Some documents do not belong in a chatbot.
AI can be genuinely useful at work. It can turn rough notes into a first draft, help you prepare for a meeting, tidy up a report, and save you from staring at a blank page at 4:47 p.m.
But it is not a magical private room just because you are logged in.
Before you paste a work document into ChatGPT, Claude, Gemini, or any other AI tool, there is one question to answer:
Do you have permission to put this information there?
Not, “Will the AI give me a useful answer?”
The hard part is remembering that work data belongs to your company, your clients, your customers and other stakeholders. You do not get to make the privacy rules up as you go along.
First, what counts as sensitive?
People sometimes imagine “sensitive data” means passwords and nothing else.
Passwords absolutely count. So do API keys, login details, and anything that could open a door you do not want opened.
But the list is much bigger than that:
-
Customer names, email addresses, phone numbers, and account details
-
Employee records, CVs, salaries, performance notes, and health information
-
Contracts, pricing, legal documents, and confidential proposals
-
Internal financial figures and sales forecasts
-
Unreleased product plans, strategy documents, and board material
-
Anything covered by an NDA or a client agreement
Here is a useful test: if you would feel uncomfortable pasting it into a public social media channel, do not casually paste it into an AI tool either.
That does not mean AI is off limits. It means you need to know which tool you are using, what your company has approved, and what data is allowed there.
“But I am using a work account” is not enough
This is where people get caught out.
An AI tool can look the same on your screen whether you are using a personal account, a paid account, or a company-approved workspace. The rules behind those accounts can be very different.
Do not assume that paying for a tool automatically makes every document safe to upload. Do not assume your colleague using it means it has been approved. And do not assume a privacy setting fixes everything.
Your company may have an approved AI environment, clear rules, and the right agreements in place. Great. Use it as intended.
If you do not know which situation you are in, that is not a sign to guess. Ask your IT, security, privacy, or legal team. One slightly awkward question is cheaper than one very awkward incident.
The five-question pause before you paste
You do not need to become a data-protection lawyer to use AI responsibly.
Just pause for ten seconds and ask these five questions:
-
Whose information is this? Is it yours, your company's, a client's, or an employee's?
-
Is any of it personal data? Names, contact details, account numbers, and identifiable details all count.
-
Is it confidential? Think contracts, pricing, internal plans, or anything under an NDA.
-
Is this specific AI tool approved for this type of work? Not “do we use AI?” but “can I put this data in this tool?”
-
Can I get the same help without the real document? Often, yes.
That last question is the one people skip.
They paste the whole thing because it is convenient.
Convenient is not a privacy policy.
Better ways to get the same result
Very often, you can ask AI to help without handing it the sensitive part.
Instead of this:
“Here are 20 CVs. Tell me which candidates I should interview.”
Try this:
“Create a scorecard for interviewing candidates for a project-manager role. Include practical questions about stakeholder management, planning, and communication.”
Instead of this:
“Here is our client contract. Find the risky clauses.”
Try this:
“Give me a checklist of contract clauses a small business should review before signing a client agreement. I will use it with our legal team.”
Instead of this:
“Here are all the notes from a difficult client meeting. Write the follow-up email.”
Try this:
“Write a calm follow-up email after a delayed project. We need to acknowledge the delay, explain that we are fixing it, and confirm the next milestone. Keep it short and direct.”
You still get a useful draft.
You just do not hand a chatbot names, private details, and a front-row seat to your company's mess.
Use placeholders. Keep the useful part.
Replace real names with [Client A]. Remove phone numbers, emails, account numbers, addresses, and internal figures. Generalise the details that do not change the task.
You are not trying to trick the AI. You are giving it enough context to help, without giving it information it does not need.
That is good prompting and good data hygiene at the same time.
Privacy settings are useful. They are not magic.
Turn on the privacy controls your approved tool provides. Read your company's guidance. Use the right workspace.
But do not let a setting give you a false sense of safety. A setting cannot give you permission to upload a confidential document. It cannot undo an NDA. It cannot replace your company's process for handling personal data.
Tools matter.
Your judgment still matters more.
The simple rule your team can actually remember
If you manage a team, give people a rule they can use on a busy Tuesday morning:
Green: public information and generic work. Fine to use in the approved tool.
Yellow: internal information with no personal or confidential details. Pause, minimise it, and check the company guidance.
Red: personal data, client data, contracts, passwords, financial details, unreleased plans, or anything confidential. Do not paste it unless your organisation has explicitly approved that exact use.
AI works best when people stay in charge
The goal is not to make everyone afraid of AI. That would be silly. The goal is to make people useful with it without being careless.
Use AI for the structure, the first draft, the template, the checklist, and the thinking help.
Keep private information where it belongs.
And when the rules are unclear, ask before you paste. That ten-second pause is part of being good at AI now.
If you want a practical starting point for giving AI better instructions without oversharing your work, my free PDF guide covers the basics.
The real shift is not handing more information to the tool. It is learning to direct it well enough that you do not need to.
That is exactly what The Prompt Engineering System teaches: how to give clear context, set the right objective, and get useful work back while you stay responsible for the result.
AI is about people. Keep it that way.
