← Back to AI FAQ

Is it safe to give my data to an AI tool?

Daniel García·

Before getting into this topic I had to learn it myself, because I had no idea what actually happened to what you write in an AI chat. The short answer is: it depends, and most people don’t read the part that it depends on.

When you type something into a free, consumer-facing AI tool, in many cases that conversation can be used to keep training the model, unless the tool itself offers (and you turn on) an option to prevent it. In business plans or in the APIs we use to build things for clients, it’s usually the opposite: by default it isn’t used to train anything, it just stays as part of the service you requested.

The rule I apply, no exceptions: never paste into an AI chat anything you wouldn’t paste into an email to a stranger. Passwords, customer data, contracts with confidentiality clauses — all of that stays out. Not because I assume bad faith from the company that makes the AI, but because any system can have a security flaw, and the less sensitive data circulating, the less there is to lose if something fails.

For a business that wants to add AI to its website or customer service, there’s a question almost nobody asks and should: where does the data live while it’s being processed? If it’s a tool with servers in the European Union and a data processing agreement (which the GDPR requires), things change quite a bit compared to copying and pasting customer data into the public-facing website of just any chatbot.

And then there’s the obvious thing we forget: if your own company doesn’t allow sharing certain information with any external provider, you shouldn’t share it with an AI either just because it looks like “just a tool.” It’s one more external provider, with its own terms of service and fine print like any other.

What I learned researching this is that the real risk usually isn’t in the AI itself, but in not reading which plan you’re using and what it’s configured for.

aiprivacy