Why an estate agent asked me what private AI is
Thursday, 6.10pm, a ten-person sales and lettings agency. A negotiator has a tenant application to sign off before the landlord rings at nine: three payslips, six months of bank statements, a passport scan and a reference letter. She pastes the lot into a free chatbot and asks whether the rent is affordable. The answer is tidy and correct. Then she looks at what she has just sent, and to whom.
Her director asked us the following week: "What is private AI, and do we need it?" Here is the plain answer.
How AI affects data privacy in a ten-person agency
Mostly through the quiet paste. Microsoft's 2024 Work Trend Index found 78% of AI users bring their own tools to work, rising to 80% in small and medium businesses. Cyberhaven (2026) found 39.7% of the data employees move into AI tools is sensitive. The UK government's Cyber Security Breaches Survey 2025/26 adds the local picture: of businesses using or considering AI, only 24% have security practices in place for it.
An agency is a concentrated case. Money laundering checks mean passports and source of funds for every buyer, under HMRC supervision; lettings adds referencing and Right to Rent copies. The sector has seen what happens when that material leaks: in 2019 the ICO fined a London agency £80,000 after passports and bank statements for 18,610 people were left exposed on a server.
Where a pasted document actually goes
Further than most people assume. Consumer ChatGPT may train on conversations unless a setting called "Improve the model for everyone" is off. Google keeps Gemini chats chosen for human review for up to three years, even after you delete your activity, and asks you not to enter "confidential information that you wouldn't want a reviewer to see". Since August 2025, consumer Claude users who opt in to training have their chats retained for five years. None of this is sinister. It is simply someone else's computer, under someone else's rules.
