The AI Adoption Free AI pre-audit ↗

Business data / Practical guide

What can you safely
share with AI?

Your team wants to use Claude, ChatGPT or Copilot with real business information. Here is what to check before uploading a contract, connecting a mailbox or sharing customer records.

By The AI Adoption · Sources checked 16 September 2026

Download the full security review PDF · 24 pages ↓

Start here

A business plan helps.
The way you use it matters.

A managed business account can be a sensible starting point for drafting, research and work with public or appropriately reduced information. Buying that account does not, by itself, establish that every use of customer, employee or confidential data is acceptable.

Three different questions often get mixed together:

Training
Can the provider use your content to improve its models?
Retention
How long are conversations, files and other copies kept?
Residency
Where are they stored, and where does the AI process them?

No training does not mean no storage. And storing a conversation in Australia does not necessarily mean the AI processes it here.

Claude, ChatGPT and Copilot: what changes?

These are business products. Personal accounts and API-based applications need their own checks. The table summarises published terms, not a test of your account.

Product Training Storage and retention
Claude Team No model training by default. Submitted feedback is an exception; an owner can disable it. [1] Saved chats are retained. After deletion, backend removal is ordinarily within 30 days, with exceptions. Do not assume an Australian residency commitment. [2]
ChatGPT Business / Enterprise Business content is not used for training by default. [3] Check retention in the purchased plan. Australian storage is available to eligible Enterprise customers; that does not establish Australian model processing. Do not assume Business has the same residency options. [4]
Microsoft 365 Copilot Prompts, responses and Microsoft Graph data are not used to train foundation models. [5] Stored interaction content follows applicable Microsoft 365 location commitments. An Australian environment can provide Australian storage; processing and optional features need separate checks. Retention follows the organisation's applicable policies. [6]

The full report also examines Grok Bot, the xAI API, Microsoft Foundry and Amazon Bedrock. Product, model and feature exceptions are covered there.

Can a provider still hold or access data?

Yes. A no-training commitment is only one part of the agreement. Saved history, security investigations, legal obligations, support and connected services can have different rules. Check those conditions before treating a workspace as suitable for sensitive records.

Do the data need to stay in Australia?

Not automatically. Australian privacy rules allow overseas transfers subject to conditions. An organisation covered by those rules may remain accountable when an overseas recipient mishandles personal information. [7]

Start with the reason for the requirement. A contract may require Australian hosting. A sensitive workflow may justify choosing local storage and processing. An ordinary procedure or public marketing brief may not need the same restriction.

Check the complete route: the original application, the AI provider, connected tools, generated files and logs. An Australian server for one part of that route does not establish that every part stays here.

“We already use Google. Does that settle it?”

No. It is a useful reason to review the tools you already use, but it does not automatically approve another provider. Compare the actual data, agreements, access and purpose. An approved email service and an assistant connected to the whole mailbox are different decisions.

Start with the work.
Then choose the data.

These are illustrative examples, not assessments of particular clients.

A health practice

A weekly report may only need appointment totals and cancellations. Calculate those from the source records and keep patient names, treatment notes and sickness explanations out of the prompt. If identifiable health information is necessary, assess the lawful use, recipient, contract and retention before uploading it. A more expensive plan does not remove that requirement. [8]

A construction business

Drafting a procedure is different from analysing a restricted tender. Check the project's confidentiality and location terms before sharing drawings, pricing or correspondence. A responsible person should review contractual commitments and safety documentation against the source.

A hospitality business

A sales summary may need product totals, not customer contact details. An invoice check may need invoice lines and an agreed rate card, not access to every finance document. Keep payments and material changes subject to an explicit human decision.

Before you connect a live account

  1. Name the task. What should the assistant produce, and who checks it?
  2. Choose the fields. Send only the information needed for that task.
  3. Check the agreement and settings. Confirm training, retention, location and any client restrictions for the exact plan and features.
  4. Limit access. Start with selected files and read access where possible. Approve sending, editing and deleting separately.
  5. Test removal and mistakes. Check what happens when a member leaves, a file is deleted or the assistant gets an answer wrong.

Keep a short record of the decision: approved for this task, approved with conditions, or held until a specific question is answered. Revisit it when the data, model, connected tools or permissions change.

For the practical setup steps, read how to adopt AI securely in your business.

What this review establishes

This is a review of public vendor and regulator documentation, with practical recommendations from The AI Adoption. It is not a penetration test, a legal opinion or certification that a particular business is compliant. Private contracts, actual settings and deletion behaviour require separate verification.

The full report contains 45 primary sources and records product-specific exceptions. This page includes additional Microsoft location references checked for this guide. The date above records the review, not a promise that provider terms will remain unchanged.

Read the full evidence and conditions Download PDF ↓
  1. Anthropic: commercial data and model training
  2. Anthropic: commercial data retention
  3. OpenAI: enterprise privacy
  4. OpenAI: data residency for ChatGPT
  5. Microsoft: Copilot data, privacy and security
  6. Microsoft: contractual data residency commitments; Copilot retention policies
  7. OAIC: sending personal information overseas
  8. OAIC: privacy and commercially available AI products

Know what to check
before you connect.

Bring the tools you use and the work you want AI to help with.

Free AI pre-audit ↗