Artificial intelligence tools such as ChatGPT, Claude, Microsoft Copilot, and Google Gemini are quickly becoming part of the everyday workplace. Employees use them to write emails, summarize documents, analyze spreadsheets, troubleshoot problems, create proposals, and improve productivity.

These tools can provide significant value, but they also create an important question for business owners:

What company information are employees putting into AI systems, and who controls what happens to that information?

The concern is not simply whether an AI company uses a conversation to train its models. Businesses must also consider account ownership, data retention, employee offboarding, access permissions, connected applications, audit capabilities, and the types of information employees are permitted to submit.

For businesses in Delray Beach, Palm Beach County, Broward County, Martin County, and throughout South Florida, now is the time to establish clear rules for using AI with company data.

Every AI Prompt Is a Form of Data Sharing

When an employee enters information into an AI tool, that information leaves the company’s immediate environment and is processed by another service.

A prompt could include:

  • A customer’s name or contact information
  • Internal pricing or financial information
  • An employee record
  • A contract or legal document
  • An email conversation
  • A spreadsheet containing customer data
  • Source code or technical documentation
  • Passwords, API keys, or network details
  • Medical, payment, or other regulated information

Employees may not think of this as uploading company data. They may believe they are simply asking a question or requesting help.

From a security perspective, however, copying information into an AI prompt should be treated similarly to uploading it to another cloud service.

Personal AI Accounts vs. Company-Managed Accounts

One of the biggest concerns is employees using personal AI accounts for company work.

An employee may sign up using a personal email address, pay for an individual subscription, and begin uploading business documents without involving management or IT. Even when the AI provider offers privacy settings, the employee—not the company—controls those settings.

That creates several problems.

The Company Does Not Control the Account

With a personal account, the business may be unable to:

  • Require multifactor authentication
  • Enforce company security policies
  • Review data-sharing settings
  • Control connected applications
  • Audit how the account is being used
  • Remove company information
  • Disable access when the employee leaves
  • Apply consistent retention or deletion policies

The employee may continue to have access to conversations, uploaded files, custom instructions, projects, and other company-related material after leaving the organization.

Settings Can Vary Between Employees

One employee may disable model training. Another may leave it enabled. A third may connect the AI tool to company email, cloud storage, or documents without understanding the permissions being granted.

Without centralized administration, the business has no reliable way to confirm that everyone is using the same protections.

Personal and Business Information Can Become Mixed

Employees may use the same account for personal questions and company work. This makes it harder to separate business records, investigate an incident, respond to a legal request, or remove company information later.

A company-managed AI workspace provides a clearer separation between personal use and business activity.

Why Enterprise and Business AI Accounts Are Different

Business-controlled AI plans generally provide protections and administrative capabilities that are not available—or are not centrally enforceable—with personal accounts.

Depending on the platform and subscription, these may include:

  • Centralized user management
  • Company ownership of the workspace
  • Single sign-on and identity integration
  • Multifactor authentication enforcement
  • Administrative security controls
  • Data-retention settings
  • Audit and compliance capabilities
  • Control over applications and integrations
  • Domain verification
  • Easier employee onboarding and offboarding
  • Contractual commitments regarding business data

For example, OpenAI states that it does not use data from ChatGPT Business, Enterprise, Edu, Healthcare, Teachers, or its API platform to train its models by default. Business plans also include additional administrative and data-control options.

Anthropic similarly states that inputs and outputs from its commercial products, including Claude for Work and its API, are not used for model training by default. Claude Enterprise also offers organization-controlled retention settings.

Microsoft states that Microsoft 365 Copilot and Copilot Chat with enterprise data protection do not use prompts, responses, or Microsoft Graph data to train their underlying foundation models. These services also inherit Microsoft 365 identity, retention, sensitivity-label, auditing, and compliance controls.

These protections do not make AI risk-free. They do, however, provide the organization with substantially more visibility and control.

Pay Attention to the Data-Sharing Checkboxes

Many consumer AI services include settings that determine whether conversations may be used to improve or train models.

These settings should never be ignored.

In a personal ChatGPT workspace, for example, data sharing is enabled by default, although users can turn off “Improve the model for everyone” under Data Controls. Turning it off prevents new conversations from being used for model training.

Other AI platforms use different wording. Settings may refer to:

  • Improving the service
  • Improving models
  • Product development
  • Conversation history
  • Activity tracking
  • Human review
  • Diagnostic information
  • Feedback sharing
  • Connected-app data

Business owners should not assume that every employee has found and configured these options correctly.

AI products also change frequently. A setting reviewed six months ago may have been renamed, relocated, or replaced. Privacy policies, integrations, and product terms can change as features are introduced.

Organizations should review approved AI platforms and their settings on a regular schedule.

“Not Used for Training” Does Not Mean “Nothing Is Stored”

Model training and data retention are separate issues.

A provider may agree not to use company prompts to train a general model while still retaining information for:

  • Providing conversation history
  • Supporting projects or shared workspaces
  • Security and abuse monitoring
  • Legal or regulatory obligations
  • Troubleshooting and service operation
  • Audit and compliance requirements

For example, OpenAI documents separate retention policies for chats and files, while Anthropic offers configurable retention controls for certain enterprise customers. Microsoft 365 Copilot interactions can be subject to the organization’s auditing, eDiscovery, and retention policies.

Businesses should therefore ask two different questions:

  1. Is our information used to train or improve the provider’s models?
  2. How long is our information stored, where is it stored, and who can access or delete it?

Both answers matter.

Connecting AI to Microsoft 365 or Google Workspace Requires Additional Care

Modern AI platforms can connect to email, calendars, SharePoint, OneDrive, Google Drive, customer-management systems, and other cloud services.

These integrations can be extremely useful, but they dramatically expand the amount of information the AI system can access.

Before approving a connection, determine:

  • What information the application can read
  • Whether it can create, edit, send, or delete content
  • Whether access applies to one user or the entire organization
  • Whether administrators can revoke the connection
  • Whether the integration has separate privacy terms
  • Whether the application stores copies of the information
  • Whether activity is logged and auditable

Businesses should also review existing file permissions before deploying an AI system that searches company data.

Microsoft specifically warns that Copilot follows a user’s existing permissions. If SharePoint, Teams, or OneDrive content is already overshared, Copilot may make that information easier for authorized—but unintended—users to discover.

AI does not necessarily create the permission problem. It can expose an existing problem much faster.

Information Employees Should Not Enter Into Unapproved AI Tools

Unless the organization has specifically reviewed and approved the platform, employees should avoid submitting:

  • Passwords or authentication codes
  • API keys and security tokens
  • Firewall, VPN, or network credentials
  • Social Security numbers
  • Credit-card or banking information
  • Protected health information
  • Private employee records
  • Confidential customer lists
  • Nonpublic financial reports
  • Legal strategy or privileged communications
  • Proprietary source code
  • Confidential contracts
  • Information covered by a nondisclosure agreement
  • Complete database exports
  • Documents containing unnecessary personal information

Even with an approved enterprise platform, employees should follow the principle of minimum necessary data. Provide only the information needed to complete the task.

A Practical AI Security Checklist for Business Owners

1. Identify Which AI Tools Are Already Being Used

Do not assume that employees are waiting for permission. Ask which platforms, browser extensions, meeting assistants, writing tools, and AI applications are already in use.

This process is sometimes referred to as identifying “shadow AI.”

2. Establish a List of Approved Platforms

Employees should know which AI services are approved for company work and which are prohibited.

Whenever possible, use company-managed accounts rather than personal subscriptions.

3. Review Privacy and Training Settings

Confirm that optional data sharing, model improvement, and unnecessary activity-tracking features are disabled unless the company has intentionally approved them.

Document the settings so they can be checked again later.

4. Require Company Credentials

Employees should use their company email address and organization-managed identity whenever the approved platform supports it.

Avoid shared usernames and passwords. Each user should have an individual account.

5. Enforce Multifactor Authentication

An AI account containing company conversations, uploaded documents, or connected cloud data should receive the same protection as email and other business systems.

6. Create a Written AI Acceptable-Use Policy

The policy should explain:

  • Which tools are approved
  • What information may be submitted
  • What information is prohibited
  • Whether files may be uploaded
  • Whether company systems may be connected
  • Who must approve new AI services
  • How AI-generated work must be reviewed
  • How suspected data exposure should be reported

7. Review Integrations Before Approving Them

AI agents, custom applications, browser extensions, plugins, and connectors may have privacy terms that differ from the primary AI platform.

Each integration should be evaluated separately.

8. Include AI in Employee Offboarding

When an employee leaves, administrators should remove access, revoke active sessions, transfer necessary business information, and review connected applications.

This is difficult or impossible when company work has been performed through a personal account.

9. Do Not Automatically Trust AI Output

AI-generated information can be incorrect, incomplete, outdated, or based on misunderstood context.

Employees should verify:

  • Technical instructions
  • Financial calculations
  • Contract language
  • Legal or compliance conclusions
  • Customer-facing statements
  • Citations and references
  • Code and configuration changes

AI should assist human judgment, not replace it.

10. Train Employees Regularly

A policy that nobody understands will not provide much protection.

Employee training should include realistic examples, such as whether it is appropriate to upload a customer spreadsheet, paste an email chain, summarize a contract, or ask an AI tool to troubleshoot a network using real credentials.

A Simple Green, Yellow, and Red AI Policy

One easy approach is to categorize AI use into three levels.

Green: Generally Acceptable

  • Brainstorming generic ideas
  • Improving grammar
  • Creating outlines
  • Rewriting public marketing content
  • Asking general technical questions
  • Creating templates without real customer information

Yellow: Approval or Extra Care Required

  • Internal emails
  • Financial summaries
  • Contracts
  • Customer correspondence
  • Proprietary procedures
  • Source code
  • Company spreadsheets
  • Files from SharePoint, OneDrive, or Google Drive

Red: Do Not Submit

  • Passwords
  • Authentication codes
  • Payment-card information
  • Social Security numbers
  • Protected health information
  • Highly confidential legal information
  • Private encryption keys
  • Security credentials
  • Information prohibited by contract or regulation

The exact categories should be customized for the organization and its industry.

The Bottom Line

AI can improve productivity, but allowing employees to use personal AI accounts with company information creates unnecessary risk.

Turning off a model-training checkbox is a good step, but it is not a complete security strategy. It does not give the business control over account access, retention, integrations, auditing, or employee offboarding.

Businesses should adopt company-managed AI accounts, establish an acceptable-use policy, review privacy settings, secure connected data, and train employees before confidential information is placed into these platforms.

TMD Technology Services helps businesses in Delray Beach and throughout Palm Beach, Broward, and Martin Counties evaluate AI tools, Microsoft 365 permissions, account security, cloud access, and employee data-handling practices.

Learn more about our computer cybersecurity services, managed IT services, and Microsoft 365 setup and migration services.

Need help determining whether your employees are using AI securely? Contact TMD Technology Services for an AI and company-data security review.

This article provides general cybersecurity information and is not intended as legal, regulatory, or compliance advice.

Recommended Posts