A Cybersecurity Awareness Month series from Thompson Coburn’s Data Governance, Privacy and Cybersecurity practice group
In 2020, a hacker went undetected for three months inside the network of Blackbaud, a South Carolina company that provides fundraising, financial, and administrative software to nonprofits, schools, and other organizations. During that time, the hacker removed large amounts of unencrypted consumer data belonging to Blackbaud’s customers. According to the FTC’s complaint, those customers numbered about 45,000 and included companies, schools, nonprofits, and health care organizations.
The Blackbaud breach was not an AI incident. We start with it because of what the FTC emphasized. Blackbaud’s security failures allowed the intrusion. Its retention practices “exacerbated the severity of the breach.”
The Retention Lesson
The FTC alleged that Blackbaud “did not enforce its own data retention policies, resulting in the company keeping customer’s consumer data for years longer than was necessary.” In some instances, “Blackbaud retained data belonging to former 2 customers, customers who had switched to products not affected by the breach, and even potential customers for years longer than was necessary.” Because Blackbaud retained backup files indefinitely, people whose data otherwise would not have been involved were swept into the breach.
The FTC treated that retention as a violation in its own right. It brought a standalone unfairness count for unreasonable data retention, which commentators described as the agency’s first. The final order, approved in May 2024, requires Blackbaud to delete data it no longer needs to provide its products or services and to maintain a data retention schedule.
The FTC order was one of several consequences. Blackbaud also paid $49.5 million to settle with 49 state attorneys general and the District of Columbia over a breach that affected more than 13,000 of its customers. Separately, it paid a $3.0 million civil penalty to resolve an SEC investigation of the incident.
Why Retention Becomes an AI Question
An AI tool connected to an organization’s systems processes the data those systems hold. That includes data the organization retains, but no longer needs and may have forgotten it has. Old exports, legacy files, and records of former customers, students, or employees all become material a connected tool might search, summarize, or surface.
Recent FTC orders follow a consistent pattern that applies to AI deployment inside of organizations.
Illuminate Education (2026). In late December 2021, a hacker used a former employee’s credentials to access Illuminate’s cloud databases. The data reached included 10.1 million students’ data, including students’ email and mailing addresses, dates of birth, student records, and health information. The FTC finalized its order on June 5, 2026. Per the order, Illuminate must delete personal information it no longer needs and follow a publicly available retention schedule that explains why each type of information is collected and when it will be deleted. For institutions that handle student data, the case shows how credentials and records left in place after a relationship ends remain points of exposure.
Drizly (2022). The FTC alleged that Drizly did not put a senior executive in charge of data security. The FTC order requires Drizly to delete consumer information it does not need and to publish a retention schedule that rules out indefinite retention. Its security program must also systematically inventory consumer information. For 10 years, the order follows the CEO to certain future companies, where he must ensure that an information security program is in place. The case shows that regulators look past retention policies to whether someone with authority is responsible for carrying them out.
Two recent examples involving AI products show the same problem.
A forgotten account at an AI vendor. In 2025, security researchers accessed the administrative interface for McDonald’s AI-powered hiring platform, McHire, built by Paradox.ai. They got in through a test account that used “123456” as both the username and the password. The researchers estimated that up to 64 million applicant records were exposed. Paradox said the account had not been used since 2019 and had been missed in its annual penetration tests. It also said it was confident no third party other than the researchers had accessed the account. No regulator has made findings here. The example still shows how an untracked account can sit in front of a large store of data that no one needed to keep accessible.
What to Establish Before Connecting AI
Before connecting an AI tool to organizational systems, establish five things about the data involved. Each one leads to a specific action.
- Identify the data held. Determine the categories of information in the systems the tool would touch. Include sensitive categories such as Social Security numbers, financial account information, student records, and health information. An organization that can’t describe what a system contains is not ready to decide whether a tool should have access to it.
- Locate where it lives. Map the data across production systems, shared drives, collaboration platforms, backups, and vendor environments. Blackbaud’s most significant retention problem involved backup files, a location an AI deployment review can miss.
- Confirm whether it is still needed. Compare what the organization holds against its retention schedule, and confirm the schedule is actually followed. For institutions subject to the GLBA Safeguards Rule, disposal is already a legal obligation. Subject to limited exceptions, the Rule requires covered institutions to dispose of customer information no later than two years after its last use for a legitimate business purpose, and to periodically review their retention policies. Delete data the schedule says should be gone before the tool is connected.
- Review who and what can access it. Check user permissions, service accounts, test accounts, and the credentials of former employees and contractors. Illuminate and Paradox both involved access that should have ended and didn’t.
- Decide which sources the tool should reach. Limit the tool to the data its intended use requires, not everything a connected user can technically reach. Assign that decision to a named owner who understands both the business purpose and the data, and document it.
Retention Decisions Are Now AI Decisions
It’s not uncommon for retention schedules to be managed as a records function, separate from technology planning. AI deployment is a good reason to bring the two together. Data an organization retains may become available to an AI tool, which can access it, process it, and draw on it in the outputs it returns. Deleting data the organization no longer needs reduces what any tool, user, or attacker can reach. It’s also a step the organization can take before deployment begins.
Next week, we turn to what happens when AI surfaces gaps that were already present in an organization’s permissions and data practices, and to who should own the response when it does.

