1. Inputting Personal Information
The most direct mistake is treating a public AI chatbot like a private diary. Pasting in text that includes your full name, student ID number, home address, phone number, or other personally identifiable information (PII) is a significant risk. These
details can be stored, reviewed by humans, or exposed in a data breach. Once your information is on a third-party server, you lose control over it. AI companies often use conversation data to train future versions of their models, meaning your personal details could be integrated into the AI's knowledge base. The golden rule is simple: if you wouldn't post it on a public website, don't enter it into a consumer-grade AI tool.
2. Uploading Confidential Academic Work
It’s tempting to upload an entire draft of a research paper or sensitive lab data to an AI for help with editing or analysis. However, doing so can have serious consequences. Many AI tools state in their terms of service that they can use submitted data for model training. This means your unpublished research, unique ideas, or proprietary code could become part of the training set, potentially showing up in someone else's query down the line. This not only jeopardises your intellectual property but can also be a breach of university policy or federal privacy laws like FERPA, especially if the data includes information about other students or research participants.
3. Ignoring Privacy Policies and Settings
When you sign up for a new tool, it’s easy to click “agree” without reading the privacy policy. This is a critical error. These documents, though often long and dense, detail exactly how the company collects, uses, and shares your data. Some companies have been found to opt users into data sharing by default. Taking a few minutes to review the policy and, more importantly, to check the tool's privacy settings can make a huge difference. Many platforms offer options to disable chat history or prevent your data from being used for model training. Actively managing these settings is one of the easiest and most effective ways to protect your information.
4. Using Unvetted Tools and Extensions
The AI boom has led to a flood of new apps, browser extensions, and websites all promising to make your life easier. However, not all of these tools are created equal. Many unvetted AI applications may have lax security or request excessive permissions, such as the ability to read your browsing history or access your files. This creates a risk of malware or data leakage. It is much safer to stick with tools that have been approved by your university or are offered by major, reputable companies with clear data protection policies. Your university's IT department often provides enterprise versions of popular AI tools that come with enhanced commercial data protection, ensuring your inputs are not used to train public models.
5. Mixing School and Personal Accounts
Using your personal AI account for university work or your university-provided AI account for personal matters can create privacy headaches. Using a personal account for sensitive academic data might violate your school's data security policies and bypass the enterprise-level protections your university pays for. Conversely, using your school account for personal queries—like asking for medical information or financial advice—means your employer (the university) could potentially access that data. The best practice is to maintain a strict separation. Use university-provided accounts exclusively for schoolwork and a separate personal account for all other tasks, ideally on different browsers or profiles to keep them fully isolated.














