A finance executive I trained last month told me she pastes her company's monthly MIS into ChatGPT every week to get a quick summary for her boss. It saves her twenty minutes. It also means three years of her company's revenue, costs and margins have gone through a server she has never seen, owned by a company she has no contract with. She had never thought of it that way. Most people have not.
This is not a post about avoiding AI. It is about using it the way you already use email, WhatsApp and cloud storage: freely, but with a clear sense of what belongs where. Once you know the rule, it takes no extra time to follow it.
Why this matters more than it feels like it does
When you paste something into a free AI chatbot, three things can happen to it. It can sit on the company's servers as a stored chat log. It can be reviewed by a human trainer to improve the model, unless you have explicitly turned that off. And in some tools, it can be used to train future versions of the model itself. None of this is hidden or illegal. It is written into the terms of service that almost nobody reads.
The practical risk is not that AI companies are out to misuse your data. It is simpler than that: once information leaves your laptop and enters someone else's system, you no longer control where it goes, how long it stays, or who inside that company can see it. For a personal to-do list, that does not matter. For a client's financial statement, it matters a great deal.
Treat every free AI chat box like a conversation happening in a crowded café. You would not read out a client's salary details or your company's unpublished results at the next table. The same instinct applies here.
The simple test before you paste anything
Ask one question: if this text or file were forwarded to a stranger by mistake, would it cause a problem? If the honest answer is yes, it does not go into a free AI tool. This single test covers almost every situation you will face at work.
Never paste this into free AI tools
- Client or customer data. Names with PAN, Aadhaar, bank account numbers, or any personally identifiable information belonging to someone else.
- Unpublished financials. Draft results, board decks, valuation numbers, or anything price-sensitive that has not been made public.
- Salary and HR data. Compensation sheets, appraisal ratings, or anyone's personal employment details.
- Passwords, API keys, and login details. These should never appear in any chat window, ever.
- Signed contracts and NDAs. If a document has a confidentiality clause, assume that clause covers AI tools too, because it almost certainly does.
- Medical or legal records belonging to a client, colleague, or family member.
Generally fine to use with AI
- Publicly available information: published annual reports, news articles, market data.
- Your own drafts and ideas, before they involve anyone else's confidential details.
- Templates, formats, and structures with the real numbers or names removed.
- General questions: "how do I structure a cash flow statement" needs no client data at all.
The trick that solves most of this: anonymise before you paste
You rarely need to give up AI's help entirely. You need to strip out what identifies the person or the company before you paste. Replace the client's name with "Client A". Replace real numbers with rounded, disguised figures that keep the same shape. Ask AI to help with structure and language, then drop your real numbers back in yourself, offline, after the AI part is done.
This gets you the AI's reasoning and drafting ability without a single real figure ever leaving your machine. It takes thirty seconds longer than pasting the raw sheet, and it is the difference between smart AI use and a data breach waiting to happen.
Free tools versus paid, and versus your company's own AI
Not all AI is equal here. A free consumer chatbot has the loosest data terms by default. A paid business plan from the same company usually includes a written commitment that your data is not used to train models, though you should still check the specific terms. If your organisation has rolled out its own AI tool, on Microsoft, Google or another enterprise platform, that is generally the safest option for work data, because it sits inside your company's existing contracts and security boundary. When in doubt, ask your IT or compliance team which tool is approved for which kind of data, rather than guessing.
What this looks like in daily office life
You are asked to summarise a client's loan application. Instead of pasting the application, you type out the shape of the situation without names or account numbers and ask AI to help you structure the summary. You are drafting a performance review. Instead of pasting the employee's actual review notes, you describe the situation generically and let AI help you phrase it, then you fill in the specifics yourself. You want a quick sanity check on a set of numbers. You round them, relabel them, and check the logic, then apply the real figures by hand.
None of this slows you down in any way that matters. It becomes a habit within a week, the same way locking your laptop screen became a habit once you did it a few times.
If you are building AI fluency at work
Judgment about what to paste and what to hold back is one of the six skills we assess in the AiM AI Fluency Test. It is a skill you can build deliberately, not something you either have or do not. If your organisation is rolling out AI tools to a whole team and wants everyone working from the same rules, our courses cover exactly this: how to get real value from AI without creating a data problem for the company.
The one habit worth keeping
You do not need to memorise a long policy document. You need one reflex: before you paste, ask whether this would be a problem if it landed in the wrong hands. If yes, strip it down or leave it out. Everything else about using AI well can be learned along the way. This one habit has to come first.