First, Define 'Confidential'
Before you can protect confidential information, you need to know what it is. In a business context, this isn't just about top-secret formulas. It includes a wide range of data that isn't publicly known and gives your company a competitive edge. This
can be anything from financial records, marketing strategies, and customer lists to internal operational details and employee records. Think about client data you're contractually obligated to protect, proprietary source code, unpublished financial results, or even internal strategy documents. Any information that could harm the company or benefit a competitor if it were leaked is considered confidential. Many employees use AI tools without fully realising that the prompts they are using contain this kind of sensitive data.
Know the Default Data Policies
The biggest risk with public AI chatbots is that they are not inherently private. Many popular services use the conversations you have with them to train their future models. This means that when an employee pastes a chunk of a sensitive report or a customer email into a public chatbot to summarise it, that data can be absorbed by the AI and potentially resurface in a response to another user, or be exposed in a data breach. This is a critical point: once you hit 'enter,' you may lose control of that information. Unless you are using a specific business or enterprise version of a tool, you should assume your conversations are not fully private by default.
Master the Art of Anonymisation
One of the safest ways to use public chatbots is to scrub your prompts of all sensitive details. This is called data anonymisation. The goal is to provide enough context for the AI to give you a useful answer without revealing any confidential specifics. For example, instead of asking, “Review this contract between Acme Corp and our client Stark Industries and highlight the penalty clauses,” you could ask, “Review this sample contract and highlight all penalty clauses.” You can replace names, company details, financial figures, and other specific identifiers with generic placeholders like “Company A,” “Client B,” or “Project X.” The AI can still understand the structure and intent of your request, but you haven't exposed any real-world data.
Check for Privacy Settings
Many AI providers are aware of these privacy concerns and have started to offer more robust controls. Some consumer versions of popular chatbots now have settings that allow you to disable chat history and prevent your conversations from being used for model training. It’s crucial to find and enable these features before you start using the tool for any work-related tasks. Take a few minutes to explore the settings or privacy policy of any AI tool you use. While these settings provide a layer of protection, they don't eliminate all risks, especially from security vulnerabilities. However, they are a fundamental first step in protecting your inputs.
Advocate for Company-Approved Tools
The safest long-term solution is to use AI tools that are officially approved and managed by your company. Many organisations are now adopting enterprise-grade AI platforms that come with strict data privacy guarantees. These business-focused versions are designed for security, often ensuring that your company's data is never used for model training and is encrypted both at rest and in transit. If your company doesn't have a clear policy on AI usage, now is the time to ask for one. A formal policy clarifies which tools are safe to use, what kind of information is off-limits for public platforms, and provides a clear set of rules for everyone to follow. This prevents 'shadow AI' usage, where employees use unapproved tools without oversight.
Always Review AI-Generated Content
Beyond data privacy, there's the risk of inaccuracy. AI models can 'hallucinate,' meaning they can invent facts, figures, or sources that sound plausible but are entirely incorrect. Using unverified AI output in a report, proposal, or client communication can lead to significant errors and damage your company's reputation. Always treat AI-generated content as a first draft, not a final product. A knowledgeable human must review, fact-check, and edit the output before it is used for any official purpose. Your professional judgment remains your most important tool.














