What the Provider Does With Your Input
Four questions that determine the actual risk of any AI service, and where to find the answers.
Risk · Analysis
The risk of a given tool is almost entirely determined by what the provider does with what you send. Four questions settle it.
A practical review based on “What the Provider Does With Your Input” includes the time required for assessment, contracting, rollout and later reassessment. Teams can use this operations reference to make that operational effort visible across owners and deadlines, while keeping the legal, security and model-risk decision in the documented approval process.
For an independent benchmark, compare the local approach with NIST AI Resource Center; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
One: is it retained, and for how long
Most services retain exchanges for some period, for abuse monitoring and support.
Consumer tiers typically retain longer than enterprise, sometimes indefinitely unless the user deletes.
Find the number. It is usually stated and rarely read.
Two: is it used for training
The question that dominates discussion and is answerable directly.
Consumer tiers frequently use input for model improvement by default, with an opt-out that users do not find.
Enterprise agreements almost always exclude it contractually.
This single difference is the main argument for providing an approved option.
Three: who can see it
Human review for abuse detection and quality is standard and is rarely prominent in the terms.
Which means somebody at the provider may read what was sent.
For most internal use that is acceptable. For confidential material it is the thing to check before anything else.
Four: where is it processed
Jurisdiction matters for regulated data and for several data protection regimes.
Providers increasingly offer regional processing, usually on enterprise tiers only.
Ask, and get the answer in the contract rather than in a sales email.
Where to find the answers
Terms of service and the privacy notice, which take twenty minutes to read for a given service.
The enterprise agreement, which differs materially and is the document that matters.
And direct questions to the supplier, whose answers should be in writing.
Nobody in your organisation has read these for the tools in use. Somebody should.
The settings question
Several services offer a toggle controlling training use.
Which means the same service can be acceptable or not depending on a setting the user controls.
That is not a basis for policy — a control that depends on every individual configuring it correctly is not a control.
Where the toggle exists, it is a stopgap while you arrange a proper agreement.
What changes
Terms change, sometimes materially, and the change is announced in an email nobody reads.
Set a reminder to re-check the terms of anything on your approved list, twice yearly.
And treat a material change as a reassessment trigger, which the review note covers.
What to check
For your most-used AI tool: retention period, training use, human review, processing location?
Has anybody read the terms, or only the marketing page?
Do you rely on a user-controlled setting for any of this?
And when did you last check for terms changes?
The point
Four questions settle the risk of any service: is it retained, is it used for training, who can see it, and where is it processed..
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.