Why Your Prompts Aren't Private
When you use a public generative AI tool, your conversations may not be as confidential as you think. Many AI companies use the data you provide—your questions, your uploads, and your feedback—to further train their models. A recent Stanford study confirmed
that several leading AI developers use customer conversations by default to improve their systems, and not all make it easy to opt out. Think of it this way: if you wouldn't post the information on a public forum, you shouldn't enter it into a standard AI chatbot. The data can be stored, reviewed by human employees, or potentially exposed in a data breach, creating risks for both you and your employer.
Rule 1: Protect Company Secrets
The most critical boundary for any professional is protecting company information. Never paste any internal data that is not public knowledge into a public AI tool. This includes unpublished financial reports, customer lists, business strategies, marketing plans, and internal memos. A significant risk involves proprietary code and intellectual property. Pasting chunks of your company's source code into a chatbot to debug it might seem efficient, but it could mean feeding your organisation's digital crown jewels directly into a third-party system, where it can be absorbed by the model. Always use company-approved AI services, which often come with enterprise-grade security and contracts that prevent your data from being used for model training.
Rule 2: Safeguard Personal and Client Data
Personally Identifiable Information (PII) should be treated with extreme caution. This category includes anything that can be used to identify an individual, such as names, Aadhaar or PAN card numbers, physical addresses, email addresses, and phone numbers. Sharing this information, whether it's your own or a client's, exposes individuals to the risk of identity theft, profiling, and fraud. The same rule applies to sensitive personal data like medical records, bank statements, or credit card numbers. While asking an AI to explain a financial concept is fine, asking it to analyse your personal bank statement is a serious privacy violation.
Rule 3: Keep Credentials and Access Keys Offline
Under no circumstances should you ever share login credentials with an AI chatbot. This includes usernames, passwords, API keys, authentication codes, or anything else used to access secure systems. Even if you're trying to troubleshoot a technical issue by pasting a log file, you must first scrub it of any sensitive access information. These details are a primary target for malicious actors, and leaking them could lead to a catastrophic security breach for your company or your personal accounts. For generating and storing passwords, a dedicated password manager is a far more secure choice.
How to Use AI More Safely
Being cautious doesn't mean you can't benefit from AI. The key is to use it responsibly. First, check if your company provides an enterprise version of an AI tool, like Google's Gemini for Workspace or ChatGPT Enterprise. These business-focused platforms typically have stricter privacy controls and do not use your data for training by default. Second, for public tools, go into the settings and opt out of data sharing for model training where possible. Many services now offer this feature. Finally, practice good data hygiene. Before you ask AI for help, generalise your query. Anonymise any data by removing names, specific figures, and other identifying details. The goal is to give the AI the context it needs without handing over sensitive information.














