Most business owners we speak to have already used ChatGPT, Copilot, Gemini or Claude for something at work. A quick summary, a draft email, a formula for a spreadsheet. It feels low-stakes. The problem is that what you type into a public AI chatbot does not simply disappear after you get your answer.
Where your prompts actually go
When you use a consumer-facing AI chatbot, your input is sent to servers owned by the platform provider. Depending on the service and the settings you have chosen, that data may be stored, reviewed by human teams for quality purposes, or used to improve future versions of the model. The default settings on most of these tools are not configured with your business confidentiality in mind. They are configured for product improvement.
This matters in concrete terms. If an employee pastes a client contract into ChatGPT to get a summary, that contract text has left your business. If someone asks Claude to help draft a retrenchment letter and includes real staff names and salary figures, that information is now sitting on a third-party server under terms your business almost certainly has not read carefully.
The risks are not purely theoretical. They include:
- Sensitive client information being stored by a platform you do not control
- Staff inadvertently sharing commercially valuable data such as pricing models or supplier terms
- Confidentiality obligations to clients or partners being quietly breached
- Accuracy problems, where the AI produces confident but incorrect output that gets used without checking
Practical steps you can take right now
The good news is that each of the major platforms offers settings that reduce, though do not eliminate, how your data is used. Here is the general picture across most of them.
- Turn off chat history and training where the option exists. Most platforms have a toggle in account settings that stops your conversations from being used to train future models. Find it and switch it on.
- Use the paid or enterprise tier if your business handles sensitive data. Business and enterprise plans typically come with stronger data handling commitments and, in some cases, contractual protections. Free tiers offer the least protection.
- Create a simple internal rule about what must never go into a public chatbot. Client personal information, financial data, legal documents, staff records and proprietary business data should be off limits. Write it down. Tell your team.
- Treat AI output as a draft, not a final answer. Accuracy is a separate concern from privacy, but both matter. A human must check anything that carries real consequences before it is acted on or sent.
- Consider whether a private deployment makes more sense for your needs. For businesses that regularly work with sensitive information, running an AI tool within a controlled environment, rather than using a public platform, is worth examining seriously.
What this means for a South African business
Data privacy, accuracy and accountability are not abstract concerns. If your business holds information about clients or staff and that information ends up on a platform you have not vetted, the consequences range from reputational damage to strained client relationships to genuine legal exposure. The specifics will depend on your industry and the nature of the data, but the principle is straightforward: public AI tools are not a safe place for sensitive business information under their default settings.
At Pr:sm, this is one of the first things we work through with clients. Before automating anything or deploying any AI tool, we help businesses understand where their data goes, what controls exist and what a sensible internal policy looks like. Getting that foundation right costs very little. Getting it wrong can cost a great deal more.
If you want to use AI productively and responsibly, the starting point is knowing what you are handing over and to whom. Visit us at getprism.site to see how we approach this with businesses across South Africa.