Hi Adopter,
Your sales manager uploads a customer spreadsheet to AI. The names are removed, so everyone feels better.
The file still shows margins, renewal dates, discount limits, and negotiated terms. A competitor wouldn’t need the names to learn quite a lot about your business.
That’s why sensitive data is a concern for any company. It includes customer information, intellectual property, trade secrets, and the small operational details you spent years figuring out.
Palantir CEO Alex Karp has been arguing that customers want control over their models, data, and “alpha.” For a business owner, think of alpha as the knowledge that gives you an edge. He has software to sell, but the ownership question is useful. Who gets access to what makes your company valuable?
I help my direct clients work through these decisions. If you want to use AI and need help handling your company’s data safely,
take a look at my one-to-one coaching.
What happens after you press send
“Does it train on our data?” is a good question. It needs company.
Training. Can your inputs or outputs be used to improve a future model? Don’t assume every AI service does this. For example, Anthropic’s commercial products exclude training by default, with exceptions including feedback and explicit opt-ins. Check the exact product and settings you use.
Storage. What gets retained, where, and for how long? A no-training promise can still allow stored conversations or files. Retention rules can differ by feature and agreement.
Access. Which people and systems can see the information? A confidential forecast shared with the wrong colleague is still a problem, even when no model learns from it.
Actions. Where can connected tools send the data? An assistant with email access introduces a different risk from one that only drafts text.
These are separate controls. A reassuring answer to one doesn’t settle the others.

What this looks like inside real companies
Mercedes-Benz describes its employee Direct Chat tool alongside explicit usage guidance, including avoiding personal or internal data in employee inputs and reviewing generated content. The page also describes knowledge agents connected to internal systems. Even a company-provided tool needs rules for how information reaches it.
In its Debrief launch announcement, Morgan Stanley describes using client consent before AI generates meeting notes and action items. The tool drafts a follow-up email for an advisor to review, edit, and choose to send. That gives AI a useful job with a human decision before the message goes out.
Both are company descriptions of their own practices. They show the kinds of boundaries to look for when choosing your own setup.
If you’d like help doing that, we can map one workflow together in coaching. We’ll look at the data it needs, who can access it, and where human approval belongs.
Give AI only what the job requires
Suppose you want AI to draft an overdue-invoice reminder. It might need the amount due, how overdue it is, and your approved payment options. It probably doesn’t need every customer’s history, your bank details, or the sales team’s private notes.
Your business software can keep the real customer record, prepare the necessary facts, and give AI that smaller version. The model drafts the message. Your software connects it back to the right customer and checks permissions before sending. Start with a person reviewing those drafts.

Have software remove unnecessary fields before data reaches the model. Writing “ignore the confidential columns” in a prompt has already sent those columns.
Removing names alone won’t protect a pricing formula or make every record anonymous. When sensitive information is necessary for the task, use a service approved for that information, with suitable terms, retention settings, and access controls. Some work may belong on systems you operate yourself. Those still need security and maintenance.
You can start this week with one recurring task. Name its owner, list the information it actually needs, and trace where that information goes. Begin with a copy containing fictional details. Check what appears in saved conversations, logs, and connected tools. Review the output before allowing real actions.
Then decide what additional access, if any, the result justifies.
AI becomes useful when it understands enough about your business to help. Deciding what “enough” means is part of the work.
Adapt and Create, Kamil



