Is it safe to put company data into AI?
This is the question that stops most Australian businesses from getting anywhere with AI — and it deserves a straight answer rather than either reassurance or alarm. The honest version is that the risk is real, well understood, and largely manageable with decisions you can make this week.
What actually happens to what you type
When you send something to a hosted AI tool, it travels to the provider's servers, gets processed, and a response comes back. Two questions determine whether that's a problem: is it retained, and is it used for training?
Retention is usually short and operational — a window for abuse monitoring and support, after which it's deleted. Business tiers typically let you shorten or control this.
Training is the one people mean when they worry. On paid business and enterprise plans from the major providers, your inputs are generally not used to train models, and that commitment sits in the terms rather than in a blog post. On free consumer tiers, the default is often the opposite.
This is the crux: the tier matters more than the brand. The same company can offer a free product that learns from your data and a business product that contractually doesn't.
Where the real risk sits
In practice, most exposure has nothing to do with the provider's policy. It looks like this:
- Someone pastes a client contract into a free tool to get a summary before a 4pm meeting.
- A staff member uploads a spreadsheet of customer contacts to "clean it up".
- Someone drafts a response to a complaint by pasting in the entire complaint, including the customer's personal details.
None of these people were being reckless by their own reckoning. They were being efficient, with no guidance to the contrary. This pattern is common enough to have a name — shadow AI — and it is the thing to address first.
An Australian small-business example
A Melbourne accounting practice decides AI is too risky and bans it. No policy is written, no tool is provided, and no one checks what happens next.
Six months later, three staff are using free consumer accounts on personal logins, because the work got easier and nobody was watching. Client financial details are going into a tier that reserves training rights, through accounts the practice can't audit or revoke.
The ban didn't reduce the risk. It moved it somewhere the practice couldn't see. A business-tier account and one page of rules would have left them materially safer.
A practical way to decide
Sort what you handle into three buckets:
| Bucket | Examples | Approach |
|---|---|---|
| Open | Marketing copy, public info, internal process notes, general questions | Use AI freely on an approved tool |
| Careful | Internal financials, staff-identifiable material, client work with names removed | Business tier only, de-identified where practical |
| Off limits | Client personal information, health or financial records, anything under an NDA or regulatory obligation | Not without specific advice and a considered decision |
Most day-to-day work sits comfortably in the first bucket, which is the part businesses miss when they apply a blanket ban. You can capture most of the benefit while leaving the genuinely sensitive material alone.
Five things worth doing
- Provide a business-tier tool. Nothing else you do matters if the practical option remains a free personal account.
- Write one page of rules. Not a twelve-page policy nobody reads — the three buckets above, on one page, with examples from your actual work.
- Say what to do when unsure. A named person to ask beats a rule that gets guessed at.
- De-identify by habit. "Client A" instead of the client's name costs nothing and removes most of the risk from most tasks.
- Train, don't just prohibit. People who understand why a rule exists follow it when it's inconvenient. People given a ban route around it.
The honest summary
Putting company data into AI is safe enough for most business work, provided you're on a business tier and you've decided in advance what's off limits. It is not safe if it means staff improvising with free tools and client information because no one gave them an alternative.
The risk is real. But the version most businesses actually run is the one created by having no position at all.
Frequently asked questions
Will the AI company train on what we type?
Could our data show up in someone else's answer?
What does Australian privacy law say about this?
Is it safer to run AI on our own servers?
What's the single most useful thing we can do?
Put this to work
Ad On Group runs AI training and enablement for Australian teams through Ad On AI — a three-month, self-paced program that takes non-technical staff from their first prompts to working AI agents.