Every project manager and estimator in this industry is sitting on a pile of sensitive material. Owner contracts with pricing terms that were never meant to leave the office. Employee records. Insurance certificates. Design documents for a client who explicitly required confidentiality in the contract itself. As AI chatbots become a normal part of daily work, a habit is forming that deserves a hard second look: people are pasting this material into tools like Claude, Gemini, and ChatGPT the same way they would paste it into a search bar, without stopping to ask where that information goes. And that’s where the problems start.
Inconvenient Truths
Here is the uncomfortable truth. Different AI products handle your data differently, and the differences are not small. A free consumer chatbot account and a company’s enterprise or business account from the same provider can operate under entirely different rules for how long your data is kept and whether it gets used to improve the model.
Some consumer tiers, across multiple major providers, default to using your conversations to train future models unless you go into a settings menu and turn that off yourself. Business and enterprise agreements often carry contractual protections that consumer accounts simply do not have. The point is not to memorize every provider’s current policy, because those policies change, sometimes multiple times a year. The point is that the policy governing the tool sitting on your desktop or phone is not something you should assume about. It is something you need to know.
Don’t Create Landmines for Your Company During an Audit
This is exactly where an audit finds a problem. Auditors and compliance reviewers, particularly on construction, bidding, or HVAC projects where confidentiality obligations are written directly into the contract, are increasingly asking a very specific question: what tools did your team use to process this project’s documents, and under what terms.
A project manager who pasted a confidential owner contract into a free consumer AI account, without knowing whether that account’s terms allowed the data to be retained or used for training, has created a real problem. It does not matter that the intent was innocent. It does not matter that the tool gave a helpful answer. The exposure already happened, and it happened in a way that is very difficult to undo, since data that has been absorbed into a training process generally cannot be pulled back out.
What Should a Project Manager or Estimator Do About It?
Do not assume you know your company’s policy. Ask. Most firms in this industry have not yet published clear internal guidance on which AI tools are approved for sensitive documents and which are not. If your company has not told you explicitly, that silence is not permission. Go to your IT department or your compliance lead and ask directly: which AI tools are we allowed to use, under what account type, and for what kinds of documents. This is a five-minute conversation that can save everyone a serious headache later.
A tool used through a personal, free account is a different animal than the same tool used through a company-managed business or enterprise account with a signed data agreement. If your firm has set up an enterprise account with specific data protection terms, use that one for anything related to client work. If you are not sure whether your company has done this, that is another reason to ask rather than guess.
Keep the Most Sensitive Material Out of Any AI Tool
Would you put your social security number or financial information into a chatbot? Probably not, so why would you risk sensitive company information in this way? Contracts with confidentiality clauses, anything involving a government client, financial records, and employee data deserve extra caution. If there is any doubt about where that information might end up, the safer move is to keep it out of any AI tool entirely until your company’s policy is clear, and to rely on in-house systems and staff for that specific task in the meantime.
Even when data is deleted from your view, it may sit on a company’s servers for a period of time before permanent deletion, and if it was ever used to improve a model, it cannot simply be un-learned. Treat every submission to an AI tool the way you would treat sending an email: once it leaves your hands, you no longer fully control where it goes or how long it exists.
None of this means avoiding AI tools. It means using them the way you would use any other outside vendor handling sensitive material: with a clear understanding of the agreement in place, confirmed with the people at your company whose job it is to know, not assumed based on what seems reasonable. The firms that build this habit early will be the ones an auditor has no reason to flag. The firms that skip this step are building a liability they will not notice until someone else finds it for them.