What should never go into an AI chat
You don't need a legal department to put this in writing. Three rules cover most of the real risk in an SME — and they fit on a single page anyone can read in two minutes.
Identifiable health, legal and financial data
The problem is rarely the content itself: it's the content with a name attached. A clinical report with no identification is a case study; with the patient's name it is sensitive data. The same sentence applies to legal matters, salaries and client accounts.
Anonymise before pasting: replace names with Client A, strip tax numbers, exact dates and case numbers.
Credentials, keys and configuration files
I see this every week: somebody pastes an entire configuration file to ask for help, with passwords and API keys buried in it. Even with retention off, the key has travelled through a channel you don't control and has to be rotated.
No password or key goes into a chat — not even to debug. Paste only the line with the error.
Third-party documents that are not yours to share
Client contracts and proposals usually carry confidentiality clauses that draw no distinction between an AI tool and a subcontractor. Using them isn't forbidden, but it requires business accounts and, in some cases, telling the client.
Check the confidentiality clause before putting client documents into any tool.
The minimum setup before any of this
- Business accounts, never personal ones, with training on the data switched off.
- One page of rules available to everyone, written in plain language.
- One person responsible for answering data questions — and for keeping the page current.
- A record of which tools are approved, to head off installations done on personal initiative.
Want to know whether your case can be automated? Let's talk for 30 minutes.
Book a call