The short answer: never type or upload customer/client personal information, confidential business information, employee/HR data, or any kind of password or access credential into a public or personal AI tool. When information leaves your systems and enters an AI provider's product, you generally lose direct control over how it's stored, retained, or used — even when the provider has reasonable privacy practices.
Why this list matters more than it seems
Most employees aren't being careless — they're being efficient. Pasting a customer email into ChatGPT to draft a reply, or uploading a contract to summarize it, feels like a small, harmless shortcut. The risk isn't any single instance; it's that this becomes routine, across many employees, with no visibility into how often it happens or what's being submitted.
Five categories that should never go into an AI tool
1. Customer or client personal information
Names, contact details, account numbers, financial details, health information — anything that identifies a real customer or client should stay out of a public AI tool. This is true even if the request seems mundane, like drafting a follow-up email.
2. Confidential or proprietary business information
Unreleased financials, strategic plans, internal-only communications, and trade secrets fall into this category. Once typed into an AI chat, that information has left your controlled environment.
3. Employee or HR information
Performance reviews, compensation details, disciplinary matters, and other HR-sensitive material should never be processed through a general AI tool.
4. Credentials of any kind
Passwords, API keys, access tokens — these should never appear in an AI prompt, even "for context" or to help debug something. If a credential has been typed into an AI tool, treat it as compromised and rotate it.
5. Anything covered by a confidentiality agreement
If your business has signed an NDA or a contract with confidentiality terms, assume that information is off-limits for AI tools unless the counterparty has explicitly agreed otherwise.
What about business-tier or "enterprise" AI plans?
Business and enterprise plans from AI providers often include different data-handling and retention terms than free/personal tiers — but "different terms" isn't the same as "no risk." The right approach is to read the specific data-processing terms for whatever plan your business uses, rather than assuming a paid plan removes the need for judgment about what's appropriate to submit.
A simple rule of thumb
Before typing or uploading something into an AI tool, ask: "Would I be comfortable if this ended up somewhere I didn't intend?" If the answer is no, don't submit it — rephrase the request without the sensitive detail, or don't use an AI tool for that task at all.
Next step
If your business doesn't yet have written guidance on this, our free AI Use Policy Template includes a prohibited-information section you can adapt today. You can also take the free 3-minute AI Risk Check to see where your business currently stands.
Related: What Is Shadow AI? · Which AI Tools Can Access Your Google Drive or Microsoft 365 Data?