When Someone Quits, Does Their AI Account Leave With Them?
Every business we work with has an offboarding checklist. Disable the Microsoft 365 account. Revoke VPN and MFA. Collect the laptop. Forward the mailbox to a manager. Transfer file ownership. Change t...

Every business we work with has an offboarding checklist.
Disable the Microsoft 365 account. Revoke VPN and MFA. Collect the laptop. Forward the mailbox to a manager. Transfer file ownership. Change the shared passwords they knew.
Almost none of them have a line on that checklist for AI.
So when someone gives notice, the account they have used every day for the last eighteen months leaves with them. The one they signed up for with a personal email address, on a personal card, and never mentioned to anyone.
Along with everything they ever put into it.
What Is Actually In That Account
Think about what a motivated employee pastes into a chat window over a year and a half of trying to work faster.
Client contracts they wanted summarized. Pricing sheets they were building a proposal from. Payroll figures they needed reformatted. Draft employment letters. Customer lists they wanted deduplicated. Meeting notes with names and numbers in them. A vendor agreement they wanted the risky clauses pulled out of.
None of that was malicious.
Every one of those is somebody trying to do a good job.
But collectively it is a copy of your business sitting in a system you do not own, cannot see into, and have no way to switch off.
Four Ways This Bites
You cannot revoke it. There is no admin console for you to log into. The account belongs to them. When they leave, you have no mechanism to end their access to what they put in there. Your only real control is asking nicely.
You cannot prove anything. When a client, an insurer or an auditor asks what company data has been entered into AI tools, the honest answer is that you do not know. That question is now showing up in cyber insurance questionnaires, SOC 2 reviews and HIPAA assessments. "We do not know" is not a defensible position. It is a finding.
Consumer tiers are not built for your data. Business and enterprise plans carry contractual commitments that your conversations are not used to train models, plus retention controls, admin visibility and audit logging. Free and personal tiers generally do not, unless an individual employee happened to find and flip the right setting. You are relying on a toggle you cannot verify, in an account you cannot see.
The knowledge walks out too. This is the one businesses underrate. Your sharpest person did not just chat with AI. They built things — saved projects with your context loaded in, prompts refined over months that turn a two-hour task into ten minutes. That was a real productivity asset, funded out of your payroll. On their last day it disappears completely, and nobody ever writes down what was lost.
Banning It Makes This Worse
The instinct is to block it. Firewall rule, acceptable-use clause, done.
It does not hold.
AI is on everyone's phone. It is built into the browser, the search bar and half the applications your team already uses. A ban does not stop the behavior. It pushes it somewhere you have no visibility at all, and now nobody will tell you what they are using, because admitting it means admitting they broke the rule.
You end up with all of the exposure and none of the information.
The businesses handling this well went the other direction. They made it easy to do the right thing.
What Doing This Properly Looks Like
One approved platform, provisioned by the company. The specific choice matters less than the fact that the company owns the tenant. Budget roughly $25 to $30 per user per month.
Tied to your identity provider. Single sign-on through Microsoft Entra, so AI access is created and destroyed by the same process that handles email. When someone is offboarded, their AI access dies in the same click. That solves the problem structurally instead of by remembering.
Admin controls that are actually yours. Retention settings you choose. Audit logs you can pull. Visibility into which teams are using it and for what.
A written policy people can follow. One page. Which tools are approved. What data classes are permitted, and which — client records, patient data, credentials, source code, financials — are not. What output must be human-reviewed before it reaches a client. Who to ask when someone is unsure. Then train on it and have it signed, rather than filing it.
Amnesty on the way in. Tell people plainly that whatever they have been using, nobody is in trouble, and everyone is moving onto the company platform. You will learn more about your real exposure in that one conversation than in any audit.
The Resignation Test
Pick your most AI-fluent employee and ask four questions.
If they resigned this afternoon, could you terminate their AI access in the same step as their email?
Could you retain the projects, prompts and workflows they built for the business?
Could you tell a client, in writing, what company data has gone into an AI tool this year?
Is any of it covered by a contract that says your data is not training a model?
If the answer to any of those is no, you do not have an AI problem. You have an unmanaged AI problem. Those are very different things when something goes wrong.
Where To Start
You do not need a committee or a six-month project.
Start with the conversation. Find out what your team is genuinely using today. Then pick one platform, provision it through your existing logins, write the one-page policy, and move everyone across. For most small and mid-sized businesses that is a couple of weeks of work, not a quarter.
The worst time to discover that your company's AI account belongs to someone else is the day they hand in their notice.
If you want to know where you stand, Methodology IT can walk your environment with you and show you what is in use, where the data is going and what your policy should say.
Learn more at methodologyit.tech or call 800-270-0016.
Ready to make IT work?
No pressure, no sales pitch. A senior tech will walk your environment with you and leave you with a report — whether you hire us or not.