It’s a common question people ask us, and the real answer depends on which “AI” you mean.

One of the most common fears we hear from business leaders about AI is what happens to their information once it goes into one of these tools. Are we handing our ideas to a machine that will pass them on to someone else, and is any of this actually secure? It is a fair question, and it deserves a proper answer.

The useful answer is that it depends entirely on which “AI” you mean. The free chatbot someone opens on their phone and the version of the same model running inside a business account are governed by very different rules. Most of the fear we hear is built on the first one and then applied to the second, and that is where people tie themselves in knots.

The distinction that clears up most of the worry

Anthropic, the company behind Claude, made that difference very visible last year. In September 2025 it changed its consumer terms so that conversations from its free and paid personal accounts can be used to train its models unless the user opts out, and it extended how long it holds that data to five years. The same announcement confirmed that business customers, meaning anyone on Claude for Work, which covers the Team and Enterprise plans, or using the API, were not affected, and that their data is not used for training.

OpenAI draws the same line, with data sent through its API not used to train its models by default, and held only briefly for abuse monitoring unless a stricter zero-retention arrangement is in place. The consumer version of ChatGPT can be used to improve the models unless you turn that setting off.

For both, the consumer products are where your words might feed the next model, while the business and API products, the ones built for companies, come with no-training terms and short retention as standard. When a business tells us it is worried about its data training a model that a competitor could later question, it is usually picturing the consumer experience and assuming it carries across. For properly set up business use, it does not.

“But how do I know they’re not just saying that?”

That scepticism is reasonable, and worth meeting head on. The reason the no-training commitment is worth more than a marketing line is that, on a business agreement, it sits inside a data processing agreement that both sides sign. Breaking it would be a breach of contract and a breach of UK GDPR at the same time, with real liability attached, so it is something you can hold a provider to.

The commercial incentives point the same way. An AI company caught quietly training on or leaking its enterprise customers’ data would lose the corporate business that funds it and risk fines set as a share of global turnover. The trust of every business customer it has is worth a great deal more, and no serious provider is going to trade the second away for the first.

You also do not have to take it on faith. The established model providers are independently audited against standards like SOC 2 and ISO 27001, and you can insist on zero-retention terms, where nothing is kept once the answer has been returned. If that is still not enough for your most sensitive work, you can run an open model inside your own environment so the data never leaves it. The more the question matters to you, the more of the trust you can design out of it.

It also helps to be consistent with yourself. A business uneasy about a few AI prompts is usually already trusting Microsoft or Google with every email, document and payroll record it has, which is a fuller picture of how it thinks than a chat tool will ever see. No vendor offers total certainty, and your bank and your accountant do not offer it either. What actually protects you is a set of practical things: enforceable terms, incentives that line up the right way, independent audits, and the option to keep things in house when it really matters.

What you do not need to lose sleep over

A few specific fears come up again and again, and most of them do not survive contact with how business AI actually works.

People worry that anything they type is quietly absorbed into the model and could resurface for someone else. With business terms that exclude training, your inputs are not used to build the model in the first place.

Adding “please do not store this” to a prompt achieves nothing, because how a tool handles data is set by the account and the contract behind it, not by instructions inside the message.

Deleting names or figures by hand before you paste a document in feels safer than it is. Manual redaction is easy to get wrong and is no substitute for proper controls.

What is worth worrying about

There are real risks here, but they are not usually the ones people raise first.

The biggest one sits inside your own organisation. If your team does not have a sanctioned tool, they will use the free consumer ones anyway, on personal logins, pasting in client details and commercial information as they go. This is the real exposure for most businesses, and it comes down to how people behave and what rules they follow. A team with a proper business account and clear rules is in a far better position than one where everyone is quietly using whatever they found online.

“Deleted” also does not always mean gone. In 2025 a court in the United States ordered OpenAI to preserve ChatGPT logs that would normally have been removed, including conversations users had deleted, while a copyright case brought by the New York Times played out. That obligation was narrowed later in the year, but the lesson holds. Once information leaves your control, what happens to it can be decided by events that have nothing to do with you. It is a good reason to keep your most sensitive material out of consumer tools and to choose providers whose retention terms you have actually read.

Then there is leakage from the data models are trained on. Security researchers at Truffle Security found close to 12,000 working passwords and keys sitting in a single large dataset used to train models, all scraped from the public web. That is a problem with how public data gets collected, and it is exactly why keeping your own data out of training matters as much as it does.

A different kind of risk shows up only as you start connecting AI to your own systems. Once a tool can read your documents or act on your behalf, it can be misled by instructions hidden in the content it reads, something the security world calls prompt injection. It is manageable, but it has to be designed for rather than assumed away.

What the rules actually do for you

Compliance is where this gets formalised, and it is worth saying plainly that it is not box-ticking. The terms you agree with a provider matter, and so does the regulation that governs how you use AI yourself.

In the UK, the use of personal data in AI sits under UK GDPR, and the regulator, the Information Commissioner’s Office, has published specific guidance on it. The ICO now treats protecting personal data against AI-related threats as part of an organisation’s existing security duty, and it expects a documented assessment, known as a Data Protection Impact Assessment, before you put higher-risk personal data through an AI system. New rules on automated decision-making came into force in February 2026, with a statutory code of practice following in May, setting out what you owe people when a system makes decisions about them.

The direction of travel is not towards making AI harder to use. The Data (Use and Access) Act, which became law in June 2025, was written to give organisations more room to use data and automated decisions, with safeguards attached. If you also serve customers in the EU, the EU AI Act adds obligations of its own, with the bulk of its rules applying from August 2026.

For an operations business, none of this needs to feel daunting. What it means in practice is that the protections you want already have names and a shape: a written commitment from the provider not to train on your data, retention settings you control, access limited to the people who need it, and an assessment on file for anything sensitive. Put those in place and the question stops being “is AI safe” and becomes “have we set this one up properly”, which is a question you can actually answer.

The practical answer

We wanted to write this because the fear is doing real damage. We see businesses that could be getting real value from AI holding off altogether, and the risk itself is rarely the reason. More often the whole area just feels murky, and they would rather not touch it than risk getting it wrong.

That instinct is understandable, and it is also the most expensive option, because the work AI could be taking off their plate carries on costing them while they wait. Holding off does not even remove the risk, it moves it somewhere you cannot see. Where there is no approved tool, people use the free consumer ones on their own logins anyway and paste company information into them as they go, which is the very exposure the caution was meant to avoid.

The practical answer is almost always to put the right controls in place. Most of the real risk lives in how a tool is configured and how people use it, and that is the part you can control. It is usually the first thing we work through with a client, before anything goes near live data. If the privacy question is what is holding you back, it is worth a conversation.