Is it safe to put company data into AI?

This is the question that stops most Australian businesses from getting anywhere with AI — and it deserves a straight answer rather than either reassurance or alarm. The honest version is that the risk is real, well understood, and largely manageable with decisions you can make this week.

What actually happens to what you type

When you send something to a hosted AI tool, it travels to the provider's servers, gets processed, and a response comes back. Two questions determine whether that's a problem: is it retained, and is it used for training?

Retention is usually short and operational — a window for abuse monitoring and support, after which it's deleted. Business tiers typically let you shorten or control this.

Training is the one people mean when they worry. On paid business and enterprise plans from the major providers, your inputs are generally not used to train models, and that commitment sits in the terms rather than in a blog post. On free consumer tiers, the default is often the opposite.

This is the crux: the tier matters more than the brand. The same company can offer a free product that learns from your data and a business product that contractually doesn't.

Where the real risk sits

In practice, most exposure has nothing to do with the provider's policy. It looks like this:

None of these people were being reckless by their own reckoning. They were being efficient, with no guidance to the contrary. This pattern is common enough to have a name — shadow AI — and it is the thing to address first.

An Australian small-business example

A Melbourne accounting practice decides AI is too risky and bans it. No policy is written, no tool is provided, and no one checks what happens next.

Six months later, three staff are using free consumer accounts on personal logins, because the work got easier and nobody was watching. Client financial details are going into a tier that reserves training rights, through accounts the practice can't audit or revoke.

The ban didn't reduce the risk. It moved it somewhere the practice couldn't see. A business-tier account and one page of rules would have left them materially safer.

A practical way to decide

Sort what you handle into three buckets:

BucketExamplesApproach
Open Marketing copy, public info, internal process notes, general questions Use AI freely on an approved tool
Careful Internal financials, staff-identifiable material, client work with names removed Business tier only, de-identified where practical
Off limits Client personal information, health or financial records, anything under an NDA or regulatory obligation Not without specific advice and a considered decision

Most day-to-day work sits comfortably in the first bucket, which is the part businesses miss when they apply a blanket ban. You can capture most of the benefit while leaving the genuinely sensitive material alone.

Five things worth doing

The honest summary

Putting company data into AI is safe enough for most business work, provided you're on a business tier and you've decided in advance what's off limits. It is not safe if it means staff improvising with free tools and client information because no one gave them an alternative.

The risk is real. But the version most businesses actually run is the one created by having no position at all.

Frequently asked questions

Will the AI company train on what we type?
On paid business and enterprise plans from the major providers, generally no — and that commitment is usually in the contract rather than just the marketing. On free consumer tiers, often yes by default, sometimes with an opt-out buried in settings. The plan you're on matters more than the brand.
Could our data show up in someone else's answer?
If a provider doesn't train on your inputs, there is no path for that to happen. Where training does occur, the risk is not that your document is served up verbatim, but that patterns from it could influence the model. Either way, this is an argument for using business tiers rather than free ones.
What does Australian privacy law say about this?
The Privacy Act and the Australian Privacy Principles apply to personal information regardless of the tool used to process it. Putting a client's personal information into an AI tool is a disclosure, and the same obligations apply as any other. If you're regulated or handle health, financial or government data, get advice specific to your situation — this guide is general information, not legal advice.
Is it safer to run AI on our own servers?
It removes the third-party question, but introduces cost, maintenance and the need for real expertise — and self-hosted models are generally less capable than the leading hosted ones. For most small and medium businesses, a business-tier account with clear rules is the more practical answer.
What's the single most useful thing we can do?
Write down what staff may and may not put into AI, and give them an approved tool. Most leakage happens not from malice but from someone with a deadline using whatever was free and to hand, because nobody had told them otherwise.

Put this to work

Ad On Group runs AI training and enablement for Australian teams through Ad On AI — a three-month, self-paced program that takes non-technical staff from their first prompts to working AI agents.

Talk to us →

Keep reading

← All resources