What AI Chatbots Actually Do With What You Paste. It Depends on the Login.


The major AI assistants your staff use ship under two sets of terms. One applies to the personal account someone created with a Gmail address on a Tuesday afternoon. The other applies to the business or work account an administrator set up. The product looks the same in both, and the fine print is close to opposite. On the personal side, what gets pasted in can be used to train models, reviewed by people, and kept for years. On the business side, training is off by default and any human access is limited to abuse and safety review. Two-thirds of the people using AI on company devices are on the personal side.
This is the first piece in a week on the AI tools themselves, after nine industry pieces on the rules that already reach them. We are starting with the general-purpose assistants because they are where the pasting happens, and because their terms answer a question most owners have never asked: when a staff member drops a client file into a chatbot, what did the vendor say it would do with it?
The account decides, not the product
Start with the number that makes this a business problem rather than a policy debate. Verizon's 2026 Data Breach Investigations Report found that 67 percent of users accessing AI services on corporate devices were using non-corporate accounts, and that 45 percent of employees are now regular users of AI on those devices, up from 15 percent a year earlier. Those are cross-industry figures. Read together, they mean most of the people using AI on a company laptop are doing it under the personal terms, not the business ones.
We covered why "we approved that tool" does not mean "we are covered" in an earlier piece. Today is the other half: what the personal terms actually say, and what changes when the login changes. Everything below comes from the vendors' own help and privacy pages, accessed September 1, 2026. These pages move, which is part of the point, so treat this as a snapshot and check the source before relying on it.
The personal tier: the default leans toward training
Take the four assistants a typical small business actually encounters, on their personal or consumer plans.
OpenAI's ChatGPT, on its consumer plans (Free, Go, Plus, and Pro), says in its own words that it "improves by further training on the conversations people have with it, unless you opt out." The opt-out is a setting called "Improve the model for everyone," or a temporary chat mode that is deleted within 30 days. In February 2026 OpenAI also began showing ads to Free and Go users, starting in the United States and since expanded to other countries, matched using the current conversation, past chats, and past interactions with ads, with a toggle to stop the use of past chats and memory; the company states it does not share conversations with advertisers.
Anthropic's Claude, which had kept a 30-day retention window, changed its consumer terms in late August 2025. Users on the Free, Pro, and Max plans now choose whether their chats and coding sessions can be used to improve the model, and if they allow it, the vendor "may retain your data in a de-identified format for up to 5 years" in its training pipelines. If they decline, the 30-day window stays. The choice was required by October 8, 2025, and it can be changed in privacy settings at any time.
Google's Gemini app, on a personal Google account, keeps activity on by default for adults, and its privacy page says the company "uses your activity to provide, develop, and improve its services (including training generative AI models)." A subset of chats is reviewed by human reviewers, and chats that have been reviewed "are not deleted when you delete your activity" but are retained for up to three years. Activity is otherwise kept 18 months by default. The same page asks users not to enter confidential information "that you wouldn't want a reviewer to see or Google to use to improve our services, including machine-learning technologies."
Microsoft Copilot, on a personal Microsoft account, states that "except for certain categories of users or users who have opted out," Microsoft uses data from the consumer assistant, including "your voice and conversation activity" and uploaded files, for AI training, with conversation activity stored for 18 months by default. Users signed in with an organizational work account are excluded, as are users in several named countries. There is an opt-out toggle called "Training on conversation activity" under privacy settings. Whether a given region is covered has shifted since the program was announced in 2024, so check the current page for yours.
Four vendors, four different mechanisms, one shared default: on a personal account, the vendor's starting position is that your content is available to improve the product, unless the user finds the setting. Whether any given user found it is invisible from outside the account, and most employers have no way to know.
The business tier: the default flips
Now the same four products on their business, team, enterprise, or work-account tiers.
OpenAI's enterprise privacy page: "We do not train our models on your data by default," across ChatGPT Business, Enterprise, Edu, and the API, with admin-controlled retention on Enterprise and Edu and an optional zero-data-retention arrangement for the API. Anthropic's commercial policy: "By default, we will not use your inputs or outputs from our commercial products" to train models, with API inputs and outputs deleted within 30 days and a zero-retention option available. Google Workspace with Gemini: "Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission," with prompts treated as customer data under its Cloud Data Processing Addendum. Microsoft Copilot on a work account, until recently named Microsoft 365 Copilot: "the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models," under a data protection addendum with Microsoft acting as processor, signaled in the interface by a green shield.
That is the whole difference in one sentence: on the business side of each of these four products, training is off by default and a data processing agreement is on. The product did not change. The login did.
What a business tier does not give you
This is where owners get overconfident, so here is the honest part.
First, a business tier is not the same as a Business Associate Agreement or any other regulated-data contract. OpenAI offers a BAA for its API, for sales-managed Enterprise and Edu accounts, and for its healthcare-specific products, and states plainly that it does not offer one for ChatGPT Business. Anthropic offers a BAA for its API and Enterprise plans, and its own page lists what stays outside it: the developer console, its Cowork task agent, features in beta, and, notably, data sent to third parties through its browser extension or connectors, which "isn't covered under Anthropic's BAA" even when the plan is. Google lists Gemini in Workspace under its HIPAA-covered functionality but excludes Gemini in Chrome. Microsoft says its work-account Copilot supports HIPAA compliance "for properly configured implementations," and that web search queries are not covered. If your industry piece in our series involved regulated data, the tier you bought is a starting point, not the finish line. The medical practice piece walks through the BAA comparison in detail.
Second, the boundary between personal and business is invisible from where you sit. ChatGPT Business lets a user hold a personal workspace and a company workspace behind the same login and switch between them; OpenAI's ChatGPT Business FAQ says workspace admins "cannot see all private member chats" by default and that data export is not available on that plan, while its enterprise privacy page describes broader admin access, so confirm with the vendor which applies to your workspace. The consumer tiers of all four come with no employer console. So a paid business tier fixes the terms for the sessions that happen inside it, and tells you nothing about the sessions that happen next to it.
Third, the terms move. Anthropic's five-year retention change arrived with a month's notice, later stretched to about six weeks. Microsoft's consumer training program was announced in a blog post in August 2024 and switched on that fall. And for several months in 2025, a court order in a copyright case required OpenAI to retain consumer, Team (now Business), and standard API chats, including deleted ones, before the obligation ended on September 26 and normal 30-day deletion resumed for new data. None of those changes required your staff to do more than click through a prompt. All of them changed what happened to your data.
Visibility comes before the toggle
The right move is not a memo telling staff to check their settings. The four vendors bury the setting in four different places, and the person who pasted the client file is not the person who will read the memo.
The move is the same one every industry piece landed on. First, find every AI assistant on the machines that touch sensitive work, and for each one, which account it is signed into, personal or business. That single fact determines which of the two sets of terms above applies, and it is the fact most owners do not have. Second, one rule that removes the judgment call: sensitive client, patient, financial, or employee information goes only into assistants on the approved, business-tier list, and summarizing or rewriting counts as going in. Third, an approved path, which usually means actually buying the business tier of the tool your staff already chose, because the terms on that side are the terms you want, and the tool they already use is the one they will keep using.
Where we fit, and where we do not
We are not lawyers, and which tier or contract your business needs is a question for counsel. We do not resell the assistants above or negotiate their terms.
What we run is the layer that makes the rule enforceable. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of the AI tools, extensions, and agents found in use across your machines, including which are signed into personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next. From there we enforce the approved list you set, so a personal login on a sensitive machine gets caught rather than trusted, and we keep watching as new tools show up. It supports the policies and contracts above; it does not replace them.
The question worth asking this week
Not "which AI tool is safest." Ask the one the terms actually turn on: of the AI assistants your staff used today, how many were signed into an account your business controls?
We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and you want that number instead of a guess, book a free 15-minute call. The discovery is free, and the answer is yours either way.
Comments