Responsible Use of Generative AI at Work · Unit 2 of 5 · about 10 minutes
Unit 2: Confidentiality and data leakage
Anything you type into a public AI tool should be treated as leaving your organisation. The prompt box looks like a private notepad; legally and practically, it is closer to an email to an external company.
Where the data actually goes
When you use a consumer AI tool, your prompt travels to the provider's servers. Depending on the tool, your settings and your subscription tier, it may be stored, reviewed by humans for quality control, used to train future models, or retained under the provider's data policy rather than yours. Enterprise versions of the same tools often carry stronger protections, which is exactly why organisations pay for them, and why "I used the same brand at home" is not the same as "I used the approved version".
Two facts worth internalising: deleting a conversation from your chat history does not necessarily delete it from the provider's systems, and a prompt can breach confidentiality even if the tool never repeats it to anyone. The breach happens at disclosure, not at republication.
The never list
Unless your organisation has explicitly approved a specific tool for the purpose, the following never go into a prompt:
- Personal data: names, contact details, identification numbers, health or financial details of clients, colleagues, students or customers. In most jurisdictions this is not just policy, it is data protection law.
- Commercially confidential material: unpublished financials, deal terms, pricing models, strategy documents, source code, tender responses.
- Third-party confidential material: anything a client, partner or supplier shared with you under a non-disclosure agreement (NDA) or an expectation of confidence.
- Credentials and security details: passwords, API keys, network details, security procedures.
The redaction habit
Most leakage happens because redaction feels like effort. It rarely is. "Summarise this complaint from [CLIENT] about [PRODUCT]" works exactly as well as the version with real names. Two seconds of substitution converts a breach into safe use. If a document is so sensitive that redacting it would gut it, that is the signal that it does not belong in an unapproved tool at all.
Scenario: the helpful analyst
An analyst is behind on a due diligence summary. She pastes twelve pages of a target company's confidential financials into a free AI tool and gets an excellent summary in forty seconds. Nothing visibly bad happens. Six months later, the deal leaks and the client's lawyers ask every adviser to account for how the information was handled. Her firm now has to disclose that the data was transferred to an AI provider under terms nobody read, with retention nobody can confirm. The summary saved her an hour. The disclosure conversation costs the firm the client.
The lesson is not "she should have worked the hour". Her firm's approved enterprise tool, with contractual data protections, was one tab away, and she did not know the difference mattered.
Key takeaways
- Treat every prompt to a public tool as a disclosure to an external company.
- Four things never go in: personal data, your organisation’s confidential material, third parties’ confidential material, credentials.
- Redaction is almost always cheap. Use placeholders.
- Approved enterprise tools exist precisely because the consumer version does not carry the same protections.
Knowledge check
Q1. Your manager asks you to get an AI summary of a supplier contract marked "Commercial in confidence". Your organisation has an approved enterprise AI tool. What is the correct move?
The approved tool exists because it carries negotiated data protections. Deleting a chat does not undo the disclosure, and the consumer version of a tool is not the approved version.
Q2. Which prompt is safe to send to a public AI tool with no special approval?
The formal-rewrite prompt contains no personal data, no confidential material and no credentials. Each of the others discloses something from the never list.