Who’s running AI on your data? The vendor you didn’t ask
Why a signed employee acknowledgment and four one-minute questions to vendors can stop data leakage — before the courts decide.
Nick Dreyfus opens on a meeting that ended four months ago: everyone hung up, the team kept talking, and the AI note taker—still in the room—did exactly what it was built to do and emailed the internal conversation to everyone who’d been on the call.
That image is the spine of the episode: most companies already have an AI program, but half of it lives outside their walls — in bookkeepers, agencies, recruiters, outsourced IT — and they rarely know which tools, which tiers, or which terms those vendors are using.
The simplest control most companies don’t have: a signed list
Nick isn’t arguing for fear. He deploys AI for a living and thinks waiting is the more expensive mistake. His practical first move is paperwork that changes the legal conversation: an employee acknowledgment that names permitted AI tools and is signed by each person.
Why that matters: if something goes wrong and you have no signed record, you end up in a he-said, she-said fight about what someone “knew” in a meeting 18 months ago. A signature is not a technical control — it won't stop someone pasting confidential pricing into a consumer model — but it is a record. It moves you from an impossible memory contest to a defensible position with counsel and insurers.
“Ignorance is a very hard position to defend when nothing was ever put in writing.” — Nick Dreyfus
Nick’s instruction: give people a sanctioned alternative at the same time. A rule without an option becomes quiet workarounds; a signed policy plus a usable tool gives your team a real path to comply.
The vendor problem is bigger — and legally different
There are two separate problems to keep apart:
Work walking out the door: vendors recycling deliverables (the old logo-swap problem) now happens at AI speed.
Data flowing into opaque systems: vendors using consumer-tier or free AI that may store and reuse your data.
Contracts typically handle the first one: ownership, confidentiality, subcontractor obligations. Most vendor agreements were written before this existed and say nothing about AI. That’s a contract gap you must close.
The second problem is quieter and harder. Consumer AI tiers are often “free because you are the payment.” If an agency runs your client lists through a $20 consumer account, your data may be training someone else’s model or sitting in a system you did not configure. You can’t prove where it went, who saw it, or how to enforce your confidentiality terms after the fact.
Worse: many embedded tools require deep access (CRM, databases, tokens). If an attacker compromises the AI vendor, they may use that tool as a skeleton key straight into your systems. Your security posture becomes as strong as the vendor’s.
Four one-minute questions every vendor should answer now
Nick reduces remediation to four simple questions you can email in under a minute. Get their answers in writing; written replies behave differently.
Are you using any AI tools on our account?
If not, are you planning to use AI on our account?
If yes, which tools and which tier — and can you run our work in an environment we control?
Who will pay for the environment or the paid tier that contains our data?
If the vendor says “never” or “not planning,” get that in writing. If they say “yes” or “maybe,” require they use your sanctioned environment or a business-tier product you approve, and make them bear the cost of containment.
Nick emphasizes the posture: you’re not asking them to stop using AI. You’re asking them to do the work you already pay for in a place you can see and govern.
When to buy a partner, not just a tool
Buying a standalone tool often shifts the burden onto an employee who must become a novice AI engineer while doing their day job. Consumption-based billing and token costs balloon fast — Nick cites a public example where a company burned through a year’s budget for generative tools in months. The right partner absorbs the operational and governance work, offers a model-agnostic layer, and lets you switch models without rebuilding workflows.
A strategic rule he gives: don’t commit your company to one model today. Build a model-agnostic environment so marketing, accounting, and engineering can pick what suits them and you can swap providers when the economics or capabilities change.
Start today — three practical steps that cost nothing
Inventory every outside party with access to your information: bookkeepers, recruiters, agencies, consultants, outsourced IT.
Send the four questions by email and keep their written answers.
Create the signed internal acknowledgment that names approved tools and provides a usable sanctioned alternative.
Nick’s closing read: he expects litigation between vendors and clients over AI-exposed data in the next six to twelve months. He doesn’t predict outcomes, but he does say this: a company that documented its rules and had counsel sign off will be in a completely different conversation than the one with no records.
If you want a next step you can run today, make the vendor list and send the email. If you’d like help translating vendor answers into contract language or an environment you can own, Nick points to iNet’s AI readiness assessment — but the first moves are yours and cost nothing other than the minute it takes to ask.
If this left you thinking of one vendor or one meeting, that’s the point: who’s running AI on your data is not a hypothetical. It is happening now, and the controls you need had to be in place before the meeting started.