
Can AI Companies Use the Data Your Team Enters?
Every day, employees paste information into AI tools like client email drafts, proposals, spreadsheets, meeting notes, and in some industries, patient or client information. While they do it to complete their work faster, most of them never stop to ask what happens to that information after they hit enter. Business owners are just now starting to ask that question, and the answer is not about the law in your jurisdiction necessarily. It’s about the terms and conditions someone clicked on and accepted when they signed up for the AI software account they’re entering information into.
The short answer: Can AI companies use the data your team enters? The short answer is often, yes. Many consumer AI tools can use the information people enter to improve their models, keep it for a period of time, and have staff review some conversations. None of this is illegal because those are the terms users agreed to when they signed up.
Key Takeaways
"Permission" is usually already given. When an employee signs up for a free or personal AI account, they accept terms that may allow the company to use what they enter. That employee rarely has authority to agree to that on your company's behalf, but the data is still shared.
The account type matters more than the tool. While the same AI product can have very different data practices on a personal plan versus a business plan, you lose control over what happens to the data once you enter it into a third party tool.
Opting out or disabling a feature is not the same as being protected. Turning off training settings doesn't necessarily stop retention, human review, or exposure through sharing features.
The bigger legal risk may be yours. Entering confidential client information, trade secrets, or protected health information into an unapproved tool can breach your contracts or privacy obligations, regardless of what the AI company does with it.
A policy is how you close the gap. Your team needs to know which tools are approved, which accounts to use, and what information never goes into any AI tool.
What AI Companies Can Do With the Information Your Team Enters
The exact data management practices vary by company and plan, and they change often. In general, information entered into an AI tool may be:
Used to train or improve models. Some consumer plans use conversations to improve future versions of the AI unless the user turns that setting off.
Kept for a period of time. Deleted chats disappear from the user’s view but can be retained for safety monitoring, abuse prevention, or legal reasons before being permanently removed.
Reviewed by people. Some providers have trained staff or contractors review a sample of conversations to improve quality and safety. So while they can’t train on your data, they can access and review the information you input into their platform as part of their data safety protocol.
Exposed through sharing features. In 2025, about 4,500 ChatGPT conversations that users had shared with a "discoverable" setting appeared in Google search results. OpenAI removed the feature and Google supposedly removed the data, the incident shows how easily a shared link can make private information public.
Processed by other companies. AI providers often rely on cloud hosts and other vendors, called subprocessors, to run their services. This means those subprocessors have access to the you enter data as well.
Can They Legally Do That?
In many cases, yes. The legal basis is usually the terms of service the user accepted. A few points matter for business owners:
There's no single federal privacy law covering most business data in the United States. Laws such as the California Consumer Privacy Act focus mainly on personal information about individuals, not on your company's confidential business information.
Regulators expect honesty about data use. In 2024, the FTC warned that companies quietly changing their terms to use customer data for AI training could be engaging in unfair or deceptive practices. That protects users from surprise changes, but it doesn't undo terms they already accepted.
Employees usually can't bind your company to a tool's terms, but that doesn't pull the information back once it's shared.
Your own obligations still apply. Client contracts, nondisclosure agreements, privacy laws, and industry regulations govern what you and your staff may share, with AI tools or anyone else. Entering confidential information into an unapproved AI software tool can breach those obligations even if the AI company never uses it. It can also weaken trade secret protection, which depends on taking reasonable steps to keep information confidential.
Laws differ by state, country, and industry. For questions about your specific situation, talk with your attorney.
What's Different in Healthcare and Behavioral Health
For healthcare providers and treatment programs, the question shifts from what the AI company can do to what the provider is allowed to share.
The disclosure itself can be the violation. Under HIPAA, a provider generally needs a business associate agreement (BAA) before sharing protected health information with a vendor. Personal AI accounts, free or paid, don't come with one.
Substance use disorder records carry extra protection. 42 CFR Part 2 restricts disclosing information that identifies someone as a patient of an SUD program. Since February 16, 2026, Part 2 has followed HIPAA's breach notification rules and penalties.
Removing names isn't enough. Clinical details, life circumstances, and locations can identify a client without a name or date of birth.
Business plans with a BAA can be part of a compliant setup, but only after review by your compliance or privacy officer.
We cover this in depth in another blog post: Shadow AI and the HIPAA and 42 CFR Part 2 Violation Dilemma.
What to Check Before Approving an AI Tool
Before your company approves any AI tool, find clear answers to these questions in its terms, privacy policy, or business agreement:
Does it train on our data? Is training off by default for business accounts, or does someone have to turn it off?
How long is data kept? What happens to conversations after they're deleted?
Can people review our conversations? Under what circumstances?
Who else processes our data? Is there a list of subprocessors?
Where is data stored? This matters for companies with location or residency requirements.
Can we control it centrally? Business plans often let an administrator manage settings, users, and sharing for the whole company.
Will the vendor sign the agreements we need? For healthcare, that means a BAA. For other industries, it may mean a data processing agreement or confidentiality terms.
Can sharing features be turned off? Public share links are an easy way for information to be leaked and accessible in search engines.
How to Protect Your Company's Data
Use business accounts, not personal ones. Require staff to use company-managed AI accounts for any work task.
Turn off training and sharing where possible. Check the settings on every approved tool, and recheck after updates.
Define what never goes into AI. Client and patient information, financial records, personnel files, passwords, contracts, and trade secrets are common examples.
Find out what's already in use. Ask staff which tools they've used, and make it safe to answer honestly.
Put it in writing. An AI use policy turns these rules into a standard your whole team follows. We listed the eight core sections you want to include in your policy in our blog post: Do We Need an AI Policy If We Don't Use AI?.
Frequently Asked Questions
Do AI companies train on what I type into ChatGPT, Claude, or Gemini?
It depends on the plan and your settings. Some consumer plans may use conversations for training unless you opt out, while business and enterprise plans typically don't train on customer data by default. Check each provider's current policy, because these terms change.
If I turn off training, is my data private?
Not entirely. Turning off training usually stops your conversations from improving future models, but the provider may still keep them for a period of time for safety or legal reasons, and sharing features can still expose them. A business account provides more protection when there is a company-level agreement in place outlining how data will be handled, managed, and stored.
Is a paid AI account safer than a free one?
Not necessarily. The meaningful difference is between personal accounts, free or paid, and business accounts with company-level agreements and controls. A personal paid plan is still a personal account.
Can I ask an AI company to delete my company's data?
Most providers let users delete conversations, and many offer deletion requests through their privacy settings or support teams. Deletion may not be immediate, and data already used to train a model generally can't be pulled back out of it.
Who is responsible if an employee enters confidential client information into an AI tool?
Usually your company. Your obligations to clients, under contracts, privacy laws, and industry regulations, apply to what your staff share. That's why a clear AI use policy and approved tools matter.
Protect Your Data Before There’s a Problem
Your company needs an AI use policy whether or not you've approved any AI tools, because your team may already be entering company information into them. In a 20-minute call, we'll talk through how AI is being used in your company today and how our AI Use Technology Toolkit helps you put a clear AI use policy in place.
Schedule a Call With Us:
https://calendly.com/micheledavisnyc/20-minute-chat
