The client data traffic light
Green data (public, already published) can go into any AI. Amber data (unpublished campaigns, client strategy, internal numbers) only into business AI plans with no training and a DPA. Red data (customer personal data, credentials, special category data, anything under NDA without client consent) only into a local model or not into AI at all.
What can go where?
| Light | Typical data | Allowed in |
|---|---|---|
| GREEN | Published posts, public websites, public competitor content, generic briefs without names | Any AI, including free plans (still keep training off where you can) |
| AMBER | Unpublished campaigns, strategies, analytics exports, internal reports, client brand books, meeting notes | Business AI plans with no training on your data and a signed or incorporated DPA, used through company accounts |
| RED | Customer lists, DMs and comments with names, e-mail addresses, health or financial data, passwords and API keys, anything under NDA the client has not cleared for AI | A local model on agency hardware, a specially approved setup, or no AI at all. Passwords never. |
Does AI train on what we paste in?
On consumer plans, often yes by default unless you switch it off. On business plans from the major vendors, no: ChatGPT Business and Enterprise, Claude Team and Enterprise, Gemini in Google Workspace and Microsoft 365 Copilot all exclude customer content from model training by their terms.
| Plan | Used for training? | Good to know |
|---|---|---|
| ChatGPT Free, Plus, Pro | Yes by default, can be switched off | Setting "Improve the model for everyone" in Data controls |
| ChatGPT Business, Enterprise, API | No by default | DPA available; EU data residency for Enterprise and API |
| Claude Free, Pro, Max | Your choice since Aug 2025; the option was presented switched on | Retention up to 5 years if training is allowed, 30 days if not |
| Claude Team, Enterprise, API | No, by commercial terms | DPA incorporated into the terms |
| Gemini app (consumer) | Yes while activity is kept (default) | A sample of chats may be read by human reviewers |
| Gemini in Google Workspace | No | Not reviewed by humans; Workspace data protections apply |
| Microsoft 365 Copilot | No | Within the EU Data Boundary (with stated exceptions) |
Sources checked Oct 5, 2026: OpenAI enterprise privacy, OpenAI data controls FAQ, Anthropic consumer terms update, Anthropic commercial terms, Gemini Apps privacy hub, Gemini for Workspace FAQ, Microsoft 365 Copilot privacy.
The lesson for agencies is simple: the brand of the AI matters less than the plan. A personal ChatGPT Plus account used for client work is the single most common data leak we see in agencies, and it is entirely avoidable.
For a practical list of what never belongs in an AI chat, read What your social media team should never paste into an AI chat.
GDPR: who is responsible for what?
When an agency handles personal data for a client, the client is usually the controller and the agency is its processor. An AI vendor you use on that work becomes your sub-processor. You need a DPA with the AI vendor, and under Article 28 GDPR the client must authorise sub-processors, which is why your client contract should mention AI.
The chain, step by step
- Client (controller) decides why personal data is processed, for example comments and DMs from its customers.
- Agency (processor) handles that data on the client's instructions under a processing agreement.
- AI vendor (sub-processor) processes the data when your team uses AI on it. That requires a DPA with the vendor and the client's general or specific authorisation of sub-processors.
A consumer AI plan breaks this chain: the vendor typically acts as an independent controller of chat data and there is no DPA. That is the legal reason behind the amber and red lights above.
What European regulators have said
The European Data Protection Board's Opinion 28/2024 says that whether an AI model is "anonymous" must be assessed case by case, and that a model developed in breach of GDPR can affect the lawfulness of using it. Practical consequence for agencies: choose established vendors that document how their models were built and give you contractual guarantees, rather than unknown tools with no paperwork.
Source: EDPB Opinion 28/2024 (PDF) ↗
AI clause for client contracts
Most agency contracts were written before AI. This generator drafts a transparent clause that tells the client which AI tools you use, for what, and under which safeguards.
Is US-based AI legal under GDPR?
Yes, with the right safeguards. Transfers to US vendors certified under the EU-US Data Privacy Framework are currently lawful. The EU General Court upheld the framework in September 2025; an appeal is pending at the Court of Justice, so keep an eye on it and prefer vendors that also offer EU data residency or standard contractual clauses.
EU data residency options as of October 2026: OpenAI offers it for ChatGPT Enterprise, Edu and the API; Anthropic's Claude is available in EU regions through cloud providers such as AWS Bedrock and Google Vertex AI; Google Workspace and Microsoft 365 apply their own data region and EU Data Boundary commitments. For red data, a local model removes the transfer question entirely.
Sources: OpenAI EU data residency, Claude regional compliance, WilmerHale on the DPF appeal.
What does the EU AI Act require from agencies?
Two obligations matter for most agencies today. Since February 2, 2025, organisations using AI must take measures to support AI literacy among staff (Article 4, softened in 2026 by the Digital Omnibus). Since August 2, 2026, the transparency rules of Article 50 apply, including disclosure of deepfakes and of AI-generated text published to inform the public on matters of public interest.
AI literacy (Article 4)
The AI Act treats any company using AI professionally as a "deployer". The Digital Omnibus, Regulation (EU) 2026/1744, in force since July 27, 2026, changed the wording: deployers must now take measures to support the development of AI literacy, rather than guarantee a sufficient level. In practice: train your people, document it, and keep the record. Working through this playbook with your team and ticking the checklists is a reasonable start for that record.
Transparency (Article 50)
From August 2, 2026, image, audio or video content that is a deepfake must be disclosed as artificially generated or manipulated, and AI-generated text published to inform the public on matters of public interest must be disclosed unless it went through human editorial review. For agencies the practical rules are: label photorealistic AI people, places and events; never publish synthetic people as if they were real customers or employees; and keep human review in your approval workflow. Platforms add their own labelling rules on top, see Reach Myths.
High-risk AI
Typical agency use (content, reporting, research) is not high-risk under the Act. Deadlines for high-risk systems were moved by the Omnibus to December 2, 2027 and August 2, 2028.
Sources: AI Act Explorer: Digital Omnibus, White & Case: AI Omnibus enters into force.
When should an agency use a local model?
Use a local model when the data is red: customer lists, private messages, health or financial details, or material under strict NDA. Open-weight models in the 20 to 30 billion parameter range now run on a well-equipped laptop or office Mac, and nothing you type ever leaves the device.
LM Studio and Ollama download and run open-weight models with a few clicks. Both can act as an MCP host, so a local model can still use your tools.
Popular open-weight families in 2026 include OpenAI's gpt-oss, Google's Gemma, Alibaba's Qwen, Mistral and Meta's Llama. Pick one that handles your client languages well.
About 16 GB of memory runs a 20B model; 32 GB runs most 24 to 32B models comfortably; 64 GB and more opens the 70B class.
Be honest about the trade-off: local models are good at summarising, classifying, anonymising and drafting, but still behind frontier models on complex reasoning and polished copy. A smart pattern is to use a local model to strip personal data from a red file, then send the anonymised amber version to your business AI.
Hardware and model sizes based on published model files as of September 2026; actual performance depends on quantisation and workload.
A one-page AI policy for your team
1. We use only company-approved AI tools on business plans. No personal accounts for client work.
2. We follow the data traffic light: green anywhere, amber only in approved business tools, red only locally or not at all.
3. Passwords, API keys and payment data never go into any AI.
4. A person reviews everything AI produces before it reaches a client or the public.
5. We label photorealistic AI-generated people, places and events.
6. AI agents connect to our tools only through official integrations with OAuth, and create drafts, not live posts.
7. We tell clients which AI tools we use and why, in our contracts.
8. When unsure, we ask the AI champion before we paste.