AI has changed the privacy threat model because data can now leave the traditional application stack through a prompt.
An employee does not need to export a database.
They can paste:
- A support conversation
- Customer feedback
- A contract
- A resume
- A bug report
- A KYC document
- A customer list
into an AI system in seconds.
The operational problem is not whether AI is good or bad.
It is that AI introduces a new processing path that many privacy programs have not mapped.
First question: what data is going to the model?
Create categories:
Public
Internal
Confidential
Personal data
Sensitive / regulated
Secrets
Then define what can be sent to which tools.
An internal coding assistant may be acceptable for source code but not for a production customer export.
Second question: what is the model provider doing?
Read the current enterprise terms and privacy documentation.
Ask:
- Is input retained?
- Is it used for training?
- Where is it processed?
- Who are subprocessors?
- Can retention be configured?
- Can data be deleted?
- What logging exists?
Do not rely on a sales statement from six months ago.
AI product policies change quickly.
Third question: what is your purpose?
Suppose you send support tickets to an LLM.
Purpose A:
Summarise support conversations to speed up resolution.
Purpose B:
Improve a general model.
These are not the same purpose.
Your privacy analysis needs to distinguish them.
Build an AI data-flow map
Customer
↓
Support platform
↓
AI API
↓
Summary
↓
CRM
Then add:
- Data categories
- Purpose
- Contract
- Retention
- Region
- Access
- Deletion
That turns “we use AI” into something you can govern.
Add controls at the point of use
Policy alone is weak.
Useful controls include:
- Approved AI tool list
- Data classification rules
- Browser or gateway controls
- DLP checks
- Redaction
- API allowlists
- Audit logs
- Prompt templates that minimise input
Watch for shadow AI
Employees will discover tools faster than procurement teams.
Look for:
- New domains
- New browser extensions
- AI SDKs
- API keys
- SaaS invoices
- Slack bots
A strong privacy program treats AI discovery as part of vendor discovery.
AI privacy is also a product problem
If your own product uses AI, the questions change.
You need to decide:
- What data enters the model
- Whether users are informed
- Whether prompts/outputs are retained
- Whether human review occurs
- How long outputs remain
- Whether model providers can reuse the data
For high-risk use cases, an impact assessment may be appropriate.
Common mistakes
Assuming “API” means private. It does not.
Assuming no training means no processing. Processing still happens.
Relying on employee policy. Add technical controls.
Ignoring logs. AI gateways often capture prompts and outputs.
Where Privra fits
Privra maps AI vendors and AI-related data flows into the broader privacy inventory so teams can see where personal data enters the AI stack, what purpose it serves, and what controls are attached.
AI is becoming part of the product stack.
Privacy needs to become part of the AI architecture too.