Man working on laptop at night surrounded by floating digital data charts and graphs in futuristic interface.

How Salt Lake City Businesses Can Prevent AI Data Leaks Before They Happen

July 21, 2026

The AI Data Leak Risk Most Salt Lake City Businesses Aren't Taking Seriously

AI data leaks affecting Salt Lake City businesses are not a future risk — they are happening right now, inside companies that assume they are too small to matter. The exposure point is not a hacker. It is an employee using a free AI tool to get work done faster.

Your accountant just pasted a client's financial records into ChatGPT to summarize a report — and your company's confidential data is now part of a third-party AI platform's input history, potentially retained, reviewed, or exposed without your knowledge or consent.

Salt Lake City's professional services economy runs on sensitive data. CPA firms handle client financials. Healthcare practices carry HIPAA-covered patient records. Construction and engineering firms generate project bids and proprietary specs. Every one of those data types is being fed into consumer AI tools by well-meaning employees who have no idea what happens next.

Most AI platforms retain user inputs by default unless enterprise-grade settings are configured — and free or personal-tier accounts almost never have those settings enabled. The risk is live, and it scales with every employee who opens a browser tab.

What Actually Happens to Data You Enter Into AI Tools

Consumer-tier AI tools — including ChatGPT Free and Plus, and Google Gemini standard — can use conversation inputs to improve their models by default. That means the salary figures, client names, or contract terms an employee pastes into a free account may be retained and reviewed by the platform, outside your network and outside your control.

Consumer-tier AI tools: Free or personal-subscription AI products that operate under general consumer terms of service, which typically permit data retention and model training on user inputs unless the user opts out or upgrades to an enterprise plan.

Consumer Accounts vs. Enterprise Agreements

Tool Tier Data Retention Default Data Processing Agreement Admin Controls
ChatGPT Free / Plus Retained; may train models No No
Google Gemini Standard Retained; reviewed by human reviewers possible No No
ChatGPT Enterprise Not used for training Yes Yes
Microsoft 365 Copilot (business plan) Governed by Microsoft data boundary Yes Yes

The framing most business owners miss is this: the question is not whether the AI got hacked. The question is whether your data was ever supposed to leave your environment in the first place. An HR manager who pastes an employee termination letter — including salary and disciplinary history — into a free AI tool to polish the wording has already lost control of that data, even if nothing visibly goes wrong.

The Five Types of Sensitive Data Employees Are Accidentally Leaking Right Now

Five data categories account for the majority of AI-related exposure risk at Salt Lake City SMBs. Most employees cannot reliably identify all five without training — which is why policy and technical controls matter more than awareness alone.

  • Client PII and financial data: Tax returns, account numbers, and financial statements regularly handled by CPAs and financial firms. See IT support for CPAs and financial firms for how 911 IT addresses this sector specifically.
  • Internal contracts, pricing, and bid documents: Competitive bids, subcontractor pricing, and project specs from construction and engineering firms represent serious proprietary exposure if entered into a public AI platform.
  • Employee records: Salaries, performance reviews, disciplinary notes, and termination letters. These are among the most commonly pasted documents because employees want help with tone and wording.
  • Regulated health information: Any data covered under HIPAA — patient names, diagnoses, treatment details — that a healthcare employee feeds into a consumer AI tool creates a potential HIPAA compliance violation regardless of intent.
  • Vendor credentials and system documentation: IT staff and operations managers sometimes paste network diagrams, login procedures, or vendor account details into AI tools for troubleshooting help — exposing infrastructure access details.

This is also an AI shadow IT problem — meaning employees are using tools the business never approved and may not know exist. Most business owners, when they audit, find more AI tool usage than they expected.

How to Build an AI Usage Policy That Employees Will Actually Follow

An effective AI usage policy for SMBs has three functional components: an approved tool list, a prohibited data list, and a signed acknowledgment. Without all three, the policy is documentation, not governance.

The Three Components of a Functional AI Usage Policy

  1. Approved and unapproved tool list: Name the tools employees may use — such as ChatGPT Enterprise or Microsoft 365 Copilot under a business data processing agreement — and explicitly prohibit consumer alternatives like ChatGPT Free, Google Gemini standard, and personal accounts on any AI platform.
  2. Prohibited data categories: Define which data types may never be entered into any AI tool regardless of platform — client PII, employee records, regulated health data, bid documents, and vendor credentials. Employees need a concrete list, not a vague directive to "use judgment."
  3. Acknowledgment process: Employees sign or digitally confirm the policy at onboarding and annually. This eliminates "I didn't know" as a defense and creates an audit trail.

A policy document sitting in a shared drive is not an AI governance strategy. Real enforcement requires cybersecurity services and IT-side technical controls — because even employees who read the policy will eventually make a mistake under deadline pressure.

This three-component policy is the gap most Salt Lake City SMBs have right now. The DIY default — letting employees figure out what is and is not appropriate — assumes they know what AI platforms do with their inputs. They almost never do.

The Technical Guardrails That Back Up Your Policy

Policy without technical enforcement is a no-speeding sign with no speed cameras. Three IT-side controls close the gap between what employees are supposed to do and what actually happens under deadline pressure.

Web Content Filtering

Web content filtering — implemented via DNS filtering tools — blocks access to unapproved AI platforms at the network level. Employees cannot access a prohibited tool from a company device on the company network, regardless of intent. DNS filtering works by intercepting domain resolution requests before a connection is established.

Data Loss Prevention (DLP)

DLP tools — such as Microsoft Purview DLP — detect and block the pasting of sensitive data strings (Social Security numbers, account numbers, protected health information patterns) into browser-based applications in real time. DLP is a component of a layered security stack, not a standalone product.

Endpoint Monitoring and Browser Extension Controls

Endpoint monitoring creates visibility into which AI tools are being accessed from company devices, including on home networks. Browser extension controls prevent employees from installing AI plugins that bypass web filtering. Together, these controls give a managed IT services in Salt Lake City provider like 911 IT the visibility to detect AI shadow IT before it becomes a breach.

What Salt Lake City Businesses Should Do This Week

Three actions in the next week will tell you where your AI exposure actually stands — and none of them require a major project or budget approval.

  1. Audit current AI tool usage: Ask your team — or check browser history and installed extensions — which AI tools employees are actively using. Most business owners are surprised by the answer.
  2. Identify your regulated and sensitive data categories: Walk through the five categories above and note which ones your business handles regularly. This takes fifteen minutes and anchors every subsequent decision.
  3. Assess your DLP and web filtering posture: Talk to your IT partner about whether DLP tools and web content filtering are currently configured to address AI platforms. If you are not sure, that is the answer.

This is a fifteen-minute internal conversation most businesses have never had. For Salt Lake City IT support tailored to this exact problem, 911 IT can walk through the assessment with you.

Frequently Asked Questions

Can ChatGPT store and share the data my employees enter into it?

On free and Plus plans, OpenAI's default settings allow conversation data to be used to improve its models, and human reviewers may access inputs. Opting out is possible but requires account-level settings most employees never configure. ChatGPT Enterprise operates under a separate data processing agreement with different retention terms.

Does using Microsoft Copilot mean my business data is protected from AI leaks?

Microsoft 365 Copilot on a qualifying business plan operates within Microsoft's data boundary and includes a data processing agreement — but protection depends on how it is configured and which data employees feed into it. A Microsoft 365 subscription alone does not automatically prevent AI data leaks.

What is an AI usage policy and does my small business actually need one?

An AI usage policy is a documented set of rules governing which AI tools employees may use, what data categories are prohibited, and how compliance is acknowledged. Any business handling client data, employee records, or regulated information needs one — not because of regulatory mandate, but because employees genuinely do not know what counts as sensitive without explicit guidance.

How do I find out which AI tools my employees are already using at work?

Start by reviewing browser extensions on company devices and checking DNS or firewall logs for traffic to known AI domains. An IT provider with endpoint monitoring in place can generate a report quickly. Asking employees directly also works — most will be forthcoming if the question is framed as an inventory rather than an investigation.

Not Sure If Your Business Has an AI Data Leak Problem? Let's Find Out Together.

In a free 30-minute call, 911 IT will review your current AI tool exposure, walk through your data categories, and tell you exactly what technical guardrails are missing — so you know your risk before it becomes a headline.

Schedule Your Free Discovery Call