A tool your company already pays for shipped an update last quarter. The release notes mentioned a new AI assistant. Nobody signed a contract. Nobody called legal. A toggle appeared in the settings, and there’s a reasonable chance it arrived already switched on.

That update changed where your company’s data goes. Most leaders assume the invoice settles that question. You pay, so you are the customer, not the product. That logic held up when software simply stored your information. It falls apart the moment software starts sending your information elsewhere for interpretation.

This shift rarely announces itself. It arrives as a feature, not a decision. And by the time anyone thinks to ask where the data went, it’s already been several places.

Summary

The more useful question is not whether a vendor trains on your data, but what you are handing over in the first place and whether it belongs in the class of information you cannot afford to lose control of. Retention windows, retrieval features that quietly pull from your own documents, and inference providers several layers past the company you actually pay all widen exposure in ways enterprise tiers were never built to close. The fix is a review nobody scheduled: treat every AI feature as its own vendor contract, and audit what you are sending with the same rigor you apply to who is receiving it.

Paying Doesn’t Take You Out of the Deal

The most expensive assumption in your software stack is that paying for a tool buys you out of the data relationship. It doesn’t, and the saying most leaders half-remember is the reason why.

“When your product is free, you are the product. People fall into the bad habit of assuming the inverse is automatically true, and it isn’t,” said Steve Anderson, Principal Developer and AWS Architect at Slingshot. “You may still be the product even when you are paying for it.”

That inversion is where most data assumptions break. Free tools have to monetize something, so we scrutinize them. Paid tools feel resolved, because the transaction looks complete. But payment and data pathway run independently. Your subscription buys access to a product, not control over the information you push through it.

“Even when you pay, your data can still get used in aggregate,” said Doug Compton, Principal AI Developer at Slingshot. “It might be anonymized. But if you are the only company that has that data, it still gets out there.”

Anonymization sounds like protection until you consider how specific your data actually is. Aggregate patterns reveal direction, priorities, and demand. If your inputs are unique to your business, stripping your name off them doesn’t make them unrecognizable.

The Update Nobody Signed

Ask how this shows up in practice and the answer is rarely dramatic. It shows up as a checkbox.

“We have seen a new AI toggle appear and default to on,” Steve said. “More reputable vendors ship it off and let you opt in.”

Default-on is only half the problem. The other half is permissions. Most companies assume a decision this consequential requires someone senior to make it.

“The other question is who gets to opt in,” Doug said. “Does it have to be an administrator, or can any user who doesn’t know much about AI turn it on?”

In plenty of tools, the answer is any user. Someone in marketing enables an assistant to summarize meeting notes and, without any awareness of doing so, changes the company’s data posture.

Then there is the paperwork underneath all of it, which nobody rereads. “Terms of service change constantly,” Doug said. “What you agreed to when you signed up may not be what you are operating under today. All they have to do is send you an email.”

"Terms of service change constantly,. What you agreed to when you signed up may not be what you are operating under today. All they have to do is send you an email."

So the agreement moves, the default moves, and the person flipping the switch may not be the person accountable for the consequence. Inside most companies, the left hand has no idea what the right hand just switched on. 

“Do You Train on My Data” Is the Wrong First Question

Executives who do ask about AI risk usually ask whether the vendor trains its models on their data. It’s the wrong opening question, because for most companies the answer barely changes the exposure.

“I do not know that it matters to most people whether you are helping train the models,” Steve said. “The exception is when you truly have some kind of magic sauce or IP that isn’t just run of the mill. That’s where you want to be diligent about what you share.”

Doug expanded the boundary of that category. “Any PII, health information, or financial data belongs in that same bucket,” he said.

That reframe is the useful one. The question isn’t whether a vendor trains on your data. The question is what you are handing over in the first place, and whether it belongs in the class of information you cannot afford to lose control of.

Even a vendor who promises never to train on your data leaves you exposed. Steve pointed to the simpler risk underneath it: your data left your premises, and someone else now keeps it safe. A breach anywhere in that chain reaches information a vendor never trained on and never intended to keep. It was there because the feature required it to be. That’s enough.

Your Vendor Has Vendors

Most leaders picture two parties: their company and the vendor they pay. The reality runs deeper, and the vendor may not be able to name everyone either.

“The model provider matters less than the inference provider,” Doug said. “Whoever is actually hosting and running that model is who you are sending your data to.” With the biggest names, one company both builds and runs the model. With cheaper options, someone else is running it, and that someone receives your data.

Doug pointed to routing services that spread requests across dozens of providers and rotate where each one lands. Your data doesn’t follow a single path. It takes whichever path was cheapest at that moment.

Geography follows the same logic. Many of the lower-cost models run offshore, which matters enormously if you have promised your own customers that their information will stay in the United States. That promise now depends on infrastructure decisions made by a vendor’s vendor.

Steve traced the chain from the inside. “We know AWS, and we know their employees have access to our data,” he said. “We do not know for certain who they share it with. And at the model provider, we do not know who they contract with. There may be no bottom to that chain.”

That isn’t a criticism of any particular provider. It is an honest description of how far visibility actually extends, even for the people who architect these systems for a living.

Retention and Retrieval Widen the Window

Two questions get skipped almost universally. The first is how long.

“The longer somebody stores your data, the longer the window for someone to reach it through a breach,” Steve said.

"The longer somebody stores your data, the longer the window for someone to reach it through a breach."

Where your data sits gets attention because it sounds like a legal question. How long it sits gets ignored because it sounds like a technical detail. Retention is the variable that converts a single moment of exposure into a standing liability. Every additional month of storage is another month of opportunity for someone who was never part of your agreement.

The second skipped question is what the feature quietly pulls in behind it. Retrieval-based tools, the ones that answer questions using your own documents, work by reaching into your content.

“For retrieval to work, the system pulls content out of your documents and embeds it in the call to the AI provider,” Doug said. “The AI has to be aware of that content, so it’s exposed.”

Nobody uploaded anything. Nobody made a decision. The feature simply did what it was designed to do, and your internal documents became part of an outbound request.

Read What You Signed, Then Audit Yourself

If price signaled protection, enterprise tiers would solve this. They do not, and it’s worth being precise about what they actually deliver.

“Enterprise plans are almost always geared toward compliance support,” Steve said. “They give you the tools to be compliant with your organization’s policies.” Administrative control, user management, audit capability, and configuration options all show up at that tier. Guaranteed data isolation frequently doesn’t.

Vendor-level assumptions fail the same way. “Different products get run by different divisions and different groups of people making different decisions,” Doug said. “They can absolutely have different policies around how they use your data.”

One vendor, two products, two answers. Every tool is its own question, and the terms vary enough that nothing substitutes for reading them.

None of this requires a new initiative, just a review nobody scheduled. Steve’s guidance: treat AI features as you would any other vendor contract. Most compliance frameworks already require that. If you haven’t made that pass yet, you are overdue.

Doug added the half that companies consistently miss. “You need to analyze the provider, but you also need to analyze your own process to see what data you are sending,” he said.

That second audit is the one that produces surprises. Leaders can usually list their vendors. Almost nobody can list what flows to each of them, which means the risk assessment gets built on an incomplete map. Some of that data carries no meaningful risk at all. Some of it should never have left the building.

The Question Is No Longer Who You Pay

The instinct to treat a paid subscription as a settled question made sense in a world where software stored your data and left it alone. AI features broke that model without renegotiating anything.

What replaces it is unglamorous and entirely doable. Assume the toggle defaulted on. Assume the terms changed since you read them. Assume the chain runs further than the vendor in front of you and that retention outlasts your attention. Then check, tool by tool, contract by contract, and pay just as much attention to what you are sending as to who is receiving it.

You know exactly what you pay every month. The harder question is what you are handing over for free.

Whitney Powell

Written by: Whitney Powell

Whitney earned her degree in Marketing and Management from the University of Kentucky and discovered her passion for marketing and events. Her go-getter attitude, willingness to learn, and problem-solving abilities elevate the Slingshot team. Known as a daredevil, Whitney loves trying new things and embracing challenges, whether traveling to new places or taking on new projects at work.

Linkedin
Dougf Cartoon Headshot

Expert: Doug Compton

Born and raised in Louisville, Doug’s interest in technology started at 11 when he began writing computer games. What began as a hobby turned into his career. With broad interests that range anywhere from snorkeling, science, WWII history and real estate, Doug uses his “down time“ to create new technologies for mobile and web applications.

Linkedin
Steve Cartoon Headshot

Expert: Steve Anderson

Steve is one of our AWS certified solutions architects. Whether it’s coding, testing, deployment, support, infrastructure, or server set-up, he’s always thinking about the cloud as he builds. Steve is extremely adaptable, and can pick up the project and run with it. He’s flexible and able to fill in where needed. In his spare time, he enjoys family time, the outdoors and reading.

Linkedin

Frequently Asked Questions

No. Payment buys access to a product, not control over the information you push through it. AI data privacy depends on the data pathway behind the feature, which runs independently of the invoice, and paid tools can still use your inputs in aggregate.

The feature can change where your company's data goes without any new contract or legal review. AI toggles sometimes ship defaulted to on, and in many tools any user can enable them, not just an administrator. Terms of service also change over time, so what you agreed to at signup may not be what governs you today.

It is the wrong opening question for most companies. The better question is what you are handing over in the first place, and whether it belongs in the class of information you cannot afford to lose control of. Proprietary IP, PII, health information, and financial data all fall in that category, and a vendor who never trains on your data still stores it somewhere a breach can reach.

Often more parties than the vendor you pay. The inference provider hosting and running the model matters more than the company that built it, and routing services can spread requests across dozens of providers based on cost. Lower-cost models frequently run offshore, which undercuts any promise you made that customer data stays in the United States.

Not reliably. Enterprise tiers are built for compliance support, delivering administrative control, user management, audit capability, and configuration options. Guaranteed data isolation frequently is not included, and the same vendor can apply different data policies to different products.