The case against putting sensitive development documents into public AI tools
Pro formas, investor lists and buyer files don't belong in consumer AI tools. Kirill Samarits on the risks for developers, with IBM, Cyberhaven, OpenAI and FBI data, and a safer way to use AI.

Real estate developers should not put sensitive documents into consumer AI tools because those tools may use the content for training unless the user opts out, conversations can be retained or preserved beyond the user's control, and staff often use personal accounts the company can't see. Pro formas, investor lists, purchase agreements, drawings and buyer files are exactly the kind of material that causes damage when it leaks. The better approach is not to ban AI but to use business-grade or private AI with clear rules.
I'm Kirill Samarits. I founded TERAMOK, a marketing agency for developers and architects, and FOS AI, an AI implementation company for real estate and construction businesses that is currently at pilot stage. I use AI every day. This article isn't against it. It's about which documents should never go into which tools, and why.
What happens to what you paste
The rules differ by product tier, and most people don't know which tier they're using.
Tool and tier | Used to train models by default? | What to know |
|---|---|---|
ChatGPT for individuals (Free, Plus, Pro) | Yes, unless you opt out | Opt out in Settings, Data controls. Rating a response can still send that conversation for training. |
ChatGPT Business, Enterprise, Edu | No | OpenAI says inputs and outputs are not used for training by default. |
OpenAI API | No | Not used for training by default since March 1, 2023. |
Table 1. Source: OpenAI Help Center and API documentation, checked September 2026. Other AI providers have their own terms; check each one.
Training isn't the only issue. In May 2025, in The New York Times' lawsuit against OpenAI, a court ordered OpenAI to preserve ChatGPT output logs that would otherwise have been deleted. According to OpenAI, the order covered ChatGPT Free, Plus, Pro and Team, and API customers without zero-data-retention agreements, until its obligations ended on September 26, 2025. Deleting a chat didn't guarantee it was gone. That is the kind of legal exposure a developer can't predict when someone pastes an investor memo into a consumer chatbot.
It is already happening at work

Figure 1. Share of workplace AI use through personal accounts. Source: Cyberhaven 2026 AI Adoption & Risk Report.
Cyberhaven's 2026 report found that 39.7% of all AI interactions it observed involved sensitive data, and that employees put sensitive data into AI tools on average once every three days. A large share of that use happens through personal accounts, where the company has no controls and no record. The best-known warning came in 2023, when Samsung restricted generative AI for staff after employees uploaded sensitive source code and internal meeting notes to ChatGPT.
The cost when it goes wrong

Figure 2. Average cost of a data breach. Source: IBM Cost of a Data Breach Report 2025.
IBM's 2025 Cost of a Data Breach report put the global average breach at $4.44M and the US average at a record $10.22M. One in five organizations reported a breach involving shadow AI, meaning AI tools used without approval, and high levels of shadow AI added $670,000 to the average cost. 63% of organizations had no AI governance policy or were still developing one.
Real estate has a particular weakness: money moves by wire, and criminals imitate the people involved. The FBI's Internet Crime Complaint Center reported $3.05B in business email compromise losses in 2025 and $275M in real estate fraud losses, and noted more than $30M in business email compromise losses involving AI. In one 2025 case it described, home buyers wired more than $449,000 after an email impersonating their attorneys. The more deal details that leak, the more convincing those emails become.

Figure 3. Reported US losses. Source: FBI Internet Crime Complaint Center annual reports, 2024 and 2025.
Which development documents need protecting
Document | Why it's sensitive | Where it can go |
|---|---|---|
Pro formas and underwriting | Pricing, margins and assumptions competitors and counterparties would value | Business-tier or private AI only |
Investor and lender lists, capital stack | Personal and financial data; relationships | Private AI, or not into AI at all |
LOIs, purchase and sale agreements | Confidentiality clauses; deal terms | Business-tier or private AI with legal sign-off |
Drawings and specifications | Intellectual property of the architect; security details | Business-tier or private AI; check the architect's agreement |
Buyer and tenant files | Personal data subject to privacy law | Private AI only, with access controls |
Wire and deposit instructions | Direct fraud target | Never into any AI tool |
Marketing copy, public listings | Already public or intended to be | Any tool |
Table 2. A starting point for an internal AI policy. Check your contracts and local privacy law.
A safer way to use AI
Pick the tier deliberately. Use business or enterprise plans, or the API, where content isn't used for training by default, and sign the provider's data processing terms.
Close the personal-account gap. Give staff a company account that's easy to use, so they stop pasting documents into personal ones.
Write a one-page policy. List which documents may go into which tools, like Table 2, and who to ask when unsure.
Keep the most sensitive work private. For underwriting, investor data and buyer files, use AI that runs inside your own environment or under a zero-retention agreement.
Train people on wire fraud. Confirm every payment instruction by phone, using a number you already had, not one from the email.
This is the problem FOS AI was set up to work on: practical AI for real estate and construction companies with the sensitive data kept under the company's control. It's at pilot stage, and I'll publish results when there are measured ones. The principles above apply whoever you work with.
Frequently asked questions
Is it safe to put a pro forma into ChatGPT?
Not in a consumer account. OpenAI's consumer ChatGPT plans may use conversations for training unless you opt out. Use a business or enterprise plan or the API, where content isn't used for training by default, or a private AI setup for the most sensitive documents.
Does ChatGPT keep deleted conversations?
It can. In 2025 a court order in The New York Times v. OpenAI required OpenAI to preserve ChatGPT output logs for Free, Plus, Pro and Team users and some API customers. OpenAI says those obligations ended on September 26, 2025.
How common is sensitive data in workplace AI use?
Very common. Cyberhaven's 2026 report found that 39.7% of AI interactions involved sensitive data, and much workplace use runs through personal accounts.
What does a data breach cost?
IBM's 2025 report put the global average at $4.44M and the US average at $10.22M. High use of unapproved shadow AI added $670,000 on average.
Sources
OpenAI Help Center, How your data is used to improve model performance, and API data controls.
OpenAI, How we're responding to The New York Times' data demands, updated October 22, 2025.
Cyberhaven, 2026 AI Adoption & Risk Report.
FBI IC3, 2025 Internet Crime Report and 2024 report.
CNBC, Samsung bans use of AI like ChatGPT for staff after misuse of chatbot, May 2, 2023.
Kirill Samarits is a real estate marketing executive and entrepreneur based in Chicago and Athens, Founder & CEO of TERAMOK and founder of BUY GREECE and FOS AI. More about Kirill · FOS AI