Ignoring the Einstein Trust Layer
One of the biggest mistakes is not understanding the foundational security architecture Salesforce has built for its AI tools. The Einstein Trust Layer is not an optional add-on; it's a core component that works in the background to protect your data.
It acts as a secure intermediary between a user's prompt and the large language model (LLM), whether it's a Salesforce model or one from a partner like OpenAI. This layer is designed to perform several critical functions automatically, including secure data retrieval, data masking, and detecting toxicity in prompts and responses. Thinking you can use Salesforce AI without relying on this built-in protection is a critical error. Instead, teams should educate themselves on how the Trust Layer functions to ensure it's leveraged correctly and its protections aren't inadvertently bypassed.
Assuming 'Zero Retention' Means Zero Risk
Salesforce promotes a “zero data retention” policy, which means your prompt data is not stored by third-party LLMs or used to train their global models. This is a crucial feature, but it's a mistake to equate it with a total absence of risk. The data still travels, and the policy primarily covers the LLM interaction itself. The entire process is logged in an audit trail within your Salesforce environment for compliance and monitoring. This audit trail contains metadata about the interaction, which is essential for governance but also creates a new data source to be managed. The mistake is forgetting that while the LLM doesn't keep your data, the interaction still creates records that must be secured and monitored according to your own company's data handling policies.
Using 'Dirty' Data for AI Grounding
Salesforce AI is most powerful when it's “grounded” in your company's specific CRM data, making its responses relevant and accurate while reducing hallucinations. The process of dynamic grounding involves securely retrieving your customer data to provide context for the AI's response. However, if your underlying data is a mess—full of duplicates, outdated information, or inaccuracies—the AI will produce flawed and unreliable output. A major mistake is activating advanced AI features without first implementing a robust data hygiene strategy. Before deploying AI tools like Einstein Copilot, you must ensure the source data is clean, unified, and trustworthy. Otherwise, you're simply asking the AI to make confident decisions based on bad information.
Neglecting User Permissions and Access Controls
Just because an AI feature is available doesn't mean every user should have access to it. Rolling out AI tools with default, overly broad permissions is a significant privacy misstep. The Einstein Trust Layer respects your existing Salesforce security model, meaning an AI-generated response won't include data a user is already unauthorized to see. But this only works if your user permissions are correctly configured in the first place. The mistake is not treating AI features like any other powerful tool that requires specific permission sets. Admins should create dedicated permission sets for AI features, assigning them only to trained and authorized users. Furthermore, field-level security should be reviewed to restrict AI models from accessing the most sensitive data fields unless absolutely necessary.
Forgetting to Check the Default Opt-In for Data Sharing
Separate from how AI features use your data internally is the question of how Salesforce itself might use your data. According to its Main Services Agreement, Salesforce can use customer data to train global predictive models and for research unless you explicitly opt out. A critical mistake is assuming you are opted out by default. For most customers, the toggle to allow this data usage is on by default. Admins need to navigate to the “Opt Out of Customer Data Access” setting and disable it if they do not want their data used for Salesforce's broader R&D. For organizations handling sensitive information, such as nonprofits or healthcare providers, failing to check this one simple setting can lead to unintended data exposure.
Failing to Audit AI-Generated Content and Interactions
Even with the Trust Layer's safeguards, AI can make mistakes or be used improperly. A final privacy error is deploying AI without a process for auditing its output and usage. The Einstein Trust Layer provides an audit trail for a reason: accountability. These logs help you trace data exposure, monitor for misuse, and refine your AI strategy. This includes reviewing AI-generated emails for tone, accuracy, and whether they inadvertently reveal sensitive details that data masking might have missed in a complex context. Without regular audits, you have no way of knowing if the AI is performing as expected or if it's creating silent compliance risks. Treat AI as a new category of user activity that requires its own dedicated oversight.













