The Myth of the Private Chat
It’s easy to think of a conversation with an AI chatbot as a private dialogue between you and a machine. But that’s a dangerous misconception. When you enter a prompt into a public AI tool like ChatGPT, that information doesn’t just disappear after you get
a response. It travels from your computer to the AI company's servers. Depending on the provider's terms and your account settings, that data can be stored and even reviewed by human employees. More importantly, many consumer-grade AI models use your conversations to train future versions of their software. This means your proprietary code, confidential client information, or internal strategic notes could potentially be absorbed into the model, creating a risk of it being surfaced in a response to another user down the line.
Real-World Risks and Consequences
The threat of leaking sensitive information isn't just theoretical; it's already happened. In a high-profile case, Samsung employees accidentally leaked confidential source code and internal meeting notes by using ChatGPT to assist with their work. The incident led Samsung to ban the use of such generative AI tools on company devices. This is not an isolated incident. Studies have found that a significant percentage of information employees paste into public AI tools is confidential, ranging from financial data to customer details and legal information. The consequences of such leaks are severe, including the loss of trade secrets, violations of data privacy regulations like GDPR, and significant reputational damage. It also risks waiving legal protections like attorney-client privilege, as a UK tribunal noted when it stated that putting client information into a public AI is like placing it in the public domain.
Your NDA Still Applies
Every employee who signs a contract agrees to confidentiality clauses and non-disclosure agreements (NDAs). These legal obligations don't become void just because the 'person' you're disclosing information to is an artificial intelligence. Sharing sensitive company data with a public AI chatbot is a form of third-party disclosure. You have no control over how that third party—the AI company—will use, store, or protect that information. As a result, pasting a client’s confidential project details or your company's unannounced financial results into a prompt is almost certainly a breach of your employment agreement. Companies are responding by creating specific internal policies that govern the use of AI, often prohibiting any proprietary or client information from being used as an input.
How to Use AI Safely and Smartly
Banning AI entirely isn't the answer, as that often just pushes usage into the shadows. The key is to use it responsibly. First and foremost, check if your company has an official AI usage policy. Many businesses are now adopting enterprise-grade AI solutions that come with contractual guarantees that your data will not be used for training models or stored long-term. When using any AI tool, adopt the habit of anonymising your data. Instead of pasting real names, figures, or project details, use generic placeholders like "Company X," "Client A," or "Product Z." Use AI for tasks that don't require sensitive information, such as brainstorming generic ideas, improving the grammar and style of a non-confidential email, or summarizing publicly available articles. The goal is to leverage AI's power without compromising the data you're paid to protect.














