Guide

AI and your company data: what to never paste

The risk is not the model. It is the tier you are on and the file you paste.

8 min read·Back to guides
A locked filing cabinet in an office

Most data incidents involving AI are not breaches. Somebody pasted something into a free account because it was the fastest way to get the job done, and nobody had ever told them where the line was. Here is where it is, and how to write it down in one page.

4
Questions before pasting
2
Tiers that behave differently
1
Page the rule should fit on
0
Times a ban has worked

The consumer tier and the business tier are different products

This is the distinction almost everybody misses, and it decides most of the rest.

On consumer tiers, the default has often been that conversations may be used to improve the service, with an opt-out somewhere in settings. On business and API tiers, providers generally commit contractually that your inputs and outputs are not used for training, and offer retention controls.

The words to look for are the same across providers: whether inputs are used for training, how long they are retained, whether a zero-retention option exists, and whether there is a data processing agreement. Read those four things on the tier you are actually on, not the one on the marketing page. Terms change; check the date on what you read.

Until somebody has done that reading and written down the answer, treat every model as a public place.

Four questions before anything is pasted

Would you email this to a supplier you have never met? If not, it does not go in a consumer tier.

Does it identify a person? Names, emails, phone numbers, addresses, health, payment details. Personal data does not stop being personal because it is inside a spreadsheet you are trying to summarise.

Did somebody else trust you with it? A customer's contract, an employee's file, a partner's forecast. Their agreement with you almost certainly did not anticipate this, and that is a question for the agreement, not for the person in a hurry.

Would it hurt if a competitor read it? Pricing, roadmaps, cap tables, the terms of a deal in progress.

One no is enough to stop. The point of four questions rather than a judgement call is that they can be answered in ten seconds by somebody who is not thinking about risk.

Kind of thingWhere it can go
Public marketing copy, published docsAnywhere, including consumer tiers
Internal drafts with no names or numbersBusiness tier
Customer or employee personal dataBusiness tier, only with a lawful basis and a DPA
Contracts and terms held on trustBusiness tier, and check what you agreed
Credentials, keys, tokensNowhere, ever

Redaction beats permission

The fastest way to make a document safe is usually to make it boring.

Most jobs do not need the identifying parts. Summarising twenty support tickets works just as well with names replaced by customer one through twenty. Analysing a contract works on the clauses, not on the parties. Modelling a forecast works on the shape of the numbers, not on the client they belong to.

Build the habit of asking what the model actually needs to see. It is faster than an approval process, it survives a change of provider, and it is the only control that keeps working when somebody uses a tool nobody has vetted.

The rule that fits on one page

Long policies do not get read and bans do not get followed. What works is a page with three lists and one route.

Green: things anybody may paste anywhere. Published material, generic questions, code with no secrets in it.

Amber: things that go in the company account only. Internal drafts, anonymised customer text, anything you would show a colleague but not a stranger.

Red: things that go nowhere. Credentials, personal data without a lawful basis, anything held under someone else's terms.

And one route: who to ask when something does not fit, with an answer promised the same day. That last line is what stops the rule from being routed around, and its absence is why most of these documents fail.

What this is not

This is a practical filter, not legal advice, and the specifics depend on where you are and what you agreed. If you handle health data, children's data, or payment details, or if you operate under GDPR, the UAE's PDPL, or a sector regulator, the questions above are the start of a conversation with somebody qualified rather than a substitute for one.

What it will do is stop the ordinary incident, which is not a sophisticated attack. It is a spreadsheet of customers in a free account on a Friday afternoon because the deadline was Monday and nobody had said otherwise.

Give people a fast, allowed path. A rule that makes the safe route slower than the unsafe one is a rule that teaches people to hide what they are doing.

Templates for the paperwork

Have a question?

We're here to help. Get in touch and let's talk.