Understand the Core Risk
The main problem with using public AI tools for work is simple: when you input information, you often lose control of it. Many free or consumer-grade AI platforms, like the standard version of ChatGPT or Gemini, may use the data you provide to train their
future models. This means your query—containing anything from confidential client information, internal financial figures, or proprietary source code—could be stored on external servers and potentially become part of the model's vast knowledge base. It's less like a private conversation and more like posting on a public forum, where your data is no longer protected by your company's security policies.
Start with Your Company’s Policy
Before you use any AI tool for work, your first step should always be to check your company's official guidelines. Many organisations have now established formal AI usage policies that specify which tools are approved and what kinds of data are permissible to use with them. These policies are designed to create clear boundaries and reduce risk. They will often distinguish between public AI and approved enterprise-grade tools that come with security guarantees. If your company doesn't have a policy, raise the question with your IT or security department. Using unvetted 'shadow AI' tools on personal accounts for work purposes is a common source of data leaks.
Anonymise Your Data Before Prompting
One of the most effective practical steps you can take is to anonymise your data before pasting it into an AI prompt. This means systematically removing or replacing any sensitive details. Instead of using a real client's name, use a generic placeholder like "Client A." Swap out specific financial numbers, project codenames, and personal details with non-specific descriptions. The goal is to provide the AI with enough context to perform the task without giving away any confidential information. Think of it as creating a template of your problem rather than sharing the original, sensitive document.
Use Business and Enterprise-Grade AI Tools
Not all AI tools are created equal when it comes to data privacy. While free public versions often use your data for training, paid business or enterprise tiers typically offer much stronger privacy protections. Services like ChatGPT Team, Microsoft Copilot for Microsoft 365, and Google's enterprise AI solutions usually include contractual guarantees that your business data will not be stored or used to train their models. These platforms are designed for workplace use and often come with enhanced security features like data encryption and access controls, making them a much safer choice for handling internal information. If your team needs AI, investing in an approved enterprise account is one of the most reliable ways to protect company data.
Opt Out of Data Training Where Possible
Some public AI services provide an option to prevent your conversations from being used for model training. It's crucial to find and enable these settings. For example, in ChatGPT, you can often go into your settings and turn off 'Chat history & training.' When this feature is disabled, your conversations won't be saved or used to improve the model. While this adds a layer of protection, it shouldn't be your only line of defence. It's still a best practice to avoid inputting highly sensitive information, even with these settings enabled, as the data is still being processed on a third-party server.











