Reading · 7 min · Lesson 2 of 9
Data you never paste
Personal data, secrets and client data: what may go into an AI tool and what may not.
The riskiest everyday habit is pasting sensitive information into an AI tool that has not been approved. Free consumer accounts may keep conversations and, depending on settings, use them to improve models. Once data has left your systems, you cannot pull it back.
Four categories should never go into unapproved tools: personal data covered by GDPR, such as names alongside health, salary or performance details; confidential client and partner information; trade secrets, including unreleased financials and strategy; and credentials, API keys and source code.
When you need AI for such material, use a company tool with a data processing agreement, or remove the identifying details first. Replacing names with roles, for example client A or employee 1, keeps most of the usefulness and removes most of the risk.
Key takeaways
- Data pasted into an unapproved tool cannot be taken back.
- Personal data, client data, trade secrets and credentials stay out.
- Use approved tools or anonymise before you paste.