AI features did not arrive as a product you chose. They arrived as updates, switched on, across your phone, your browser, your email client, and your work software. Each one has settings. Almost nobody has looked at them, partly because they are scattered and partly because the labels are vague enough that it is unclear what turning something off actually does.
This is a pass through the ones that matter, with what each control genuinely affects.
What changed in 2026
- Default-on became the norm. AI features shipped enabled rather than opt-in across mainstream operating systems and applications, which shifted the burden to users.
- Training and history separated. Products increasingly offer distinct controls for whether your data trains models and whether conversations are retained, which is clearer but means two settings to check instead of one.
- On-device processing expanded genuinely. More features run locally, which is a real privacy improvement — but which features do and which quietly call a server is often undocumented.
- Connected-account scope grew. Assistants gained access to mail, calendars, files, and messages, moving the main exposure from what you type to what you have authorized.
The checklist
| Setting |
Where to look |
What it controls |
| Model training on your data |
Assistant privacy or data controls |
Whether your inputs improve future models |
| Conversation history |
Same area, usually a separate toggle |
Whether chats are stored and for how long |
| Connected accounts |
Account or integrations page |
What the assistant can read on your behalf |
| Third-party app permissions |
Each major account's security settings |
Live OAuth grants, including for tools you stopped using |
| On-device versus cloud processing |
Device AI settings |
Whether requests leave the device |
| Voice assistant recordings |
Voice or privacy settings |
Retention and human review of audio |
| Browser AI features |
Browser settings |
Page content sent for summarization or assistance |
| Email and document assistance |
Suite admin or personal settings |
Whether message content is processed |
| Work tools |
Ask your administrator |
Organization-level defaults you cannot see |
Do the connected-accounts and third-party-permissions rows first. They are the highest-value items and the ones people have never checked. An assistant authorized to read your mailbox has access to far more sensitive material than any chat transcript, and grants persist after you stop using the tool that requested them.
What the settings do not cover
Two things sit outside these controls.
The first is that consumer and business tiers of the same product frequently have different default data handling. A business or enterprise agreement typically includes contractual commitments not to train on your inputs; a free consumer account typically does not. If you use a personal account for work material, you are on the consumer terms regardless of what you are working on.
The second is that deletion and retention are different. Removing a conversation from your history does not always mean it is deleted from backend storage immediately, and retention periods vary. Check the specific product's documented retention rather than assuming deletion is instant and complete.
The durable habit is simpler than any settings pass: treat consumer AI tools as you would a public forum post that happens to be private today. Anything genuinely sensitive — client material, health information, credentials, unreleased work — belongs in a tool with contractual protections, not in a settings-based hope. The organizational version of this exercise is in AI tool sprawl.
Common mistakes
- Turning off training and assuming history is off too. They are separate controls in most products.
- Never auditing OAuth grants. This is the largest and least-checked exposure.
- Using a personal account for work data. Different terms, different protections.
- Assuming on-device means everything stays local. Some features are hybrid; the split is often undocumented.
- Doing this once. Updates add features with new defaults. Revisit periodically.
FAQ
Does opting out of training delete data already used?
Generally no. Opt-outs are usually forward-looking. Data already incorporated into a trained model cannot practically be extracted.
Is on-device processing actually private?
When genuinely local, yes — it is a real improvement. The difficulty is that documentation about which requests stay local is often thin.
Do business accounts really have better protection?
Typically yes, because the protection is contractual rather than a settings default. Read the specific agreement rather than assuming.
What is the single highest-value action?
Reviewing third-party app permissions on your email and cloud storage accounts, and revoking anything you no longer use.
Where to go next
For the subscription and access audit at team scale, read AI tool sprawl. For reducing your public data footprint, data broker opt out, and for account security itself, passkey migration guide.