Last updated: August 2026
Every time an engineer pastes a calculation, a spec, or a CAD description into an AI tool, a fair question follows: where does that data go? For engineering work the stakes are higher than a stray email draft, because the input can be a client’s confidential design, a trade secret encoded in geometry and tolerances, or technical data that sits under export control. AI tool data security for engineering comes down to one distinction most coverage skips, and once you understand it, protecting your IP becomes a set of concrete choices rather than a vague worry.
This is the data-governance companion to our broader guide to the best AI tools for engineers, and it goes deeper than the narrower question of whether ChatGPT trains on your drawings. We are not lawyers, and nothing here is legal advice: export-control and contract questions belong with your compliance team and counsel. What we can do is lay out what the major vendors actually say, dated and attributed, so you know which questions to ask.
Short answer: The tier decides everything. On consumer chatbot tiers, your inputs can be used to train the model by default; on the business, enterprise, and API tiers of the major vendors, they are not. So use a company-approved enterprise or API tier, turn off training on any consumer tool you must use, and never paste export-controlled or client-confidential data into a consumer chatbot. Check your company AI policy and your client contracts first, redact or abstract before prompting, and treat every vendor commitment as a stated policy that can change, so verify the current terms. Choosing a tool that does not train on your data is a real, available option.
What actually happens to your data
The single load-bearing distinction is consumer tiers versus business, enterprise, and API tiers. On a consumer chatbot, your conversations may be used to improve the model, and on some services that is the default until you turn it off. On the business and API tiers of the same vendors, the commitment is the opposite: your inputs are not used for training. Same company, same underlying model, completely different data handling, decided entirely by which tier you are on.
Two other properties matter alongside training. The first is retention: how long the provider stores your inputs and outputs before deleting them. The second is human review: whether any person, for abuse monitoring or quality, can read what you submitted. Enterprise tiers generally tighten both, and some add data-residency controls and zero-data-retention options for regulated work. The safeguards exist; the job is to be on the tier that gives them to you.

What the major vendors actually say
The statements below were read from each vendor’s own page in August 2026. Policies change, sometimes materially, so treat these as dated snapshots and re-verify the current terms before you rely on them.
| Vendor | Consumer tier (default) | Business / Enterprise / API |
|---|---|---|
| OpenAI | Consumer ChatGPT can use chats to improve models unless you opt out in data controls | “By default, we do not use your business data to train our models” for ChatGPT Business, Enterprise, Edu, and the API Platform; you own your inputs and outputs |
| Anthropic (Claude) | Changed in 2025: Free, Pro, and Max chats can be used for training if you allow it, a choice users had to make by October 8, 2025, with retention up to five years if allowed | Claude for Work (Team and Enterprise), Government, Education, and API use, including via Amazon Bedrock and Google Cloud Vertex AI, are excluded from that training |
| Microsoft Copilot | Consumer Copilot governed separately | “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs,” and Copilot has opted out of Azure OpenAI abuse-monitoring human review |
| Google Gemini (Workspace) | Consumer Gemini conversations may be reviewed by humans | Gemini for Google Workspace submissions “aren’t used to train models and are never reviewed by humans” |
Anthropic’s 2025 change is the reason the “verify current terms” caveat is not boilerplate. Historically Claude did not train on user chats by default; the update announced on August 28, 2025 gave consumer Free, Pro, and Max users a choice, with training on and five-year retention if they allow it, or the existing thirty-day retention if they do not. The commercial tiers were explicitly carved out. A policy you checked a year ago can read the other way today, which is exactly why the tier and the current terms both matter.
The risks that are specific to engineering
General AI-privacy advice stops at “do not share sensitive data.” Engineering work carries three exposures that deserve their own treatment.
- Client NDAs and data-handling clauses. Pasting a client’s file into a third-party service can breach a contract that dictates where the data may be stored and processed, even if the AI vendor never trains on it. The obligation is yours, not the vendor’s.
- Export-controlled technical data. For defense and aerospace work, controlled technical data under ITAR or the EAR can only be accessed by authorized persons, and uploading it to a public or foreign-hosted service can constitute an unauthorized export. This is a principle to raise with your compliance team, not a rule to self-interpret, and nothing here is legal advice.
- Trade secrets in the design itself. A CAD assembly encodes years of decisions about geometry, tolerances, materials, and suppliers. Trade-secret protection depends on keeping the information secret, and entering it into an unrestricted public tool can undermine that status.
Stamped and sealed work adds a professional-liability layer on top, which we cover in our guide to whether you can use AI for stamped drawings.

How much confidential data is actually leaking
The risk is not hypothetical. In its 2026 AI Adoption and Risk Report, published on February 11, 2026, security firm Cyberhaven reported that 39.7 percent of all AI interactions it observed involved sensitive data, and that a large share of usage runs through unmanaged personal accounts rather than governed corporate ones, including 32.3 percent of ChatGPT usage and 58.2 percent of Claude usage (Cyberhaven). Personal accounts are precisely the consumer tiers where training can be on by default.
The classic cautionary tale predates the current tooling: in 2023, Bloomberg reported that engineers at Samsung had pasted proprietary source code into ChatGPT, prompting the company to restrict the tool. The lesson is not that AI is unsafe, but that the wrong tier plus confidential input is a bad combination, and it is an avoidable one.
Practical safeguards
None of this requires abandoning AI. It requires a short, boring routine.
- Use a company-approved enterprise, business, or API tier whose terms say it does not train on your data, rather than a personal consumer account.
- Turn off training on any consumer tool you genuinely must use, through its data-controls setting, and confirm it stayed off.
- Never paste export-controlled or client-confidential data into a consumer chatbot, and check the relevant NDA or contract before uploading a client’s files anywhere.
- Redact, anonymize, or abstract before prompting: ask about the method with generic numbers instead of pasting the real drawing or dataset.
- Prefer zero-data-retention or private-cloud deployments for regulated work, where the vendor offers them.
- Read your company AI policy first, and route export-control and contract questions to compliance and legal rather than deciding alone.
AI has real limits beyond data handling, which we cover separately in our look at the limitations of AI in engineering. On the data question specifically, the empowering fact is that a compliant option exists: you can pick a tier that does not train on your work.
Frequently asked questions
Does ChatGPT train on my data?
It depends on the tier. As of 2026, OpenAI states that by default it does not use business data from ChatGPT Business, Enterprise, Edu, or the API Platform to train its models, and that you own your inputs and outputs. Consumer ChatGPT can use your chats to improve the model unless you opt out in the data-controls setting. If you are handling confidential engineering data, use an approved business or API tier and verify the current terms, because policies change.
Is it safe to upload CAD files or drawings to an AI tool?
Only on the right tier, and only if no contract or export rule forbids it. A CAD file can contain trade secrets and client-confidential detail, so uploading it to a consumer chatbot that may train on inputs risks both your IP and any NDA you signed. On a business or enterprise tier that does not train on your data, the training risk is addressed, but you still must confirm the upload complies with client contracts and any export-control obligations. When in doubt, abstract the question instead of uploading the file.
Who owns the output an AI tool generates?
On the major business tiers, the vendor does not claim ownership of your output. As of 2026, OpenAI states you own your inputs and outputs to the extent permitted by law, and Microsoft states it does not claim ownership of Copilot output. Both note that similar prompts can produce similar results for different customers, so output may not be uniquely yours. Ownership terms vary by vendor and tier, so check the specific service agreement.
Can I use AI with ITAR or export-controlled data?
Treat that as a compliance question, not a tooling one, and we are not lawyers. Controlled technical data under ITAR or the EAR can generally only be accessed by authorized persons, and uploading it to a public or foreign-hosted AI service can be an unauthorized export. Some vendors offer government or private-cloud deployments intended for controlled data, but whether a specific setup is compliant is a determination for your export-control and legal teams, made before any data is uploaded.
How do I stop an AI tool from training on my data?
The most reliable route is to use a business, enterprise, or API tier whose terms state it does not train on your inputs. On a consumer tier, look for the data-controls setting and turn off the option that allows your chats to improve the model, then confirm it stayed off. Even then, do not paste export-controlled or client-confidential engineering data into a consumer tool, and check your company AI policy first.
Sources
- OpenAI, Enterprise privacy
- Anthropic, Updates to consumer terms and privacy policy (Aug 28, 2025)
- Microsoft, Data, privacy, and security for Microsoft Copilot
- Google Workspace, Generative AI privacy commitments
- Cyberhaven, 2026 AI Adoption and Risk Report
Written by the CognitiveFuture editorial team. We are not lawyers, and this article is not legal advice; export-control, contract, and trade-secret questions belong with your compliance team and counsel. Vendor commitments quoted here were read from each provider’s own page in August 2026, are stated policies that can change, and should be re-verified against the current terms before you rely on them. We do not independently audit any vendor’s data handling.