Which AI model does Box AI use, and how does the AI model work?
Box AI uses AI foundational models from multiple vendors, such Microsoft, Google, and others. We have a commitment to transparency of AI models, and we will always provide information on which models are used.
Does Box AI use an external service, or are all models internal?
Box AI takes a platform-neutral approach to apply the best AI models depending on the need. Box currently uses models from vendors such as Microsoft, Google, and others.
How does Box AI work with user data?
The Box AI Platform handles interactions with the user’s content and AI. First, a query is submitted to the AI Platform. The query will gather relevant data from the user’s file; for example, if the user is asking a question about a document, the most relevant parts of the document are retrieved. The AI model then evaluates the query and relevant content and returns a response to the Box AI Platform, which is then sent back to the user. Throughout the interaction, the Box AI Platform ensures that the user can only see information that they have permission to access.
How does Box help protect customers from malicious AI-generated answers?
We evaluate the LLMs offered by our trusted technical partners on a safety basis to avoid exposing users to malicious answers they may inadvertently generate. Box will only engage with providers that have rigorous controls in place to prevent malicious content. Additionally, we test use cases regularly to ensure all models meet our high standards of quality and safety.
Is data cached or saved by model providers for any reason? If so, what data and for how long (e.g., request text, text representation)?
Box model providers do not log or store any information that a customer submits. The model provider processes the query and keeps the information in memory only for the time needed to return the response. Box does not train on any data, nor do any vendors train on any data that is sent from Box. Box AI will only ever train on data with customer approval.
What data/content/components of a file are transiting to any internal or external service to support these AI features?
The Box AI Platform is an internal Box service that handles AI queries. Based on the query, it retrieves relevant parts of content and sends the query together with the relevant text to an AI model (typically one that is hosted in a location like Azur or GCP) and then returns the response.
How is Box storing and using queries?
Box never stores user queries. Box logs the activity that a query was submitted for a file by a user, but we do not store the query or response.
Do model providers train on user data? Does Box?
No. Box’s model providers do not train on any data that they receive from Box. Box also does not train AI models based on customer data. This is a critical pillar to our AI principles and for our customers to know that it is safe to use AI without worrying their data will be leaked into a model and released. Note that in the future, customers may wish to have custom-trained AI models based on some of their content, but if Box releases this type of feature, the customer will explicitly approve that they want this type of trained model.
What specific controls are in place to ensure privacy of data?
Box safeguards customer data with robust security protocols, including encryption and data security best practices, ensuring that all content processed by Box AI remains secure and confidential.
Box AI is governed by Box’s built-in permissions, and it’s designed to keep customers in control of their data so that users can only see and interact with the files they are allowed to access. Box customers maintain control over their own data and processes. Customers may enable or disable the use of Box AI, and can decide whether or not Box AI should be applied to their content. Box does not store Box AI questions or answers, nor do our AI model providers. Our providers delete Box AI queries and results from their systems immediately once a response is returned. Once a document or application is closed in Box, all question and answer information is deleted from Box AI.