◈ The Promptory Daily · Issue #035

The Fastest-Growing AI Risk in Small Business Isn't a Cyberattack — It's Employees Pasting Data Into Free Tools

What happens to the data. Not in theory — right now. Every time someone on a team pastes a client email into ChatGPT, uploads a contract for review, or uses a free-tier AI tool to process anything that came out of the business, something is happening to that data. Most business owners have no idea what.

◈ The Number Behind This Issue

The fastest-growing AI risk in small business right now isn't a cyberattack. It's employees pasting sensitive data into free AI tools without realizing the data may be stored, logged, or used for model training.

According to OpenAI's own data, 27% of all ChatGPT consumer messages in 2025 were work-related — most sent from personal, free accounts with no enterprise data protections in place. Add the EU AI Act reaching full enforcement in August 2026, accelerating US state privacy legislation, and a regulatory environment moving faster than most businesses have noticed, and data governance becomes a decision that can't be pushed to next quarter.

The good news: getting ahead of this doesn't require a legal team or an enterprise IT department. It requires the right stack, and the right conversation about what a team should and shouldn't be doing with AI today.

What's Actually Changing, and Why It Matters Now

This isn't fear-mongering — it's a timeline, and it's moved closer than most small businesses realize.

◈ August 2026 — EU AI Act, Full Enforcement Begins

The world's first comprehensive AI regulation becomes fully applicable this August. High-risk AI systems — including those used in HR, credit, insurance, and healthcare — face strict data governance requirements. If a business serves EU customers or partners, this affects it directly. If it doesn't today, it may soon.

◈ Now — US State Privacy Laws, Accelerating Fast

New York, Virginia, Kentucky, Connecticut, and a growing list of states have enacted or are advancing AI-related legislation covering employment screening, consumer protection, and data practices. The patchwork is getting complex. Businesses that haven't looked at this since 2024 are operating on outdated assumptions.

◈ Ongoing — Shadow AI, Already Happening

Shadow AI — employees using unauthorized AI tools with company data — isn't a future risk. It's happening in most businesses right now. A 2026 survey found 41% of employees use AI tools their company hasn't approved. Each one is a potential data exposure with no policy, no audit trail, and no oversight.

Ask Jordan

Reader

We're a 14-person financial planning firm. I've been hearing a lot about AI data privacy and I'm honestly not sure what our actual exposure is right now. My team uses ChatGPT and a few other AI tools but nobody has guidelines around it. Where do I even start?

Jordan

Good instinct to ask this now. In financial services with no AI usage policy, the exposure is real, not theoretical. First question: do you know which specific tools your team is using, and whether any of them are free consumer tiers rather than enterprise versions? That one answer tells me most of what I need to know about where the risk actually sits.

The AI Governance Stack

Five tools built for the business that wants to use AI aggressively and responsibly. Together they create a governance layer that most small businesses don't have and most regulators are now expecting.

Airia — AI Governance & Security

Free tier / from $50/mo.

The governance layer that makes everything else in an AI stack compliant and controlled. It sits between a team and the AI models they're using, enforces policies in real time — which data can be sent where, which models different team members can access, what gets logged and audited — and generates the compliance documentation regulators are starting to ask for. It also prevents shadow AI by giving everyone an approved, governed access point to sanctioned AI tools.

What it specifically solves: shadow AI visibility, runtime data-exposure policies, exportable audit trails, built-in frameworks for EU AI Act / NIST AI RMF / ISO 42001 / HIPAA / SOC 2, and AI cost visibility by team and project.

Pricing: free forever (1 user, 100 monthly executions, 10 agents) · Individual $50/mo · Team $250/mo (unlimited users, 10K executions) · Enterprise custom, 14-day free trial on all plans. For most small businesses, the Team plan covers the governance layer completely — a fraction of what a single compliance incident would cost.

Apollo.io — CRM With Enterprise Data Terms Baked In

Free / from $49/mo.

When lead generation and client outreach run through an AI platform, where contact data lives and how it's handled matters. Apollo's enterprise tier includes GDPR-compliant data processing and clear data residency policies — no ambiguity about how contact records are used.

Reclaim AI — Calendar Data That Stays In Your Environment

Free / from $10/mo.

Reclaim processes calendar and scheduling data — meeting titles, attendees, time blocks — all in scope for data governance. It's SOC 2 Type II certified, processes data in accordance with GDPR, and doesn't use calendar data to train models. In regulated industries, even scheduling data carries sensitivity.

Tidio — Client-Facing AI With Configurable Data Controls

Free / from $29/mo.

Any AI tool that touches client communication collects client data, full stop. Tidio allows configuring data retention policies, opting clients in or out of data collection, and maintaining a clear record of what's captured during intake and support. GDPR and CCPA compliant.

Lindy AI — Agents With SOC 2, GDPR, and HIPAA Compliance

Free / from $19.99/mo.

Lindy is SOC 2 Type II certified, GDPR compliant, and HIPAA eligible — which means healthcare, legal, and financial services businesses can build AI agents without creating a compliance gap. When AI is taking autonomous actions on a firm's behalf, the compliance certification of the platform matters as much as the capability.

5 Things Worth Doing This Weekend

These aren't compliance tasks. They're five conversations and one policy document that most businesses could finish by Sunday afternoon — and probably should have done already.

◈ 1 — Find out which AI tools your team is actually using

Ask the team to list every AI tool they've used for work in the last 30 days — including browser extensions, free tiers, and anything they signed up for on their own. The list will surprise you.

◈ 2 — Check whether any of those tools are free consumer tiers

Free ChatGPT, free Gemini, free consumer AI tools — their default terms allow input data to be used for model training unless explicitly opted out, or a paid business tier is used. If a team is pasting client data into free tools, that's an exposure worth knowing about.

◈ 3 — Write one paragraph defining what data should never go into an AI tool

Client names, financial records, health information, passwords, proprietary contracts, PII. One paragraph, sent to the team — that's a policy starter. Refine it later, publish it now. (See the full one-page template when ready to formalize it.)

◈ 4 — Identify the highest-risk AI touchpoint and add a human review step

Which AI-assisted workflow, if it produced a wrong output, would cause the most damage? Client communication? Contract review? Financial reporting? Add one human review checkpoint to that workflow before anything goes external.

◈ 5 — Start a free governance-tool account and run one workflow through it

A free tier is usually enough to understand what a governed AI environment looks like inside a business — enough to decide whether a paid team tier is worth it.

◈ The One Thing

The businesses that win with AI won't be the fastest adopters. They'll be the most disciplined ones. Strategy before tools, process before automation, governance before scale — get the foundation right and everything else compounds from there.

Not sure where your own data governance gaps are? A free Jordan session can walk through your specific situation.

J

Have questions about your AI stack?

Jordan is The Promptory's free AI advisor. Describe your workflow and your challenges — Jordan will reason through your situation and tell you exactly which tools fit.

◈ Talk to Jordan — Free →
← All Issues Browse 152 Vault Tools →