AI Security & Privacy

20 minute readLast updated August 27, 2026

Part 1 · Privacy

What AI tools do with your company data, and how to fix it in one afternoon

This training has two parts. Part 1 covers what AI vendors do with your company data: the five things every company must know, the four privacy levels of AI tools, and a checklist your team can finish in one afternoon. Part 2 covers how attackers use AI against your company. Every claim links to its source.

1. Deleted chats are not deleted

When your team pastes text into an AI tool, that text lands on the vendor's servers. Deleting the chat removes your copy. The vendor keeps its copy for about 30 days. If the law requires it, they keep it longer.

In May 2025, a court ordered OpenAI to keep every consumer chat as evidence in the New York Times lawsuit, including chats users had deleted. Enterprise customers were excluded. Consumer accounts were not.

In 2025, shared chat links showed up in Google search results. Over 370,000 Grok chats, about 4,500 ChatGPT chats, and hundreds of Claude chats. The exposed pages held names, email addresses, and uploaded files.

The company rule: nothing goes into an AI chat that you would not send to a stranger. Ban share links for anything with client information. Move work accounts to a business plan, where deletion is a contract.

2. You are opted in by default

Most AI tools train on your chats unless you turn it off. ChatGPT personal plans train by default. Claude asks at signup, with the toggle already set to on. Gemini keeps activity on by default, and human reviewers read a sample of chats. Copilot personal accounts train by default too.

Paying does not fix it. A 20 dollar ChatGPT Plus plan trains by default, same as free. The line that matters is personal account versus business account. Business plans from OpenAI, Anthropic, Google Workspace and Microsoft do not train on your data. It is in the contract, and your employees cannot switch it back on by accident.

One setting almost nobody finds: in June 2026 Google turned on Save Media. Photos, files and voice recordings uploaded to Search can train its AI unless you opt out. Media picked for training can be kept up to 4 years, even if you delete the original.

3. What training really does with your data

Models memorize repetition. A line the model saw ten times in training comes back about a thousand times more often than a line it saw once. In 2023, researchers spent about 200 dollars and made ChatGPT print thousands of memorized snippets, including real emails and phone numbers. What leaked was public web text, not user chats. So far, nobody has documented company data pasted into a chatbot coming back out of a model. Samsung's engineers pasted secret chip code into ChatGPT in 2023. The code never resurfaced.

Two reasons to still care. First, training cannot be undone. Opt out today, and your data stays inside every model trained yesterday. Second, in January 2026 a US federal court ruled that typing trade secrets into a consumer chatbot can end their legal protection. Nothing has to leak. The paste alone can be enough.

AI tools also keep a memory file about each user. They remember you across conversations. Ask any tool "what do you remember about me" and read the answer. Connected apps grow that file. Give an AI your mailbox or your drive, and the vendor can read everything in it. Give each connection the least access that does the job. Clear the memory in every tool your team uses, and cut the connectors nobody uses.

4. The chatbot laws are here

If a customer chats with your AI, they must know it is an AI from the first message. In the EU this is binding since August 2, 2026, under Article 50 of the AI Act. A visible label on the chat window satisfies it, per the Commission's guidelines. A note buried in the website footer does not. Fines reach 15 million euros or 3 percent of global revenue. Small and mid-sized companies pay the lower of the two. If your chatbot is a third-party tool with your branding, you are treated as the provider. You cannot point at your vendor.

The US has its own laws. Maine requires disclosure since September 2025. California since 2019. Utah requires an honest answer the moment a customer asks. More states follow each year.

Laws follow the customer, not the company. Enforcement follows presence and money. Following the strictest rule costs one sentence at the start of the chat, and that sentence satisfies every country at once.

AI content follows the same logic. AI images or video that look like real people or events must be labeled. AI written text needs a label only in one case: it informs the public and no real human reviewed it.

5. Your team is already using AI

Workers use AI at work without telling anyone, mostly on personal accounts. One study measured 27.4 percent of the company data entering AI tools as sensitive, and 73.8 percent of workplace ChatGPT use on personal accounts. Those accounts belong to your employees, not to your company. When someone quits, your data quits with them. Count everything: meeting notetakers record calls, browser extensions read what is on screen.

The fix has two parts. Part one: a one page policy. Which tools are allowed. Which data never goes into any AI tool: customer data, financials, contracts, anything under NDA. AI accounts go on the offboarding checklist. Part two: buy the business plan and give people official access. No training by contract, admin visibility, and offboarding becomes removing a seat.

The four privacy levels of AI tools

Every AI tool your company touches sits on one of four levels.

Level 1: little control. DeepSeek stores user data in China, per its own policy, left a database with chat histories open on the internet, and is banned on government devices in several countries. Meta AI chats feed ad targeting, with no US opt-out. Grok trains on posts and chats by default. Company data never goes into level 1 tools.

Level 2: consumer accounts of the big names. ChatGPT, Claude, Gemini and Copilot on personal plans. Training on by default, human review in some cases, long retention. A paid personal plan is still level 2. After the toggles are flipped, level 2 is fine for generic work. Sensitive data stays out.

Level 3: business tiers. Same models, different contract. No training on your data, in writing. Deletion windows around 30 days. Admin controls and audit trails. Enterprise customers were excluded from the 2025 court order. This is where your company should live.

Level 4: nothing retained. Zero data retention agreements (OpenAI and Anthropic offer them), or a model running on your own servers. If you handle health, legal or financial client data, this level exists for you.

Two questions grade any AI tool in five minutes. Who owns the account, an employee or the company? Does the contract say no training, with a deletion window?

The comparison table

The four levels, tool by tool. Policies change often. This table is a snapshot of August 25, 2026.

TierChatGPT (OpenAI)Claude (Anthropic)Gemini (Google)DeepSeek
FreeTrains on your chats by default. Opt out in Settings, then Data Controls. Deleted chats wiped in about 30 days, unless the law requires keeping them. Shows ads in the US.Asks at signup, with the training toggle already set to on. If it stays on, chats can be kept up to 5 years. If off, deleted chats purge within 30 days. No ads.Activity is on by default. Human reviewers read a sample of chats. Reviewed chats are kept up to 3 years, even after you delete them.Your data is stored in China, per its own policy. Trains by default. No stated retention limit. Left chat histories open on the internet in January 2025.
Paid personalSame training default as Free. Paying removes ads only from Plus up.Same policy as Free. Paying changes limits, not privacy.Same as Free. Paying does not remove training or human review.No paid personal plan exists.
Business / TeamNo training on your data, by contract. Admin controls. Deleted conversations removed in about 30 days.No training, per the Commercial Terms. Deleted chats purge within 30 days. Org owners can export all chats.Through Google Workspace: no training on customer data, content stays in your domain, admin-controlled retention.Does not exist.
EnterpriseNo training. Admins control retention. Excluded from the 2025 court order that froze consumer chats.No training. Custom retention controls, audit logs, compliance certifications.Same Workspace protections plus more certifications and admin retention controls.Does not exist.
API (developers)No training on API data since March 2023. Inputs kept up to 30 days for abuse checks, then deleted.No training. Inputs and outputs auto-deleted within 30 days.The free API tier trains and has human review. The paid tier does not. Vertex AI: no training without permission.The hosted API follows the same China-storage policy. Self-hosting the open model keeps data on your own servers.
Zero data retentionAvailable for the API on approval: prompts are not stored after the answer.Available for the API through sales. Some models are excluded.Possible on Vertex AI with an exception request.Only by self-hosting.
Sold or fed to ads?Says it does not sell your data. Ads run on the Free and Go plans only.States it does not sell your data. No ads.Says personal data is not sold. States Gemini chats are not used for ads today.States no ad targeting and no selling. Still shares data widely: service providers, its corporate group, law enforcement.

The one afternoon checklist

First hour, the AI you use. Have everyone flip the training toggles on personal accounts used for work. In ChatGPT: Settings, Data Controls, "Improve the model for everyone", off. Claude and Copilot have the same switch in their privacy settings. Check the Google one at Search Services History: turn Save Media off and delete what is already saved. Read what each tool remembers and clear what should not be there. Disconnect every app the AI can reach that you do not use. No share links with client information, ever.

Second hour, the AI you provide. Open your website chatbot and read its first message like a customer would. If it does not say it is an AI, add the line. One visible sentence at the start covers the EU and US laws. Label AI images or video that look like real people or events. Keep one human review step in front of AI text you publish.

Third hour, the system that keeps it fixed. List every AI tool in use and grade it with the four levels. Ban level 1 for company data. Move real work to a business plan. Write the one page policy: allowed tools, the never-paste list, AI accounts on the offboarding checklist. Send it to the team and say it plainly: you know they use AI, you want them to, this is the safe way.

This takes one afternoon. Most companies have not done it. Run it and you are ahead of them, with the legal risks closed.

Part 2 · Security

How attackers use AI against your company, and the four defenses

Part 1 was about your vendors. Part 2 is about attackers. Four risks, each with a real case behind it, and each with a fix your team can run this week.

Prompt injection: your chatbot can be turned against you

A chatbot follows instructions in the text it reads. It cannot reliably tell your instructions from a visitor's. This is called prompt injection, and OWASP ranks it as the number one security risk for AI applications.

In December 2023, a visitor told a Chevrolet dealership's chatbot to agree with everything he said. The bot then agreed to sell a 76,000 dollar SUV for one dollar. The chat went viral. The dealership shut the bot down.

The quieter version is worse. An AI that reads emails or documents will also follow instructions hidden inside them. In June 2025, researchers showed that one crafted email could make Microsoft 365 Copilot leak internal company files, with no click from the employee. Microsoft fixed it and found no abuse in the wild. The lesson stays: everything your AI reads is input, and input can carry commands.

The defense. Give your customer bot a short list of what it may say and do: no discounts, no refunds, no personal data. Require a human approval before any AI action that moves money or sends data. Before launch, spend an hour attacking your own bot. Tell it to ignore its rules and watch what it does.

Your chatbot's promises bind you

In February 2024, a Canadian tribunal ordered Air Canada to honor a refund policy its chatbot invented. The airline argued the chatbot was responsible for its own words. The tribunal rejected that. What your bot tells a customer, your company said.

The defense. Limit the bot to approved policy text. Give it a clear path to a human for anything about money. Keep the transcripts and read them every week. The transcripts also show you what customers actually ask.

Deepfake fraud: the video call can lie

In early 2024, an employee at the engineering firm Arup joined a video call with the company's CFO and several colleagues. Every person on the call except the employee was an AI deepfake. The employee made 15 transfers, about 25 million dollars in total. No system was hacked. The people were.

The defense is one rule. Any request to move money or change payment details gets verified on a second channel: call the person back on the number you already have. No exceptions for urgency. Urgency is the tell. Seeing a face or hearing a voice is no longer proof.

AI oversharing: your own files, one question away

An AI assistant connected to company files shows each employee everything their account can technically open. Most companies carry old permission mistakes: a salary file in a shared folder, a contracts folder open to everyone. Nobody found those files by browsing. The AI finds them on the first question. Microsoft published deployment guidance for exactly this problem.

The defense. Before rolling out an AI assistant over your files, check who can open the most sensitive folders. Then pilot with a small group and have them ask the AI for salaries, contracts, and passwords. Fix what it finds. Roll out wider only after the test comes back clean.

Part 1 protects you from your vendors' defaults. Part 2 protects you from people who use AI against you. Every fix above is a procedure, not a product. One afternoon for part 1, one week for part 2, and your company is ahead of most.