Using AI safely at work: what to share and what not to
AI chat tools are handy for summarising, rewriting and research. But what you paste into them can affect customers, colleagues and your company. A practical guide.
AI chat tools became everyday equipment remarkably fast. Summarising a long email, rewriting a paragraph, working out an Excel formula: it saves time. Your colleagues probably use them already, whether you’ve arranged it or not.
The risk isn’t in using them. It’s in what gets shared. A complaint email with a name, address and bank account. A personnel file. A contract with confidential pricing. The moment that text sits in a chat window and someone clicks Send, it’s with an outside party.
What happens to your text
That depends on the service and the subscription. With some free or personal versions, what you enter may be stored and used to improve the service. Business versions often come with better terms, such as a data processing agreement and a commitment not to use your data for training. Read the terms of the service you use; don’t assume it’s fine.
For your policy the difference is significant: a business account covered by a data processing agreement is very different from a free account an employee set up on their own.
What does the GDPR say?
Entering personal data into an AI service means processing that data, so the normal GDPR rules apply. You need a lawful basis, you may only use data for the purpose it was collected for, and if an outside party processes it on your behalf, you need a data processing agreement.
A customer who gave you their details to fulfil an order hasn’t agreed to them ending up in a random chat tool. The Dutch data protection authority has reported receiving data breach notifications caused by employees entering personal data into AI chatbots. An incident like that can be a notifiable breach.
On top of that, since February 2025 the EU AI Act requires organisations that deploy AI systems to ensure sufficient AI literacy among their staff. Explaining what is and isn’t allowed is part of that.
What not to paste into a public AI tool
A practical rule of thumb for employees:
- Personal data of customers, patients or clients: names combined with contact details, addresses, bank accounts, dates of birth.
- Special category data: health, criminal records, religion, ethnicity. Stricter rules apply.
- National identification numbers, which are often legally restricted in how they may be used.
- Employee data: appraisals, sick leave, salaries.
- Confidential business information: contracts, pricing agreements, quotes, plans that aren’t public yet.
- Passwords, API keys and access codes, even when they “happen” to be in a piece of configuration or code.
What’s usually fine
- General questions, explanations and examples.
- Rewriting text with no personal data or confidential content.
- Text where you first replaced identifying details with labels, such as [customer] or [amount].
- Work in a business AI workspace your organisation pays for and has proper agreements with, within the rules you set for it.
Setting good agreements
Pick one or two services you do use. Banning everything pushes people to personal accounts. An approved alternative with clear agreements works better.
Write down what doesn’t go in. Short and concrete, like the list above. Nobody reads a ten-page policy.
Teach people to anonymise. Replace names and numbers with labels before sharing a text. The result is usually just as useful.
Remind people in the moment. Knowing the policy is one thing; remembering it when you want a customer email summarised is another. A short warning at the moment of pasting or sending does more than an annual training session.
Make mistakes reportable. If someone did share something they shouldn’t have, you want to hear about it quickly so you can assess whether it’s a breach. That only happens when reporting doesn’t lead to punishment.
In short
- Whatever you paste into an AI tool leaves your organisation.
- Personal data, special category data, ID numbers, employee data, confidential documents and passwords don’t belong there.
- Choose approved services with proper agreements rather than a blanket ban.
- Teach anonymising and remind people at the moment it matters.
ClickCheck can give that reminder: when someone sends text in an AI tool, the extension checks on their own computer whether it contains personal data. Read more about safe AI use with ClickCheck.