The security question: what happens to the document you paste in
Where your documents actually go when you use an AI tool, and the five questions that get you a straight answer.
When you paste a document into an AI tool, it leaves your building. That plain fact sits underneath most AI security questions, and it isn’t a reason to avoid the tools. It is a reason to know where the document goes, who can open it, and how long it survives once you have finished with it.
Nearly all AI security questions come down to four things: storage, access, training and location. The answers vary by product and by contract, so the useful skill is knowing what to ask. Start with what physically happens to the document, because every other answer depends on it.
What happens to a document you paste in?
Your document travels over the internet to a data centre, where the provider’s software reads it and sends a response back. Nothing about that is unusual. Your email, your accounts package and your file storage all work the same way.
Two things matter after that. First, whether the provider keeps a copy once it has answered, and for how long. Second, who inside that company can open the copy, and under what conditions.
Most business products keep your conversation so you can go back to it, which means a copy sits on their systems until you delete it or their retention period runs out. A tool that kept nothing at all would also lose your history, so a flat claim of storing nothing is rarely the full picture.
Who else can read it?
That copy raises the worry people voice most often, which is human access. Reputable providers restrict staff access, log every use of it, and limit it to named support and abuse cases.
Some also run a review process where a small sample of content goes to human reviewers for safety checks. Business agreements commonly switch that off, so ask which arrangement applies to your account rather than assuming the safer one.
The honest position is that access controls are a promise, backed by a contract and an audit, rather than a law of physics. That is true of your accountant and your bank too, which is why the question is about who you trust and on what terms.
Sub-processors, in plain terms
Provider staff aren’t the only people in the chain, because most providers don’t own the building. They rent their servers from large cloud companies, and those cloud companies are sub-processors: firms that handle your data on behalf of the company you actually pay.
So a short supplier list can hide a longer chain, and you are entitled to see it. UK GDPR requires a data processing agreement wherever another company handles personal data on your behalf. That duty comes from the law rather than from a customer asking nicely, so a supplier who treats the request as unusual has told you something useful.
The ICO’s guidance on AI and data protection sets out how the wider rules apply to these systems. The ICO aims it at compliance and technical staff, so read it as the reference behind your questions rather than as an introduction.
What training on your data actually means
Sub-processing covers where your material sits. Training covers what a provider may do with it, and the two get muddled constantly.
Training means using your content to improve the underlying model, so patterns from it can shape answers that other customers receive later. It doesn’t mean your invoice appears on somebody else’s screen. It does mean your content has fed the model’s behaviour, and you can’t pull that back out cleanly.
Keep those two ideas apart. Deleting a stored copy and unpicking what a trained model has absorbed are separate questions with separate answers. Most providers will do the first on request, and nobody can do the second neatly.
A personal subscription and a business contract are different products
Training is also where two versions of the same tool part company. A personal subscription is a consumer product bought on a card, and its default settings often allow training on what you type.
A business or enterprise agreement is a different product with different terms: training on your content switched off by default, a data processing agreement, and administrative control over who holds an account. Same brand, same screen, different contract.
So a team using personal accounts for company documents has made a purchasing decision that nobody signed off. Writing an AI use policy is how you catch that before it becomes a habit.
Residency and retention
That contract will use two more words, and both are simpler than they sound. Residency is where your data physically sits, whether that is the UK, the EU, the US or somewhere else. Retention is how long a copy lasts after you finish with it.
Ask for both as facts rather than as reassurance. A vague answer here is easy to spot, because both have real answers. Residency should name a country or a region, and retention should give you a number of days.
Neither carries the same weight for every job. Drafting a marketing email carries a different risk from summarising an occupational health report, and the material you feed in decides which one you are in. That is also why preparing documents matters: what you put in front of the tool is a choice you make first.
The five AI security questions to ask a supplier
Storage, access, training and location turn into five questions. Put them in an email before you buy anything, and read the answers as much for tone as for content. A supplier who deals with businesses will answer each in a paragraph.
- Do you keep a copy of what we send you, and for how long?
- Who can read it inside your company, and does any of it reach human reviewers?
- Do you train your models on our content, and will you switch that off in writing?
- Which sub-processors handle our data, and where do their servers sit?
- What happens to our data if we cancel, and how quickly?
If the work involves health records, children’s data or legal casework, that is the point to involve your IT partner, and probably your solicitor as well.
What a straight answer sounds like
Judge the replies on how concrete they are. A straight answer names a number, a place or a document. 30 days. London and Dublin. Here is the sub-processor list, and here is the agreement we sign.
An evasive answer reaches for adjectives instead. Enterprise-grade security. Bank-level encryption. Your data never leaves our platform, which describes a boundary without naming who stands inside it.
Neither of those is a reason to walk away on its own, because a good product can have a poor sales team. Ask again in writing, and treat a second vague answer as the answer. Suppliers worth buying from find AI security questions boring, because they answer them every week.
