All insights

AI vendor risk: what your new tools are doing with your data

AI tools arrive quietly. Someone adds a meeting note-taker, a front-desk chatbot, or an intake summarizer, and within a month it is part of how the business runs. The tool works. The question nobody asked is what happens to the data it sees.

Five questions to ask before you sign

  • Is our data used to train your models? If yes, can we opt out in writing?
  • Where is the data stored, and how long is it kept after we delete it?
  • Which subprocessors touch it, and can we get that list?
  • Will you sign a Business Associate Agreement? (If you handle health information, this is not optional.)
  • How do we export or permanently delete everything if we leave?

The recording problem

Meeting and call assistants create a written record of conversations that previously left no trace. That transcript is discoverable, breach-reportable, and often stored by a vendor you have never evaluated. Decide deliberately which meetings may be recorded, and turn it off everywhere else.

Keep a one-page tool inventory

List every AI or SaaS tool in use, who owns it, what data it touches, and whether an agreement is in place. Most small businesses find two or three tools nobody approved. Finding them is the work; fixing them is usually a short conversation.