A client recently asked me a very sensible question.
“Where will our data be stored if we use AI for our marketing?”
Fair.
Except that the “data” in question was product information we were using to create social posts.
Which we were then going to publish.
On the internet.
For everyone to see.
We were, essentially, worrying about where the press release would sleep at night before releasing it into the wild wearing a branded polo shirt.
But her question stuck with me.
Because I keep hearing versions of it.
A board I worked with was worried about employees putting company information into ChatGPT.
My son’s firm has gone further. Staff aren’t allowed to use generative AI at all. Not even to make an ordinary email to the boss sound less like it was written during a hostage negotiation.
The explanation?
“Our data has to stay in Australia.”
And this is where things get interesting.
Because businesses are taking several genuinely important issues...
Privacy.
Confidentiality.
Cyber security.
Intellectual property.
Model training.
Data storage.
Data sovereignty.
...and collapsing them into one large, mildly hysterical security casserole.
Then putting it in front of the board with a little parsley on top and calling it:
“The ChatGPT Risk”
It isn’t one risk.
And until we separate the ingredients, we can’t manage any of them properly.
Five Anxieties in a Trench Coat
When somebody asks:
“Is ChatGPT safe?”
the only responsible answer is:
Safe for what?
Using AI to rewrite public website copy is not the same as uploading an employee grievance.
Generating ten LinkedIn headlines is not the same as uploading the board papers.
Summarising publicly available industry research is not the same as feeding it your customer database.
The technology might be identical.
The information isn’t.
And that is the distinction businesses keep missing.
There are several different questions hiding inside “AI privacy”.
Privacy
Are we dealing with information about an identifiable person?
Customers. Employees. Candidates. Patients. Suppliers.
If personal information is involved, privacy law may apply.
The Office of the Australian Information Commissioner is very clear that the Privacy Act applies when organisations covered by it use AI to handle personal information. It recommends due diligence, privacy by design, staff training and clear governance around AI use.
Confidentiality
Does this information need to remain confidential?
Think:
Client documents.
Internal strategy.
Pricing.
Board papers.
Legal advice.
Unpublished financials.
None of these necessarily creates a privacy issue.
But I still wouldn’t paste next year’s acquisition strategy into a random chatbot while sitting at Gate 34 waiting for a flight.
Intellectual property
Is this information part of what makes the business valuable?
Source code.
Product designs.
Methodologies.
Algorithms.
Processes.
Commercial know how.
Your secret sauce should perhaps remain more secret than sauce.
Security
Who can access the information?
How is it encrypted?
How long is it retained?
What happens if someone leaves?
What systems does the AI connect to?
Can administrators see what people are doing?
Can the information be deleted?
Now we’re asking useful questions.
Data residency
Where is the information physically stored?
Also important.
But notice something.
It is one question out of several.
Which brings us to my favourite AI privacy myth.
No, Australia Is Not a Giant Data Terrarium
There is not a universal Australian rule saying:
“All information belonging to an Australian business must remain inside Australia at all times or the Privacy Police will arrive.”
Australian privacy law specifically anticipates personal information being disclosed overseas.
Where APP 8 applies, organisations generally need to take reasonable steps to ensure an overseas recipient handles the personal information appropriately, and in some circumstances the Australian organisation remains accountable for what happens to it.
So:
“Our data must be stored in Australia.”
may be absolutely true for a particular business.
But the next question should be:
“What specifically requires that?”
Perhaps it is:
A law.
A regulator.
A government contract.
A client agreement.
An industry requirement.
A cyber insurance condition.
A company policy.
Or perhaps it is Doris from Risk, who said it in a meeting in 2022 and everyone has been too frightened to ask Doris where she got it from.
This distinction matters.
Because there is a world of difference between:
“We are legally prohibited from processing this information outside Australia.”
and:
“Someone once told us we probably shouldn’t.”
Governance begins with knowing which one you are dealing with.
Where Does the Data Live? It’s Complicated.
Here is another wrinkle.
Even “stored in Australia” isn’t one simple thing.
You need to distinguish between:
Storage: Where does the information sit when it isn’t being used?
Processing: Where does the AI actually do the work?
Access: Who can see it?
Retention: How long is it kept?
Training: Can the provider use it to improve its models?
Subprocessors: What other services touch it?
This is why asking only where the server lives can give you a wonderfully reassuring answer while completely missing the risk.
For example, OpenAI currently offers eligible Enterprise, Edu and API customers Australian data residency for certain customer content stored at rest. Its current in region inference options, however, are in the United States and Europe.
That doesn't mean the product is unsafe.
It means:
Storage and processing are not the same question.
Tiny detail.
Rather important.
“But Doesn’t ChatGPT Train on Everything We Put Into It?”
This is another favourite.
The answer is:
It depends on which product and how it is configured.
For OpenAI’s business products including ChatGPT Business, Enterprise and the API, OpenAI says business inputs and outputs are not used for model training by default.
Personal ChatGPT workspaces operate differently. Users can control whether new conversations are used to improve the models through their Data Controls settings.
And this is exactly why businesses need approved environments rather than everyone quietly setting up their own account and hoping for the best.
The question isn't:
“Does ChatGPT train on our data?”
It is:
“Under our particular account, contract, configuration and use case, what happens to our information?”
Much less exciting. Much more useful.
The Innocent Little Email That Ate Compliance
Let’s take the simplest possible example.
Two employees want AI to improve an email.
Employee One types:
Please make this sound friendlier: “Could you send me the report by Friday? I need it for Monday’s meeting.”
The AI learns almost nothing about the business.
Employee Two types:
Please rewrite this email to my boss explaining why Project Phoenix is six months late, naming the three employees currently under investigation, including the client’s threatened legal claim and explaining the $2.4 million cost overrun.
Same activity.
“Using AI to improve an email.”
Wildly different risk. This is why I dislike blanket AI rules.
“Nobody may use AI.”
Too crude.
“Everyone may use AI.”
Also too crude.
Both avoid the harder job. Teaching people judgement.
The Traffic Light That Beats the 47 Page Policy
Most founder led businesses do not need an AI governance manual so substantial that it requires its own sherpa.
They need something a human being can remember at 4.17pm on a Thursday.
I’d start here.
🟢 GREEN
Generally appropriate in an approved AI tool.
Public website content.
Published research.
Marketing content intended for publication.
Generic brainstorming.
Non confidential email wording.
Templates.
Synthetic examples.
Public job advertisements.
If you accidentally fed this information to the office pot plant, nobody would call Legal.
Carry on.
🟠 AMBER
Stop and think.
Internal strategy.
Pricing and margins.
Financial summaries.
Supplier information.
Draft contracts.
Unpublished campaigns.
Product roadmaps.
Internal procedures.
Proprietary methodologies.
De identified customer insights.
This doesn't automatically mean “no AI”.
It means:
Use an approved business environment and understand the controls.
🔴 RED
Do not casually feed this into an AI system.
Identifiable customer information.
Employee records.
Health information.
Passwords.
API keys.
Legal advice.
Board papers.
Raw CRM exports.
M&A documents.
Sensitive source code.
Performance management information.
Regulated or classified datasets.
Could organisations eventually use AI with some of these things?
Absolutely.
But that requires appropriate architecture, contracts, security, access controls and governance.
It requires slightly more effort than typing:
“Please keep this confidential.”
into the prompt.
The Australian Cyber Security Centre recommends that small businesses explicitly understand what information can be shared with an AI system, what the provider collects, where the information is stored, who owns it and whether it will be used for model training.
In other words: know what you’re putting in the machine.
Revolutionary stuff.
You Do Not Need Everyone to Become a Privacy Lawyer
This is where companies tend to overcorrect.
A legitimate risk appears.
Someone calls a meeting.
The meeting produces a committee.
The committee produces a policy.
The policy produces a 63 page PDF.
Nobody reads the PDF.
Employees continue using AI on their phones.
Congratulations.
We have achieved governance theatre.
The better approach is to give people three questions.
1. What am I putting into the AI?
Public? Internal? Confidential? Personal? Sensitive?
2. Am I using an approved tool?
Not “an AI tool”.
Our approved AI tool.
Correct account. Correct settings. Correct access.
3. Would I be comfortable if someone outside the business saw this?
Not a perfect legal test. A very useful human one.
And when the answer is uncertain:
stop and ask.
That is a policy people might actually follow.
Prompt Engineering Can Help. It Cannot Perform Miracles.
Good prompt design reduces unnecessary disclosure.
Instead of uploading an entire customer record, remove the identifiers.
Instead of uploading six employee reviews, ask AI to build the review framework first.
Instead of pasting a confidential contract, describe the general commercial issue.
Instead of giving AI the whole spreadsheet, give it the information actually required for the task.
This is simply good data hygiene.
But prompt engineering cannot rescue a bad governance model.
A brilliant prompt cannot fix:
A consumer account being used for sensitive work.
Poor access controls.
A contractual breach.
An inappropriate integration.
A badly configured CRM connection.
A provider you have never assessed.
Or Trevor uploading the entire payroll file because he wanted the AI to “find some interesting trends”.
Trevor needs boundaries.
This Is Not Really an AI Problem
And that, I think, is the bigger point.
The companies handling AI well aren't necessarily the ones with the cleverest prompts.
They are the ones that are building organisational judgement.
They know:
What work should AI do?
What information may it use?
What tools are approved?
Where does human judgement remain essential?
What requires escalation?
Who owns the risk?
Because this is the difference between AI use and AI capacity.
AI use is buying everyone ChatGPT.
AI capacity is building the systems, judgement and operating rules that allow those people to use it well.
A company that allows everything hasn't built AI capacity.
A company that bans everything hasn't built it either.
They have merely chosen opposite sides of the same mildly panicked fence.
So, Where Is Your Data Stored?
Ask it. It is a sensible question. Just don't stop there.
Ask:
What information are we giving the AI?
Why does it need it?
Is it personal, confidential, commercially sensitive or regulated?
Is this the right AI environment for that information?
Will our information be retained or used for training?
Where is it stored and processed?
Who can access it?
What other systems does it connect to?
Can we remove it?
And perhaps most importantly:
“Does our team know the difference?”
Because your biggest AI privacy risk may not be an evil robot sitting in California plotting to steal your spreadsheet.
It may simply be a well meaning employee with a deadline, a personal chatbot account and absolutely no idea what the rules are.
And that is fixable.
AI use is not AI capacity.
Build the judgement.
Build the rules.
Then use the extraordinary technology available to us without either losing our minds or handing it the keys to the filing cabinet.
AI is the instrument. Your expertise is the advantage.
Multiply Your Best Thinking
Angela Sedran | The Business Race Engineer
This article is general business information, not legal, privacy or cyber security advice. Organisations with regulated or particularly sensitive information should obtain advice specific to their circumstances.