Is my company data safe if we use AI tools?
By Max Bridge · 28 August 2026
It depends entirely on which tool and which settings. Business and enterprise API tiers from the major providers do not train on your data by default, while consumer chat products often do. The bigger risk for most SMEs is not the model provider, it is staff pasting client data into free tools nobody approved.
“Is AI safe” is too broad to answer. Three different questions hide inside it, and they have different answers.
Does the provider train on our data?
This is the one people ask about, and it is largely settled for business use. The major providers do not train on data sent through their paid API and business tiers by default. Consumer chat products are a different matter, and several do use conversations for training unless you opt out.
The practical implication: the tier matters more than the brand. The same company can offer a product that trains on your input and one that does not.
Where does the data physically go?
For UK businesses handling personal data, this is a UK GDPR question about international transfers and lawful basis, not an AI question. Check where the provider processes data, whether a data processing agreement is available, and what the retention period is. Most enterprise tiers publish all three. If a vendor cannot tell you, that is your answer.
Retention is the detail people miss. “We do not train on it” and “we do not keep it” are different claims. Providers commonly retain inputs for a period for abuse monitoring.
Who inside your business can send what?
This is the risk that actually bites SMEs, and it has nothing to do with the model. Someone pastes a client contract into a free tool to summarise it. Someone uploads a spreadsheet of customer records to draft an email campaign. No policy was broken because no policy existed.
The controls that help are unglamorous:
- A named list of approved tools, and a clear statement that anything else is not approved.
- A rule about what never gets pasted, usually client personal data, credentials and anything under NDA.
- A sanctioned tool that is good enough that people do not go looking for alternatives. Most shadow AI use is a symptom of not providing something usable.
How we handle it in builds
We work within your existing systems and permissions rather than creating a parallel copy of your data. Where a build needs a model, we use business tiers with data processing terms in place, keep the data flow as narrow as the task requires, and document what moves where so you can answer the question yourself later.
You keep the accounts and the credentials. When we hand over, you are not dependent on us to see or stop anything.
Worth doing before you adopt anything
Write down which categories of your data are sensitive, which tools are approved for each, and who to ask when someone is unsure. It takes an afternoon and it prevents most of what goes wrong.
Max Bridge, Director
Max started The AI Bridge in 2025 after several years at PwC in Restructuring, working on turnarounds for businesses from £20m to £1bn in revenue. He is a chartered accountant (ACA) and builds the automation and AI systems The AI Bridge delivers.
Want this looked at properly?
Book a free 30-minute call. We will look at your actual process and tell you what is worth automating first.
Book a free consultation