When AI Features Turn On by Default: What to Check
The way most people first use a new AI feature in 2026 is not by choosing it. It is by opening a familiar app and finding a feature already on, summarizing their documents, suggesting replies, or, in the terms of service, permitting the content to be used to improve the product. The default moved from off to on, and the notice was a banner you dismissed.
For confidential work this is the risk that does not announce itself. Here is what to check when a tool you rely on grows an AI feature you did not request.
Default On Is the New Normal
Vendors enable AI features by default because adoption numbers look better when you have to opt out rather than opt in. That is a product decision, not a scandal, but it means the burden of checking falls on you. A feature being on does not mean you agreed to what it does. It means you did not turn it off.
The two things worth checking are what the feature sends and what the provider does with it. Those are separate questions, and a reassuring answer to one does not cover the other. We covered the gap between “private mode” and actually private in what AI tools log even in private mode.
The Training Question
The setting that matters most for confidential material is usually whether your content is used to train or improve the provider’s models. This is often a separate toggle from the feature itself, and it is often on by default. If you handle client, patient, or contract material, content used for training is a disclosure you may not be permitted to make.
Look for the specific wording. “Improve our services” and “help train our models” can mean the same thing, and both mean your text left your control. A clear “we do not train on your content” is what you want, ideally backed by a contractual term rather than a help-page sentence. We put the questions that produce contractual answers in questions to ask an AI vendor about data.
The Retention Question
The second question is how long the provider keeps what the feature sends. A feature that transmits your document to summarize it has, at minimum, transmitted your document. Retention decides how long it exists on their side and who could reach it. “Zero data retention” is a strong claim with a specific meaning, and it is worth confirming rather than assuming. We spelled out what it does and does not cover in what zero data retention actually means.
What to Actually Do
When a tool enables an AI feature, run three checks. Find the training toggle and turn it off for confidential work. Read the retention terms for the feature specifically, not the general policy. And decide whether the feature should be on at all for the material you handle, or only for low-sensitivity content.
If the feature acts rather than just drafts, treat it with the fuller scrutiny an agent deserves. We covered that in how to vet an agentic feature before you enable it.
For the material that genuinely cannot leave your control, the cleanest answer is not a toggle at all. A local tool that processes your text on your own machine has nothing to send and nothing to retain, which removes the default-on risk entirely. Where your work touches personal data, that also simplifies your obligations under regimes like the GDPR, because there is no third-party processing to account for.
How to Flag This to Your Team
When a vendor flips a default, the useful internal message is specific about what to change.
Before:
Heads up, the document tool has AI now, might want to check your settings.
After:
The document tool enabled AI summaries by default this week, and the “help improve our models” toggle is on by default too. For any client file, turn that toggle off in Settings under Privacy. Do not use the summary feature on privileged material at all until we confirm the retention terms.
The second version names the toggle, the location, and the exception, which is what makes people actually do it.
A Wrivio Context for a settings advisory could say:
Rewrite this as a clear internal advisory. Keep every setting name, location, and toggle exactly as written. State the specific action for each person. Do not generalize a specific instruction into “check your settings.”
Press Ctrl+Shift+Space, paste your draft, and check the diff. A rewrite that keeps “turn that toggle off in Settings under Privacy” precise is doing its job; one that softens it to “review your privacy settings” has removed the instruction.
Common Questions
Why are AI features on by default now?
Because opt-out adoption numbers look better than opt-in, so many vendors enable new AI features by default. A feature being on means you did not turn it off, not that you agreed to everything it does.
What is the most important setting to check?
Usually whether your content is used to train or improve the provider’s models. It is often a separate toggle from the feature itself and often on by default, and for confidential material it can be a disclosure you are not permitted to make.
Does turning off the feature stop my data being used?
Not necessarily. The feature toggle and the training or data-use toggle can be separate. Turn off both, and check the retention terms for what was already sent.
How do I avoid the default-on risk entirely for sensitive work?
Use a tool that processes your text locally on your own machine. If nothing is transmitted, there is no default setting that can send or retain your content.
Is “improve our services” the same as training on my data?
Often, yes. Vague phrases like “improve our services” can include using your content to train models. Look for an explicit statement that your content is not used for training, ideally as a contractual term.
Download Wrivio for Windows to rewrite confidential text on a local model with no default toggle to check, because nothing ever leaves your machine.
Read Next
Zero-Click Agent Hijacking: What It Means for Work
Researchers showed an AI browser agent hijacked by a poisoned calendar invite, with no click required. What that changes about handing work to an agent.
What Happens to Your Data When an AI Startup Is Acquired
Acquisitions and shutdowns can rewrite the privacy terms you agreed to. What to check now, and why portable, local options age better.
What Your Data Is Exposed To When An Agent Acts For You
When an AI agent acts on your behalf it reads context, browses, and sends data to services. What actually leaves your machine, and how to scope the access.
Why Your AI Assistant Suddenly Feels Different
Your AI tool can change overnight with no new name and no changelog. Here is why it happens and how to keep your writing output stable anyway.
This article is filed underPrivacy & Compliance, which has 85 articles.