N 41.053° · W 73.539°
/AI THOUGHT LEADERSHIP

AI and Data Privacy: What Small Businesses Must Know

By Scott McKenna, Founder · 2026-04-16 · AI Thought Leadership · Updated May 13, 2026

Someone on your team pastes a customer's email thread into a chatbot to get help writing a reply. It takes four seconds and nobody thinks about it again. That single habit, repeated across a year, is how most small businesses actually expose customer data. Not through a breach. Through convenience.

The good news is that the fix is mostly configuration and a one-page rule, not a compliance project. What follows is the practical version, aimed at a business with no legal department.

Three questions to ask about any AI tool

Before you or anyone on your team puts business information into a tool, you need answers to three things. Every reputable provider publishes them, usually on a page called trust, security, or data processing.

Does it train on my inputs?

Consumer accounts on many chatbots use your conversations to improve the model unless you turn that off. Business and team tiers typically do not, by default and by contract. This is the single largest difference between the free account someone signed up for and the paid account you should be using.

How long is my data kept?

Retention varies from zero days to indefinite. Zero-retention options exist on some API tiers. For chat tools, thirty days is common, often for abuse monitoring. Knowing the number matters because it determines what you can honestly tell a customer who asks.

Will they sign a data processing agreement?

If you handle anything regulated, or you have clients who impose their own terms, you need a written agreement with the vendor. Providers that will not offer one should not touch your customer data. For health information specifically, that means a business associate agreement, and most consumer AI tools will not sign one.

What counts as customer data is broader than you think

People correctly avoid pasting in social security numbers and card details. The exposure usually happens with material that does not feel sensitive:

A useful test: if you would not forward the item to a competitor, do not paste it into a tool whose retention and training terms you have not read.

The settings that matter, in the order they matter

Most of the real risk disappears with an afternoon of setup.

Move everyone onto a business or team account under your control, so you can enforce policy centrally and remove access when someone leaves. Personal accounts used for work are the most common gap we find, and they are invisible to you.

Turn off training on your data explicitly, even where the tier claims it is off by default. Check it again after major product updates, because defaults occasionally change.

Turn off chat history where the tool allows it and where your team does not need it. Less stored means less to worry about.

Be deliberate about connectors. Granting an AI assistant access to your entire email or file storage is a much larger decision than granting it a single folder. Do it when there is a real reason, not because the setup wizard suggested it.

The one-page rule your team will actually follow

A twelve-page policy will be read once. Write something a new hire can absorb in two minutes, and make it specific to your tools. A workable version says: use the company account only; never paste customer identifiers, health information, financial account details, or anything under a client NDA; redact names before asking for help with a real email; recordings require everyone's agreement; and if you are unsure, ask before pasting.

Pair it with an approved list. Two or three tools people may use, and a note that anything else needs a quick check first. Shadow tool use is driven by ambiguity, so removing ambiguity solves most of it.

When AI should stay out of it entirely

Some material does not belong in a general-purpose AI tool regardless of settings. Patient records, anything covered by a client's confidentiality agreement, information about children, immigration status, and material you hold on behalf of another business under contract. If a category feels like it might be regulated, treat it as regulated until you have checked.

There is a middle path worth knowing about: models that run entirely on your own hardware never send anything anywhere. They are less capable than the frontier services and take effort to set up, but for summarising sensitive documents the tradeoff can be worth it.

Finally, be honest with customers if they ask. "We use AI tools to draft correspondence, we do not put your personal details into them, and we do not allow them to train on our data" is a clear answer that most people accept. Vagueness is what makes people uncomfortable.

Frequently asked

Is it safe to use a free AI chatbot for work?

For general questions with no customer information in them, yes. For anything involving a real client, a free consumer account is the wrong container, because the default terms usually permit training on your inputs and you have no administrative control over the account. Move to a paid business tier before the habit spreads.

Do Connecticut businesses have specific AI privacy obligations?

Connecticut has a consumer data privacy law that applies above certain thresholds of data volume, so many very small businesses fall outside it. That does not remove your obligations under contracts, sector rules such as those covering health or financial information, or plain duty of care. Check with an attorney rather than assuming you are exempt.

Can I use AI note-takers in client meetings?

Only with everyone's clear agreement, obtained before recording starts. Announce it at the top of the call and let people decline. Beyond the legal question, transcripts capture asides and half-formed thoughts that participants never meant to preserve, so consider whether you need the recording or just the summary.

What should I do if someone already pasted sensitive data?

Delete the conversation, check whether the account had training enabled, and note what was exposed and when. If the data belongs to a client under contract, read the contract's notification clause before deciding it was harmless. Then fix the underlying cause, which is almost always an unmanaged personal account.

Want this handled for you?

Get a free audit of your website, Google reviews, and local SEO — we’ll show you exactly where you’re losing customers. Delivered in 24 hours, no sales call.

Get my free audit → or book a 15-min call

Want AI Working for Your Business?

We help local businesses in Stamford, Greenwich, Norwalk, and Fairfield County implement AI marketing that generates real results.

Get Your Free AI Marketing Audit →
SERVICES: Digital Marketing SEO Services Google Ads LOCATIONS: Stamford Greenwich Norwalk White Plains RESOURCES: Blog Free Audit Free Tools