Keep four kinds of business data out of AI tools unless two things are true: the tool is one your business has approved, and you’re authorized to use it for that data. The four kinds are personal information about customers and employees, passwords and financial account details, trade secrets and other people’s confidential material, and HR or legal records. Passwords and keys are the exception, because they never belong in a prompt at all. Public material you’re free to reuse and deliberately made-up examples are generally fine in an approved tool. This is a conservative baseline for a small team, not legal advice. Check your own contracts and any laws that apply to you, and ask a lawyer when the stakes are high.
The Operating Rule
Sensitive data stays out if either of two things is missing: an approved tool, or authorization to use that tool for that data. Three checks decide both:
- The tool. Whether the tool is one you’ve vetted. A business plan with a signed agreement is different from a personal account with default settings, and even among business products the terms and controls vary. The previous article in this series covers how they differ for ChatGPT.
- The permission. Your customer contracts, NDAs, and privacy notices may limit who can see the data. A vendor’s privacy settings don’t override them.
- The law. Some data is regulated, and regulations can require specific contracts and safeguards before a vendor touches it.
Credentials are different. Passwords, keys, and tokens stay out of every AI tool, whatever the plan or agreement, and one that has been exposed has to be invalidated. For everything else on the lists below, the answer is “not unless the tool is approved and the use is authorized,” which is why the examples in this article are a starting point and not a statement about what any law requires.
Category 1: Personal Information About Customers and Employees
Personal information is anything that identifies a person, alone or combined with other details. For AI tools, treat these as off-limits unless the tool is approved and the use is authorized:
- Names combined with contact details such as email, phone, or home address
- Government ID numbers such as Social Security numbers, driver’s license numbers, and tax IDs
- Payment card numbers, security codes, and bank account or routing numbers
- Health information about identifiable people
- Anything else that lets someone single out a specific customer or employee
Why this category is first: privacy laws can attach duties to it. A few examples, each simplified:
- GDPR. Where it applies, an organization that uses a vendor to process personal data for it needs a contract that sets out what the vendor may do with the data. That requirement comes from Article 28 of the GDPR, and a contract alone doesn’t establish compliance. GDPR can apply even if your organization is outside the EU—for example, when you process personal data to offer goods or services to people in the EU or monitor their behavior there. It also covers processing connected to the activities of an EU establishment. These scope rules appear in Article 3 of the GDPR. Whether it reaches you depends on those facts, not just on where your customers live.
- California’s CCPA. It applies to for-profit businesses that do business in California and collect consumers’ personal information, if they meet at least one of three tests: annual gross revenue above an adjusted threshold ($26,625,000 since January 1, 2025, per the California Privacy Protection Agency); annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households; or earning 50% or more of annual revenue from selling or sharing consumers’ personal information, as written in the statute. The tests are alternatives, so a small business can be covered without meeting the revenue test, and vendors acting for a covered business have duties of their own.
- HIPAA. It applies if you’re a covered entity, such as many health care providers and health plans, or a business associate handling protected health information for one. Many businesses that touch health information aren’t. If you are covered, HHS says you need a written business associate agreement (BAA) with a vendor that handles that information for you. The agreement has to cover the actual service and use, and it doesn’t replace the other safeguards and risk analysis HIPAA requires, as HHS’s cloud computing guidance explains. Whether an AI vendor will sign one for the service you want to use is something to settle before any health data goes in.
If you don’t know whether these apply to you, find out before you upload, not after.
Category 2: Passwords, Credentials, and Financial Account Data
This category is the simplest, because there’s almost never a good reason to share it:
- Passwords, API keys, access tokens, and payment gateway secrets
- Bank logins, and full card numbers or security codes
- Unredacted bank statements that show account numbers or who you paid
Don’t paste credentials into any AI tool, including one on a business plan. A leaked password is easy to misuse, and a shared key can be copied. If a password, key, or token does end up in a chat, treat it as exposed and promptly invalidate it through the service that issued it: reset the password, or revoke the exposed key or token and issue a replacement if you need one. Make sure the old credential no longer works. Creating a new one doesn’t necessarily disable the old one.
If you’re a public company or work with one, unreleased financial results and pending deals carry extra legal weight. Most small businesses don’t have that problem, but the same instinct applies: keep numbers nobody has been cleared to see out of tools nobody has been cleared to use.
You can still get help with financial questions. Do the math in your own spreadsheet, then ask the AI a general question about the result. Suppose you calculate, in a made-up example, that your days sales outstanding is 64. Ask: “What actions improve a days sales outstanding of 64 days in a service firm?” The AI never sees a customer name or an invoice. A 13-week cash flow tracker is a good example of analysis that can stay in your own sheet.
Category 3: Trade Secrets and Other People’s Confidential Material
This covers what makes your business hard to copy, and what clients and suppliers have trusted you with:
- Source code, algorithms, and database designs
- Secret recipes, formulas, and manufacturing methods
- Negotiated supplier prices and discount tables
- Bids and proposals that aren’t public
- Client files covered by an NDA or a confidentiality clause
U.S. federal law defines a trade secret as information that has independent economic value from not being generally known, and that its owner has taken reasonable measures to keep secret. Handing secrets to a tool you haven’t vetted makes it harder to show you were careful. That doesn’t mean one paste ruins a trade secret, and the answer depends on the tool, its terms, and the facts. It does mean secrecy is something you have to act on, and “everyone just used the free version” is a poor record to defend.
Client material is a separate question from your own. If you’ve promised a client confidentiality, read what the contract says about sharing with outside services before you upload anything. If it’s unclear, ask the client, or keep the file out of the tool.
Category 4: HR Records and Legal Matters
Employee and legal matters carry both privacy and liability:
- Individual salaries and compensation schedules
- Performance improvement plans, discipline, and termination paperwork
- Complaints and investigation notes
- Medical leave and accommodation requests
- Communications with your attorney and notes on legal strategy
Keep personnel records inside systems built for them, with the access controls those systems provide. For legal material, the concern is privilege. Confidential communications made to get or give legal advice may be protected, and not everything you send a lawyer qualifies. Disclosing those communications through an outside service can create confidentiality or privilege risks, depending on the facts and where you are. Whether a particular AI tool does is a question for your attorney. Until you’ve asked, leave privileged material out.
What’s Generally Fine
Much of what people want from AI doesn’t involve any of the above. These are generally fine in a tool your business has approved:
- Public material you’re free to reuse: published marketing copy, headlines, captions
- Deliberately made-up examples: “Why does my
SUMIFSreturn zero?” with invented numbers and no real names - Generic questions about spreadsheets and code, with invented data
- Brainstorming that contains nothing confidential
Be careful with what looks harmless. Unreleased marketing plans, meeting agendas, and SOP drafts can contain confidential information, and real data doesn’t become safe because the question is simple. If an approved tool is a personal account, turn off model training. That’s one control. It isn’t permission to upload.
Redaction Lowers Risk, It Doesn’t Grant Permission
When you need AI help with real business data, redaction can reduce the risk. It doesn’t replace approval, and real data needs approval even after you’ve redacted it unless the proposed use has been assessed and authorized. These steps help:
- Replace names and codes with labels. “Client A,” “Store 1,” “Employee B.”
- Remove account numbers, routing numbers, and email addresses.
- Ask whether anyone could still tell who it is. A distinctive amount, a rare product, a small town, or a small group can point to one customer.
- Prefer a small, invented example when you only need help with a formula or an approach. Made-up data carries no risk to a real customer.
Be wary of two tricks. Multiplying every figure by the same factor keeps every ratio and pattern, and anyone who knows one original amount can work out the rest, so it doesn’t anonymize anything. Rounding dates doesn’t make the underlying records okay to send either.
Replacing names with labels is pseudonymization, and it isn’t the same as making data anonymous. The UK Information Commissioner’s Office explains in its introduction to anonymisation that pseudonymised information can still be personal data. That guidance is UK-specific and under review, so use it for the distinction, not as a recipe for what’s safe to upload.
The ICO’s point is about personal data. Separately, and as a matter of plain reasoning, removing identities doesn’t remove trade secrets, contract restrictions, or all risk of re-identification.
One last test: if this prompt appeared on the front page of a trade publication tomorrow, would it cost you a customer or break a contract? If so, don’t send it.
A One-Page Policy You Can Copy
A policy people will read has to be short. This example is deliberately stricter than the law requires in many cases. It isn’t a statement that regulated processing can never be lawful, only a clear house rule for a small team. Adjust the details to your business and have a lawyer look at it if you’re subject to regulation.
AI tool use at [Company Name]
Never paste, in any AI tool: passwords, keys, or tokens; full card or bank account numbers; Social Security or other government ID numbers; health information about identifiable people.
Ask first, and use only an approved tool for it: customer or employee personal details; client files or anything covered by an NDA; our source code, formulas, supplier prices, or bids; salary, discipline, investigation, or legal matters; any real business data, even with names removed.
Fine to use, in approved tools: public material we’re free to reuse; deliberately made-up examples with no real confidential information; generic questions about spreadsheets and code, with invented data.
Rules: Use only [approved tool(s)]. Don’t share logins. Turn off model training on any personal account, but that isn’t permission to upload. Check AI output before you rely on it. If something sensitive gets pasted, tell [name or role] right away. Don’t delete it first.
Questions go to: [name or role]. Last reviewed: [date]. Review it again when our tools, their terms, or an incident change things.
Make It Stick
A policy only works if people know it and can follow it:
- Name one person to ask. The “ask first” category fails if nobody answers.
- Provide an approved tool. If the safe option is harder than the risky one, people will use the risky one.
- Tell the team why, with one real example, not just a list of rules.
- Review it when things change. Tools, terms, laws, and incidents change what’s safe. Review the policy when one does, and check it at least once a year even if none has.
Frequently Asked Questions
If I use a business plan, can I paste anything?
No. “Business plan” isn’t one setting. Training, retention, access, and authorization are separate checks, and they vary by vendor and configuration. OpenAI’s API data controls documentation, for example, separates no-training defaults from abuse-monitoring logs, stored application state, and controls that depend on eligibility. A training control is one safeguard, not permission to upload. Your contracts and the law still decide what you’re allowed to send, and credentials stay out regardless.
What about AI features built into software I already use?
Treat them like any other tool. Find out who processes the data, whether it’s used for training, and what your agreement with the software vendor says before you use it with sensitive material.
Can I upload customer data if the customer agrees?
Consent may help, but it depends on what the customer was told, the law that applies, and your contract. Get advice before you rely on it.
What if someone already pasted something on the list?
Tell the person responsible for security or privacy right away, whatever the data was. Stop sharing it, and promptly invalidate any password, key, or token that was exposed: reset the password, or revoke the key or token and issue a replacement if needed, and confirm the old credential no longer works. Write down what was shared, when, and in which tool, without making more copies of it. Then follow your response process for contacting the vendor, deleting chats, files, or other copies, keeping the evidence you need, and notifying anyone you’re required to notify. The FTC’s data breach response guide advises acting quickly, documenting what you find, and not destroying evidence. Turning off training afterward doesn’t undo the disclosure, and neither does deleting a chat. Whether a notification duty applies depends on what was shared and the law that covers it, so ask your lawyer if you aren’t sure.
John Serra