The question that brings most people to this topic is a simple one. Is it safe to put a client file into ChatGPT, or a patient note into Copilot? The honest answer starts somewhere people rarely look: not with the brand, and not with the model, but with which plan the person clicked when they signed up. That single fact usually decides more than everything else combined, and most coverage of this subject gets it wrong.
Same logo, two different contracts
Every major AI vendor runs at least two sets of terms. There's a consumer tier, aimed at individuals paying by card, and there's a business or enterprise tier with a different agreement behind it. They look nearly identical on screen. They are not the same product in any way that matters to a business holding confidential information.
The clearest documented example is Anthropic's consumer terms change on 28 August 2025. Training on user chats moved from no to yes unless the user opted out. Retention moved from 30 days to as long as five years for anyone who stayed opted in. Existing users had until 8 October 2025 to make a choice.
Now the part that gets left out of the write-ups. That change applied to Claude Free, Pro and Max. Anthropic listed the exclusions explicitly: Claude for Work, Claude for Government, Claude for Education, and API use, including through third parties such as Amazon Bedrock and Google Cloud's Vertex AI. Same company, same model, and two entirely different data outcomes, separated by nothing more than which subscription somebody was on.
So when a staff member says "we use Claude" or "we use ChatGPT", you have not yet learned anything useful about where the material goes. The follow-up question is the one that matters: on which plan, paid by whom, with which settings.
A court order you were never part of
The second case is even more instructive, and it is regularly told badly. On 13 May 2025, in the New York Times litigation, Magistrate Judge Ona T. Wang ordered OpenAI to preserve and segregate all output log data that would otherwise be deleted on a going forward basis. In practice that overrode user deletion requests, including deletions people had made for their own privacy reasons.
Look at who it reached. The order covered ChatGPT Free, Plus, Pro and Team, along with API use that was not under a zero data retention agreement. ChatGPT Enterprise was excluded. API customers with zero data retention were not impacted. The order was lifted around 26 September 2025.
The lesson here has nothing to do with anyone breaking a promise. OpenAI's published commitments were what they were. The point is sharper and more durable than a villain story: a vendor's data commitments can be overridden by a court in a jurisdiction your business has no relationship with, and the contract tier you bought decided whether that applied to you. Which plan you are on decides what happens to your data. That sentence is worth carrying into every AI conversation you have this year.
Residency is not sovereignty
Here's the distinction that most vendor marketing blurs, and the one that will make you sound like the most informed person in the room. Residency is about storage location. Sovereignty is about which country's laws can compel access. They are different questions with different answers, and only one of them is usually on the sales page.
A provider can honestly tell you your data is stored in Australia while remaining a company incorporated in the United States and therefore subject to United States legal process. The reach follows the company, not the disk. Amazon's Bedrock service in the Sydney region, for instance, can pin Claude inference to Australian infrastructure, which is a real and useful control. Amazon Web Services is still a US company. Both facts are true at once, and a serious assessment has to hold both.
The Australia and United States CLOUD Act Agreement took effect on 31 January 2026. It formalises how the two governments make requests of each other's service providers. It does not put a wall around an Australian private business whose material sits with a provider in US jurisdiction. Read it as plumbing between governments, not as a shield for your client files.
None of this makes cloud AI unusable. Most work in most businesses is genuinely fine in a well configured cloud tool, and later lessons will say so plainly. What it does mean is that "our data stays in Australia" is an answer to a narrower question than the one you were probably asking.
The five questions worth asking about every tool
You can do most of this yourself, this week, with no budget. Take the list of AI tools anyone in the business touches, and for each one write down five things.
- Which tier is it on? Consumer, business or enterprise, or API. Include the shadow ones: personal accounts people use for work count, and they are usually the consumer tier.
- Who pays for it? A tool on someone's own credit card is almost never covered by your business terms.
- What's the training default? Not what you set once, what it defaults to, and whether that default has changed since you set it.
- How long is material retained, and what does deletion actually do?
- What happens under a legal hold? The May 2025 order is the worked example. Ask whether your tier would have been inside or outside it.
Half the value of that exercise arrives before you change a single setting, because it turns a vague worry into a list. The workbook for this course has the inventory laid out so you can fill it in as you go. One caveat before we move on, and it applies to the whole course: this is general information, not legal advice. What your obligations actually require depends on facts about your business, so take the specifics to your lawyer, your accountant or your professional body.
A few quick questions to lock it in. No marks recorded, just for you.
Answer all the questions to continue.
Save your progress
Pop your email in and we'll send you a link to pick up where you left off, on any device. No account needed.
Saved.
Check your inbox for a link to continue on any device.