs, in local AI versus cloud AI. For a business whose confidentiality obligations are the blocker rather than the budget, it is the page to read next.
A middle path exists too: cloud services with contractual guarantees and pinned processing locations, used for ordinary material, with a local option reserved for the genuinely sensitive minority. Most firms end up here.
Two sectors where this stops being optional: financial services, where the regulatory perimeter shapes the architecture, and professional services, where client confidentiality does.
The Risks Worth Knowing About
Beyond data leaving the building, two failure modes matter for anyone connecting these tools to real systems. The first is prompt injection: instructions hidden in content the model reads - a document, an email, a web page - that cause it to do something you did not ask for. The second is over-trusting output that then flows into another system without validation. OWASP maintains the standard catalogue of these risks for anyone building on top of language models.3
If you are only using an assistant in a browser, this is background reading. If you are connecting one to your email, your files or your customer records, it is the design conversation.
What Your Customers Will Start Asking You
Procurement questionnaires have begun including AI questions: what you use, what happens to their data, whether you have a policy, whether you follow any recognised framework. ISO/IEC 42001 is the AI management system standard and certification against it is voluntary; the NIST AI risk management framework is the equivalent common reference in US deals.4 Neither is likely to be a requirement for a smaller supplier yet, but having a dated, versioned policy to attach is cheap and increasingly expected.
Separately, if you sell software or an AI feature rather than merely using AI internally, the EU AI Act's transparency duties for systems that interact with people or generate content apply from 2 August 2026, with heavier obligations for high-risk uses deferred to December 2027 and August 2028.5 Internal use of an assistant is not the regulated activity. What you ship can be.
Businesses going through investment or acquisition should expect the same questions with more teeth attached - our technical due diligence work now routinely covers AI usage, data handling and licensing on both sides of a deal.
Sources
- Information Commissioner's Office - Guidance on AI and data protection.
- National Cyber Security Centre - Guidelines for secure AI system development.
- OWASP GenAI Security Project - Top 10 for LLM Applications (2025).Covers prompt injection, sensitive information disclosure and improper output handling among others.
- ISO - ISO/IEC 42001:2023 AI management systems, and NIST - AI Risk Management Framework. Both voluntary.
- European Commission - Regulatory framework for AI, with Regulation (EU) 2024/1689 on EUR-Lex.Dates checked 28 July 2026; the staged timeline has already been amended once.
Need a Rule in Place This Month?
We write the policy, pick the sanctioned tool, and brief your team. Usually a matter of days rather than weeks.