On the night of 17 September I sat up until three in the morning for a webinar out of Cornwall. Two hours of a bloke called Elliott Prince showing how he runs his whole business through an AI assistant: his invoices, his emails, his client reports, all of it sitting in a folder on his computer that the AI can read. Most of it was for people who sell things. Then a woman on the other side of the world put her hand up and asked the only question that mattered to me: you've just handed this thing your whole business. How do you know it's safe?
His answer was good, and it wasn't technical, so I'm going to give it to you the way I'd give it to a mate at the Dalby saleyards. Then I'll tell you what I'd do about it. Usual note: general information, not legal advice. I read the source documents and I checked the settings myself on 18 September, and again on 11 October before this went up, but these things move, so check yours.
First, fence the paddock. He doesn't let the AI wander over his whole computer. He points it at one folder, and that's all it can see. If you use one of these tools on your files, do the same. One folder. Not "Documents". Not the whole drive. The thing you never put in the paddock can't get out of the paddock.
Second, you decide what goes in. His line was simple: "I'm not putting my passport in there. That's just a personal choice." Mine's the same, and I'd add the list: passport, driver's licence, Medicare card, tax file number, bank logins, anyone else's medical details. If you wouldn't hand it to a stranger at the counter, don't paste it into a chat box.
Third, treat it like the cloud you already use. He said if he'd be comfortable storing something in Google Drive, he's comfortable with it in an AI tool, and no more than that. That's a fair yardstick. Most of us out here already trust a cloud with something. Use the same judgment, not a different one.
Fourth, and this is the one to do today: find the training switch. Every one of these tools has a setting that decides whether your conversations get used to teach the next version of the model. In ChatGPT it's under Settings, Data Controls, and it's called "Improve the model for everyone". On a personal account that switch is on unless you turn it off. In Claude it's under Settings, Privacy, called "Model Improvement". I'm not going to tell you which way yours is set, because it depends on when you signed up and what plan you're on. Go and look. It takes a minute. One more thing on Claude, because it changed in September: if you tell it your chats can be used, it also keeps them for five years instead of thirty days. That's the trade. If you're on a paid business account, the big providers say business data isn't used for training by default, and you can read that in their own words. But "by default" is not "always", so look anyway.
Fifth, the bit that made me sit up. Elliott put it plainly: "A lot of people are cowboying it at the moment, or telling their staff not to use AI. Their staff are using AI anyway."
That's the line I'd like every small operator out here to hear. The bloke in your office is already pasting customer emails into ChatGPT to make them sound better. The bookkeeper is already asking it to tidy the spreadsheet with everyone's names and phone numbers in it. Banning it doesn't stop it. It just stops you knowing about it.
And here's the local twist. Our own privacy regulator, the OAIC, said in October 2024 that as a matter of best practice businesses should not enter personal information, and particularly sensitive information, into publicly available AI tools. That's their words. It doesn't matter whether the Privacy Act binds you, and if you've read my earlier posts you'll know most operators out here are exempt. This isn't about the law. It's about the caravan park's booking list, the ag contractor's client sheet, the footy club's membership roll, ending up inside a system nobody in town can see into or get anything back out of.
So here's what I would do, and why. Not what you should do. What I'd do.
If it's your own household: - Find the training switch in every AI tool you use, tonight, and set it the way you want it. Then you've made a choice instead of having one made for you. - Keep your own paperwork out of it. Ask it how to write a complaint letter. Don't paste the letter with your Medicare number in it. - If it's on your computer and it reads files, give it one folder. Fence the paddock.
If you run a small operation and other people's details are in your care: - Write down the rule. One page. What staff can put into an AI tool, what they can't, and which tool. "Nothing with a customer's name, number, address or bank details" covers most of it. Then tell them, instead of pretending they're not using it. - If the business is going to use AI properly, use a business account, read the provider's own line on training, and say so in your privacy policy. The OAIC asks for that too. - Keep a human in the loop on anything that goes back to a customer. The tool drafts. You send. - Ask the question you'd ask of any supplier: where does my information go, and can I get it back?
He stayed up to answer that woman's question and he answered it honestly. I stayed up to hear it. Now it's yours. If any of this makes you want to go and check a setting, that's the right instinct, and the silliest question is still the one you don't ask.