Back to all lessons
Awareness Lessons
3 weeks ago

AI Chatbots Collect Your Data by Default — Know the Risks

Popular AI chatbots such as ChatGPT, Claude, and Gemini collect and store user conversations by default, exposing potentially sensitive personal, professional, or financial information to service providers and third parties. Many users are unaware that their interactions may be used for model training, reviewed by human contractors, or subject to data breaches. This matters because employees and individuals routinely share confidential data with AI tools without understanding the privacy implications. Emerging privacy-preserving tools using cryptography signal that the industry is responding, but users cannot wait for the market to catch up — they must take proactive steps now.

Tactical Insight

Immediate actions

  • Review and disable conversation history and data-sharing settings in all AI chatbot accounts you use today.
  • Avoid entering personally identifiable information (PII), financial data, passwords, or proprietary business data into AI chat interfaces.
  • Opt out of model training data programs where the option is available (e.g., ChatGPT's data controls in settings).

Long-term improvements

  • Establish an organizational policy defining which types of data are prohibited from being entered into third-party AI tools.
  • Evaluate and prefer AI solutions that offer on-premises deployment or verifiable privacy guarantees (e.g., zero-knowledge or end-to-end encrypted services).
  • Conduct regular vendor privacy assessments for any AI tools integrated into business workflows.

User awareness measures

  • Train employees on the data retention and usage policies of AI tools before allowing their use in a work context.
  • Publish internal guidance distinguishing between approved and unapproved AI platforms based on data sensitivity classification.
  • Monitor emerging regulatory requirements (e.g., EU AI Act, GDPR) and adjust acceptable-use policies accordingly.