Employees across the Bay Area are already pasting company data into AI tools, often through personal accounts IT can’t see or control. Consumer and business versions of the same AI product can handle data very differently, and opting out of model training doesn’t mean your data is deleted. The fix isn’t banning AI. It’s giving employees one approved, centrally managed AI workspace, a short role-specific policy on what’s safe to share, and regular reviews as tools change.

Key Takeaways

  • Information entered into an AI tool may be processed, stored, reviewed, or passed to connected services.
  • Consumer and business versions of the same product may handle company data differently.
  • Turning off model training doesn’t always mean prompts and files are deleted right away.
  • Personal AI accounts can leave employers with little visibility or control.
  • Businesses need an approved AI environment, a clear policy, employee training, and regular reviews.

An employee needs to summarize a report, polish an email, or make sense of a messy spreadsheet. They open an AI tool, paste in the details, and have an answer in seconds.

It doesn’t seem like a big deal, right? But few people stop to ask where that information goes after they hit “send,” and for Bay Area businesses, that gap is becoming one of the biggest risks no one’s tracking.

Here’s what we’re seeing with clients across the Bay Area: employees are already using AI, often before their employer has formally rolled anything out. The real question isn’t whether people are using it. It’s whether they know what’s safe to share, which accounts they should be using, and what happens to that information once it’s out of their hands.

Bay Area Businesses Are Moving Fast on AI

Businesses here tend to hear about new tools early. Someone knows a friend at an AI company, sees a new platform trending online, or gets a recommendation from a colleague. Trying it out feels natural.

The City of San Francisco is a good example of taking a measured approach. Before expanding access widely, the city ran a six-month pilot with more than 2,000 employees. Participants used generative AI for tasks such as email assistance, project planning, research, and summarization, with some reporting time savings of up to five hours per week.

By July 2025, that groundwork let the city roll out Microsoft 365 Copilot Chat to nearly 30,000 employees, paired with enterprise security protections, training, and written guidelines. Those guidelines draw a clear line: employees can use approved enterprise AI tools for certain work, but they’re told to stay off public or consumer tools without approval and never enter sensitive city information into anything unapproved.

That’s a useful model for local businesses. San Francisco didn’t just hand out access and hope for the best. It piloted, picked an approved platform, set rules, and trained people on them. Most of the businesses we work with are missing at least one of those pieces.

What Happens When Someone Enters Data Into AI?

Once an employee submits a prompt, that information leaves their device and moves through the AI provider’s systems. It is processed automatically, turned into a response, and, in many cases, logged as part of the interaction.

What happens next depends on the service. The provider may retain the conversation for a period of time, scan it for security concerns, or allow certain content to be reviewed by a person, depending on the product and its settings. If the employee turns on web search, uploads a document, or connects another app, more services may become involved.

The protections also vary by account type. OpenAI, Microsoft, and Google offer data protections for eligible business and enterprise customers, including commitments that covered customer data will not be used to train their foundation models. Those protections depend on the exact product, subscription, features, and settings in use.

An employee using a free personal account may not receive the same protections as someone using a company-managed account. The two versions may look nearly identical, but they can handle company data very differently.

The Risks That Are Easy to Miss

Most employees know not to upload an entire customer database to a public chatbot. The riskier moments are the ordinary ones, when sensitive information is part of a routine task.

Someone polishing a customer email might include a name, pricing, and contract terms. A manager summarizing meeting notes might share details about an employee. Someone on the finance team might upload a spreadsheet with forecasts or account numbers. A developer troubleshooting an issue might paste in proprietary code or a live credential.

These situations are easy to overlook because the sensitive information is embedded in work employees already do every day. A general warning to “be careful” does not give them enough direction. A useful AI policy should include examples relevant to different roles, whether that is an accounts payable clerk, a nonprofit case manager, or a paralegal at a local firm.

AI shield surrounded by documents, chat icons, and warning symbols, illustrating the privacy risks of sharing business data with AI tools.

Your Data Can Be Stored Even When It Isn’t Used for Training

Many of the businesses we talk with are still figuring out what to ask about AI and data privacy. One of the first questions is often: Does the provider use our data to train its models?

That is a good place to start, but training and retention are two different things. A provider can exclude your conversations from model training and still hold onto them temporarily for security monitoring, legal requirements, or your chat history. Deleting a conversation from your screen does not necessarily mean every copy has been removed.

Before approving a platform, ask:

  • How long are prompts and files retained?
  • Can administrators control that retention?
  • Who can access stored information, and where is it processed?
  • What happens when someone deletes a conversation?
  • What changes when an employee connects another app?

The answers can differ between consumer and business versions of the same tool. Check the terms for the exact product and subscription your team will use.

Connected Apps Expand What AI Can Reach

AI gets more useful the more it can touch email, calendars, cloud storage, customer platforms, and internal documents. That’s also where the risk grows. 

An AI tool connected to company files may be able to retrieve more information than an employee realizes. If access permissions are too broad, it could surface files that should remain restricted. Each connected service may also have its own retention rules and privacy terms.

Review every app connected to the AI platform, including what information it can access, who can use it, and how the connected service stores that data.

Illustration of an AI platform connected to cloud storage, documents, and data tools, showing how connected apps can expand access to business information.

Personal Accounts Create a Blind Spot

This is often called shadow AI: employees using tools for work without the company’s knowledge, sometimes just by signing up for a free account to summarize a document or draft an email. Signing up with a work email doesn’t make it a company-managed account. IT has no visibility into what was entered, how long it’s stored, or whether privacy settings were ever changed, and no way to close the account or remove files when that employee leaves.

Banning AI outright usually just pushes this underground. A better starting point is giving people an approved account and practical guidance on what’s safe to share.

AI Output Can Spread Information, Too

The risk doesn’t end once the AI produces an answer. A response can repeat confidential details from the prompt, pull in something from a connected document, or surface personal information that shouldn’t travel further. From there, it’s one copy-paste away from an email, a presentation, or a support ticket. 

AI-generated work still needs a human review, especially anything touching customers, employees, finances, or legal matters.

What Your Business Should Review

Start by finding out what employees are already using and for what, ideally through an anonymous survey so people feel comfortable answering honestly. Define what should never go into an unapproved tool: passwords, customer or patient records, payment information, personnel files, legal communications, proprietary code, and unpublished financials or contracts.

Then choose an approved AI workspace you can manage centrally, with real identity controls, audit logs, and a clean process for cutting off access when someone leaves. Pair it with a short, role-specific policy; an accounts payable employee needs different examples than a marketing employee or a systems administrator. Review it regularly, since AI platforms add features faster than most policies can keep up.

Business team reviewing AI policy guidelines together as they discuss how to protect company data.

A Safer Way to Put AI to Work

Employees shouldn’t need to read a privacy policy every time they want AI help with a document. They should have one approved place to work, with clear boundaries.

TSG’s Managed AI Services give businesses a single, company-branded AI workspace with access to leading platforms like ChatGPT, Claude, Gemini, and Llama without separate subscriptions for each.

The workspace also puts your business in control:

  • Zero Data Retention: models never train on your data, and each client runs in an isolated Microsoft Azure tenant.
  • Role-based access: admins choose which models, tools, and features each employee can use, monitor usage, and roll out updates on their own schedule.
  • Centralized billing: no more juggling subscriptions across platforms.

Employees get the flexibility to use the AI that fits their work; your business gets one place to manage access, privacy, and cost. TSG also provides managed automations and local support from a team that knows your broader tech environment.

A safer approach to AI starts with knowing which tools employees use, what company information they enter, and whether the right protections are in place. These are conversations TSG is already having with Bay Area businesses, and they are a good starting point for any company reviewing its use of AI. 

Reach out to our team at TSG and let us show you a safer way to put AI to work.

Frequently Asked Questions

Do popular AI tools use business data to train their models?

It depends on the product, account type, and settings. Many enterprise AI services state that customer prompts and responses aren’t used to train their models by default. Consumer products may work differently. Always check the current policy for the exact version your employees use.

Who should be responsible for managing AI use in a business?

One person should oversee the company’s AI program, with support from leadership, department managers, and whoever manages IT. Legal, compliance, or HR may also need to help when AI involves regulated data, employee information, or customer decisions.

What should employees never enter into a public AI tool?

Passwords, customer or patient records, protected health information, payment details, employee files, legal communications, proprietary code, and non-public financial data.

About TSG

The Swenson Group (TSG) is an award-winning Bay Area Managed Service Provider that has helped thousands of organizations achieve more by leveraging cost-effective technologies to become more productive and secure. Services include Managed Print, Document Management, IT Services, Managed AI and VoIP. Products include MFPs, Copiers, Printers, Production Systems, Software and Solution Apps. For the latest industry trends and technology insights, visit TSG’s main Blog page.