
The safe default is useful customer context, not the customer record
If you run a small business, the temptation is obvious. Connect your CRM, inbox, help desk, booking system, or shared drive to an AI tool and ask it to find unhappy customers, draft replies, spot buying patterns, or summarize open work.
That can be sensible. It can also quietly give a third-party system far more access than the task requires.
The practical answer to “what customer data can a small business safely connect to an AI tool?” is this: connect the least sensitive data that is sufficient for the job, through a business-grade tool with clear contractual controls, limited permissions, and a human review step. Do not treat “the provider says it does not train on your data” as the whole security decision.
A useful example is a service company asking AI to group recent support messages by issue. The tool may need the message text, product or service involved, date, and case status. It probably does not need the customer’s full name, street address, payment details, government identifier, or every historical interaction. Remove those fields before the data leaves your system.
That approach also fits the FTC’s long-standing guidance: collect only what the business needs, restrict access, protect what it keeps, and dispose of information when the business reason ends. The FTC has specifically warned that AI providers’ privacy promises matter, including promises about whether customer content is used to train or update models. (ftc.gov)

Choose the data tier before you choose the AI tool
| Criterion | Lower-risk operational data | Restricted customer data |
|---|---|---|
| Typical examples | Public FAQs, product descriptions, anonymized support themes, order status without identifiers (better) | Payment details, identity documents, health information, precise financial records, private complaints with names attached |
| Suitable use | Drafting, classification, summarization, search, internal brainstorming (better) | Only with a specialist workflow, appropriate contract, strict access controls, and documented review |
| Main control | Minimize fields and use an approved business account | Use a regulated or security-reviewed service, confirm retention and deletion terms, and involve qualified legal or security advice (better) |
| Human review | Review before customer-facing action or consequential decision | Required before any decision, disclosure, recommendation, or account change (better) |
A business plan is safer than a consumer chat account, but “no training” is not “no access”
Major providers now distinguish business offerings from consumer tools. OpenAI says data from ChatGPT Business, ChatGPT Enterprise, and its API platform is not used to train models by default. Microsoft says prompts and responses in Copilot Chat with enterprise data protection are not used to train foundation models. Those are meaningful protections, especially compared with handing customer information to an unapproved personal account. (openai.com)
They do not mean the data disappears after the answer is generated. Microsoft documents that prompts and responses can be logged, retained, and made available for audit, eDiscovery, and compliance features, depending on the subscription. OpenAI’s consumer-service guidance says content may be stored on OpenAI systems and trusted service providers’ systems, and that authorized personnel may access content for support, abuse investigations, legal matters, or security incidents. (learn.microsoft.com)
That distinction changes the questions you ask a vendor. Ask where prompts, files, embeddings, chat history, logs, and backups are stored. Ask how long each is retained. Ask whether subcontractors can process the data. Ask how deletion works, whether deletion covers derived indexes, and whether your team can export its data when the relationship ends. Ask whether the tool can restrict access by role and whether administrators can review usage.
A provider’s security page is evidence, not a substitute for reading the plan terms. OpenAI, for example, describes encryption in transit and at rest, access controls, and independent SOC 2 Type 2 examination for relevant business services. Those controls reduce risk. They do not make an unrestricted connection to your whole CRM automatically appropriate. (openai.com)
The FTC’s position is useful here. If an AI company makes a confidentiality or data-use promise, it must honor that promise. Your business still remains responsible for deciding whether the disclosure is necessary and whether your own privacy notice, customer agreements, and sector obligations permit it. (ftc.gov)

Connect customer data in a controlled sequence
-
Define the task before connecting a system
Write down the decision or output the AI must produce, then identify the smallest fields needed to produce it.
-
Classify the information
Separate public, internal, personal, confidential, regulated, and highly sensitive data. Treat free-text messages as personal data because customers often reveal more than your form requests.
-
Remove direct identifiers where possible
Replace names, email addresses, phone numbers, account numbers, and exact addresses with internal labels or generalized descriptions.
-
Approve the specific product and plan
Check the actual terms for training, retention, human access, subprocessors, deletion, encryption, authentication, audit logs, and breach notification.
-
Use narrow permissions
Give the integration read-only access where possible, limit it to the required records, and keep payment, payroll, identity, and medical systems disconnected.
-
Test with synthetic or historical scrubbed data
Look for accidental disclosure, incorrect classification, prompt injection, excessive permissions, and outputs that expose information from another customer.
-
Keep a human accountable
Require review before the AI sends a message, changes an account, recommends a price, denies a request, or makes a decision that could materially affect a customer.
Keep these categories out of a general-purpose AI connection
Some information deserves a hard stop unless the tool was selected specifically for that use.
Payment card numbers, bank account details, tax identifiers, passwords, authentication codes, identity documents, and private security credentials should not be pasted into a general-purpose chatbot. In most cases, the AI does not need them to answer the business question. The FTC advises businesses not to retain customer credit card information without a genuine business need and to limit access to sensitive personal information. (ftc.gov)
Health information needs a separate decision. If a HIPAA-covered business uses a cloud provider to create, receive, maintain, or transmit electronic protected health information on its behalf, HHS says the provider must have a HIPAA-compliant business associate agreement and appropriate safeguards. A generic “enterprise” label is not a BAA. A tool that will not sign the required agreement is not suitable for that workflow. (hhs.gov)
Be equally cautious with children’s information, precise financial circumstances, legal disputes, immigration documents, employee investigations, and customer messages that contain intimate personal details. The question is not merely whether the model can process the content. It is whether you have a legitimate purpose, a lawful basis where applicable, a clear customer-facing explanation, and a way to control what happens afterward.
The same rule applies to commercially sensitive information. A small business may not think of customer data as a competitive asset, but a connected AI system can reveal pricing patterns, churn, sales volume, growth, or customer concentration through prompts and usage. The FTC has noted that model providers may infer business information from how companies use their APIs. (ftc.gov)
Practitioners are using AI, while admitting they are still working out the controls
The adoption numbers explain why this question has become urgent. The U.S. Chamber reported that 58% of small businesses used generative AI in 2025, with generative AI chatbots reaching 44% among the technology tools small businesses use. Goldman Sachs reported in March 2026 that 76% of surveyed small businesses were using AI, but only 14% said it was fully integrated into core operations. Among those using it, 93% reported a positive business impact, while data privacy concerns remained one of the barriers to deeper integration. (uschamber.com)
That is the pattern practitioners actually describe: useful experiments first, governance later. The risk is not that every AI connection will cause a breach. The risk is that a rushed connection becomes permanent before anyone decides what the tool can see, who can change the settings, or what happens when an employee leaves.
Security reporting supports a sober view rather than panic. Verizon’s 2026 breach report says vulnerability exploitation accounted for 31% of breaches in its dataset and describes third-party supply-chain breaches as an expanding attack surface. AI is part of the environment, but ordinary weaknesses still matter: exposed credentials, excessive permissions, unpatched software, and poorly controlled vendors. (verizon.com)
For a small business, the best first connection is usually a narrow, read-only workflow built around data that would cause limited harm if exposed. Use AI to summarize anonymized support themes, search approved internal procedures, draft replies from a controlled knowledge base, or classify leads without exposing payment or identity information. This is also where routine AI support with humans ready for the exceptions makes practical sense: automate the repetitive layer, and keep a person responsible for unusual or sensitive cases.
The less obvious point is that data minimization often improves the AI result. A model does not become more useful simply because it receives every historical record. Irrelevant details create noise, increase the chance of disclosure, and make it harder for an employee to understand why the system produced an answer. Give the tool the context needed for the task, not a copy of the business.