Skip to content

Applied AI

What not to paste into an AI chat (and what to do instead)

Your team already uses AI chat tools. Which data must never leave the company, what to do instead, and how to write a short internal rule people follow.

4 MIN READ

In most companies, the question "should we let the team use AI chat tools?" arrived too late: the team already uses them. To draft an email, summarise a document, prepare a proposal. The real decision is not whether to allow or ban them — a blanket ban just pushes the usage out of sight — but something more concrete: which information may leave the company and which may not, and how to turn that line into a short internal rule people actually follow. This article is about drawing that line.

Pasting is sending

An AI chat feels like just another desktop tool, and that is the trap. When you paste text into an external chat, that text leaves the company and is processed on a third party's servers. What happens next — how long it is kept, who can see it, what it is used for — depends on terms of service almost nobody has read, and which differ depending on the type of account.

The starting principle is the same one you would apply to any other external service: pasting is sending. The useful question is not "is this AI secure?" but the old one: would I email this to an outside supplier I have no contract with? If the answer is no, it does not go in the chat either.

Four kinds of data that must not leave

Personal data. Names of customers, employees or candidates tied to their situation: a payslip, a sick note, a complaint with contact details. Processing personal data carries legal obligations, but the internal rule does not need a legal opinion behind it: operationally, it does not get pasted.

Client information and contracts. Much of what you know about your clients is covered by confidentiality agreements. Pasting a client's contract "just to summarise it" may breach your own commitment to them. That data is not entirely yours; neither is the decision to move it.

The company's internal numbers. Margins, negotiated prices, live offers, plans not yet announced, proprietary code. None of this sinks the business by appearing in a chat once — but it is exactly the kind of information whose journey you no longer control once it has been sent.

Credentials and access. Passwords, access keys, configuration files with secrets inside. Never — not even "just so it can help me find the bug". A credential that has left gets rotated; that is the entire policy.

What to do instead

The good news is that almost everything generative AI does well, it does just as well without the real data.

  • Generalise before you paste. Strip out names, figures and identifying detail. "A manufacturing client is complaining about a late delivery" produces the same quality of answer as the version with a name attached.
  • Use fictional examples with the same structure. For templates, formats and formulas, an invented figure works exactly like a real one.
  • Get company accounts. The terms of a service the company contracts are not the terms of a free personal account: what is stored, and what it is used for, is agreed in a contract. If the team is going to use AI daily, that difference matters — read it before deciding, not after.
  • Build an internal assistant for the recurring cases. If the real need is to ask the same questions of your own documents again and again, there are options designed for that, with the data under the company's control. It is a separate project, not the first step — but it is the natural exit once the usage stops being occasional.

An internal rule people actually follow

AI usage policies that get ignored all look alike: long, abstract, and made entirely of prohibitions. One that works usually fits on a single page:

  • What is allowed, with examples drawn from the company's real tasks. A rule that only forbids does not eliminate the usage: it hides it, and hidden usage is precisely the usage you cannot protect.
  • What is not, with the four kinds of data above grounded in examples from your own business, not abstract categories.
  • Which account to use, if the company has contracted one.
  • Who to ask when in doubt — and that person needs to answer quickly. If asking is slow, people stop asking.

And a review date: tools and their terms change, and a frozen policy loses authority the moment it stops describing reality.

Three questions before pasting anything into an AI chat

  1. Does this identify a specific person or client?
  2. Would I be uncomfortable seeing this text outside the company?
  3. Does the request work just as well if I remove the real data?

If the answer to the third is yes — and it almost always is — the problem solves itself: generalise, and paste with a clear conscience.

At Dateliers this is one of the first topics we cover when a team starts working with AI: not to slow the usage down, but so it can grow without incidents. If you want to see how we approach it, this is how we work.

After reading

Does this sound like your case?

If this describes something sitting on your desk, tell us about it. We'll come back with a first read before proposing anything.

Tell us about your case

A first 30-minute call with direct senior interlocution — no commitment and no sales pitch.