Keeping your data where it belongs
Five direct questions that sort responsible AI vendors from the rest, and why closed commercial models do not learn from your business data.
When you put your business data through an AI system, that data goes somewhere to be processed. For a lot of owners this is the real hesitation about AI, and it should be. Client records, quotes, contracts, care notes: these are not things you want fed into a system that treats them as training material for someone else's product.
The good news is that this is a solved problem, and asking a few direct questions sorts the responsible vendors from the rest quickly.
Where is my data actually processed?
AI models run on servers, and those servers sit in specific countries. For many Australian businesses, particularly in care, insurance and professional services, where the data is processed matters for both regulation and client trust. Ask plainly: which country will my data be sent to, and can it be kept within Australia if I need that?
A vendor who knows their setup will answer this in one sentence. A vendor who gets vague or says they will check has just told you they never thought about it.
Will my data be used to train the model?
This is the question that matters most, and it has a clean answer. The consumer versions of popular AI tools may use what you type to improve their models. The commercial versions of those same models, the ones a business should be using, contractually do not. Your data goes in, an answer comes back, and nothing is retained to train anything.
Closed commercial models do not learn from your data. That is the whole point of paying for them.
Insist on this in writing. It is a standard commitment from the serious model providers, so any vendor building on them should be able to point to it without hesitation.
Who inside the vendor can see it?
Beyond the model itself, there are people: the team that builds and maintains your system. Ask who has access to your live data, whether access is logged, and what happens to that access when the project is finished. Reasonable answers involve access being limited to the people who need it and removed when they do not.
This is basic hygiene, but it is worth confirming, because it is exactly the sort of thing that gets skipped in a rush.
What happens to my data when we stop?
If you end the arrangement, your data should come back to you and copies held by the vendor should be deleted. Ask how, and ask for confirmation when it is done. A vendor who plans for the end of the relationship as carefully as the start is one who intends to keep your trust.
None of these questions require you to understand the technology. They require the vendor to. If straight questions get straight answers, you are dealing with people who take your data as seriously as you do.
Want these five questions answered about your setup?
Ask us them directly. We will answer them about our own work, in writing.
The AI your team is already using
Shadow AI is not a discipline problem, it is people finding tools that help. The risk is that nobody knows what has been sent where. How to find out, and what to do about it without banning anything.
What Australian privacy law asks of you
Whether the Privacy Act applies to your business, the four principles an AI project actually touches, and the disclosure rule for automated decisions arriving in December 2026.