Where Does Your Data Go? The Question Every Brand Needs to Ask Before Trusting an AI Vendor
- Mark Dunn
- 6 days ago
- 5 min read
Updated: 2 minutes ago

If your AI vendor can't tell you exactly where your data goes, you already have your answer.
That's the uncomfortable truth sitting beneath a much bigger conversation happening in advertising and marketing right now. As AI tools get folded into every part of the media and creative process, a critical question is getting skipped: when your agency or platform runs your business through an AI tool, where does that data actually live?
The Data at Stake Is Not Trivial
Ad spend. Talent contracts. Media plans. Performance data. This is some of the most competitively sensitive information a brand owns and too much of it is being pasted into generic LLM tools with no access controls, no audit trail, and no contractual guarantee it won't be used to train someone else's model. That's not innovation. That's negligence wearing a chatbot interface. The pattern is easy to fall into because it's fast. An account team is under deadline pressure, a public AI tool is one tab away, and dropping a media plan or a client's performance numbers into a prompt feels like a shortcut, not a risk. But every one of those prompts is a data disclosure. And once that data leaves a controlled environment, the brand has no way to verify where it went, who touched it, or whether it quietly became training material for a competitor's future model.
An Old Problem With a New Interface
The frameworks for handling this responsibly already exist. They didn't emerge overnight, and they aren't controversial:
NIST's AI Risk Management Framework gives organizations a structured way to identify, measure, and manage the risks that come with deploying AI systems, including data governance and security.
OWASP's guidance on large language model risks catalogs the specific ways LLM-based tools can leak, mishandle, or expose sensitive data from prompt injection to insecure output handling.
ISO/IEC 42001, the world's first international standard for AI management systems, gives organizations a certifiable framework for governing how AI is developed, deployed, and used responsibly, covering everything from risk assessment to data protection and third-party oversight.
What "Doing It Right" Actually Looks Like
Handling this correctly isn't complicated in principle, even if it's harder in practice than plugging into a public API. It comes down to a few non-negotiables:
Data stays inside a controlled environment. Client data shouldn't be routed through a third party's shared infrastructure. Running AI inside a private cloud environment with the organization's own access controls, rather than a vendor's default settings, keeps the data inside the walls it's supposed to stay inside.
Every request is logged. If a request can't be traced: who made it, when, and what it touched, there's no way to answer for it later. An audit trail isn't a nice-to-have; it's how an organization proves what happened when a client asks.
Encryption is standard, not optional. Data encrypted at rest and in transit is baseline hygiene, not a differentiator. If a vendor treats it as a premium feature, that's a signal worth noticing.
Zero-training terms are contractual, not implied. A verbal assurance that a vendor "wouldn't" use client data to train its models isn't a guarantee. It has to be written into the agreement, in plain terms.
None of this is cheap or fast to build. It's slower to stand up than dropping an API key into a public tool and calling the result "AI-powered." But that scaffolding is quickly becoming the baseline cost of operating responsibly in any industry that handles sensitive client or customer data advertising.
3 Questions Every Brand Should Ask Its AI Partners
Before signing off on any AI-enabled agency, platform, or tool, brands should get clear, specific answers to three questions:
Where does my data physically go when your AI processes it? Not a general description, an actual answer about infrastructure and location.
Who can access it, and is every access logged? If the vendor can't produce an audit trail on request, the access controls likely don't exist in any meaningful form.
Will you put "never trained on our data" in the contract? Verbal reassurance is not a guarantee. If it's not in writing, it's not a commitment.
If the answers get vague, so should the brand's interest.
The Standard Has Already Shifted
This isn't a hypothetical future requirement, it's the standard being set right now. Governance frameworks like ISO 42001 and NIST's AI Risk Management Framework already spell out what responsible AI deployment looks like. Industry bodies like the IAB are actively building the disclosure and diligence infrastructure to hold AI use in advertising to a higher bar. The organizations that treat this as foundational not optional are the ones building trust that compounds over time.
Thriving Responsibly in the AI Era
At Prodigy, our agentic AI platform is built to the highest security standards. Our clients’ confidential data remains in a secure, walled garden inside our own AWS environment via Bedrock. Every request is gated by strict access controls, logged end to end, encrypted at rest and in transit, and covered by zero-training terms. Not because it's a nice-to-have. Because NIST, OWASP, and ISO 42001 have already written the rulebook.
Unlike general market LLMs, Prodigy is built with the following guardrails:
SOC 2 Type 2 Compliance - demonstrates that we have rigorous controls across five criteria: Security, Availability, Processing integrity, Confidentiality, Privacy
GDPR Adherence - EU’s General Data Protection Regulation (GDPR) is the gold standard of data privacy. By adhering to this, it means:
User data is only collected and processed with clear consent.
Individuals have control over their personal data, including rights to access, correct, delete, or transfer it.
Data minimization and purpose limitation are practiced — we only use what we need, and only for the reasons we clearly state.
We’re transparent about data practices and maintain strict protocols for breach notification and accountability.
ISO 42001 Alignment, also known as Artificial Intelligence Management System (AIMS) - the international standard for managing AI responsibly, this was developed in 2023 as AI established itself in the enterprise. Our AIMS alignment ensures our platform is:
Transparent: We provide explainable outputs so clients understand how AI-driven decisions are made.
Traceable and auditable: From model training to deployment, we maintain full visibility into data sources, workflows, and outcomes.
Ethically aligned: We have safeguards in place to prevent bias, ensure fairness, and maintain accountability.
Continuously monitored: Risk management around AI use is not a one-time effort — it’s ongoing and evolves with the tech.
The AI era in advertising won't be won by whoever moves fastest - it will be won by whoever brands can actually trust with the keys. At Prodigy we're grateful for the Fortune 500 brands who entrust us with their data and help inform how we move forward together in the future.