UpTrajectory Review

The headline announces a blunt reality: every email your company generates is now raw material for artificial intelligence systems. The provided text is sparse—just a fragment about privacy, employee data, and AI demands—but the claim itself is worth taking seriously. If your business runs on email, and nearly all do, then the casual communications between your staff, your vendors, and your customers are no longer ephemeral. They are being scraped, stored, and fed into models that learn patterns, preferences, and proprietary workflows. This is not hypothetical. Major AI developers have already faced lawsuits and regulatory scrutiny for training on data scraped without explicit consent, and the default posture of most large language model builders has been to assume that publicly accessible or leaked data is fair game.

For a small-business operator, the stakes are immediate and practical. Your email is not just a communication tool; it is a repository of customer lists, pricing strategies, unresolved complaints, internal disagreements, and the kind of informal negotiation that reveals how you actually do business. If that material trains an AI model, your competitive edge—your unique process, your client relationships, your hard-won operational knowledge—could be distilled into a product that your competitors also use. The fragment mentions employee data specifically, and that matters too. Your staff have a reasonable expectation that their internal communications are not being harvested to teach a machine how to write performance reviews or termination letters.

What is genuinely new here is not the existence of data scraping but the normalization of it. A few years ago, the idea that your private correspondence might train a commercial AI would have triggered alarm. Now it is treated as an inevitability, a background condition of doing business. We are skeptical of that resignation. The legal ground is still shifting. Courts have not settled whether training on copyrighted or confidential material without consent constitutes fair use or theft. Regulators in Europe and several U.S. states are actively drafting rules that could force AI companies to disclose their training sources and allow opt-outs. The idea that every email is automatically fair game is a corporate preference, not a settled legal fact.

The second-order effects are unevenly distributed. Large corporations with dedicated legal teams and enterprise software agreements can negotiate terms, audit vendors, and demand contractual guarantees that their data will not be used for training. Small businesses rarely have that leverage. When you sign up for a productivity tool, a CRM, or an email client, the terms of service often include a clause granting the provider broad rights to use your content to improve their services—a euphemism that increasingly includes AI training. Your data becomes the subsidy that makes cheap or free tools viable, and you bear the risk if that data leaks, biases a model, or surfaces in a competitor's AI-generated output.

What to watch next: the outcome of ongoing lawsuits against AI developers, the implementation of state-level privacy laws that may restrict training on personal data without consent, and whether enterprise software vendors begin offering explicit, auditable opt-outs as a competitive differentiator. In the meantime, operators should audit their vendor agreements for training-data clauses, train staff to treat email as a permanent record rather than a disposable note, and consider whether sensitive negotiations belong in encrypted channels with retention limits. The era of assuming your inbox is private is ending. Act accordingly.

Takeaway: Audit your software vendor contracts for AI training clauses and treat internal email as permanent, potentially public data.

Excerpt from the original — The Economist Business

Privacy, employee data and the demands of AI