
Posted on
by AAHB
In Part 1, I explained how AI actually works. The short version: it does not know anything. It predicts the next most likely word based on patterns it absorbed from enormous amounts of text. That single concept changes how you should think about every AI tool you use.
But there is a second risk, and it might be the more urgent one.
It is not about what AI gets wrong. It is about what happens to the information you put in.
Right now, your team is almost certainly using free AI tools for work. They are summarising documents, drafting emails, brainstorming ideas, maybe even processing client information. And most of them assume it works like a search engine: you type something in, you get an answer back, and your data disappears into the void.
That is not what happens. Not even close.
When you type something into a free AI tool, that information does not just vanish after you get your response. It is stored. It may be reviewed by humans. And in many cases, it can be used to train future versions of the model. Your confidential client data, your financial figures, your internal strategy documents – all of it potentially becoming part of the patterns the AI learns from.
You Are Not the Customer. You Are the Product.
There is an old saying in tech that applies perfectly here: if you are not paying for the product, you are the product.
Free AI tools are not free because the companies behind them are feeling generous. They are free because your data has value. The conversations you have, the documents you paste in, the questions you ask – all of this helps these companies improve their models, understand how people use AI, and build better (paid) products.
This is not a conspiracy theory. It is right there in the terms of service, buried in language that almost nobody reads.
Here is what typically happens when you use a free AI tool:
Your conversation is stored. Not just for the length of your session. Your prompts and the responses you receive are saved on the company’s servers, and unless you actively delete them, they can be retained indefinitely.
Humans may review it. Most AI companies use a combination of automated systems and human review to monitor conversations for safety and content moderation. If something in your conversation gets flagged, a real person could end up reading the client proposal you just pasted in.
It may be used for training. On free tiers, your conversations can be fed back into the training process for future versions of the model. The financial data you summarised today could eventually become part of the patterns the model learns from.
These companies are not rubbing their hands together trying to steal your secrets. Most of them handle data responsibly within the terms they have set. The problem is that most people using these tools have absolutely no idea what those terms actually are.
Free Versus Paid: The Difference Actually Matters
Not all tiers of an AI tool are created equal. The privacy protections you get depend entirely on which version you are using, and the differences are significant.
Free and consumer tiers generally allow the company to use your conversations for model training by default. You can often opt out, but you have to find the setting yourself (it is usually buried several clicks deep in your account settings), and even opting out does not always prevent your data from being stored or reviewed for safety purposes.
Paid individual tiers vary. Some offer the same privacy as free, just with better performance. Others provide genuine data protections. You need to read the fine print for each tool.
Business and enterprise tiers are where the real protections live. These typically come with contractual guarantees that your data will not be used for training, will not be reviewed by humans (except in narrow safety circumstances), and will be handled according to specific data processing agreements. This is what enterprise customers pay for, and it is a fundamentally different product from the free version.
Imagine you are writing something sensitive on a whiteboard. The free tier is like writing on a whiteboard in a shared office building. You can erase it when you are done, but you have no idea who walked past and read it, whether someone took a photo, or whether the building management keeps security footage. The enterprise tier is like writing on a whiteboard in your own locked office, with contractual agreements about who has a key.
Same whiteboard. Very different levels of privacy.
Why This Should Matter to Every Australian Business
An employee needs to summarise a client’s financial situation for an internal report. They copy the client’s name, account details and financial figures into ChatGPT’s free tier and ask it to write a summary. They get a great result in 30 seconds. Job done.
Except that client’s personal and financial information has now been sent to servers overseas. It is being stored. It may be reviewed by humans at the AI company. It could potentially be used to train future models. And none of this was disclosed to the client, nor did the client consent to their information being handled this way.
Now imagine that client finds out. Not from you. Maybe from a news article about how free AI tools use data for training. Maybe from their own accountant raising concerns. However they find out, that conversation is not going to be about terms of service or data processing agreements. It is going to be about trust. And trust, once broken, is very hard to rebuild.
If your clients found out that their personal information was being fed into a free AI tool without their knowledge, would they still trust you with it?
For most businesses, the honest answer is no. And that is reason enough to take this seriously.
What You Can Do About It
Create a “red list” of data that never goes into free tools
Sit down and define the categories of information that should never be pasted into a free AI tool. Client names and personal details, financial records, health information, legal matters, employee records, anything covered by a confidentiality agreement. Write it down. Make it visible. Make sure your team knows it exists.
It does not need to be complicated. A simple list on one page that everyone can reference is infinitely better than no policy at all.
Understand what your team is actually using
Most business owners have no idea which AI tools their team is using, let alone which tier they are on. Take 15 minutes this week to find out. Ask your team what they use, how they use it, and whether they are on free or paid versions. You might be surprised by the answers.
Check one setting today
If your team uses ChatGPT (and there is a very good chance they do), go into Settings, then Data Controls, and look for the option to disable “Improve the model for everyone.” Turning this off means your conversations will not be used for training. It takes about 30 seconds. It does not solve everything, but it is a meaningful first step.
Most other AI tools have an equivalent setting. Find it. Toggle it.
Write a one-page AI usage policy
You do not need a 50-page governance document. You need one clear page that answers three questions: What data can go into AI tools? What data cannot? And who is responsible for checking?
Businesses can overthink this to the point of paralysis, spending months developing comprehensive AI governance frameworks while their team continues using free tools with no guardrails at all. A simple, imperfect policy that exists today is worth infinitely more than a perfect policy that arrives in six months.
Consider paid tiers for sensitive work
For the cost of a few coffees per month per user, business and enterprise tiers of most AI tools come with genuine data protection guarantees. Your data will not be used for training. It will not be reviewed by humans. You get a proper data processing agreement.
If your team is using AI for anything involving client data, internal strategy or confidential information (and they probably are), this is one of the easiest risk-reduction decisions you will make.
The Bottom Line
AI is not the enemy here. I use these tools every single day and they are genuinely transformative for how I run my business. But there is a difference between using AI with your eyes open and using it because everyone else is and hoping nothing goes wrong.
Free AI tools are not private by default. Your data is stored, it may be reviewed, and it can be used for training. The privacy protections you get depend entirely on which version of the tool you are using and which settings you have enabled.
For Australian businesses, this is not just a best-practice consideration. It is a trust question. If your clients found out their personal information was being fed into a free AI tool without their knowledge, would they still trust you with it?
The fix is not to panic or to ban AI. The fix is to know which data goes where, to have a simple policy your team can follow, and to make intentional decisions about which tools you use for which tasks.
That is what using AI with confidence looks like.
Key Takeaways
- Free AI tools are not private by default. Your conversations may be stored, reviewed by humans, and used to train future models.
- The privacy protections you get depend on which tier of the tool you are using. Free, paid and enterprise tiers are fundamentally different products when it comes to your data.
- Your clients trust you with their information. If they found out it was being fed into a free AI tool without their knowledge, that trust is at risk.
- A simple “red list” of data that never goes into free tools is the single most impactful step you can take today.
- You do not need to ban AI. You need a one-page policy, a quick settings check, and intentional decisions about which tools handle which data.
This is Part 2 of the AI with Confidence series, where I break down what Australian business owners actually need to know about AI. No jargon, no hype, just the practical fundamentals. Next up: why your data might not be ready for AI, and what “ready” actually means.
Disclosure: This article was created with the assistance of Artificial Intelligence tools to support research and outlining. While AI helped structure the piece, the final writing, views, and insights are entirely those of the author. All content has been reviewed and fact-checked by the author to ensure accuracy. The images featured in this post were generated using AI.

