The Core Risk: Why Secrecy Matters
When you input information into a public AI tool like ChatGPT, you are essentially sending that data to a third party. Many free AI models use the data they receive to train their systems, meaning your prompts could potentially be seen by others or become
part of the model's future responses. The consequences can be severe, ranging from regulatory fines under laws like GDPR to the loss of valuable intellectual property, such as source code or strategic plans. Even seemingly harmless information can be pieced together to reveal confidential details about company operations or clients. One study found that approximately 8.5% of employee prompts to AI tools contain sensitive data, including customer information and internal financial details. This unintentional sharing is a significant data security risk that every employee must help prevent.
The Golden Rule: Think Before You Prompt
The simplest way to stay safe is to adopt a single guiding principle: Never input anything into a public AI tool that you wouldn't feel comfortable posting on a public internet forum. This includes names, contact details, financial figures, internal project names, client information, and proprietary code. Before you paste any text or upload a document, pause and ask yourself if the information is public knowledge or internal and confidential. This simple habit is the first and most effective line of defence against accidental data leaks.
Green Light: Safe Tasks for Public AI
AI is an excellent assistant for many general tasks that don't involve sensitive data. These 'green light' activities are generally safe to perform with public AI tools. You can ask an AI to brainstorm generic marketing slogans, draft a standard professional email, or explain complex public topics in simple terms. It's also useful for improving the grammar and style of non-confidential text, writing boilerplate code snippets that don't contain proprietary logic, or summarizing publicly available articles and reports. In these cases, you are leveraging the AI's language and reasoning capabilities without feeding it sensitive information.
Yellow Light: Proceed with Extreme Caution
Some tasks fall into a grey area where AI can be used, but only after careful data sanitisation. This is where 'prompt hygiene' becomes critical. For example, you might want to analyze customer feedback trends or generate a report from a spreadsheet. To do this safely, you must first anonymise the data. Replace all personally identifiable information (PII) like names, addresses, and account numbers with generic placeholders (e.g., “Customer A,” “Location 1”). Instead of using exact financial figures, use ranges or generalised descriptions. The goal is to provide the AI with the structure and context of the data without revealing any of the confidential specifics. This approach requires diligence, as even a combination of anonymised details can sometimes be used to re-identify an individual or company.
Red Light: Tasks to Never Perform with Public AI
Certain categories of work should be considered strictly off-limits for public AI platforms. Never upload or paste legal contracts, documents related to litigation, or information covered by attorney-client privilege. Avoid inputting unreleased financial reports, strategic business plans, employee performance reviews, or personal employee data like salaries and health information. Customer lists, proprietary source code, and any data protected by a non-disclosure agreement (NDA) are also firmly in the red zone. Performing these tasks with public AI is equivalent to a voluntary disclosure of your company's most valuable secrets to an unauthorised third party.
Always Defer to Company Policy
While these guidelines offer a solid starting point, your employer's official policy is the ultimate authority. Many companies are now providing employees with enterprise-grade AI tools, such as Microsoft Copilot for Enterprise or Google Gemini for Workspace, which come with contractual privacy and security guarantees that public tools lack. These platforms are designed to keep your company's data isolated and confidential. Your organisation's IT or security department will have specific rules about which tools are approved for use and what kinds of data can be used with them. Always familiarise yourself with these internal policies and complete any required training on responsible AI use. When in doubt, ask your manager or IT support before using an AI tool for a work-related task.















