Book a process review
← All posts

Safe use · 1 min read

What not to paste into an AI tool

A simple rule your whole team can follow, based on guidance from the NCSC and the ICO.

Most staff who use AI at work started with a free tool on a personal account. That is understandable: it saves time. The risk is what gets pasted in.

The National Cyber Security Centre’s advice for managers is clear that confidential information should not go into public AI tools. And the Information Commissioner’s Office is equally clear that data protection law applies to AI in the same way it applies to everything else.

Never paste into a personal or free AI account

  • Client information: names, contracts, pricing, anything under NDA.
  • Personal data: staff records, customer details, health or financial information.
  • Commercially sensitive material: bids, forecasts, unreleased plans.
  • Credentials: passwords, API keys, access links.

Usually fine

  • Public information, such as your own website copy.
  • Generic drafting: “Write a polite reminder about an overdue invoice.”
  • Your own notes, once names and identifying details are removed.

Write the four “never” categories on one page and share it with the team today. A short rule that everyone remembers beats a long policy nobody reads.

Give people a safe alternative

Banning AI rarely works. Providers such as Google and Anthropic state that their business plans do not use your data to train their models by default, and an assistant set up on your own documents goes further, because it answers from your information rather than the internet. If staff have an approved tool, the rule becomes easy to follow.

Keep a simple record

Note which tools are in use, who has access and what data they touch. If a client asks how you use AI, you will have a clear answer.