Laptop displaying Cyber Security in a modern office setting

Photo by cottonbro studio on Pexels

Most employees now use an AI chatbot at work in some form, whether or not their employer has actually said yes to it. That gap between what people are doing and what companies have approved is where the real risk sits. AI tools are genuinely useful for drafting emails, summarizing documents, and speeding up research, and none of that has to stop. The point of this guide is not to talk anyone out of using AI at work. It is to walk through the handful of habits that keep a useful tool from quietly becoming the way sensitive company or customer information ends up somewhere it should not be.

None of what follows is legal advice. Data protection law varies by country and by industry, and your own company may have rules that are stricter than anything described here. Check your company's actual policy and your local law before treating any of this as the final word.

What happens to what you paste into a chatbot

What happens to your input depends entirely on which plan and which vendor you are using, so the honest answer is to check the current policy for your specific tool rather than assume. Consumer-facing free accounts have historically been more likely to use conversations to improve their underlying models unless a user manually opts out in settings, while paid business and enterprise plans typically state that customer data is excluded from training and comes with clearer retention limits. Vendors change these terms over time and the details differ between products, so this is a starting point for a conversation with your IT or compliance contact, not a fact to memorize and repeat.

Retention is a separate question from training. Even a tool that never trains on your input may still store the conversation for some period for abuse monitoring, debugging, or legal reasons, and that stored copy is itself something a company needs to think about if the input included anything sensitive. The NIST AI Risk Management Framework frames this kind of data handling as one of the core risks any organization deploying AI tools needs to actively manage, not something to assume away because the vendor seems reputable.

The practical takeaway is simple even without memorizing every vendor's fine print. Treat anything you type into an AI tool as something that leaves your control the moment you hit enter, unless you have specifically confirmed otherwise for the plan you are on. If you would not want that sentence forwarded to a stranger, do not paste it into a tool whose data policy you have not checked.

What you should never paste into any AI tool

Some categories of information carry enough risk that they should stay out of any AI chatbot regardless of which plan you are using, because the cost of a mistake is high and the benefit of pasting it in is small. Customer personal data is the first one: names paired with addresses, phone numbers, payment details, or account numbers should never go into a general-purpose chatbot to get help drafting a response or summarizing a complaint. Passwords and API keys are the second, and this one trips people up constantly when they paste an error log or a config file into a chatbot for debugging help without noticing a credential sitting in the middle of it.

Unreleased financials, source code covered by an NDA with a client or partner, and health information about employees or customers round out the list. None of these need to be handled by memorizing a long rulebook. A useful mental shortcut is to ask whether you would be comfortable saying the same sentence out loud in a crowded coffee shop. If the answer is no, it does not belong in a chat window either.

Check your company's AI policy before you start

The first real step is finding out whether your company already has a written AI policy, because a growing number do even at small businesses, and using it saves you from guessing. Ask your manager, HR, or IT contact directly if you have not seen one. A written policy usually settles the questions that otherwise get argued out informally in a group chat: which tools are approved, what data classes are off-limits, and who to tell if something goes wrong.

If no policy exists yet, that is worth flagging rather than treating as permission to do whatever seems reasonable. Small businesses without a formal policy are not exempt from data protection obligations just because nobody wrote them down. The FTC's business guidance on privacy and security makes clear that businesses are expected to handle personal information responsibly regardless of company size, so raising the gap with an owner or manager is doing them a favor, not creating extra work for no reason.

Use an approved business account, not your personal login

A personal AI account and a company-approved business account are not the same product even when they share a name and a logo. Business and enterprise tiers usually come with an admin console, clearer data handling terms, and sometimes the ability to keep company data inside a private workspace rather than a shared consumer environment. Using your personal login for work tasks means none of those protections apply, and your employer has no visibility into what was typed in or how it is being handled.

If your company has not set up an approved account yet, that is a reasonable thing to ask for rather than working around. Framing it as a request, something like asking whether the business can get a proper business-tier subscription instead of everyone using free personal accounts, usually lands better than either quietly using a personal account or quietly avoiding AI tools altogether.

Redact before you paste

A lot of the risk in everyday AI use can be removed with one extra step: strip out anything identifying before you paste text in, then add it back into the AI's response yourself afterward. Replacing a customer's real name with "the customer," swapping a real account number for a placeholder, or cutting a paragraph down to just the part you need help rewording all take a few seconds and remove the actual sensitive content from the conversation.

This habit is especially useful for the common task of asking AI to help draft a reply to an email or a support ticket. You can paste the customer's question with names and identifiers removed, get help with tone and structure, and then paste the identifying details back into the final message yourself, on your own system, where the chatbot never sees them.

Browser extensions and AI features that read everything on your screen

A browser extension that summarizes web pages, an AI sidebar built into your browser, or a plugin that reads your inbox to draft replies can end up seeing far more than the one task you installed it for, because many of these tools work by reading the content of whatever page or document is open at the time. That is convenient when you are looking at a public article and inconvenient when you forgot it was running while you had a spreadsheet of customer data open in another tab.

Before installing any browser-based AI tool for work, check what permissions it asks for and what it says about what it collects. An extension that requests access to read and change data on every website you visit is asking for more than most single-purpose tools actually need, and that gap between the permission requested and the task it claims to do is worth pausing on before clicking install.

AI note-takers joining meetings need consent

An AI note-taking bot that joins a call to transcribe and summarize it is recording a conversation, and recording a conversation without telling the people on it is a problem regardless of how useful the summary turns out to be. Rules about consent to record vary by location, and in some places every participant has to agree before a call can be recorded at all, so assuming it is fine because the tool is convenient is not a safe default.

The fix costs one sentence at the start of the call: say the meeting is being transcribed by an AI note-taker and give anyone on the call the chance to object before it starts recording. This matters even more for calls with clients or job candidates, where a bot silently capturing the conversation and later surfacing in an unexpected way can do real damage to a relationship that had nothing to do with the notes themselves.

Verify AI output before it reaches a customer

An AI-drafted email, product answer, or policy explanation is a draft, not a finished product, and treating it as finished before a human reads it is where a lot of AI mistakes at work actually happen. Chatbots can state a return policy that is not quite right, invent a detail about a product, or answer a legal or compliance question with something that sounds confident and is wrong. None of that shows up as an obvious error in the text itself, which is exactly what makes it risky.

The habit that prevents most of this is simple: read every AI-generated response that will reach a customer before it goes out, the same way you would proofread a message before sending it. This is especially important for anything touching pricing, refunds, medical or legal questions, or a specific promise about what the company will do, since those are the categories where an inaccurate answer creates a real obligation or a real complaint.

Keep a human accountable for every AI-assisted task

Every task where AI plays a role should still have a named person responsible for the outcome, not just for the AI's involvement in producing it. If an AI-drafted email goes out with wrong information, "the AI wrote it" is not an answer a customer or a regulator will accept, and it should not be the internal answer either. The company is responsible for what leaves its name on it, whoever or whatever drafted the first version.

In practice this means treating an AI tool the way you would treat a very fast, occasionally overconfident junior assistant. It can do a lot of the first draft, but a specific person signs off before anything reaches a customer, a regulator, or the public. Small businesses that skip this step tend to find out the hard way, after an error has already gone out, rather than catching it beforehand.

A one-page AI policy template a small business can adapt

A business does not need a long legal document to get most of the benefit of having an AI policy. A short one-page version, reviewed and adjusted with your own legal or compliance advisor, can cover the essentials:

Which AI tools are approved for work use, and where to ask if a tool is not on the list. What data must never be pasted into any AI tool, spelled out with the same categories covered earlier in this guide: customer personal data, passwords and credentials, unreleased financials, NDA-covered material, and health information. A requirement to use only company-approved business accounts for any task involving real customer or company data. A rule that AI-generated content going to a customer, a regulator, or the public must be reviewed by a named person before it goes out. A requirement to announce any AI note-taker or recording tool at the start of a meeting. A named contact for questions or for reporting a mistake, so employees know exactly who to tell if something sensitive was pasted somewhere it should not have been, without worrying that flagging it will get them in trouble.

A policy like this does not need to anticipate every situation. It needs to give employees a clear default for the common cases and a clear person to ask when a situation falls outside them.

The honest bottom line

AI tools are a real productivity gain for a small business, and none of the caution in this guide is an argument for avoiding them. The goal is to get the speed and convenience without quietly creating a data leak, a compliance problem, or a wrong answer that reaches a customer under the company's name. A short policy, an approved business account, a habit of redacting before pasting, and a human checking the output before it goes out cover most of the risk without slowing anyone down in any meaningful way.

Frequently asked questions

Is it safe to paste customer information into ChatGPT or a similar chatbot? Generally no, unless you are using a business or enterprise plan your company has approved and configured for that purpose. A free consumer account may use your input to improve its models, and even a business plan should only receive customer data if your company's policy and the vendor's contract allow it.

Do business or enterprise AI plans really keep my data private? Most vendors say business and enterprise tiers exclude your conversations from model training and offer stricter retention terms than the free consumer version, but the exact protections vary by vendor and change over time. Check the current data policy for the specific plan your company uses rather than assuming it matches what you have heard about the product in general.

Can I use an AI note-taker in a client meeting without telling anyone? No. Many places require consent before a conversation is recorded or transcribed, and even where it is not legally required, showing up with a bot silently capturing a call damages trust if someone notices later. Announce the tool at the start of the meeting and let anyone object.

What should I do if I already pasted something sensitive into a chatbot by mistake? Delete the conversation if the tool allows it, and tell your manager or IT contact what happened so they can judge whether anything further is needed. Trying to quietly undo it yourself usually makes things worse if it turns into a bigger problem later.

Are free AI tools ever fine to use for work tasks? They are usually fine for low-risk tasks that involve no real customer, employee, or company data, like brainstorming generic ideas or rewording a public blog post. Once a task touches anything identifiable or confidential, switch to an approved business account or avoid the tool entirely.

Who is responsible if an AI tool gives a customer wrong information? The business is responsible, not the AI vendor. A generated answer that goes out under your company's name is treated the same as anything a human employee wrote, so someone needs to review AI output before it reaches a customer, especially for pricing, policy, or safety questions.

→ Browse the full AI tools directory