Technology Intelligence
Cyber Security

The Free AI Account That Cost a Client Relationship

10 minutes read4 August 2026
The Free AI Account That Cost a Client Relationship

Turning off model training in a consumer AI tool does not remove the confidentiality problem. Disclosure to an outside service, data retention and third-party access can each breach an NDA or client contract regardless of the training setting. Businesses should keep confidential material out of public tools by default and use placeholders, redaction and generalised scenarios instead.

It rarely starts with recklessness. It starts with a deadline, a helpful tool and a switch labelled something like "Improve the model for everyone" that the person has already turned off. The account is free, it is behind their own login, and it has never let anyone down. So the document goes in.

The uncomfortable truth is that confidentiality obligations do not read your settings screen. A duty of confidence attaches to the information, not to the toggle. Turning off training may change what a model retains for its own improvement, but it does not change the fact that the information has left the business and reached an outside service. For anything held under a non-disclosure agreement, a client contract or a professional duty, that distinction is the whole ballgame.

"Training is off" answers a narrow technical question. It does not answer the questions a client, a contract or a regulator would actually ask.

The Quick Answer

Turning off model training in a public AI tool does not make it safe for confidential information. The confidentiality risk has three parts, and training data is only one of them:

  • Disclosure — sending the information to an outside service can itself breach an NDA or contract, whatever the service later does with it
  • Retention — most tools keep conversations for a period, and some settings keep chat history even when training is off
  • Access — staff, contractors and systems at the provider may be able to see content for support, abuse monitoring or legal reasons

For everyday work, keep confidential material out of public tools and use placeholders, redaction and generalised scenarios instead. Reserve genuinely sensitive work for an approved environment with a contract, agreed retention and access controls behind it.

Treat a free consumer AI account as a public service, not a private business vault. It does not carry enterprise protections just because it sits behind your login.

Last checked: 4 August 2026. AI providers change their data-handling terms, retention periods and settings frequently, and the position for a specific tool should be confirmed in that provider's current documentation before it is relied upon. This article is general information, not legal advice.

A fictional scenario

The following scenario is fictional. It is written to illustrate how an ordinary, well-intentioned decision can go wrong, and any resemblance to a specific business is coincidental.

A twelve-person consultancy is bidding for its largest contract yet. The prospective client has sent over a detailed brief and a data pack, both covered by a mutual non-disclosure agreement signed weeks earlier. The bid is due Friday. On Wednesday evening, a capable and conscientious consultant is drafting the executive summary and wants a second pair of eyes on the structure and tone.

There is no colleague free, so she opens a free AI account she has used for months. She has already turned off the training setting, so she reasons the conversation is private. She pastes in the client's brief, several figures from the data pack, the draft response and a note about the two competitors she believes are also bidding. Within minutes she has a tighter summary. The bid goes in on time. It is a good bid.

Three weeks later the client's procurement lead asks, during a routine security questionnaire, whether any third-party AI tools were used in preparing the response, and if so, under what terms. The honest answer is yes, a free consumer account, with no business agreement in place. The client's own policy prohibits its confidential material being processed by unapproved services. The consultancy has not lost the bid on price or quality. It has created a confidentiality problem that now has to be disclosed, explained and — at best — forgiven.

In the scenario, nothing was hacked, nothing leaked publicly, and the training setting was off the whole time. The damage was done at the moment the information was disclosed to a service the client had not approved.

Why "training is off" is not the whole answer

The training toggle addresses one specific concern: whether your inputs are used to improve the provider's models. That is a real concern, and turning it off is sensible. But it leaves three larger issues untouched.

1. Disclosure is the event that matters

A duty of confidence — whether it comes from an NDA, a client contract or a professional obligation — typically restricts who information may be shared with. An AI provider is a third party like any other supplier. Sharing the information with that third party can itself be the breach, regardless of what the provider then does with it. A client who discovers their bid, dispute or data pack was pasted into a free chatbot rarely asks whether the training toggle was off; they ask why their information went to an outside service they never agreed to.

The Information Commissioner's Office and the National Cyber Security Centre have both pointed to the same underlying point in their AI guidance: information entered into an online tool is disclosed to whoever operates that tool, and the sensible default is to assume that anything you type could be seen or retained beyond the immediate conversation.

2. Retention keeps the information around

Even with training disabled, most consumer tools retain conversations for a period so that features work and abuse can be investigated. Some providers keep chat history when training is switched off, and separately retain deleted conversations for a window before permanent removal. Legal obligations can extend that further: providers have been required by courts to preserve output logs even where their own policy would have deleted them. The point for a business is simple — turning off training does not mean the conversation vanishes.

3. Access is broader than the person prompting

Consumer AI services commonly reserve the right for authorised staff or systems to review content for support, safety, security and legal reasons. That is not sinister — it is how large services are run — but it means the audience for a confidential document is potentially wider than the one person who pasted it in. Under an NDA that permits disclosure only to named parties or to those with a strict need to know, that wider access can be exactly the problem.

ConcernWhat the training toggle doesWhat it does not do
Model trainingCan stop your inputs being used to improve the provider's modelsDoes not remove the information from the provider's systems
Disclosure to a third partyNothing — disclosure has already happened when you pasteDoes not undo the fact the information left the business
RetentionMay reduce, but does not eliminate, how long content is keptDoes not guarantee immediate or permanent deletion
Access by othersNothing — provider review rights usually still applyDoes not limit who at the provider may see content

Named cases are worth noting only as illustrations, not as a claim about any one provider. In 2023, Samsung restricted employee use of generative AI tools after internal reports that staff had entered sensitive material, including source code, into ChatGPT. The lesson that spread from that episode was not that any single tool was uniquely unsafe — it was that capable professionals, under time pressure, will paste confidential work into whatever tool is fastest unless the rules and the tooling say otherwise.

The workflow that lets the work still get done

None of this means AI is off-limits. It means the confidential parts stay out of the public tool while the useful work still happens. In practice, three techniques cover most day-to-day tasks.

  1. 1Placeholders — replace the sensitive specifics with tokens such as "[Client]", "[Competitor A]", "[£value]" and "[Location]", ask the AI to help with structure, tone or logic, then reinsert the real details afterwards. The model helps with the shape of the work without ever seeing the confidential content.
  2. 2Redaction — before uploading any document, strip names, addresses, account numbers, figures and hidden metadata, not just the obvious fields. Remember that tracked changes, comments and document properties can carry information you thought you had removed.
  3. 3Generalisation — rewrite the situation in general terms. Instead of pasting the client brief, ask about "a consultancy responding to a competitive tender in the logistics sector". You get the same drafting help without disclosing whose tender it is.

Two supporting habits make these techniques reliable rather than occasional. First, need-to-know discipline: the person prompting should only be handling information they are entitled to see in the first place, which keeps the blast radius small. Second, a quick check before hitting send — if you would not be comfortable reading the prompt aloud to the client it concerns, it needs a placeholder or a rewrite.

Removing a name is not the same as making information anonymous. "The senior partner at our Leeds office who is handling the dispute" identifies one person to anyone who knows the business. Genuine anonymisation removes every combination of role, date, location and distinctive event that could point back to a person or a deal. Where that cannot be done cleanly, generalise the whole scenario instead.

Credentials are the one category where no wording is ever safe. Passwords, API keys and recovery codes entered anywhere outside your password manager or the system they belong to should be treated as exposed, and rotated.

When enterprise deployments genuinely change the answer

This article is about free, consumer-grade accounts. Business and enterprise AI services can be a different proposition, because the difference is contractual, not just technical. Providers commonly offer business tiers under an agreement that does not use your content to train models by default, sets out retention terms, provides administrative controls and offers security and compliance commitments.

That can make an approved enterprise deployment an appropriate home for some confidential work that a free account never could be. But two cautions apply. A business contract is not a blank cheque — client NDAs may still require you to name your sub-processors or seek permission before any third-party processing, so the client's terms have to be checked as well as the provider's. And the protections only exist if the deployment is genuinely the business tier under that contract; logging into a free consumer account with a work email address does not conjure enterprise terms into being.

How to tell whether you are actually on a protected deployment
  • There is a signed business or enterprise agreement, not just accepted consumer terms
  • The account was provisioned and is administered by the business, not set up personally by a member of staff
  • The provider's business-tier terms state that content is not used for model training by default
  • Retention, deletion and data-location terms are documented and acceptable to the relevant client contracts
  • The tool appears on the business's approved AI tool register with a named owner

If any of these is missing, treat the tool as a public service for confidentiality purposes until the position is confirmed.

Deciding which tools qualify is exactly what supplier due diligence is for. Businesses should consider assessing an AI provider's data-handling terms, retention, sub-processors and security posture before approving it for confidential work, and recording the outcome so that the answer to "were any third-party AI tools used, and under what terms?" is ready before a client ever asks.

What the consultancy should have had in place

Returning to the fictional scenario, three inexpensive controls would have changed the outcome. A clear rule that client material under NDA never goes into a consumer tool. A placeholder-and-redaction habit that let the consultant get the drafting help she wanted without disclosing the brief. And a short, approved list of tools staff may use for business work, so the fast option and the safe option are the same option.

None of that requires a large budget or a legal department. It requires the business to decide, in advance and in plain language, where confidential information may and may not go — and to make the safe route the easy one. This is general information rather than legal advice, and businesses should take their own advice on the confidentiality obligations that apply to their specific contracts.

Where to go next

For the full list of information categories to keep out of public tools, and the practical alternatives for each, read the confidential-information guide in the AI Governance hub.

Protecting Confidential Information When Using AI

For ready-to-use prompts designed to keep confidential details out of AI tools while still getting useful work done, see the Safe Business Prompting collection in the Prompt Library.

Safe Business Prompting collection — IT Club Prompt Library

And for the wider set of guides, checklists and templates on using AI safely in a small business, start at the AI Governance hub.

AI Governance for Small Business — Knowledge Centre

If confidential information has already gone into a public tool, capture what happened, what was exposed and who was told using the AI Incident Record, so the response is calm and documented rather than improvised.

AI Incident Record (PDF)

Sources and further reading

NCSC — ChatGPT and large language models: what's the risk?

NCSC — AI and cyber security: what you need to know

ICO — Introduction to anonymisation

OpenAI Help Centre — Data Controls FAQ

OpenAI — How your data is used to improve model performance

OpenAI — Enterprise privacy

Bloomberg — Samsung Bans Generative AI Use by Staff After ChatGPT Leak (May 2023)

TechCrunch — Samsung bans use of generative AI tools like ChatGPT after April internal data leak

Plain-English Takeaway

A free AI account is a public service, not a private business vault, and switching off model training does not undo the fact that confidential information has been disclosed to a third party. Businesses should treat information held under NDAs, client contracts or professional duties as off-limits to public tools by default, and get the work done with placeholders, redaction and generalised scenarios. Genuinely sensitive work belongs in an approved environment with a contract behind it. This is general information, not legal advice.

Related Articles

Cyber Security

What the Air Canada Chatbot Case Means for Your Website

In 2024, a small-claims tribunal in British Columbia decided that Air Canada was responsible for wrong information its website chatbot gave a grieving customer — and rejected the airline's argument that the chatbot was somehow a separate entity accountable for its own words. The case is not binding in the United Kingdom, and it turned on Canadian law, so it should not be treated as a UK precedent. But the principle behind it travels well: a customer is generally entitled to rely on what your systems tell them, whether the words come from a static web page, a member of staff or an automated assistant. For a UK small business adding a chatbot to its website, the useful question is not "did the chatbot say it?" but "would we stand behind this if a person had said it?". This article explains the case, sets it beside UK consumer-protection framing, and turns it into practical constraints for customer-facing bots.

Read article
Cyber Security

Is Your Business Ready for the Vulnerability Patch Wave?

AI-assisted security tools can search large codebases and identify possible software vulnerabilities much faster than traditional manual research alone. This may create a Vulnerability Patch Wave — a sustained increase in security advisories, emergency fixes and updates that organisations must assess, test and deploy faster than before. This article explains what the wave is, why discovery is accelerating, why fixing remains slower and what businesses should do.

Read article
Cyber Security

Is Temporary Chat Safe for Sensitive Business Discussions?

ChatGPT Temporary Chat does not appear in normal chat history, does not use or create saved memories and is not used to improve OpenAI's models. However, OpenAI may retain a copy for up to 30 days for safety purposes, Custom Instructions may still apply and the information is still transmitted to and processed by an external service. This article explains what Temporary Chat actually protects and why confidential business information still requires care.

Read article

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor