Somebody on your team is pasting client information into an AI tool right now. Not maliciously. They are summarizing a long thread or figuring out how to answer a difficult email. The question nobody asked first was whether that information was allowed to leave your building.
Let us be plain. This is general information for business owners, not legal advice, and no substitute for having your own attorney read your own contracts. What we can do is show where the lines usually sit, what the vendor language means, and what to bring to your lawyer.
Start With the Contract You Already Signed
Before anyone gets to privacy law, most businesses run into a simpler problem. They already promised, in writing, to keep something confidential. Read your client agreements and your standard nondisclosure agreement, and look for three things. First, how confidential information is defined, because it is often broad enough to include anything a client tells you. Second, whether there is a list of permitted recipients, which usually covers employees and named subcontractors and nothing else. Third, whether any clause covers transferring data to third parties.
Here is why that matters. Sending client data to an AI vendor is sending it to a third party. Whether that is fine depends on your contract, not on how the tool feels to use. A chat box feels like a private notebook. Contractually, it is a service provider.
Regulated Data Has Its Own Rules
Some categories carry obligations that exist whether or not anybody wrote them into your contract.
- Health information. Under the HIPAA rules described by the U.S. Department of Health and Human Services, a business associate is generally an entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. HHS explains that a covered entity may disclose that information to a business associate if it first obtains satisfactory assurances, in the form of a contract or other written arrangement, that the information will be safeguarded. Translated: a vendor handling health data generally needs a signed agreement first.
- Payment card data. Card numbers are governed by the payment card industry rules your merchant agreement binds you to. There is never a good reason to paste one into a general purpose tool.
- Personal data under state privacy law. The Texas Attorney General’s office describes the Texas Data Privacy and Security Act, effective July 1, 2024, as applying to companies that conduct business in Texas or serve Texas residents and process personal data, with a general small business exemption unless the business sells sensitive data. It requires covered controllers to limit collection to what is adequate, relevant, and reasonably necessary, and to maintain reasonable data security. Sensitive data there includes information revealing racial or ethnic origin, religious beliefs, health conditions, genetic and biometric data, children’s data, and precise geolocation.
- Sector rules you already know about. Financial, legal, education, and government contract work carry their own obligations. If you have answered a compliance question about a filing cabinet, the same answer applies to a prompt box.
One caveat. Privacy laws change. Confirm current requirements with counsel rather than relying on a summary, including this one.
What “We Do Not Train on Your Data” Actually Means
This sentence appears on nearly every AI vendor’s page, and it does mean something real. It just answers a narrower question than people think.
OpenAI’s enterprise privacy page, for example, states that by default it does not use business data for training its models, and that data from its business, enterprise, education, and API products is not used for training unless a customer explicitly opts in. That is a clear commitment about training. Now notice what it does not say. It does not say the data never reaches the vendor’s servers, or that it is never stored. The same page describes retention that varies by product, including admin controlled retention on the business tiers.
Three questions hide inside that one sentence.
- Is it used to train models? Look for whether the commitment applies by default or only after a setting is changed.
- How long is it retained, and who can see it? Look for retention periods, admin controls, and whether vendor staff can review content for abuse monitoring or support.
- Who owns the inputs and outputs, and where do they live? Look for ownership language and any statement about processing location and subprocessors.
Where do you find this? Not in the headline. Look for pages named enterprise privacy, trust center, data processing addendum, or business terms, and read the terms for your actual plan. Save a dated copy, because terms change.
Consumer Tier Versus Business Tier
The product looks identical either way. Same interface, same model, wildly different contract.
A free or personal paid account is typically governed by consumer terms, tied to an individual rather than your company, with no administrative visibility for you. A business tier typically adds company ownership of the account, administrative controls including retention settings, centralized user management, and the commercial terms your client questionnaires ask about. On the OpenAI page above, the business tiers are also where you find the statement that you own your inputs and outputs.
The consequence is uncomfortable. If your team uses personal accounts for company work, your data sits under an agreement your company never signed, in an account you cannot administer, and it walks out the door when the employee does. That is the problem we described in our article on shadow IT with a newer logo. The fix is the same: provide a sanctioned tool good enough that nobody goes around you.
The Practical Rule of Thumb
You cannot ask your team to run a legal analysis before every prompt. You can give them one test. Before pasting, ask: would I be comfortable if this exact text appeared in an email to a stranger with my company name on it? If not, it does not go into a tool that is not covered by a business agreement you actually have.
Here is a never list worth posting where people can see it. None of this goes into a public or personal tier tool without an approved exception.
- Anything identifying a person plus something sensitive. A name with a diagnosis, a salary, a complaint, a legal matter, or an immigration status.
- Credentials and keys. Passwords, API keys, tokens, connection strings, recovery codes. These end up in pasted log files by accident, so look first.
- Account and payment numbers. Card numbers, bank details, government identification numbers.
- Documents marked confidential or under an NDA. Unsigned contracts, client strategy documents, and anything belonging to a client rather than to you.
- Unreleased company information. Pricing models, acquisition discussions, personnel actions, security findings about your own environment.
Now the constructive half, because a list of nos with no yeses gets ignored. Redact before you paste, use placeholder names, ask about the shape of the problem rather than the specifics, and route sensitive work into the sanctioned tool. Most of what people want AI for does not need the identifying details.
The Bottom Line
The legal lines around AI and client data are less mysterious than they sound. Your confidentiality agreements probably already govern this. Regulated data categories carry obligations that follow the data. Vendor promises about training are real but narrow, and your tier determines which apply. Give your team a sanctioned tool, one test, and a short never list, and you have handled most of the risk.
Again, this is general information and not legal advice. Take your contracts and your data map to your attorney. If you want help building the map, and setting up sanctioned tools so the policy is enforceable rather than decorative, we do that work, and it pairs well with preparing your team for AI without the hype. Contact us today.
Sources:

Comments are closed