“TRUST STARTS & ENDS WITH THE TRUTH”

AI and Data Privacy: What AI Tools Keep and How to Protect Yourself

AI and Data Privacy: What AI Tools Keep and How to Protect Yourself

POSTED September 17, 2026
BY Matt Aubin

Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.

AI and data privacy is the protection of personal information that AI systems collect, store, infer, and train on, including chats, photos, and voice recordings. Our Orlando investigators handle the cases where those details land in the wrong hands, from cloned voices to fake profiles built from stolen photos. We cover what AI tools keep, what Florida law protects, and what to do when your data is misused.

Key takeaways

  • One in four malicious breaches in IBM’s 2026 study was AI-enabled, costing $6 million on average.
  • Turning off ChatGPT’s training setting stops OpenAI from training on your chats, and deleting saved conversations is a separate step.
  • Florida’s core privacy duties apply only to companies with more than $1 billion in global revenue that also meet one of three business tests.
  • If AI is being used to impersonate you, save the original files and links first, then report the accounts.

How does AI affect data privacy?

AI affects data privacy in three ways: what it collects, what it infers about you, and what it exposes when the AI system itself is breached.

Collection is the familiar part. Chatbots keep what you type, many photo apps sort pictures by the faces in them, and smart speakers send voice commands to cloud servers for processing. Every one of those inputs can sit on a company server long after you have forgotten it.

Inference is the part most people miss. AI systems can draw conclusions about you, such as your likely income or a health condition, from data that looked harmless on its own. You never have to share a diagnosis for a model to guess at one.

Exposure is the third risk. When a company’s AI tool is breached, everything fed into it is in play, and in IBM’s 2026 Cost of a Data Breach research, more than 20% of organizations reported a breach targeting AI models or applications. Security teams feel the same pressure, since AI now shapes both attack and defense inside most business networks.

A useful way to think about a consumer chatbot: typing personal details into one is closer to mailing a postcard than sealing a letter. Plenty of hands can touch a postcard on its way, and you never learn who read it.

How does AI cause data privacy issues?

AI causes data privacy issues by collecting more personal information than people realize, keeping it on company servers, and drawing sensitive conclusions from it. Problems grow when that data is used to train models without clear consent, shared with vendors, or exposed in a breach of the AI system itself.

Does AI keep your data private?

AI keeps your data private only as far as the tool’s settings, your account type, and the company’s policies allow. ChatGPT shows how much depends on those choices, because OpenAI trains on conversations from personal accounts unless you opt out.

What people assumeWhat is true
Turning off AI training deletes my chatsThe training setting controls whether chats are used to improve models. Deleting saved conversations is a separate step
Personal and work AI accounts handle data the same wayOpenAI does not train on ChatGPT Business, ChatGPT Enterprise, or API data by default. Personal plans are used for training unless you opt out
Florida law covers every company that uses my dataCore duties apply only to for-profit companies with more than $1 billion in global revenue that meet one of three business tests
AI privacy risk starts and ends with chatbotsMore than 20% of organizations in IBM's 2026 study had a breach targeting AI models or applications

Each row turns on a choice, either yours or the company’s, and a default you never changed still counts as a choice.

Does ChatGPT use your data?

Yes, on personal plans. OpenAI uses conversations from individual ChatGPT accounts to train its models unless you opt out by turning off “Improve the model for everyone” under Settings, then Data Controls. By default, OpenAI does not train on business products such as ChatGPT Business, ChatGPT Enterprise, or its API.

How do I stop AI from training on my data?

Start with the settings of each AI tool you use and look for a training or data-sharing control. In ChatGPT, that control is the “Improve the model for everyone” toggle, and Temporary Chat keeps a conversation out of training. For work, use a business account your employer approves.

What are the biggest AI privacy concerns right now?

The biggest AI privacy concerns right now are personal chats becoming training data, inference, impersonation built from scraped media, facial recognition surveillance, and breaches of AI systems.

Personal chats becoming training data. Pasting a medical note, a contract, or a screenshot of a bank statement into a chatbot takes two seconds. Anything typed into a consumer chatbot should be treated as something a stranger could one day read.

Inference and profiling. A model that knows your purchases, your location history, and the hours you are online can build a profile far more detailed than anything you filled out on a form.

Impersonation built from scraped photos and audio. Public videos, podcast clips, and profile photos give criminals the raw material for cloned voices and fake accounts. The warning sign is a familiar voice or face attached to an unusual request, especially one involving money or secrecy. Our breakdown of how attackers turn scraped audio into cloned voices explains why a recording alone proves nothing.

Facial recognition and surveillance. In December 2023, the FTC barred Rite Aid from using facial recognition for surveillance for five years after its system falsely flagged customers, particularly women and people of color, as shoplifters. Surveillance also happens closer to home. Networked cameras and smart devices can be repurposed to record conversations, which is why we include them when checking a home or office for hidden recording devices.

Breaches of AI systems. One in four malicious breaches in IBM’s 2026 study was AI-enabled, and those breaches cost $6 million on average, about $1 million above the $4.99 million global average. The most common weak points around AI tools were compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations (27%).

What should you do if your data is already being misused?

If your data is already being misused, save the original evidence, then report the accounts and any fraud to the right places.

  1. Save the originals. Keep the files, links, usernames, and dates. Screenshots help, but original files carry metadata that screenshots lose.
  2. Report the fake account or content to the platform where it appears.
  3. Report identity theft at IdentityTheft.gov, the FTC’s reporting site, if someone opened accounts or applied for credit in your name.
  4. File a complaint at ic3.gov, the FBI’s Internet Crime Complaint Center, if money moved or someone is extorting you.
  5. Freeze your credit with Equifax, Experian, and TransUnion.
  6. Avoid contacting the person you suspect. A confrontation gives them time to delete accounts and files.

When the harm is financial, the next job is tracing. Our team handles tracing who opened accounts in your name and turns the findings over to police once the person is identified. When the evidence may end up in court, preserving the original files and metadata needs to happen early, since volatile evidence does not last.

Can you remove your data from AI?

Partly. You can change a tool’s data settings to limit future training and delete the conversations you saved. Personal details on people-search sites and in breach dumps are a separate problem. A Digital Risk Profile finds where that information sits, and many listings can be removed through takedown requests or legal options.

Find out what is already out there about you

A Digital Risk Profile maps exposed accounts, leaked credentials, and misused photos across the surface web, deep web, and dark web, then ranks what to handle first.

See what a Digital Risk Profile covers

Confidential and handled by a licensed Florida investigator.

What does Florida law say about AI and your personal data?

Florida’s main privacy law, the Florida Digital Bill of Rights, gives residents rights over their personal data, but its core duties reach only very large companies.

A business counts as a controller under the law only if it makes more than $1 billion in global gross annual revenues and meets one of three tests: earning at least half its revenue from online ads, running a cloud-connected smart speaker with a voice assistant, or operating an app store with at least 250,000 apps. The largest platforms fall inside that test. Your dentist, your gym, and most Florida employers do not.

One section reaches further. Under section 501.715, any for-profit business that operates in Florida and collects consumer data needs your prior consent to sell sensitive data, and a business that sells it must post the notice “NOTICE: This website may sell your sensitive personal data.” Sensitive data includes biometric data used to identify a person and precise geolocation, and both sit at the center of face matching, voice matching, and location tracking.

Impersonation falls under separate statutes, covered in our guide to Florida’s rules on AI-generated impersonation.

The information in this section is general. For advice on a specific situation, talk to a Florida attorney.

How can businesses protect customer data when employees use AI?

Businesses protect customer data by deciding which AI tools employees may use and which data may go into them, then backing that decision with access controls and encryption.

Start with account type. A consumer chatbot and a business-tier account from the same company can follow different training rules, as the OpenAI example earlier in this guide shows.

Consider an office manager who pastes a client spreadsheet into a free chatbot to fix the formatting. The task takes a minute, and a list of client names and phone numbers now sits outside every control the company set up.

Encryption is the next gap. Only 37% of organizations in IBM’s 2026 study encrypted sensitive data both at rest and in transit.

For most small firms, the fastest fix is a security assessment and a written usage policy that staff can follow. Leaks also happen outside software, and auditing how leadership conversations and insider access are protected closes gaps a chatbot policy never touches.

What is shadow AI?

Shadow AI is the use of AI tools at work without approval or oversight from IT or security teams. Common examples include free chatbots, browser extensions, and AI note-takers connected to work accounts. The risk is that company and customer data leaves through a channel no one monitors or logs.

When should you bring in a private investigator for an AI privacy problem?

Bring in a private investigator when you need to know who is behind the misuse of your data, or when you need evidence documented for an attorney or a court. IT support can lock down an account. Finding the person who used it is investigative work.

Situations where an investigator helps:

Southern Recon Agency is a Florida licensed private investigation agency, License A1400197, based in Orlando and serving Tampa, Sarasota, and Osceola County. Our team includes Certified Digital Forensics Examiners and Certified Ethical Hackers, and founder Matt Aubin sits on the Executive Board of the Florida Association of Licensed Investigators as Treasurer.

TL;DR

AI and data privacy covers what AI systems collect, infer, and train on, and what happens to that information in a breach. On personal ChatGPT plans, training stays on until you switch it off, and deleting saved chats is a separate step. Florida’s main privacy law reaches only the largest platforms, although its sensitive-data consent rule applies to far more businesses. If your photos, voice, or accounts are already being misused, save the originals, report to the platform, IdentityTheft.gov, or IC3, and get the evidence examined while it is fresh.

Get the evidence reviewed while it is still fresh

If your photos, voice, or accounts are being misused, we trace the source, preserve the evidence, and tell you plainly what your options are.

Request a confidential privacy consultation

Florida licensed agency A1400197. Call 844-307-7771.

Frequently asked questions

Is it safe to put personal information into ChatGPT?

Treat anything you type into a personal ChatGPT account as information the company stores and may use to train its models, unless you have switched that setting off. Leave out Social Security numbers, bank account details, medical records, passwords, and other people’s private information. For work data, use an account your employer has approved.

Can AI be used to find where I live?

AI tools can speed up the work of connecting scattered public information, such as a property listing, a tagged photo, and a gym check-in, into a home address. The defense is reducing what is out there: tighten social media location settings, request removal from people-search sites, and check which of your details are already exposed.

Do work AI accounts protect company data better than personal ones?

Often, yes, at least on training. OpenAI does not train on ChatGPT Business, ChatGPT Enterprise, or API data by default, while personal plans are used unless the user opts out. Account type is one control among several. Companies still need a written usage policy, access controls, and encryption for sensitive records.

Do Florida companies need my consent to sell my biometric data?

Yes. Any for-profit business that operates in Florida and collects consumer data needs prior consent to sell sensitive data, which includes biometric data used to identify a person and precise geolocation. A business that sells sensitive data must also post the notice “NOTICE: This website may sell your sensitive personal data.”

Can a private investigator find out who is using my photos?

Often, yes. Investigators trace fake accounts through linked usernames, reused images, domains, and other connections, then document the findings for a platform report, an attorney, or police. A Digital Risk Profile also shows where else your photos and personal details appear online, including forums and dark web marketplaces.

Everything in this article is general information and is not legal advice. For help with a specific situation, contact a licensed investigator or a Florida attorney.

About the author

Matt Aubin, CDFE, is the founder of Southern Recon Agency, a Florida-licensed private investigation firm (License A1400197) focused on AI threat investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner and serves as Treasurer on the Executive Board of Directors of the Florida Association of Licensed Investigators. The agency works with clients in Orlando, Tampa, Sarasota, and Osceola County.

WHAT CLIENTS SAY ABOUT US
Mark A., Tampa, FL | Attorney, 16 years

I have worked with Southern Recon on several investigations. He is an excellent investigator who always gets the job done no matter how complex or dangerous the situation. His fees are very reasonable and he usually puts in more hours than he gets paid for in order to make sure he does a professional job. I highly recommend Southern Recon Agency.

Tina G., Ontario, Canada

Matt provided me with superior service. He handled my investigation in a very professional manner and was always available for me 24/7. He helped solve my case and provided me with accurate evidence proving the suspicion of my husband’s infidelity. I highly recommend his services. Words cannot express the gratitude I have for his services!

Chris G., Tampa, Fl

I requested a background investigation on person that I was looking to conduct business with. I corresponded with the professionals at the Agency over email and the telephone. At no time, was I confused or concern about the process of this investigation. The process was thoroughly explained. Matt Aubin potentially saved me thousands of dollars by giving me an accurate understanding of who I was looking to do business with. Needless to say, I will not be conducting any business with this individual. I am extremely grateful for the work performed by Matt and the agency. It was worth every penny. The level of service provided exceeded my expectations.

Donnie C., Orlando, Fl

These folks are professional and will get results for you quickly. They are not the run of the mill grinding hours for billing people that often fill this profession. Thanks!