
Staff in many businesses have discovered that an AI assistant can summarize a long email thread, draft a response, or classify a batch of inquiries in seconds. The same convenience creates a risk: customer information is pasted into a public chatbot with no record of who did so, which account was used, or what the provider's terms permit.
The solution is not to prohibit AI, which tends to drive its use out of sight. Instead, decide where AI belongs in the business, place it inside defined processes, and send it only the information it needs.
Understand what the provider's terms say.
Providers distinguish between consumer and business products, and the difference matters.
OpenAI states that "by default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform — including inputs or outputs — for training or improving our models." It also states that qualifying organizations can configure how long business data is retained, including a zero-retention option in the API platform.
Anthropic's Privacy Center states that, by default, it will not use inputs or outputs from its commercial products, which include Claude for Work, Team, Enterprise, and the API, to train its models. It notes that this changes if a customer explicitly reports feedback or bugs, or otherwise chooses to allow it. Separate terms and settings govern its consumer plans.
Two conclusions follow. First, the account type determines the terms, so a personal account used for business information is not equivalent to a business account. Second, terms and settings change, so the people responsible for the data should read the current versions rather than rely on a general understanding.
Where AI belongs in a business process
The safest place for AI is inside a defined step of a process, not as an open-ended conversation. Examples include classifying an incoming inquiry by topic, summarizing a case history for review, extracting fields from a document, and drafting a reply for approval. In each case, we define the input, check the output, and log the step.
This is also how we approach AI in the automation work we undertake: the model performs a specific task within a workflow that an organization controls, and a person reviews anything that carries consequence.
Practices that keep customer data out of the wrong places
- Decide which tools are approved. Name the accounts, plans, and tools that may be used for business information, and state that personal accounts are not among them.
- Define what must never be pasted. Exclude payment card details, government identifiers, credentials, and health or other regulated information unless the provider's contract and your own obligations expressly allow it.
- Send the minimum. An AI step that classifies an inquiry rarely needs the sender's full name, address, and phone number. Pass only the fields the task requires, and replace identifiers with references where possible.
- Use business or API access with the training default confirmed. Verify the current terms and confirm the setting before processing the first customer record.
- Keep a record. Log what was sent, which service it went to, and what was returned so you can answer questions later.
- Keep a person in the loop for consequential output. Review a draft reply or summary before it reaches a customer or informs a decision.
- Review contracts where data is regulated. If a business handles health, financial, or other regulated information, it should confirm what agreements the provider offers and what its own obligations are before any use. That is a matter for counsel, and this article is not legal advice.
- Train the team and review quarterly. A short policy people understand is more effective than a long one that gets ignored, and the tools and terms change often enough to justify regular review.
The short version
Keep customer data out of general-purpose chatbots by giving AI a defined place in business processes, using business-grade accounts whose terms you have read, sending only what each step needs, and keeping a person responsible for anything consequential. If you would like our team to help place AI inside your processes with these controls, reach out to us — we will transparently assess the approach before any commitment.
Sources
Provider terms verified as of October 2026. They change; confirm the current versions. This article is educational and not legal advice.
Have a system you want your website to talk to?
Book a free discovery call. We will tell you where your applications stand before you commit to anything.
Book a discovery call