“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
AI and data privacy is the protection of personal information that AI systems collect, store, infer, and train on, including chats, photos, and voice recordings. Our Orlando investigators handle the cases where those details land in the wrong hands, from cloned voices to fake profiles built from stolen photos. We cover what AI tools keep, what Florida law protects, and what to do when your data is misused.
AI affects data privacy in three ways: what it collects, what it infers about you, and what it exposes when the AI system itself is breached.
Collection is the familiar part. Chatbots keep what you type, many photo apps sort pictures by the faces in them, and smart speakers send voice commands to cloud servers for processing. Every one of those inputs can sit on a company server long after you have forgotten it.
Inference is the part most people miss. AI systems can draw conclusions about you, such as your likely income or a health condition, from data that looked harmless on its own. You never have to share a diagnosis for a model to guess at one.
Exposure is the third risk. When a company’s AI tool is breached, everything fed into it is in play, and in IBM’s 2026 Cost of a Data Breach research, more than 20% of organizations reported a breach targeting AI models or applications. Security teams feel the same pressure, since AI now shapes both attack and defense inside most business networks.
A useful way to think about a consumer chatbot: typing personal details into one is closer to mailing a postcard than sealing a letter. Plenty of hands can touch a postcard on its way, and you never learn who read it.
AI causes data privacy issues by collecting more personal information than people realize, keeping it on company servers, and drawing sensitive conclusions from it. Problems grow when that data is used to train models without clear consent, shared with vendors, or exposed in a breach of the AI system itself.
AI keeps your data private only as far as the tool’s settings, your account type, and the company’s policies allow. ChatGPT shows how much depends on those choices, because OpenAI trains on conversations from personal accounts unless you opt out.
| What people assume | What is true |
|---|---|
| Turning off AI training deletes my chats | The training setting controls whether chats are used to improve models. Deleting saved conversations is a separate step |
| Personal and work AI accounts handle data the same way | OpenAI does not train on ChatGPT Business, ChatGPT Enterprise, or API data by default. Personal plans are used for training unless you opt out |
| Florida law covers every company that uses my data | Core duties apply only to for-profit companies with more than $1 billion in global revenue that meet one of three business tests |
| AI privacy risk starts and ends with chatbots | More than 20% of organizations in IBM's 2026 study had a breach targeting AI models or applications |
Each row turns on a choice, either yours or the company’s, and a default you never changed still counts as a choice.
Yes, on personal plans. OpenAI uses conversations from individual ChatGPT accounts to train its models unless you opt out by turning off “Improve the model for everyone” under Settings, then Data Controls. By default, OpenAI does not train on business products such as ChatGPT Business, ChatGPT Enterprise, or its API.
Start with the settings of each AI tool you use and look for a training or data-sharing control. In ChatGPT, that control is the “Improve the model for everyone” toggle, and Temporary Chat keeps a conversation out of training. For work, use a business account your employer approves.
The biggest AI privacy concerns right now are personal chats becoming training data, inference, impersonation built from scraped media, facial recognition surveillance, and breaches of AI systems.
Personal chats becoming training data. Pasting a medical note, a contract, or a screenshot of a bank statement into a chatbot takes two seconds. Anything typed into a consumer chatbot should be treated as something a stranger could one day read.
Inference and profiling. A model that knows your purchases, your location history, and the hours you are online can build a profile far more detailed than anything you filled out on a form.
Impersonation built from scraped photos and audio. Public videos, podcast clips, and profile photos give criminals the raw material for cloned voices and fake accounts. The warning sign is a familiar voice or face attached to an unusual request, especially one involving money or secrecy. Our breakdown of how attackers turn scraped audio into cloned voices explains why a recording alone proves nothing.
Facial recognition and surveillance. In December 2023, the FTC barred Rite Aid from using facial recognition for surveillance for five years after its system falsely flagged customers, particularly women and people of color, as shoplifters. Surveillance also happens closer to home. Networked cameras and smart devices can be repurposed to record conversations, which is why we include them when checking a home or office for hidden recording devices.
Breaches of AI systems. One in four malicious breaches in IBM’s 2026 study was AI-enabled, and those breaches cost $6 million on average, about $1 million above the $4.99 million global average. The most common weak points around AI tools were compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations (27%).
If your data is already being misused, save the original evidence, then report the accounts and any fraud to the right places.
When the harm is financial, the next job is tracing. Our team handles tracing who opened accounts in your name and turns the findings over to police once the person is identified. When the evidence may end up in court, preserving the original files and metadata needs to happen early, since volatile evidence does not last.
Partly. You can change a tool’s data settings to limit future training and delete the conversations you saved. Personal details on people-search sites and in breach dumps are a separate problem. A Digital Risk Profile finds where that information sits, and many listings can be removed through takedown requests or legal options.
Find out what is already out there about you
A Digital Risk Profile maps exposed accounts, leaked credentials, and misused photos across the surface web, deep web, and dark web, then ranks what to handle first.
See what a Digital Risk Profile covers
Confidential and handled by a licensed Florida investigator.
Florida’s main privacy law, the Florida Digital Bill of Rights, gives residents rights over their personal data, but its core duties reach only very large companies.
A business counts as a controller under the law only if it makes more than $1 billion in global gross annual revenues and meets one of three tests: earning at least half its revenue from online ads, running a cloud-connected smart speaker with a voice assistant, or operating an app store with at least 250,000 apps. The largest platforms fall inside that test. Your dentist, your gym, and most Florida employers do not.
One section reaches further. Under section 501.715, any for-profit business that operates in Florida and collects consumer data needs your prior consent to sell sensitive data, and a business that sells it must post the notice “NOTICE: This website may sell your sensitive personal data.” Sensitive data includes biometric data used to identify a person and precise geolocation, and both sit at the center of face matching, voice matching, and location tracking.
Impersonation falls under separate statutes, covered in our guide to Florida’s rules on AI-generated impersonation.
The information in this section is general. For advice on a specific situation, talk to a Florida attorney.
Businesses protect customer data by deciding which AI tools employees may use and which data may go into them, then backing that decision with access controls and encryption.
Start with account type. A consumer chatbot and a business-tier account from the same company can follow different training rules, as the OpenAI example earlier in this guide shows.
Consider an office manager who pastes a client spreadsheet into a free chatbot to fix the formatting. The task takes a minute, and a list of client names and phone numbers now sits outside every control the company set up.
Encryption is the next gap. Only 37% of organizations in IBM’s 2026 study encrypted sensitive data both at rest and in transit.
For most small firms, the fastest fix is a security assessment and a written usage policy that staff can follow. Leaks also happen outside software, and auditing how leadership conversations and insider access are protected closes gaps a chatbot policy never touches.
Shadow AI is the use of AI tools at work without approval or oversight from IT or security teams. Common examples include free chatbots, browser extensions, and AI note-takers connected to work accounts. The risk is that company and customer data leaves through a channel no one monitors or logs.
Bring in a private investigator when you need to know who is behind the misuse of your data, or when you need evidence documented for an attorney or a court. IT support can lock down an account. Finding the person who used it is investigative work.
Situations where an investigator helps:
Southern Recon Agency is a Florida licensed private investigation agency, License A1400197, based in Orlando and serving Tampa, Sarasota, and Osceola County. Our team includes Certified Digital Forensics Examiners and Certified Ethical Hackers, and founder Matt Aubin sits on the Executive Board of the Florida Association of Licensed Investigators as Treasurer.
AI and data privacy covers what AI systems collect, infer, and train on, and what happens to that information in a breach. On personal ChatGPT plans, training stays on until you switch it off, and deleting saved chats is a separate step. Florida’s main privacy law reaches only the largest platforms, although its sensitive-data consent rule applies to far more businesses. If your photos, voice, or accounts are already being misused, save the originals, report to the platform, IdentityTheft.gov, or IC3, and get the evidence examined while it is fresh.
Get the evidence reviewed while it is still fresh
If your photos, voice, or accounts are being misused, we trace the source, preserve the evidence, and tell you plainly what your options are.
Request a confidential privacy consultation
Florida licensed agency A1400197. Call 844-307-7771.
Treat anything you type into a personal ChatGPT account as information the company stores and may use to train its models, unless you have switched that setting off. Leave out Social Security numbers, bank account details, medical records, passwords, and other people’s private information. For work data, use an account your employer has approved.
AI tools can speed up the work of connecting scattered public information, such as a property listing, a tagged photo, and a gym check-in, into a home address. The defense is reducing what is out there: tighten social media location settings, request removal from people-search sites, and check which of your details are already exposed.
Often, yes, at least on training. OpenAI does not train on ChatGPT Business, ChatGPT Enterprise, or API data by default, while personal plans are used unless the user opts out. Account type is one control among several. Companies still need a written usage policy, access controls, and encryption for sensitive records.
Yes. Any for-profit business that operates in Florida and collects consumer data needs prior consent to sell sensitive data, which includes biometric data used to identify a person and precise geolocation. A business that sells sensitive data must also post the notice “NOTICE: This website may sell your sensitive personal data.”
Often, yes. Investigators trace fake accounts through linked usernames, reused images, domains, and other connections, then document the findings for a platform report, an attorney, or police. A Digital Risk Profile also shows where else your photos and personal details appear online, including forums and dark web marketplaces.
Everything in this article is general information and is not legal advice. For help with a specific situation, contact a licensed investigator or a Florida attorney.
Matt Aubin, CDFE, is the founder of Southern Recon Agency, a Florida-licensed private investigation firm (License A1400197) focused on AI threat investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner and serves as Treasurer on the Executive Board of Directors of the Florida Association of Licensed Investigators. The agency works with clients in Orlando, Tampa, Sarasota, and Osceola County.