Home  ›  Blog  ›  Risk and Compliance
Risk and Compliance

Is It Safe to Put Customer Data Into AI Tools?

Short answer

It can be safe on a paid business plan with the data controls checked, for ordinary business information. It is not safe on a free personal account, and health records, payment card numbers, government ID numbers, and credentials should never go in at all. What protects you is the account type, the retention and training settings, and a one-page rule your team follows.

Key Takeaways
  • Training, retention, and human review are three separate settings, so a vendor can truthfully say it does not train on your data while still keeping a copy.
  • OpenAI states that ChatGPT Business, Enterprise, and API data is excluded from model training by default and remains owned by your organization.
  • Most real incidents come from personal free accounts, shared logins, and over-broad integrations, not from a model repeating your customer list.
  • Never paste health information, full payment card or bank numbers, government ID numbers, employee records, or credentials into a general AI chat tool.
  • Wisconsin Statute 134.98 puts the duty to notify affected people on you when personal information in your possession is acquired without authorization.
  • Write one page with a green list, a red list, and the name of the person to tell when something goes wrong, and post it where the work happens.

Is it safe to put customer data into AI tools? It can be, on a paid business plan with the right settings, for most ordinary business information. It is not safe on a free personal account, and some categories of data should never go in at all, no matter what plan you are on. The difference is not which brand you picked. It is the account type, the data controls, and a short written rule your team actually follows.

This guide covers what really happens to what you paste, which settings to change today, which data is off limits, what Wisconsin law expects of you, and how to write the one-page rule that keeps a well-meaning employee from creating a problem.

What Actually Happens to Data I Paste Into an AI Tool?

Three things happen, and only one of them is the one people worry about. Your text travels to the provider's servers, it gets stored for some period of time, and it may or may not be used to train future models depending on your plan and settings. Training is the headline risk. Storage and access are the more likely ones.

Some definitions, because the marketing language is deliberately fuzzy. Training means your content becomes part of the material used to improve the model itself. Retention means the provider keeps a copy of your conversation for a period of time, usually for abuse monitoring and support, even when it is not training on it. Human review means a person at the provider or a contractor may read a flagged conversation. All three are separate settings, and a vendor can truthfully say "we do not train on your data" while still retaining it for 30 days.

Here is where the major providers land on business plans. OpenAI states that data from ChatGPT Business, ChatGPT Enterprise, and its API platform, including both inputs and outputs, is excluded from training or improving its models by default, that your organization owns the data, and that it is encrypted in transit and at rest. Consumer plans work differently, and OpenAI publishes a separate control for turning model training off on personal accounts. Anthropic and Google offer comparable business and enterprise tiers with their own data commitments. The pattern across all of them is the same: the business tier is the one built for this, the free tier is not, and the default on a free account is not the default on a paid one.

The practical takeaway is unglamorous. Most breaches involving AI tools are not a model regurgitating your customer list. They are an employee pasting a spreadsheet into a personal free account on a home laptop, a shared login nobody can trace, or a browser extension with permission to read every page.

Which Settings Do I Need to Change This Week?

Log in as an administrator, not as a user, and check five things. This takes about twenty minutes per tool and it is the single highest-value security work a small business can do with AI right now.

  1. Confirm you are on a business or team plan, not a personal one. Look at the billing page. If the invoice goes to somebody's personal card, you are on a personal plan regardless of what the login looks like.
  2. Find the data controls page and read the training setting. Screenshot it with the date visible. You will want that screenshot the first time a client asks how you handle their information.
  3. Check retention. How long are conversations kept, and can an admin delete them? Set the shortest retention that still lets you do your job.
  4. Review who has access. List every seat. Remove anyone who left. Turn on two-factor authentication and require it.
  5. Check connected apps and integrations. Anything that has been granted access to your Google Drive, your email, or your CRM through an AI tool is now part of your data footprint. Revoke what you are not using.
The screenshot test: Before anything goes into an AI tool, ask whether you would be comfortable if that exact text appeared in a screenshot in a customer's inbox. Not because that is likely, but because it is the fastest test a busy person will actually run. If the answer is no, strip the identifying details first. The AI almost never needs the real name to do the job.

What Customer Data Should Never Go Into a General AI Tool?

Keep regulated and high-consequence data out of general-purpose chat tools entirely, even paid ones, unless you have a specific agreement and configuration that covers it. General-purpose means the chat assistant your team opens in a browser tab, as opposed to a system your vendor has configured for that data category.

  • Protected health information. Patient names, conditions, chart notes, appointment reasons. A standard business subscription is not a compliant setup for this without the right agreement in place, and a dental or medical office should assume the answer is no until their compliance advisor says otherwise.
  • Full payment card numbers, bank account and routing numbers. There is never a business reason to paste these into a chat window.
  • Social Security numbers, driver license numbers, passport numbers. These are exactly the identifiers that trigger breach notification duties if they get out.
  • Anything under a client confidentiality agreement. Check the contract. Some professional services agreements require notice or consent before you process client material in a third-party tool.
  • Employee records. Performance issues, medical leave, disciplinary notes, compensation. Use categories and hypotheticals instead.
  • Passwords, API keys, and access credentials. Obvious, and it happens constantly during troubleshooting.

What is usually fine on a paid business plan: draft marketing copy, your own service descriptions and pricing, anonymized customer questions, a de-identified review you want help responding to, internal process documents, and spreadsheets with the name column removed. The habit worth building is redaction as a reflex. Replace "Karen Mueller at 812 Wisconsin Street" with "the customer" before you paste, and you have solved most of the problem without reading a single policy page.

What Rules Apply to a Small Business in Wisconsin?

There is no single AI law you have to comply with, but three existing sets of rules already reach your use of AI: state breach notification, federal consumer protection, and whatever industry rules already applied to you. AI does not create an exemption from any of them.

Wisconsin Breach Notification

Wisconsin Statute 134.98 requires an entity that knows personal information in its possession has been acquired by a person it did not authorize to acquire it to make reasonable efforts to notify each person the information is about. It reaches out-of-state entities holding information about Wisconsin residents, requires a company that merely stores data for someone else to notify the owner of that data, and preempts cities, villages, towns, and counties from writing their own notice rules. It also states that it does not create a private right of action. Practical translation: if your customer list ends up somewhere it should not be, the notification duty is yours, and "it was in an AI tool" is not a defense.

Federal Consumer Protection

The Federal Trade Commission announced an enforcement sweep called Operation AI Comply on September 25, 2024, targeting deceptive claims about AI and deceptive conduct carried out with AI, including a company whose tool generated fake reviews. Two things follow for a small business. Do not overstate what your AI does in your own marketing, and do not use AI to fabricate anything a customer would rely on. Also remember that a privacy promise on your website is an enforceable representation. If your privacy policy says you do not share customer information with third parties, and you paste customer information into a third-party AI tool, those two facts are in conflict.

Your Existing Industry Rules

Health care, financial services, legal, and insurance all carry rules that predate AI and apply to it unchanged. If you were not allowed to email a document to an outside vendor before, you are not allowed to paste it into a chat window now.

How Do I Write a One-Page AI Data Rule for My Team?

Write one page, in plain language, with a green list, a red list, and a name to ask. The National Institute of Standards and Technology's AI Risk Management Framework, released in January 2023, organizes AI risk into four functions (govern, map, measure, and manage). That is more structure than a ten-person business needs, but it is a sound outline for your one page.

  1. Govern: who owns this. One named person approves new AI tools and holds the admin logins. One sentence.
  2. Map: which tools are approved, and for what. List them by name. If a tool is not on the list, it is not approved, and adding one takes a two-minute conversation, not a form.
  3. Measure: the green list and the red list. Green is what may go in (marketing drafts, anonymized questions, internal process notes). Red is what may never go in (the list from the section above). Keep both to bullet points.
  4. Manage: what to do when something goes wrong. "If you pasted something from the red list, tell [name] the same day. Nobody gets in trouble for reporting it. People get in trouble for hiding it." That sentence buys you more safety than any software control.

Post it where the work happens, walk the team through it once in a fifteen-minute meeting, and revisit it twice a year. A policy that lives in a shared drive nobody opens is decoration.

What Does This Look Like for a Lake Geneva Business?

Picture a vacation rental host in Fontana managing eleven properties, with a two-person office handling guest messages, cleaning schedules, and owner statements. They want AI to draft guest replies, because the same twenty questions arrive every week.

What the setup looked like after a cleanup:

  • Two paid business seats on one company-owned workspace, billed to the business card, with two-factor authentication required. The personal free accounts both staff had been using got retired the same day.
  • A saved assistant loaded with the house manuals, check-in instructions, local recommendations, and cancellation policy. No guest names, no reservation numbers, no payment details in the uploaded documents.
  • A redaction habit for guest messages: the guest's name and address get replaced with "the guest" and "the property" before the message is pasted in for a suggested reply. The reply gets personalized by hand in the booking platform, where the real names belong.
  • Owner statements, which contain real names and revenue figures, never go near a chat tool. Those live in the accounting system.
  • A one-page rule taped inside the office cabinet with a green list, a red list, and the owner's cell number for the "I think I pasted something" call.

What went wrong anyway: a cleaner was added to a shared calendar automation that had been granted access to the whole Drive, which included the owner statements folder. Nobody noticed for six weeks. The fix was not an AI setting. It was reviewing connected app permissions, which is now a quarterly calendar item. That is the realistic threat model for a small business, and it is why the settings review in this post matters more than the model comparison in our post on choosing between ChatGPT, Claude, and Gemini.

What Goes Wrong, and How Do I Catch It?

The failures are boring and repeatable, which is good news, because boring problems have checklists.

  • Shadow accounts. Staff using personal free logins for work. Catch it by asking directly, without blame, and by making the approved tool genuinely easier to use than the workaround.
  • Over-broad integrations. An AI tool granted access to an entire Drive or mailbox when it needed one folder. Review connected apps quarterly and revoke anything unused.
  • Departed employees. Seats and shared assistants left active after someone leaves. Add "remove AI seats" to your offboarding checklist next to "collect the keys."
  • Confidently wrong output going out the door. An AI-drafted reply that quotes the wrong policy or invents a discount. Require a human to send anything customer-facing until you have a month of clean output.
  • Privacy policy drift. Your website still says something your operations no longer match. Read your own privacy policy once a year against what you actually do.

Do This This Week

  1. List every AI tool anyone at your business uses, including the free personal ones. Ask, do not assume.
  2. Move company work onto one paid business plan with company-owned logins and two-factor authentication.
  3. Open the data controls page on that plan, confirm the training and retention settings, and screenshot it with the date.
  4. Review connected apps and revoke every integration you are not actively using.
  5. Write your red list: health information, payment card and bank numbers, government ID numbers, employee records, credentials, and anything under a confidentiality agreement.
  6. Write the one-page rule with a green list, the red list, and the name of the person to tell when something goes wrong.
  7. Add "remove AI seats and revoke tokens" to your employee offboarding checklist.
  8. Read your own privacy policy and confirm it still describes what you actually do with customer information.

Where to Go From Here

The decision is not whether AI is safe in the abstract. It is whether your business is running it on the right account, with the right settings, under a rule your team can recite. Get those three right and general business use is reasonable. Get them wrong and the tool is not the problem; the missing process is.

If you would like an outside read on where customer information currently flows in your business and which of those paths should never touch an AI tool, our AI Opportunity Audit maps the processes and the data along with them. And if you are still deciding whether AI belongs in your operation at all, our post on what AI can actually do for a small business is a calmer starting point than most of what you will read online. None of this is legal advice, and if you handle health, financial, or legal records, run your plan past the advisor who already knows your obligations.

Sources and Further Reading

  1. Enterprise Privacy at OpenAI. OpenAI, February 2026.
  2. Managing Data, Sharing, and Privacy in ChatGPT Business. OpenAI Help Center, February 2026.
  3. How Your Data Is Used to Improve Model Performance. OpenAI, February 2026.
  4. AI Risk Management Framework. National Institute of Standards and Technology, January 2023.
  5. NIST AI RMF Playbook. National Institute of Standards and Technology, 2023.
  6. FTC Announces Crackdown on Deceptive AI Claims and Schemes. Federal Trade Commission, September 2024.
  7. Wisconsin Statute 134.98: Notice of Unauthorized Acquisition of Personal Information. Wisconsin Legislature, current through 2026.
  8. Plans and Pricing. Anthropic, February 2026.
Questions

Frequently Asked

Does ChatGPT train on my business data?

OpenAI states that inputs and outputs from ChatGPT Business, ChatGPT Enterprise, and the API platform are excluded from training its models by default, and that your organization owns and controls that data. Free and personal plans work differently and have their own training control you must set yourself. Check the data controls page on the exact account you are logged into, not the one described in a marketing page.

Can I put customer names into an AI tool?

You usually do not need to. Replace the name and address with the customer and the property before you paste, then personalize the reply by hand in the system where the real record lives. On a paid business plan, ordinary names in ordinary business correspondence are lower risk, but the redaction habit costs you five seconds and removes most of the problem permanently.

Is AI use covered by HIPAA or Wisconsin privacy law?

HIPAA applies to covered entities and their business associates regardless of the technology, so a standard chat subscription is not an appropriate place for patient information without the right agreement and configuration. Wisconsin Statute 134.98 sets the breach notification duty for personal information held by your business. Neither law has an AI exemption. If you handle regulated records, confirm your plan with your compliance advisor before you start.

What is the biggest AI data risk for a small business?

Staff using personal free accounts for company work, followed closely by integrations granted access to an entire mailbox or drive when they only needed one folder. Both are fixed with process rather than software: move everyone onto company-owned business seats, review connected app permissions quarterly, and add removing AI access to your employee offboarding checklist.

No Cost · No Obligation

See Exactly Where You Stand Online

Get a free Lake Geneva Local Visibility Audit. We will show you where you stand on Google, AI search, listings, reviews, and social, plus what to fix first.