top of page

What Business Information Should You Never Put Into AI Tools?

BrightPath Digital Editorial Team
Aug 24
13 min read

Using AI at work can feel harmless.

You need to summarise a document.

Draft a customer response.

Analyse some figures.

Improve a proposal.

Turn meeting notes into an action list.


So you copy the information, paste it into an AI tool and ask for help.


Thirty seconds later, the job is done.


But there is a question worth asking before you press Enter:

Should that information have been put into the AI tool in the first place?


As AI becomes part of everyday business software, the biggest risks are not necessarily dramatic science-fiction scenarios.


They are ordinary employees doing ordinary jobs and sharing information they did not realise needed protecting.


A customer complaint.

A spreadsheet.

A contract.

An employee issue.

A password.

An unpublished quotation.

A confidential project.


The technology makes sharing information incredibly easy.


That does not make sharing it appropriate.


Small business checking sensitive information before entering it into an AI tool
AI can save time, but sensitive information should not be pasted into a tool without considering what is being shared, why it is needed and how the service protects it.

What Business Information Should You Never Put Into AI Tools?

As a practical default, do not enter information such as:

  • passwords

  • one-time authentication codes

  • recovery codes

  • API keys and access tokens

  • customer personal information

  • employee HR information

  • bank and payment details

  • identity documents

  • confidential contracts

  • legally sensitive correspondence

  • commercially sensitive plans

  • unpublished financial information

  • security configurations

  • confidential source code or intellectual property


unless your business has specifically approved the AI system and the particular use of that information.


That final qualification matters.


Not all AI services handle business data in the same way.


The real rule should therefore be:

Do not put sensitive business information into an AI service until you know what the information is, why the AI needs it, which service is processing it and whether your business has approved that use.


Public AI Tools and Business AI Tools Are Not Necessarily the Same

It is easy to talk about “AI” as though every service works identically.


They do not.


There can be substantial differences between:

a personal AI account

and:

an organisation-managed business AI service


Business products may provide additional contractual protections, administrator controls, authentication, retention settings, auditing and restrictions around how organisational data is used.


That can materially change what an organisation decides is appropriate.


But it does not mean:

“We pay for AI, therefore anything can be uploaded.”


A business still needs to understand:

  • what service employees are using

  • which account they are using

  • where information is processed

  • what the provider says about data usage

  • what retention controls exist

  • who can access conversations

  • whether connected applications expose additional information

  • which business policies apply

  • whether personal information is involved

  • whether the task actually requires the sensitive information


This is why our guide to 73% of UK Workers Now Use AI—But Are Small Businesses Using It Properly? recommends a controlled workflow rather than allowing everybody to make their own decisions about business information.


Approved information → approved AI tool → human review → appropriate business use

is a much stronger process than:

Copy → paste → hope.


1. Never Paste Passwords, Authentication Codes or Recovery Keys Into AI

This is the clearest category.


Do not paste:

  • passwords

  • temporary passwords

  • PINs

  • two-step verification codes

  • recovery codes

  • password-reset links

  • private encryption keys

  • API keys

  • access tokens

  • application secrets


into a general-purpose AI prompt.


An AI assistant does not need your password to explain how to reset one.


It does not need your real API key to help troubleshoot a piece of code.


Replace the real value with something obviously fake:

API_KEY = YOUR_KEY_HERE

rather than:

API_KEY = sk-live-actual-secret-value


If a genuine secret has accidentally been exposed somewhere it should not have been, do not simply delete the conversation and assume the problem has disappeared.


Where appropriate, revoke or rotate the credential.


The secret is valuable because it grants access.


Treat it accordingly.


2. Be Extremely Careful With Customer Personal Information

Imagine a customer sends you a long complaint.


You want AI to turn it into a concise summary.


So you paste the entire email.


That might include:

  • their full name

  • email address

  • telephone number

  • home address

  • order information

  • account details

  • information about family members

  • information about a dispute

  • photographs

  • other personal details


The AI probably does not need most of that information to summarise the issue.


A better input might be:

“A customer says an order arrived four days late and one item was damaged. They have asked for a replacement and refund of the delivery charge. Summarise the issues and prepare a polite draft response.”


The task remains possible.


The unnecessary personal information has disappeared.


That is a useful habit:

Give the AI the information required to perform the task — not every piece of information you happen to have.


This closely matches the wider principle of data minimisation: organisations should process only the personal information required for the purpose.


3. Take Extra Care With Sensitive Personal Information

Some information deserves an even higher level of caution.


Examples could include information concerning:

  • health

  • disabilities

  • ethnicity

  • religion

  • biometric information

  • sexual life or sexual orientation

  • trade union membership

  • criminal allegations or offences


There can be additional legal obligations around particular categories of personal information.


A general-purpose AI chatbot should not become the place where an employee casually pastes an entire sensitive customer or staff record because they want a quicker summary.


Ask:

Does the AI genuinely need this information?


Often, the answer is no.


You may be able to replace:

“John Smith, who has [specific medical condition]...”

with:

“An employee requires an agreed workplace adjustment...”


The task can still be completed without exposing the underlying information.


4. Employee HR Information Should Not Become Prompt Material by Default

AI can be tempting in HR situations.


For example:

“Summarise these performance notes.”

“Draft a response to this grievance.”

“Compare these candidates.”

“Help me decide who should be made redundant.”


Those tasks can involve extremely sensitive information.


Documents could contain:

  • salaries

  • home addresses

  • sickness information

  • disciplinary records

  • performance concerns

  • grievance allegations

  • recruitment data

  • identification documents

  • bank information

  • protected characteristics

  • confidential management discussions


Do not assume that because the document already exists electronically it is appropriate to place it into another system.


There is also a second problem.


AI output can sound decisive even when the situation requires context, employment-law knowledge and human judgement.


Use AI to support appropriate administrative tasks where your organisation has approved the process.


Do not turn it into an unaccountable HR decision-maker.


5. Avoid Pasting Bank, Payment and Detailed Financial Information

There is an enormous difference between asking:

“Calculate the percentage increase between £125,000 and £143,000.”


and uploading:

the company's complete bank statement containing account numbers, transactions, customer references and employee payments.


The first is a calculation.


The second exposes considerably more information than the task requires.


Be particularly cautious with:

  • bank account details

  • payment-card information

  • customer payment records

  • payroll exports

  • tax documents

  • detailed bank statements

  • finance-system exports

  • unpublished management accounts

  • commercially sensitive forecasts


AI can absolutely help businesses analyse information.


But ask whether it needs the raw identifiable data.

Often it does not.


You might instead supply:

Month 1 revenue: £125,000

Month 2 revenue: £143,000

Marketing spend: £12,000

New customers: 42

and ask the AI to analyse those figures.


The useful information remains.


The irrelevant financial records do not.


6. Think Before Uploading Contracts and Legal Correspondence

Uploading a contract and asking:

“Explain what this clause means in plain English”


is an obvious AI use case.


It can also involve a confidential business document containing information about:

  • customers

  • suppliers

  • pricing

  • commercial terms

  • disputes

  • intellectual property

  • employees

  • future projects

  • settlement discussions

  • confidential negotiations


There may also be circumstances involving legal professional privilege or other confidentiality requirements where sharing material with a third-party service requires particular care.


Do not assume AI is your solicitor because it can explain legal terminology convincingly.


If the issue matters commercially or legally, use the AI output to help you understand questions — not as a replacement for appropriate professional advice.


Where possible, provide only the relevant clause and remove identifying or commercially sensitive information.


7. Protect Trade Secrets, Strategy and Intellectual Property

A business does not need to be Coca-Cola to have commercially valuable confidential information.


A small business may have:

  • an unreleased product

  • a new pricing model

  • a customer list

  • supplier terms

  • proprietary processes

  • acquisition plans

  • tender information

  • product designs

  • source code

  • manufacturing information

  • campaign plans

  • unpublished research

  • commercial negotiations


The mistake is thinking:

“Nobody would be interested in our information.”


That is the wrong test.


Ask:

“Would we willingly publish this information on our website today?”


If not, understand where it is going before giving it to another service.


Some business-grade AI products and development tools are specifically designed to work with organisational information under defined contractual and technical controls.


That is different from an employee independently opening a personal account with an AI service and pasting confidential material into it.


8. Do Not Hand Over Your Security Blueprint

AI can be genuinely useful for technical troubleshooting.


But be careful about giving an external service a detailed map of how your systems work.


Think twice before supplying:

  • administrator usernames

  • internal IP addresses

  • VPN configurations

  • firewall rules

  • private certificates

  • authentication information

  • security keys

  • complete network diagrams

  • unpatched vulnerability details

  • backup credentials

  • privileged scripts

  • access-control information


There is nothing wrong with asking:

“Why might this firewall rule prevent HTTPS traffic?”


But the AI may not need your complete production firewall configuration, public IP addresses and administrator credentials to answer it.


Strip the problem down to what is actually relevant.


Security information becomes more valuable when several seemingly harmless pieces can be combined.


“But I Removed the Customer's Name”

Good.


But do not automatically assume that means the information is anonymous.


Imagine you paste:

A 47-year-old managing director of a manufacturing company in Runcorn contacted us yesterday about [very specific issue].

You removed the name.


Could somebody who knows the situation still identify the person?


Possibly.


Likewise:

Customer 18473 bought a £17,450 product on 6 August and lives at postcode WA7...

has no name but could still potentially be linked to an identifiable person.


Removing a name is redaction.


Whether information has genuinely become anonymous depends on whether somebody can still reasonably identify the individual from the remaining information and other information available to them.

The practical lesson is simple:

Remove unnecessary context as well as obvious identifiers.



A Better Way to Give AI Business Information

You do not always need the original document.


There are several safer approaches.

Use a Generic Example

Instead of:

Here is the actual confidential employment letter. Improve it.

try:

Create a structure for a letter covering these five points. Use placeholders for all names, dates and financial figures.

Redact the Source

Replace:

Mike Smith 18 Example Road 07900 123456

with:

[CUSTOMER NAME] [ADDRESS] [TELEPHONE]

Extract Only the Relevant Section

Do not upload a 40-page contract when you need help understanding one paragraph.


Use Aggregated Figures

Instead of detailed individual transactions, provide monthly totals or categories where that is sufficient.


Create Synthetic Data

If you are testing a process, use invented records:

Customer AOrder 123£500Status: delayed

rather than a real customer's details.


Summarise Before Using AI

Sometimes the safest prompt is one you write yourself:

A customer disagrees with a £250 cancellation charge and says the policy was unclear when booking. Give me a checklist of points I should review before responding.

The AI does not need to see the customer's original email at all.


AI Data Protection Is Not Just About Model Training

One of the most common misunderstandings is:

“The provider says it doesn't train on our data, so we're safe.”


Whether prompts are used to train a model is important.


It is not the only question.


Businesses should also consider:

  • retention

  • logging

  • authorised access

  • account security

  • connected applications

  • administrators

  • data location

  • contractual terms

  • regulatory obligations

  • accidental sharing

  • compromised accounts

  • third-party integrations

  • how information is deleted

  • whether the task was appropriate in the first place


For example, some enterprise AI products explicitly state that organisational prompts and responses are not used to train their underlying foundation models.


That is valuable protection.


It is not permission to paste a password into the prompt.


Good vendor controls and good employee judgement are both required.


Connected AI Tools Create Another Question: What Can the AI Access?

AI tools increasingly connect with:

  • email

  • calendars

  • cloud storage

  • documents

  • CRM systems

  • project tools

  • websites

  • internal databases


That can make them dramatically more useful.


It also makes permissions more important.


There is a big difference between:

AI can read this one document

and:

AI can search every file this employee can access.


The same principle you would use elsewhere in IT still applies:

Give systems the access they need — not every permission available.


If an AI system can take actions as well as read information, the consequences of a poor permission model become more significant.


Convenience is not a substitute for access control.


Your Employees May Already Be Using AI Without Telling You

This is the uncomfortable part for many businesses.


You may have never formally introduced AI.


That does not mean nobody is using it.


Someone may already be using a personal AI account to:

  • rewrite customer emails

  • summarise meeting notes

  • improve quotations

  • analyse spreadsheets

  • write code

  • prepare marketing

  • review CVs

  • summarise contracts

  • answer technical questions


Often there is no malicious intent.


They are trying to work faster.


Simply announcing:

“AI is banned.”

may not solve the problem.


If the tools are useful, employees can easily continue using them informally.


A better approach is to establish clear boundaries.


Our wider guide to AI for small businesses recommends knowing which AI tools are actually being used, which information is being entered and which outputs eventually reach customers.


Create a Simple AI Information Policy

A ten-page AI policy nobody reads is less useful than one page everybody understands.


Your starting point could be:

GREEN — Generally Acceptable

Examples:

  • public website information

  • generic brainstorming

  • spelling and grammar checks

  • non-confidential marketing ideas

  • generic templates

  • public research

  • fictional examples

  • anonymised or synthetic data where appropriate


AMBER — Approval or Care Required

Examples:

  • internal documents

  • quotations

  • customer communications

  • non-public financial information

  • source code

  • contracts

  • business strategy

  • employee information

  • customer information


These may be appropriate in an approved business AI environment for an approved purpose, but should not automatically be pasted into whichever AI tool an employee prefers.


RED — Do Not Enter

Examples:

  • passwords

  • MFA codes

  • recovery codes

  • API secrets

  • private encryption keys

  • payment-card security codes

  • credentials that provide access to business systems


Then define:

Which AI tools are approved?

Which accounts should employees use?

Which information classes are permitted?

Who approves exceptions?

Which outputs require human review?

What should an employee do if they accidentally share restricted information?


That turns vague anxiety about AI into something employees can actually follow.


Use This 10-Second Test Before Pasting Anything Into AI

Before submitting information, ask:

1. Is this information already public?

If yes, the confidentiality risk may be much lower.


2. Does the AI actually need all of it?

If no, reduce it.


3. Does it identify a customer, employee or other individual?

If yes, consider whether the task can be completed without that information.


4. Is it commercially confidential?

Would you be comfortable if a customer, competitor or supplier saw it?


5. Does it contain credentials or secrets?

If yes, stop.


6. Am I using a business-approved AI account?

A personal account may not have the controls your organisation expects.


7. Do I know how this tool handles the information?

If not, find out before uploading sensitive material.


If you cannot confidently answer those questions, do not paste yet.


What if You Have Already Put Sensitive Information Into an AI Tool?

Do not panic.


Work out what happened.


If You Shared a Password, API Key or Access Token

Treat it as potentially exposed.


Change, revoke or rotate it as appropriate.


If You Shared Personal Information

Record what information was involved, which service received it and who may be affected.


If the incident could represent a personal-data breach, assess it under your normal data-protection process and obtain appropriate advice where required.


Check the Service

Understand:

  • whether the conversation can be deleted

  • what retention arrangements apply

  • whether administrators can access it

  • whether sharing links were created

  • whether the provider offers support for the issue


Fix the Process

The most useful question afterwards is:

Why did the employee think this was the right way to complete the task?


Perhaps:

  • no approved AI tool existed

  • nobody had explained the rules

  • the secure process was too difficult

  • employees did not recognise the information as sensitive

  • the company had no AI policy


Fix that problem too.


Otherwise it will happen again.


AI Can Still Be Extremely Useful

None of this means businesses should be frightened of AI.


That would miss the opportunity completely.


AI can be excellent for:

  • structuring rough notes

  • creating first drafts

  • summarising public information

  • generating ideas

  • improving readability

  • adapting approved content

  • creating checklists

  • analysing appropriate datasets

  • preparing meeting structures

  • simplifying complex explanations


Our guide to turning real business activity into useful content recommends exactly that approach: start with genuine business knowledge and let AI help organise or communicate it.


Likewise, if you are using AI to produce website copy, our guide to AI-written website content explains why human review, accuracy and genuine business input still matter.


The goal is not:

Use less AI.


It is:

Use AI deliberately.


Frequently Asked Questions

Is It Safe to Put Business Information Into ChatGPT?

It depends on the information, the account or product you are using, its current data-handling terms, your organisation's configuration and the purpose.


Do not treat all ChatGPT plans — or all AI services — as having identical controls.


Business information should still be classified before it is shared, and passwords, authentication secrets and similar credentials should not be pasted into prompts.


Does ChatGPT Use Business Data to Train AI Models?

OpenAI states that inputs and outputs from ChatGPT Business and Enterprise are not used to train its models by default.


That is an important distinction from assuming every AI product or account has identical data practices.


It also does not remove your responsibility to decide whether a particular piece of sensitive or personal information should be processed by the service in the first place.


Is Microsoft Copilot Safe for Confidential Business Information?

Microsoft provides enterprise data protection for eligible organisational Copilot use and states that prompts, responses and Microsoft Graph data under those protections are not used to train foundation models.


However, the correct question is still not simply:

“Is Copilot safe?”


It is:

“Is this particular use of this particular information approved and appropriately controlled within our organisation?”


Can I Upload Customer Information to AI?

Do not upload identifiable customer information by default simply because it makes a task easier.


Determine whether the information is genuinely necessary, whether your organisation has approved the tool for that processing and whether your data-protection obligations have been considered.


Where possible, minimise, redact or anonymise the source information.


Can I Upload a Contract to AI?

Possibly, depending on the tool, organisation and contract.


But contracts can contain commercially confidential information, personal data, intellectual property and legally sensitive material.


If you only need help with one generic clause, supplying the complete identifiable contract may be unnecessary.


Can I Paste Customer Emails Into AI?

You may not need to.


Extract the problem or question and ask the AI to help with that instead.


For example:

“A customer says their delivery was late and damaged. Draft a polite response offering these two options...”


is generally a better starting point than supplying the customer's entire email history.


Is Removing a Name Enough to Make Information Anonymous?

Not necessarily.


Other information may still allow an individual to be identified.


Remove unnecessary contextual information as well as obvious identifiers, and do not assume replacing someone's name with “Customer A” automatically solves every privacy issue.


What Is the Safest Rule for Employees Using AI?

A practical rule is:

Use approved tools. Share the minimum information required. Never share credentials. Protect personal and confidential information. Check important outputs before using them.


Final Thought: Think Before You Paste

The biggest AI security mistake a small business can make may not involve an advanced cyber attack.


It might simply be an employee copying the wrong information into the wrong box.


AI tools make it incredibly easy to move information from:

email → prompt

spreadsheet → prompt

document → prompt

CRM → prompt


The technology removes friction.


Your business still needs judgement.


Before pasting information into AI, ask:

Does the tool really need this?

Could I remove identifying details?

Is this an approved business service?

Would I have a problem if this information were exposed?


If the answer to the last question is yes, stop and check first.


The objective should not be to prevent your business benefiting from AI.


It should be to make sure speed and convenience do not quietly remove the controls you would apply everywhere else.


BrightPath Digital helps small businesses create practical digital foundations around websites, business technology, AI and security without unnecessary complexity.


If your business is starting to use AI but has never considered what employees are entering into it, contact BrightPath Digital to discuss the practical controls worth putting in place.

Comments


bottom of page