When your team uses generative AI tools like ChatGPT, Claude, Gemini, or Perplexity, you're not just typing prompts into a box – you're making decisions about how your organization's data is handled. One of the biggest choices you face is whether to allow your data to be used for training large language models (LLMs).
This isn't simply a privacy setting. It's an organizational governance decision that affects security, intellectual property, compliance, and responsible AI adoption.
What It Means to "Use Data for Training"
In plain terms, allowing an AI company to use your data for training means information you provide to the service — such as prompts, documents, files, or other content — may be used to help improve its AI systems.
That doesn't mean your confidential strategy document simply gets copied into an AI model for someone else to retrieve. Model training is considerably more complicated than that. But from an organizational perspective, the important issue is simpler: information your organization provides may be used for purposes beyond completing the immediate task you gave the AI tool.
For leaders overseeing organizational knowledge, corporate IP, or regulated data, this should raise red flags.
For organizational leaders, the question therefore isn't simply, "Does this AI tool train on our data?" It is also: What information are we comfortable providing to this service, under what terms, and who gets to make that decision?
Current AI Training & Privacy Settings
- ChatGPT (OpenAI): In paid "Team" or "Enterprise" plans, data is not used for training by default. Admins can enforce this setting for the entire organization.
- Claude (Anthropic): Paid "Pro" and enterprise plans allow you to disable training. With enterprise accounts, settings can be enforced centrally.
- Perplexity: For individual paid accounts, you can adjust privacy settings yourself to restrict training use.
- Gemini: Personal Google accounts and some Google Workspace accounts don't necessarily have the same protections as enterprise grade accounts. Google says Gemini chats and uploaded files for Workspace users with enterprise-grade protections aren't reviewed by humans or used to improve generative AI models. Personal Gemini/Google accounts have completely different data-use rules.
The bottom line: Don't assume that paying for an AI tool means your organization's data is automatically excluded from training. Protections vary by vendor, product, account type, subscription tier, and settings — and they change over time. Organizations should verify the terms and controls for the specific tools they use.
AI Is Now Built Into Everything
ChatGPT, Claude, Gemini, and Perplexity are some of the most visible AI platforms, which makes them a natural place to start. But they represent only part of the governance challenge.
Generative AI is increasingly built into presentation tools, meeting platforms, project management systems, CRMs, design applications, research tools, note-taking apps, meeting transcript tools, and countless niche SaaS products. Many organizations may already have dozens of applications with AI capabilities — sometimes without realizing it.
And the data practices of these products vary considerably. Some exclude business data from AI training by default. Others provide an opt-out setting. Some protections depend on the subscription tier or type of organizational account.
That's why an organizational AI policy shouldn't simply say, "We've approved ChatGPT." It should establish expectations for any tool that receives organizational information and uses AI to process it.
Beyond Training: Other Security Risks Still Apply
Even if you disable training, risks remain:
- Data sharing and access. Your queries may be logged for debugging or abuse detection.
- Accidental oversharing. Staff may paste in sensitive documents without realizing implications.
- Shared links. Many platforms let you generate shareable links to chats or threads. These links sometimes get indexed by search engines, meaning your "private" exchange could show up publicly.
- Connectors and integrations. Adding third-party connectors (e.g., linking your Google Drive, SharePoint Online, CRM, Dropbox, or Slack tenant to an AI platform) can expand the risk surface. A misconfigured connector could expose sensitive data far beyond what you intend.
- Compliance gaps. Industry-specific requirements (HIPAA, GDPR, federal contract rules, etc.) may be impacted.
The choice isn't between "safe" and "unsafe," it's about being intentional, managing risks, setting expectations, and having clear organizational policies.
Even when AI training is disabled, organizations should still consider whether prompts contain confidential information, intellectual property, research data, customer information, or other sensitive organizational knowledge.
What This Means for Your Organization
- For Enterprise/Team Accounts: Take advance of centralized controls. Set organizational defaults so staff don't have to decide on an individual basis.
- For One-Off Paid Accounts (like Perplexity Pro): Adjust privacy settings manually in the account dashboard. Train staff to check and confirm settings.
- For All Accounts: Establish clear internal guidance about what data can and cannot be shared with AI tools.
This isn't about saying "don't use AI." It's about using it thoughtfully, balancing productivity with security, protecting intellectual property, and reducing compliance risk.
A Practical Next Step
Business leaders should ask:
- Have we set organization-wide privacy defaults where possible?
- Do we know what kinds of data our teams are putting into these tools?
- Do we have clear policies about AI usage? And are staff trained to follow them?
Intentional use of AI means thinking beyond convenience to long-term security and governance. As with any other technology decision, your mission, intellectual property, and, potentially, your stakeholders' data, deserve protection.
✅ Key takeaway: Paid plans give you more control over whether your data is used for training. But disabling training isn’t the end of the conversation — it’s the beginning of building a thoughtful, security-aware AI policy.
This Is Ultimately a Governance Decision
Whether your organization allows AI platforms to use prompts for training is only one part of a broader governance conversation. Organizations also need clear expectations for what information employees may share with AI tools, how confidential and proprietary information should be handled, who approves new AI tools, and how organizational knowledge should be protected.
Strong Information & Data Governance provides the framework for making these decisions consistently rather than leaving them to individual employees.
Continue Exploring
If you're developing AI policies or broader governance practices, these resources may help:
Foundational Resources
- Information & Data Governance: An Executive Guide
- Information & Data Governance FAQ
- Information & Data Governance Consulting