The AI tool leaking your business data is probably the free one. Here's how to use AI safely without creating new security risks.
------------------------------------------------------------------------------------------------------------------
TL;DR: Free consumer AI accounts were designed for personal use, and the data handling rules that come with them reflect that. Business and customer data flowing through a personal ChatGPT or Claude account may be used to train the underlying model, stored in jurisdictions with different privacy laws, or accessible to the vendor in ways that create real compliance exposure. NIST and the FTC both flagged data governance as the primary AI risk category for small businesses in 2024. The fix is five questions asked before any tool connects to business data, not a slower adoption pace.
------------------------------------------------------------------------------------------------------------------
AI adoption in small businesses often looks like progress from the outside and creates problems from the inside. An employee finds a free AI tool that summarizes documents well and starts using it on customer contracts. Someone connects a productivity AI to the company Google Drive to make it smarter. Nobody asks IT. Nobody reads the terms of service. The tools work great and there are no obvious red flags.
Until there are.
Think of it like bringing a personal blender into a commercial kitchen. It works fine for making a smoothie at home. It's not rated for the volume, the cleaning standards, or the liability environment of a professional food operation. Nobody would argue the blender is dangerous in either setting; the problem is using it in a context it wasn't designed for, in an environment that’s way more regulated than your home.
The rules have changed. NIST and the FTC both flagged data governance as the primary AI risk category for small businesses in 2024. These aren't enterprise concerns. They apply to a four-person accounting firm in Findlay using AI to draft client communications and not thinking twice about where that data is going.
Safe AI adoption isn't complicated. Five questions, asked before any tool connects to business data, address the vast majority of the risk.
Shadow AI is the AI equivalent of shadow IT: tools employees are using without IT awareness or approval. Unlike the shadow IT of the past (think personal Dropbox accounts for work files), shadow AI is more pervasive because the tools are free, instantly accessible, and genuinely useful. An employee who finds a productivity benefit from a free AI tool isn't doing something unreasonable. They're doing something that creates risk the business doesn't know about.
The specific risks fall into three categories worth understanding before you can address them.
Data training exposure. Many free consumer AI platforms include terms that allow the provider to use inputs to improve or train their models. Business data, customer information, and internal communications that flow through those tools may become training data. That's not a hypothetical. It's in the terms of service that almost nobody reads.
Jurisdictional data storage. Data processed by AI tools may be stored on servers in jurisdictions with privacy laws that differ from Ohio's data breach notification requirements or your customers' expectations. For businesses with compliance obligations, this can create direct regulatory exposure without anyone in the organization knowing it happened.
Vendor access to data. Some AI tools retain conversation histories or document contents for defined periods. Who at the vendor can access that data, under what circumstances, and for how long are basic due diligence questions most businesses skip entirely.
According to IBM's 2025 Cost of a Data Breach Report, breaches involving unsanctioned AI tools carried significantly higher remediation costs than breaches in more controlled environments. The combination of unvetted data handling and reduced IT visibility makes them expensive when they occur. And they're occurring more often as adoption outpaces governance.
These five questions address the core risk categories for small businesses adopting AI tools. Ask them before connecting any tool to business data. The answers are almost always in the vendor's privacy policy, data processing agreement, or terms of service: the documents everyone skips.
1. Does this tool use my inputs to train its models?
Business-grade AI tools (ChatGPT Team, Claude for Work, Microsoft 365 Copilot, Gemini for Workspace) offer settings that opt out of model training. Free consumer accounts often don't. If the answer is yes or unclear, use the business tier or find a different tool. This one question eliminates the most common exposure.
2. Where is my data stored, and under what jurisdiction?
For businesses with regulatory obligations or customer privacy commitments, the answer matters. SOC 2 Type II compliance indicates independent verification of security controls. ISO 27001 indicates a documented information security management system. If the vendor can't answer this question clearly, that's an answer too.
3. Who at the vendor can access my data, and under what circumstances?
Understand whether vendor employees can access your data for support or troubleshooting, and what the notification requirements are if that access occurs. It's a reasonable question. A vendor who treats it as unreasonable is telling you something.
4. How long does the vendor retain my data, and what are my deletion rights?
Some AI tools retain conversation histories indefinitely by default. For businesses handling sensitive customer information, knowing the retention period and how to request deletion is basic data hygiene, not paranoia.
5. Does this tool require access to more data than it actually needs?
An AI writing assistant doesn't need access to your customer database. An AI meeting tool doesn't need read-write access to your file storage. Minimum necessary access is a principle that applies to AI tools just as it does to user account permissions. If the tool is asking for more than it needs, ask why.
The practical differences between a free consumer AI account and a business-grade one go beyond price, and they matter more than most people realize until something goes wrong.
Business and team tiers of ChatGPT, Claude, Microsoft Copilot, and Google Gemini all offer data processing agreements, explicit opt-outs from model training, and enterprise-grade security controls. Microsoft 365 Copilot, specifically, operates within Microsoft's existing enterprise security and compliance framework, which means your existing data governance policies extend to Copilot interactions automatically. That's a meaningful structural advantage over a standalone AI tool with its own separate data handling environment that nobody in your organization has reviewed.
The cost difference is real but not prohibitive. ChatGPT Team runs $25 to $30 per user per month. Claude for Work runs $25 per user per month. Microsoft 365 Copilot is available as an add-on to existing Microsoft 365 subscriptions at $30 per user per month. Those aren't free, but they're not expensive relative to the compliance exposure of using free consumer accounts for business purposes. One breach investigation costs more than years of business-tier subscriptions.
The FTC's guidance specifically notes the importance of using AI tools with clear privacy and confidentiality commitments. Business-grade accounts provide those commitments in writing, in the form of legally enforceable data processing agreements. Free consumer accounts generally don't. That's not a minor distinction. It's the difference between a vendor who's accountable for how they handle your data and one who isn't.
The most common AI security mistake isn't using the wrong tool. It's connecting the right tool to more data than it needs.
An AI assistant granted read access to the entire company Google Drive because it was easier than limiting permissions, is a broader exposure than one connected only to the documents relevant to its function. When an AI tool is compromised, breached, or used in ways that violate its terms, the blast radius is determined by what it had access to. Minimum necessary access reduces that blast radius before anything goes wrong rather than after.
Practically, this means: grant AI tools access to specific folders or document sets rather than entire drives. Use read-only permissions where write access isn't required. Review AI tool permissions on the same schedule as user account permissions. Remove access for AI tools that are no longer actively used. An unused AI integration with lingering access to business data is a risk that costs nothing to eliminate and often gets forgotten entirely.
As we covered in The AI Market Is Loud. Most of It Will Gather Digital Dust. Here's What Actually Works, the right approach to building an AI stack includes a data security review before any tool connects to business data. Data minimization is the practical version of that review: not whether to connect, but how much access to grant when you do.
The principle isn't new. It's the same minimum necessary access standard that applies to user account permissions, third-party integrations, and vendor relationships. AI tools are just the newest category where businesses forget to apply it.
The human layer of AI safety is the one that gets skipped most often, and it's the one that matters most in practice. Technical controls help. A team that understands what they can and can't put into AI tools makes better decisions than policies alone can enforce.
Training doesn't have to be formal or time-consuming. A one-page guidance document covering which tools are approved, what types of data can be used with each, and what to do when unsure, handles most real-world scenarios. The goal isn't a compliance exercise. It's making sure that when an employee is about to paste a client's financial records into a free AI tool, something in their head says, "wait."
The scenarios worth specifically naming in any guidance document: don't put customer names and account details into free consumer AI accounts. Don't use personal AI accounts for work purposes. Don't connect AI tools to business systems without IT approval. When in doubt, use the approved business-grade tool rather than the convenient free one.
Regular reminders work better than one-time training. A quarterly email that highlights a current example (a real news story about a data exposure from AI misuse) is more effective at maintaining awareness than an annual compliance module nobody remembers by February. People retain things that feel relevant and current. Abstract policy training doesn't stick the same way a concrete example does.
One thing worth saying plainly: the employees creating the most AI security risk aren't the ones trying to cause problems. They're the ones who found something useful, assumed it was fine, and never thought to ask. That's not a character flaw. It's a training gap, and it's one of the cheapest security problems a business can fix.
The businesses getting AI adoption right aren't the ones moving slowest. They're the ones asking five questions before connecting a new tool to business data, using business-grade accounts instead of free consumer ones, and making sure their team knows the difference. None of that is complicated. It's just deliberate.
The exposure that comes from shadow AI and unsanctioned tools isn't inevitable. It's the result of moving fast without a checklist. The checklist is short. The questions aren't hard. And the cost of skipping them shows up in exactly the kind of incident nobody wants to explain to a client.
CNWR helps businesses across Northwest Ohio and Southeast Michigan implement AI tools safely, which means vetting the tools before they connect to business data, configuring access permissions correctly, and making sure the security posture keeps pace with the adoption. We've been navigating technology risk for businesses in this region since 1995. AI safety is the newest version of a familiar challenge: new tools create new exposure, and the exposure is manageable when someone's paying attention.
If your team is already using AI tools and you're not sure which ones or how they're configured, that's worth sorting out. Get in touch with CNWR and let's take a look.
1. Can I just use the free version of ChatGPT for work tasks?
It depends on what you're doing with it. Generic drafting and brainstorming carry limited risk. Customer data, internal financials, or anything covered by a confidentiality obligation is a different story. OpenAI's free tier allows inputs to be used to improve the model. The Team tier opts out by default. For anything involving business or customer data, use the business tier.
2. How do I know if my employees are using AI tools I haven't approved?
A combination of policy and technical controls helps. On the policy side, a clear acceptable use guideline specifies which tools are approved and why others aren't. On the technical side, endpoint monitoring and web filtering can identify access to AI platforms that haven't been vetted. A managed IT partner can implement both without significant overhead from internal staff.
3. What compliance obligations does my business have around AI use?
It depends on your industry. HIPAA applies if your tools process protected health information. PCI-DSS applies if they touch payment card data. Ohio's data breach notification law applies if a breach involves personal information of Ohio residents, regardless of which tool caused it. For most small businesses, the starting point is understanding what data flows through which AI tools and whether those tools' handling meets your existing obligations.