The AI feature added to software you already use: what to check
Tools you have paid for are shipping assistants that read everything in them. Three questions decide whether that is a feature or a change to the deal you agreed to.

Short answer
Ask three things: does the feature send your content to a third-party model provider, is it on by default for existing data, and is your content used for training. The answers are usually in a subprocessor list and a data-processing page rather than the announcement, and the defaults changed without you agreeing to them.
On this page
A tool you have used for years adds an assistant. It reads your documents, your messages, your customer records — everything already in the product — and it appeared in an update you did not choose.
That may be excellent. It is also a change to what happens to your data, and it is worth ten minutes before you use it or turn it off.
1. Where does the content go?
Most products do not run their own model. They send content to a provider, which means your data now transits a company you have no relationship with.
Look for the subprocessor list — a page most vendors maintain, often linked from the privacy policy or a trust centre. A new model provider appearing there is the clearest evidence of what changed.
What you are checking:
- Which provider, and in which jurisdiction.
- Whether it is optional — some tools offer a local or self-hosted mode, or let an administrator disable the feature entirely.
- Whether it applies to all your data or only what you paste into the assistant. These are very different, and the announcement rarely distinguishes them.
2. Is it on by default, for content that already existed?
The important distinction is between a feature you invoke and one that indexes.
- Invoked — nothing happens until you ask it something. Your exposure equals what you type.
- Indexed — the product processes your existing library so search and suggestions work across it. Your exposure is everything you ever put in the tool, including things you added years before this feature existed under different terms.
Indexing is often the default, and it is usually a single toggle in admin settings. Find out which one you have before deciding whether it matters.
3. Is your content used for training?
Most business plans say no, and many free plans say something less definite. The word to look for is opt-out: a default of yes that you may decline is a different arrangement from a default of no.
Check the answer for your specific plan. Free and paid tiers routinely differ here, and the free tier's terms are the ones written most loosely.
Read the data-processing page, not the launch blog post. The blog post describes the feature; the data page describes the agreement.
What to do with the answers
If the tool holds ordinary work, the honest answer is usually that this is fine and the feature is useful. Not everything needs a review.
If it holds client data, personal data, or anything under a confidentiality obligation, then the questions above are the ones your own obligations depend on. A supplier adding a subprocessor may be something you are required to assess, and possibly to tell someone about.
If you are in a team, check the admin console rather than your own settings. These features are usually organisation-wide, and the person who needs to decide is not always the person who noticed.
The pattern worth naming
This is the third time in a decade that the same shape has appeared: a capability arrives in software you already trusted, enabled by default, described as an enhancement, and it changes where your data goes.
The response that ages well is not refusal. It is the habit of checking three things when it happens — where the data goes, whether the default is index or invoke, and whether training is opt-out — and then deciding on purpose.
That takes ten minutes and it is the difference between adopting a feature and discovering later what you adopted.
Frequently asked questions
- Where do I find which provider a tool sends my data to?
- The subprocessor list, usually linked from the privacy policy or a trust centre page. A new model provider appearing there is the clearest evidence of what a feature actually changed.
- What is the difference between an invoked and an indexed AI feature?
- An invoked feature processes only what you give it. An indexed one processes your whole existing library so search and suggestions work across it, which means content you added long before the feature existed.
- Is my content used to train models?
- It depends on the vendor and, importantly, on your plan — free and paid tiers often differ. Look for whether training is opt-out, which means the default is yes.
- Should I disable these features?
- Not by default. For ordinary work they are usually a genuine improvement. For client data or anything confidential, check the three questions first, because your own obligations may depend on the answers.
Sources
- Art. 28 GDPR — Processor — GDPR
- Data portability — GDPR Article 20
Published by
Skrill
Discover useful apps, software, AI tools, digital products, reviews, comparisons, alternatives, and practical recommendations.
About the publication
