David Nowak.
Home/Articles/Is my data safe with AI?
Article

Is my business data safe with AI?

The short answer: it depends entirely on how the AI is set up — not on "AI" as a whole. There are three ways AI handles your data, and each has different trade-offs. Here's the honest breakdown, and the questions to ask any vendor.


The setups

The three ways AI handles your data

Most business AI falls into one of three setups. None is "wrong" — they just trade off convenience against control.

SetupWhat happens to your dataTrade-off
Public toolsYou paste info into a shared tool (like a free chat assistant). It may be used to improve the service.Easiest to use. Data leaves your business. Don't put anything sensitive here.
Private APIsThe vendor promises your data isn't used for training, under a contract.More control, still sends data to a third party. Trust depends on the contract.
On your machinesAI runs on hardware you own. Nothing leaves your business.Most control and strongest privacy. Costs more and needs setup.
"AI is safe" is the wrong question. The real question is: where does the data go, and who can touch it?
What matters

Which of your data actually matters

Not everything is worth worrying about. The line is usually simple:

  • Fine to use anywhere: public facts, product descriptions, general drafts.
  • Handle with care: customer lists, contact details, anything personally identifiable.
  • Keep off public tools: financial records, contracts, proprietary process, anything a leak would hurt.
Why this matters

Most "AI data breach" stories aren't someone hacking in. They're a business feeding client data into a free tool and then finding that data used in ways they didn't intend. The safest rule is simple: if you wouldn't put it on a billboard, don't put it in a public tool.

Before you sign up

Questions to ask any vendor

Before you sign up, ask these five. A good vendor answers plainly. A bad one deflects.

  1. Is my data used to train your model?
  2. Where is my data stored, and is it encrypted?
  3. Can your staff see my data?
  4. What happens if I stop paying — do you delete it?
  5. Is there a contract, or is it in a terms-of-service box?

The answers tell you which of the three setups you're really in — regardless of what the marketing says.

Your call

Your decision, honestly

Here's the honest trade-off: public tools are the fastest way to try AI, and they're fine for low-sensitivity work. The moment your data is sensitive, or you're in a regulated industry, the on-your-machines route becomes worth it.

There's no single right answer — it depends on what data you handle and how much it's worth if it's exposed. What matters is that you choose with your eyes open.

The 30-second takeaway

Know where your data goes before you use an AI tool. Public tools are fine for non-sensitive work; sensitive data needs a private setup. Ask the five questions above, and never assume.

I'm David. I build AI that runs on your machines.

Twenty years in engineering leadership, now helping small and mid-size businesses put AI to work without handing their data to a cloud. If you'd rather I build it than you learn it, let's talk.

Book a 30-minute call
David Nowak