Adopting an AI tool feels like a low-stakes decision. A monthly per-seat price, a credit card, a login. Nobody convenes a committee. Six months later that tool holds your customer summaries, your draft contracts, your sales scripts, and a workflow three people depend on daily. At that point it is not a subscription. It is infrastructure.
We are not here to scare anyone off AI. We use these tools daily and think most businesses should. But a few questions are worth asking before you commit, and they all live in documents nobody reads: who owns what you put in, whether it trains the model, whether you can get it back out, and what happens the day you cancel. Ten minutes now saves a miserable quarter later.
Where the Fine Print Actually Lives
The answers you need are almost never in the marketing page or the pricing table. They are spread across several separate documents, and the important ones are usually the least promoted.
- The terms of service. Where ownership of inputs and outputs is defined, along with termination rights.
- The privacy policy. What is collected and why. Consumer and business versions of the same product often have different policies, which surprises people.
- The data processing addendum. Usually a separate PDF you have to go looking for. This is where sub-processors, storage locations, and deletion timelines are spelled out.
- The trust or security center. Most serious vendors publish one. Fastest place to find certifications, data residency, and retention defaults in readable form.
- The plan comparison table. Read it for data rights, not features. The gap between the individual plan and the business plan is often about how your data is treated.
Training Rights: The Question With a Real Answer
The most common question we get is whether the AI tool is learning from company information. The honest answer is that it depends on which plan you are on, and the difference is not subtle.
OpenAI’s policy on how data is used to improve model performance states that “by default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Team, ChatGPT Enterprise, and the API.” The same policy explains that individual consumer accounts work the opposite way, improving through training on conversations unless the user opts out. Microsoft makes a similar commitment for Copilot, stating that “prompts and responses aren’t used to train the underlying foundation models.”
Notice the pattern. Business tiers are opted out by default, consumer tiers opted in. If half your team is expensing personal subscriptions, half your company data is on the wrong side of that line and nobody decided to put it there.
Also, “not used for training” is not the same as “not stored.” Microsoft’s documentation notes that for Copilot Chat, “both the prompt and response are logged and stored in Exchange for auditing/eDiscovery.” That is a feature, not a flaw. It also makes your AI conversations discoverable business records.
What “Export Your Data” Really Gets You
Almost every vendor offers an export. Fewer offer one that is useful. There is a large difference between getting your data and getting it in a form another system can read.
OpenAI’s help documentation describes the ChatGPT export as a ZIP file containing your chat history and other account data, notes that processing can take up to a week, and states that the download link is valid for 24 hours. It also notes the feature is not available for Business or Enterprise workspace accounts, which use a separate administrative process. None of that is unreasonable. It is just worth knowing before migration week.
- Test the export before you need it. Run one in the first month. Open the file. See whether a human or another tool can use it.
- Find out who can request it. On business plans, users often cannot export their own history. An administrator has to. Know who.
- Ask what is not included. Custom instructions, saved assistants, uploaded knowledge files, and fine-tuned models often do not come along.
- Confirm the deletion timeline. “We delete your data on termination” should come with a number of days and a note on whether backups count.
The Real Lock-In Is the Workflow, Not the Data
Here is the part nobody plans for. Your data is usually portable. Your process is not. When a team builds its quoting, intake, or reporting routine around one vendor’s feature, switching stops being about file formats and starts being about retraining humans.
The tells are recognizable. A custom assistant that only exists inside one product. A prompt library stored in the vendor’s interface instead of your own files. An automation built on a proprietary trigger. A knowledge base you uploaded to a tool that will not give it back in usable shape. Each one is small. Together they are why companies stay on tools they have outgrown.
Terms can also change underneath you. In a February 2024 post, staff in the Federal Trade Commission’s Office of Technology and Division of Privacy and Identity Protection warned that “it may be unfair or deceptive for a company to adopt more permissive data practices, for example, to start sharing consumers’ data with third parties or using that data for AI training, and to only inform consumers of this change through a surreptitious, retroactive amendment to its terms of service or privacy policy.” The FTC added it will keep bringing actions against companies that change the rules of the game after the fact. That is real protection, and a clear signal that terms do get quietly rewritten.
How to Stay Portable Without Slowing Down
Portability is not about avoiding commitment. It is about making sure the commitment stays a choice you can revisit.
- Keep prompts in your documents, not theirs. Your prompt library belongs in your own file storage, in plain text. It is portable, searchable, and yours.
- Keep source material at the source. Let the tool read from your document system rather than become the only place a document lives.
- Write the process down in plain English. A workflow documented as steps a person could follow can be rebuilt anywhere. One that exists only as clicks inside a product cannot.
- Buy the business tier. Not for the features. It is where the training opt-out, admin controls, and export rights live.
- Put a review on the calendar. Once or twice a year, someone rereads the terms for your most-used AI tools and confirms nothing material changed.
- Ask the exit question before you sign. “What happens to our data 30 days after we cancel?” A good vendor answers immediately. A bad one changes the subject.
The Bottom Line
AI vendor lock-in is rarely the result of a bad decision. It is a series of small reasonable ones made without anybody tracking the total. The tools are useful, the pricing is fair, and the terms are readable if you spend ten minutes with them.
So do the ten minutes. Know which plan tier each team is on and what it does with your data. Test the export while you still like the vendor. Keep your prompts and your process documented outside the product. Then commit fully, because a tool you can leave is a tool you can trust. Our guide on preparing your team for AI without the hype pairs well with the contract side.
If you want a straightforward inventory of the AI tools already in use across your business, what plan each one is on, and where your data actually sits, that is a conversation we have often. Contact us today.
Sources:
- OpenAI, How your data is used to improve model performance
- OpenAI Help Center, How do I export my ChatGPT history and data
- Microsoft Learn, Microsoft 365 Copilot privacy and protections
- Federal Trade Commission, AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive

Comments are closed