Is it safe to put our information into AI? A plain answer
It depends entirely on which information and which tool. A practical way to sort what is fine, what needs care, and what should not go near a general-purpose tool.
The short answer
It depends. Not on whether AI is “safe” in general, because that question doesn’t really mean anything. It depends on two things: which piece of information you’re about to type in, and which tool you’re typing it into. Get those two things right and most businesses have very little to worry about. Get them wrong and you can create a real problem without ever meaning to.
This isn’t a technical question so much as a habits question. Once your team understands the difference between the two, most of the anxiety goes away, because the decision becomes obvious most of the time.
Free personal tools versus business tools
There’s a genuine and important difference between a free, personal AI account and a paid business or enterprise arrangement, and it’s worth understanding the general pattern even though the exact wording changes from provider to provider and changes over time.
Broadly speaking, providers tend to describe their free, consumer-facing tools as ones where your conversations may be used to help improve their models, unless you go digging into settings and turn that off. Their business, team or enterprise tiers, on the other hand, are typically described as not using your data for training by default, and usually come with a proper agreement you can point to if anyone ever asks what happens to your information.
The practical takeaway isn’t “free bad, paid good” as a blanket rule. It’s that a paid business tier usually comes with something a free personal account doesn’t: a document you can read, a setting you can check, and someone accountable if it’s wrong. That’s worth having before anything sensitive goes anywhere near the tool.
Always check the current terms yourself. Provider policies change, and this article deliberately doesn’t quote specific vendor promises, because a promise printed here today could be out of date by the time you read it. Read the actual terms for the tool you’re using, not a summary of it.
Where is it actually stored?
“Where does our information live?” is a completely reasonable question to ask any supplier, AI or otherwise. Some tools store and process data offshore. Some offer a choice of region. Some don’t tell you unless you ask directly. None of this automatically makes a tool unsafe, but it changes what you’re agreeing to, and it’s the kind of thing worth having in writing rather than assumed.
If you wouldn’t be comfortable emailing a piece of information to an overseas contractor you’ve never met, be just as thoughtful about pasting it into a tool whose servers you haven’t asked about.
A practical way to sort your information
Rather than trying to memorise a rulebook, it helps to sort what you might type into an AI tool into three rough bands.
Generally fine
- Public marketing copy, website text, and social media drafts
- Generic drafting: letters, policy templates, job ads, meeting agendas
- Your own already-published content, being reworked or summarised
Needs some care
- Internal documents that aren’t public but aren’t sensitive either, like draft budgets or internal procedures
- Supplier details, pricing arrangements, or anything covered by a supplier confidentiality clause
- Rough business strategy that you wouldn’t want a competitor to see, even if no individual’s privacy is at stake
Should not go near a general-purpose tool without a proper arrangement
- Client or customer personal details: names matched with addresses, dates of birth, account numbers
- Health information of any kind, about staff, clients, students or anyone else
- Children’s information
- Financial records, including anything that could identify an individual’s financial position
- Anything you hold under a confidentiality obligation to someone else, such as a client contract or a funding agreement
That last category doesn’t mean AI is off-limits for that work. It means it needs a proper business arrangement first: a paid tier with the right agreement, appropriate access controls, and ideally a tool that’s been set up so that information doesn’t leave your organisation’s control. That’s a setup question, not a reason to avoid AI altogether.
Questions worth asking any AI supplier
- Is our data used to train your models, and can that be turned off?
- Where is our data stored and processed?
- How long is it retained, and can we ask for it to be deleted?
- Who at your company, or which subprocessors, can access it?
- What happens to our data if we cancel?
A supplier that answers these clearly and in writing is telling you something useful about how seriously they take the question. One that can’t or won’t answer is telling you something too.
“We don’t use AI” isn’t a safety position any more
It’s tempting to think the safest option is simply to ban AI tools at work. In practice, that rarely works, because staff will use AI anyway, on their own personal accounts, on their own phones, often with the best intentions and no bad faith at all. A staff member trying to draft a difficult email faster, or summarise a long document before a meeting, will reach for whatever’s on their phone if there’s nothing sanctioned at work.
That means the real choice in front of most businesses isn’t “AI or no AI”. It’s managed or unmanaged. A managed approach means agreed tools, a simple policy on what can and can’t go into them, and a bit of training. An unmanaged approach means it’s already happening, just without anyone having thought it through.
You stay accountable either way
Under Australian privacy law, if your business collects personal information, you generally remain responsible for that information even when a third party is processing it on your behalf, including an AI provider. That accountability doesn’t disappear because a tool did the work. It’s a reason to be deliberate about which tools handle personal information and on what terms, not a reason to avoid AI altogether.
None of this is legal advice, and this article isn’t a substitute for checking your specific situation with a professional or with the Office of the Australian Information Commissioner. But as a starting point for a sensible, calm conversation with your team about what’s fine to type in and what isn’t, it should get you most of the way there.
If in doubt, ask yourself one plain question before you paste anything in: would I be comfortable if this ended up somewhere I didn’t expect? If the answer is no, that’s your answer.