AI tools have quietly become part of the working day. Staff use them to draft emails, summarise meetings, clean up spreadsheets, and write code. Productivity is up — and in most businesses, nobody has told anyone what they're allowed to put into these tools.
That gap is where the trouble starts. The risk usually isn't a hacker; it's a well-meaning employee pasting a client contract into a free chatbot to get a quick summary.
Here are the rules we recommend to every business we work with.
1. Never Paste Sensitive Data Into a Public AI Tool
This is the single most important rule. Once information leaves your network, you've lost control of it.
Assume anything typed into a free consumer AI tool may be stored, reviewed by humans for quality purposes, or used to train future models. Several major companies have banned public AI tools outright after staff pasted proprietary source code into them.
Keep out of public AI tools:
- Customer and client personal data — names, addresses, dates of birth, financial details
- Health, HR, or disciplinary records
- Contracts, pricing, and commercial terms
- Source code and internal system documentation
- Passwords, API keys, and access credentials
- Anything covered by an NDA or confidentiality clause
- Financial results before publication
- CVs and candidate information
If you'd hesitate to email it to someone outside the company, don't paste it into a chatbot.
2. Understand the Difference Between Free and Business Accounts
Not all AI tools handle your data the same way, and the distinction matters legally as much as technically.
Free and personal consumer accounts typically retain your conversations and may use them for model training. Business, team, and enterprise tiers generally exclude your data from training, offer data processing agreements for GDPR compliance, provide administrative oversight, and support data residency requirements.
Paying for proper business licences is one of the cheapest risk reductions available to you. It also gives you something you cannot get from a free account: a contract.
3. Turn Off Training and Chat History Where Available
Most AI platforms let you opt out of having your conversations used for training, though the setting is rarely on by default and is sometimes buried.
Check the privacy settings of every AI tool in use, disable training on your data, and turn off or limit chat history retention where the feature isn't needed. Review these settings periodically — providers change defaults after updates more often than you'd like.
4. Get Visibility of What Your Staff Are Actually Using
"Shadow AI" is the term for tools adopted without approval or oversight. In nearly every assessment we run, the list is longer than management expects — browser extensions, note-taking apps that silently join meetings, AI features embedded in software you already licence.
You cannot govern what you can't see. Start with an honest, blame-free audit: ask people what they use and why. Staff adopt these tools because they solve a real problem, and if you ban everything without offering an approved alternative, usage simply goes underground.
5. Approve a Short List of Tools
Rather than an open field or a blanket prohibition, give people a small set of vetted options that cover the common use cases — writing, summarising, coding, transcription.
An approved list makes the safe choice the easy choice. It also concentrates your licensing spend, simplifies training, and makes support far more manageable.
6. Write an AI Acceptable Use Policy People Will Actually Read
A short, clear policy beats a long one nobody opens. It should cover which tools are approved, what data can and cannot be entered, when AI output must be checked by a human, whether AI-assisted work needs disclosing to clients, and how staff request approval for a new tool.
One page is usually enough. Make sure new starters get it during onboarding.
7. Always Verify AI Output Before It Leaves the Building
AI tools produce confident, fluent, well-structured text that is sometimes wrong. They invent citations, misstate figures, and fabricate legal references. Lawyers have been sanctioned for filing documents containing cases that never existed.
Treat every AI output as a first draft from a fast but unreliable junior colleague. Check facts, figures, names, dates, and any calculation. Never send AI-generated content to a client or regulator without a human reading it properly.
The accountability sits with the person who pressed send, not the tool.
8. Be Careful With Meeting Transcription Tools
AI notetakers are genuinely useful and quietly risky. They record everything, including the informal conversation before and after the agenda.
Get consent from participants before recording, be aware of the legal requirements in your jurisdiction, don't use them for HR, legal, or confidential commercial discussions, and know where the recordings and transcripts are stored and for how long. Delete what you no longer need.
9. Watch the Permissions You Grant
AI tools increasingly ask to connect to your email, calendar, file storage, and CRM. Each connection is a door.
Apply least privilege: grant read-only access where that's sufficient, limit access to specific folders rather than entire drives, review connected applications quarterly, and revoke access for tools nobody uses any more. Be especially cautious with AI agents that can take actions on your behalf rather than just answering questions.
10. Remember That GDPR Still Applies
Putting personal data into an AI tool is processing it. That means you need a lawful basis, an appropriate agreement with the provider, awareness of where the data is being processed geographically, and a record of the activity.
The EU AI Act adds further obligations depending on how you're using AI, with requirements phasing in over the next couple of years. If you're making decisions about people — hiring, credit, service eligibility — using AI, the compliance bar is significantly higher.
11. Train Your Team
Most AI-related data leaks come from people trying to do their jobs well and not realising the implications. That's a training problem, not a discipline problem.
Cover what data is sensitive, why free tools differ from business ones, how to check AI output, and who to ask when unsure. A short session that gives people practical confidence is worth more than a policy document filed away unread.
12. Assume Nothing Is Truly Private
A useful mental test before typing anything into an AI tool: would I be comfortable if this appeared in a data breach disclosure, or on the front page of a trade publication?
If the answer is no, don't paste it.
Getting the Balance Right
None of this is an argument against using AI. Businesses that use it well are genuinely more productive, and the ones that ban it outright tend to find their staff using it anyway on personal devices, entirely outside their visibility.
The goal is deliberate adoption: approved tools, clear rules, proper licences, sensible permissions, and a team that understands why it matters.
If you'd like help auditing what's in use across your business, choosing the right tools, or putting a workable AI policy in place, we can help.
Contact Joe Hunter IT to talk it through.
