Data Leakage

I was doing a review of an agency's AI setup a few months ago and asked a simple question: where does the data go?

The head of strategy looked at the CTO. The CTO looked at the founder. Nobody knew.

They had eleven people using four different AI tools across three teams. Some on paid accounts, some on free tiers, some using tools they'd found and set up themselves. The work was good. The outputs were impressive. But client briefs, competitive analyses, financial projections, and occasionally raw datasets were being processed by tools whose data handling policies nobody had read.

When we mapped it, we found data from two regulated-industry clients flowing through a free-tier tool that explicitly stated in its terms of service that inputs could be used to train the model. The agency's client contracts made no mention of AI processing. The clients hadn't been told.

Nothing had gone wrong yet. But the exposure was considerable, and the thing about data leakage is that you don't find out about it from your own monitoring. You find out when a client's legal team asks a question you can't answer.

They closed the gap in about two weeks. An approved tool list, a data classification for each client, and an update to the standard terms that covered AI processing explicitly. It also meant one difficult but necessary conversation with those two clients. Both appreciated being told.

Most agencies I'm working with right now have some version of this problem. The tools are ahead of the governance, which is fine as long as you close the gap before someone else finds it.

Previous
Previous

The Contract Problem

Next
Next

Client Value