Switching on AI adds a party to the conversation
Before AI, a chat had two ends and a vendor in the middle. Turning on automated answers usually adds a third organisation, because the model generating the reply is typically operated by somebody other than your chat provider. That is not a reason to avoid AI chat, and it is a reason to know what the arrangement is before a customer or an auditor asks.
This is the AI-specific half of the broader vendor question. General due diligence covers what leaves your site and where your chat vendor stores it; this one is narrower and easy to miss, because the extra hop appears the moment somebody ticks a box in a dashboard and nothing on the page looks different afterwards.
What actually leaves
For the bot to answer, something has to reach the model. In practice that is the visitor’s message, some amount of the conversation so far so the reply makes sense in context, and the relevant slice of the content you trained it on. Whatever your pre-chat form collected may travel with it if it is part of the conversation context.
The thing worth internalising is that anything a visitor types into the chat is potentially part of that payload. Visitors do not know this and will occasionally paste things nobody wanted: an order number, an address, a full card number, a password. Your policy for that traffic is what determines your exposure, far more than the contract does.
Keep the wrong things out at the source
The cheapest control is not sending sensitive data in the first place, and most of that is design rather than configuration. A pre-chat form that asks only for what you need to reply is a smaller payload by construction. A widget that never invites account credentials avoids the category entirely, which is the practical form of the rule that a public chat widget is not an authentication channel.
- Ask for the minimum in the pre-chat form, and review it when it grows
- Never invite passwords, full card numbers or government identifiers into chat
- Give agents a scripted line for when a visitor volunteers something sensitive anyway
- Keep internal-only material out of the AI-enabled content set
The questions worth asking your provider
Ask these of any chat vendor offering AI answers, including us, and prefer written answers to reassuring ones. They are short, specific, and a vendor who cannot answer them quickly has told you something useful.
- Which model provider is used, and is it named anywhere a customer could find it
- Is conversation content used to train anybody’s model, and can that be turned off
- How long is the content retained on the provider’s side, and by whom can it be read
- Where is it processed geographically, if that matters to your obligations
- What happens to the AI path if you later turn the feature off
Tell your customers, in words they will understand
If AI is answering, say so, and if conversation content reaches a third party to make that happen, your privacy notice should reflect it in language a normal person can follow. This is not just a compliance chore. Disclosure is cheap when you do it deliberately and expensive when a customer discovers it themselves.
Keep the three descriptions consistent: what the widget says, what your privacy notice says, and what your team says when asked. The failure mode that damages trust is not the data flow, which is ordinary. It is a customer finding that the answers do not line up.
Decide before you are asked
Write the answers down before a questionnaire or an access request arrives. Retention, who can read what, which content is exposed to the bot, and what you disclose are all your decisions, and having them in a document turns a stressful week into a copy-and-paste. It is also the material your sales team needs when a security review lands mid-deal.
Review it whenever you change the AI setup, because widening what the bot can see is exactly the kind of change that happens quietly and invalidates the previous answer.
How MyLiveChat fits
The controls on your side are worth knowing. The per-article toggle in the knowledge base decides which content the AI chatbot may draw on, so internal notes and anything you would not want quoted can stay out of the AI path while remaining available to your team. What your pre-chat form asks for is equally your choice, and it is the single biggest lever on what ends up in a conversation at all.
Conversations remain searchable and exportable in transcripts, which is what makes an access or erasure request practical to answer rather than theoretical. Everything in transit is TLS-encrypted on every plan, which covers the hop but is a separate question from who may read the archive afterwards.
What to measure
Mostly this is reviewed rather than measured, on a schedule you set.
- How often sensitive data appears in transcripts despite the policy, sampled quarterly
- Whether the AI-enabled content set still matches what you intended it to contain
- Time to answer a data-access request, rehearsed rather than discovered
- Whether the widget, the privacy notice and the team all describe the AI the same way
If you need to confirm which provider and model your account is really calling, rather than which one is configured, why no model is marked active on your AI models page shows where that answer actually lives.