Every engagement starts with a clarity intake — no blind guesses, no cold meetings.
Fusion Advisory
Insights/Consideration

Where Does Your Company Data Actually Go When Your Team Uses AI?

Risk & Security9 min readJuly 13, 2026

The question to answer before you roll out AI: what vendors really do with your data, what “trains on your data” actually means, and the five questions that de-risk any tool.

MS
Mike Sweigart
Managing Partner — Technology & AI

Your team is already using AI at work. Someone in finance pasted a vendor contract into a chatbot last week to get a plain-English summary. Someone in sales dropped a customer list into one to draft follow-up emails. Someone in HR asked it to rewrite a performance review.

Nobody asked permission. Nobody thought they needed to. To them it felt like using a calculator, not exporting company data to a third party.

So the question in front of you is not whether to allow AI. That decision was made for you months ago by people trying to do their jobs faster. The only real question is whether it is happening with guardrails or without them.

This article answers the question most executives are quietly embarrassed to ask out loud: when my people use these tools, where does our data actually go?

Where does your company data actually go when someone uses AI?

It depends almost entirely on which tier of the product they are using, not which brand is on the login screen. This is the single most misunderstood thing in the entire conversation, and it trips up smart buyers constantly.

There are three broad paths your data can take.

Free and consumer tiers

This is an employee signing up with a personal or work email on a personal plan. Historically, consumer tiers across the software industry have carried looser data terms than business tiers, and the provider may reserve broader rights over what gets typed in. Settings can sometimes narrow this, but they are settings, not contracts. You have no procurement agreement, no negotiated terms, and no visibility. If you asked today which employees had accounts and what they had uploaded, you could not answer.

Paid business, team, and enterprise tiers

These are sold to companies, and the commercial terms are typically written for companies. That generally means contractual commitments around confidentiality, administrative controls, and the ability to sign a data processing agreement. Same brand. Same interface. Materially different legal posture.

Do not take my word for the specifics of any given product, and do not take a salesperson's either. Terms change, and they differ by tier and by region. Read the terms attached to the exact plan you are on.

API access embedded in your own software

This is when AI is built into a tool you own, and data moves through a developer interface rather than a public chat window. Business-grade API terms have generally been the most restrictive of the three, which is one reason serious deployments tend to graduate to this path. It is also where you gain logging, permissions, and audit trails. We walk through that progression in detail in our guide on moving from a chatbot habit to AI actually built into your company software.

Here is the executive takeaway. Two employees can use the identical product and be in completely different risk positions because one pays $20 a month personally and one is on a company agreement. The brand tells you nothing. The tier tells you everything.

What does "trains on your data" actually mean?

It means your inputs could be used to improve the underlying model that other customers also use. That is one specific concern, and it is not the same as the other two questions you should be asking.

Untangle these three:

  • Training use. Does what we type become material that shapes the product itself? Most business tiers say no. Many consumer tiers have historically said yes unless you opt out.
  • Retention. How long is our content stored on their systems, even if it is never used for training? A vendor can train on nothing and still hold your data for years.
  • Access. Who at the vendor, or at their subcontractors, can look at it? Safety review, abuse monitoring, and support escalation are all legitimate reasons humans sometimes see content.

A vendor can honestly answer "we don't train on your data" while retaining it for eighteen months and allowing staff review. That is not deception. It is a narrow answer to a narrow question. Ask all three.

Should you just ban AI tools at work?

No, and a ban usually makes your exposure worse rather than better. This is counterintuitive enough that it is worth sitting with.

When you ban a tool that people find genuinely useful, they do not stop using it. They move it off your network. They use a personal account on a personal phone, and now the same customer data is flowing through an unmanaged consumer account you have no contract with, no logs for, and no ability to revoke when that person leaves. You did not eliminate the risk. You made it invisible.

This is what people mean by shadow AI. The pattern is old. It is the same thing that happened with personal cloud storage and unapproved messaging apps a decade ago, and it resolved the same way. Sanctioned tools beat prohibition.

A sanctioned path gives you four things a ban never will: contractual terms, an admin console, visibility into usage, and a place to send people so they stop improvising. It also removes the incentive to hide, which matters more than any technical control. People conceal what they think they will be punished for, and you cannot govern what you cannot see. The same dynamic drives most failed rollouts, which we cover in our piece on why AI projects stall on adoption rather than technology.

What should you ask an AI vendor before trusting them with company data?

Five questions, and you do not need a technical background to ask any of them. Send them in an email and judge the vendor as much by how fast and how plainly they answer as by the answers themselves.

1. How long do you retain our data, and can we shorten it?

Why it matters: every day your data sits on someone else's servers is a day it can be breached, subpoenaed, or exposed. Retention is the size of your blast radius.

2. Is our content used to train or improve your models?

Why it matters: if your pricing model, client list, or proprietary process becomes training material, you have quietly donated your competitive advantage. Get the answer in the contract, not the FAQ.

3. Who are your sub-processors?

Why it matters: almost every AI vendor is standing on someone else's infrastructure. Your data is not going to one company. It is going to a chain of them. A vendor that cannot produce a current sub-processor list has not thought about this seriously, and that tells you plenty.

4. What happens when we leave?

Why it matters: exit terms are leverage, and they are cheapest to negotiate before you sign. Ask how deletion is requested, how long it takes, what is confirmed in writing, and what persists in backups.

5. Where is data stored, and will you sign a DPA?

Why it matters: geography drives which laws apply, which matters if you operate across borders or serve regulated clients. A data processing agreement is the document that turns marketing assurances into obligations. A vendor selling to businesses should have one ready. Hesitation here is a real signal. If you want a fuller framework, we published a walkthrough on how to evaluate AI vendors when you don't have a CTO.

What guardrails work without killing adoption?

Three, and they take weeks rather than quarters. The goal is not zero risk. It is informed risk with a named owner.

Classify what is actually sensitive. Most companies treat all data as equally precious, which means employees treat none of it that way. Draw a short list of what never goes into a general-purpose tool: customer PII, employee records, unreleased financials, anything under NDA, credentials. Everything else is fair game. A one-page list people remember beats a forty-page policy nobody opens. Related: the messiness that makes this hard is usually the same messiness we describe in our article on the data problem sitting behind most failed AI efforts.

Give people one approved tool and pay for it. The business tier of a mainstream tool costs a fraction of one hour of outside counsel reviewing a data incident. Buy it, roll it out, and tell people explicitly that it is approved. Ninety percent of shadow AI disappears when there is a sanctioned option that is not annoying to use.

Keep a human accountable for the output. AI drafts. A person signs. Whoever's name is on the deliverable owns its accuracy, full stop. This one rule prevents most of the failure modes we catalog in our piece on what actually goes wrong in AI implementations, and it is also the honest answer to the anxiety underneath all of this, which we address directly in whether AI is going to replace your team.

Write these down. Not as a legal document, as a page your team can actually follow. We published a template for exactly that in our one-page AI policy you can adopt this week, and if you would rather start by finding out where you stand, our AI readiness assessment takes a few minutes.

The bottom line

Your data is already moving. The tier your team is on determines where it lands, and right now you probably do not know what tier they are on.

The fix is not sophisticated. Pick an approved tool, buy the business tier, write down what never gets pasted anywhere, ask vendors five questions before you sign, and keep a human's name on every output. That is a few weeks of work, and it converts an unmanaged liability into a managed one.

Research from groups like McKinsey, Gartner, and MIT Sloan consistently finds that most corporate AI efforts never make it past the pilot stage. Governance is rarely the headline reason, but it is often the quiet one. Teams that have no clear rules either freeze or improvise, and neither produces results you can take to a board.

You do not need to become an expert in any of this. You need a short set of decisions made deliberately, by you, instead of by default. If you want help making them, tell us about your situation through our intake form and we will point you at the shortest path from where you are to something defensible.

What’s next?

This article is designed to help you move through the consideration stage of your AI evaluation.