What AI can retrieve
There’s another category that’s becoming increasingly important: information the AI retrieves from other systems.
AI tools can connect to other applications through APIs, MCP servers, plugins, connectors, and other integrations. Those connections allow an AI system to go and get information from those applications itself.
For example, you might ask an AI assistant: “Find the latest tickets related to this issue.”
The AI could use an integration to query a ticketing system, retrieve matching records, and then use those records to formulate its answer.
The same applies to information returned from any API or MCP connection. If an AI system retrieves a database record, email, document, ticket, or other piece of information, that information has now become part of the context the AI is processing.
This is why an approved internal system and an approved AI system aren’t necessarily the same thing.
Your ticketing system might be approved to handle sensitive information. Your database might be approved. Your email system might be approved. That does not automatically mean every AI service that can connect to those systems is authorized to receive the information they contain.
The interface may be local, but the processing is happening somewhere else. And if AI can retrieve the information from another source, that information may leave that system as well.
What about “We don’t train on your data”?
This is another area where the wording can be misleading.
An AI provider may tell you:
- “We don’t train our models on your data.”
- “We don’t retain your data.”
- “Your data is not used for training.”
Those statements may be important, but they describe what happens after the information reaches the provider. The information was still transmitted to that provider. Even if information isn’t used for training, you still need to consider whether that company is authorized to receive and process it.