Understand the Core Risk
Publicly available AI models like ChatGPT learn from the vast amounts of data they process. When you input a prompt, that information can potentially be stored and used to train the model further. This means that if you paste a paragraph from a confidential
internal document or client communication, that sensitive information could become part of the model's knowledge base. A study found that a high percentage of employees admit to entering high-risk information into public AI tools. This creates a significant risk, as that data could inadvertently be surfaced in a response to another user, leading to a serious data breach.
The Golden Rule: Never Paste Sensitive Data
The most important rule is to treat public AI tools as if they are a public forum. Never input personally identifiable information (PII), proprietary source code, unreleased financial figures, client lists, legal strategies, or any internal data you wouldn't post on a public website. In 2023, employees at Samsung accidentally leaked confidential source code and internal meeting notes by pasting them into ChatGPT. This highlights the real-world consequences of treating AI as a private assistant. Unless your company has explicitly approved a tool for confidential use, assume everything you enter could be exposed.
Know the Difference: Public vs. Enterprise AI
Many companies are now adopting enterprise-grade AI solutions. Tools like Microsoft Copilot for Microsoft 365, Google Workspace AI, or ChatGPT's Team and Enterprise tiers often come with contractual guarantees that your company's data will not be used for training public models. These private, sandboxed environments are designed for business use. They allow employees to leverage AI on internal documents securely. The key is to use only the tools that your company’s IT or security department has vetted and approved. Avoid using free, public versions for work tasks involving any level of sensitive data.
Anonymise and Generalise Your Prompts
If you must use a public AI tool for a general task, learn to anonymise your data first. Instead of pasting, "Summarise this email from our client, Acme Corp, about their concerns with the Q3 revenue forecast of ₹5.2 crores," you should generalise it. A safer prompt would be, "Summarise this email from a client about their concerns with a recent financial forecast." You can replace specific names, figures, and project details with generic placeholders like `[Client Name]`, `[Product]`, or `[Financial Figure]`. This allows the AI to understand the context and perform the task—like improving grammar or structure—without being exposed to the actual confidential information.
Check for, and Help Create, a Company AI Policy
A clear corporate AI policy is essential for navigating this new landscape. Your organisation should have guidelines that define what constitutes confidential data, which AI tools are approved for use, and what the rules of engagement are. If your company doesn’t have one, raise the issue with your manager or IT department. Proactive employees can help shape responsible AI adoption. These policies are not meant to restrict innovation but to create a safe framework that protects the company’s intellectual property, client data, and regulatory compliance.
Always Verify the Output
Even when used safely, AI models can make mistakes, a phenomenon often called "hallucination." They can generate plausible-sounding but factually incorrect information. Never trust AI-generated content without a thorough human review, especially for important documents, code, or financial calculations. Using AI is about augmentation, not abdication of responsibility. You are still accountable for the final work product, including any errors or biases it may contain.














