Category: blog
AI tools are being added to business workflows
Common examples
- Chatbots
- Copilots
- Meeting transcription
- Document analysis
- CRM automation
- Code assistants
- Customer service tools
- AI features inside email and cloud platforms
The privacy risks are connected to data handling
Before approving any AI tool, document the answers to the questions below
Questions
1. What data will enter the AI system
Identify every data type processed
- Prompts
- Uploaded files
- Customer records
- Employee information
- Email content
- Meeting recordings
- Source code
- CRM data
- Cloud storage files
- Metadata
- Usage logs
- AI outputs
- Embeddings and indexes
Classify the information
- Public
- Internal
- Confidential
- Personal
- Regulated
Do not assume that the prompt is the only stored data
Connected AI tools may retrieve files, process account information, record activity, and create additional data artifacts
A data flow should be documented before deployment

2. Is business data used for model training
Ask directly
- Is our data used to train models
- Is training enabled by default
- Are prompts and outputs used for model improvement
- Are uploaded files used for testing or human review
- Is data shared with another model provider
- Can training be disabled at the tenant or account level
- Is the restriction stated in the contract
The same vendor may apply different rules to
- Consumer accounts
- Business subscriptions
- Enterprise accounts
- API services
- Reseller platforms
- Embedded software features
A business plan should not be approved based on the vendor name alone
The specific service and account type must be reviewed
Training exclusions should be confirmed in vendor documentation and contract language
The FTC states that AI companies must honor privacy and confidentiality commitments
3. What is retained
Retention must be reviewed by data type
Ask how long the vendor retains
- Prompts
- Outputs
- Uploaded files
- Conversation history
- Recordings
- Transcripts
- Logs
- Support tickets
- Embeddings
- Search indexes
- Fine-tuning data
- Backup copies
- Security investigation records
Ask whether retention can be configured
Possible settings may include
- No content retention
- Short-term retention
- Seven days
- Thirty days
- Ninety days
- Custom retention
- Indefinite retention
Content retention and log retention may use separate settings
A tool may delete user-visible conversations while retaining security logs or backup copies
The policy should state
- Default retention period
- Configurable retention options
- Deletion process
- Backup deletion process
- Legal exceptions
- Verification method
- Responsible vendor contact
Terms such as zero retention require technical clarification
Ask what the term means for prompts, outputs, logs, backups, and support access
4. Can specific data be deleted
Deletion requests should be operational
Ask
- Can one user record be deleted
- Can one uploaded file be deleted
- Can a complete workspace be deleted
- How quickly is deletion completed
- Are replicas and backups included
- Are embeddings and indexes removed
- Are support copies removed
- Is deletion verified in writing
The contract should define deletion timelines
The process should be tested before sensitive data is connected
Deletion must also be considered during employee offboarding and customer privacy requests
5. Where is the data stored and processed
Document the vendor’s data locations
Ask
- Which countries process the data
- Which cloud providers host the service
- Is regional storage available
- Are cross-border transfers performed
- Which subprocessors receive data
- Can subprocessor changes be reviewed
- Are data residency restrictions supported
A vendor may use separate locations for
- Primary processing
- Disaster recovery
- Support operations
- Monitoring
- Backups
- Model hosting
Each location may have different legal and contractual requirements
A cloud migration assessment should include AI data flows when AI services are connected to cloud storage or business applications
6. Who can access the data
Access must be limited to business requirements
Ask whether the platform supports
- SSO
- MFA
- Role-based access
- Least privilege
- Admin approval
- IP restrictions
- Session controls
- Privileged access management
- User offboarding
- API key controls
Review access for both employees and AI agents
An AI agent may access more information than the user operating it if permissions are configured incorrectly
Confirm
- Which systems the agent can access
- Which folders and records are available
- Whether write access is enabled
- Whether actions require approval
- Whether access is logged
- Whether service accounts are used
Vendor personnel access should also be documented
Ask
- Who can view prompts or files
- When support access is permitted
- Whether approval is required
- How access is recorded
- How long access logs are retained
7. Can activity be audited
AI use should be traceable
Ask what audit logs include
- User identity
- Timestamp
- Prompt activity
- Files accessed
- Systems queried
- Outputs generated
- Actions performed
- Approvals
- Configuration changes
- Administrative access
- Export activity
Ask whether logs can be
- Searched
- Exported
- Sent to a SIEM
- Retained under company policy
- Reviewed during an incident
Monitoring should identify unusual activity
Examples
- Bulk document access
- Repeated requests for customer data
- New integrations
- Unexpected downloads
- Use outside approved departments
- Changes to retention settings
- API key activity from unknown locations
AI security should be included in the wider network security review

8. What happens when the contract ends
The offboarding process should be written before deployment
Ask what happens to
- Customer data
- Prompts
- Outputs
- Uploaded files
- Logs
- Backups
- Embeddings
- Indexes
- Fine-tuned models
- Credentials
- API keys
- Access tokens
- Integrations
Define
- Export format
- Export deadline
- Deletion deadline
- Backup expiration
- Credential revocation
- Access termination
- Written deletion confirmation
The business should retain usable copies of required records
Copies should be stored under company-controlled retention and backup policies
X-Tek’s backup and business continuity guidance covers recovery planning, restoration testing, and system redundancy
9. Does the AI use match privacy obligations
AI processing may change how personal information is handled
Review
- Customer privacy notices
- Employee privacy notices
- Data processing agreements
- Retention schedules
- Consent requirements
- Contract restrictions
- Industry requirements
- Data subject request procedures
Ask whether the business can locate and remove an individual’s information across
- Prompts
- Outputs
- Logs
- Connected applications
- Knowledge bases
- Backups
- Search indexes
The NIST AI Risk Management Framework provides a structure based on
- Govern
- Map
- Measure
- Manage
The NIST Generative AI Profile identifies data privacy as a generative AI risk category
SMBs can apply the framework through a smaller operating process
10. What data should never be entered
Create prohibited data categories
Examples may include
- Passwords
- API keys
- Payment card data
- Social Security numbers
- Health information
- Unredacted employee records
- Legal correspondence
- Customer credentials
- Trade secrets
- Unreleased financial information
- Full customer databases
Data minimization should be applied
Remove unnecessary
- Names
- Account numbers
- Email addresses
- Identifiers
- Contract terms
- Internal project names
- Unrelated file content
Use synthetic or anonymized data for testing where possible
A simple rule can be applied
If the information would not be sent to an unknown third party by email, it should not be entered into an unapproved AI tool
Managed AI Services
AI privacy requires ongoing administration
Not only initial vendor approval
X-Tek managed AI services can support the operational controls around AI adoption
Service activities may include
- AI tool inventory
- Shadow AI discovery
- Vendor risk review
- Data classification
- Retention policy review
- Account configuration
- SSO and MFA deployment
- Role and permission review
- SaaS AI feature review
- Endpoint and network monitoring
- Logging and alerting
- Employee policy support
- Incident response planning
- Backup and recovery review
- Periodic security assessments
AI tools should be reviewed as part of the existing IT environment
They should not operate outside identity management, endpoint protection, email security, network controls, backup, and incident response
The AI security mistake review from X-Tek covers shadow AI, personal accounts, embedded features, API keys, monitoring, and response planning

SMB Review Checklist
Before approving an AI tool
- Is the business purpose documented
- Is every data source identified
- Is personal data involved
- Is confidential data involved
- Is model training disabled or contractually restricted
- Are retention periods documented
- Can deletion be verified
- Are storage locations known
- Are subprocessors listed
- Is a DPA required
- Are SSO and MFA supported
- Are permissions limited
- Are agent actions logged
- Can logs be exported
- Are personal accounts prohibited
- Are embedded AI features reviewed
- Is human approval required for high-impact actions
- Are backups included in the recovery plan
- Is AI use included in incident response
- Is the vendor reviewed periodically
Any unanswered question identifies a control gap
The response should be documented before rollout
The tool should be classified as
- Approved
- Conditional
- Prohibited
AI adoption can continue within defined data, access, retention, and monitoring controls
Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075

