Skip to main content
Safety 29 July 2026 · By The Clerq team · 6 min read

Using AI safely at work: what never goes in the chat box.

The chat window feels like a private scratchpad. It is a form on someone else's server. Here are the working rules: what never goes in, how to anonymise what can, and what to do when something already has.

Nothing about a chat box signals consequence. It looks like a search bar, it answers like a colleague, and it is precisely this friendliness that causes the trouble: people paste things into AI tools that they would never email to a stranger - which, mechanically, is roughly what pasting is.

Direct answer

Is it safe to use AI at work?

It depends on the tool and the data. Keep personal data, client confidential material, unreleased figures, credentials and anything HR, health or legal related out of public AI tools. Use an employer-approved plan for real data, or anonymise first: swap names for roles and strip identifiers. If something slips through, report it promptly.

This is not an argument against using AI at work; the productivity case is real and worth building properly. It is an argument for knowing where the line sits before the habit forms, because the line is easy to hold from day one and awkward to retrofit.

What happens to what you type?

When you paste text into a public AI tool, it leaves your organisation's custody and lands on the provider's servers, subject to their terms rather than your employer's controls. On consumer plans, conversations may be reviewed for safety and used to improve future models unless you find the setting that says otherwise; chat history sits behind one password that may be weaker than your work login. Business and enterprise plans are different animals: typically no training on your data, contractual confidentiality and admin controls - which is exactly why employers buy them, and why "which plan am I on?" is a security question, not a billing one.

The practical translation: the risk is rarely a movie-style breach. It is ordinary loss of custody - confidential text sitting in an uncontrolled account, retrievable by whoever ends up with access, in breach of the promises your organisation made to clients, staff and regulators.

What should you never put into an AI tool at work?

  • Personal data about identifiable people: colleagues' salaries, performance notes, health matters, home addresses, a customer's complaint history. There is no "it was quicker" defence under UK data protection law.
  • Client and customer confidential material: contracts, pricing, deliverables, anything you hold because they trusted your organisation to hold it.
  • Unreleased numbers: financials, forecasts, deal terms, anything price-sensitive or board-level before it is public.
  • Credentials: passwords, API keys, door codes, account numbers. No exceptions, no "just this once".
  • Anything under NDA or legal process: disputes, disciplinary matters, grievances, due diligence. If lawyers are near it, AI tools are not.

The portable test: would you pin it to a noticeboard in the building lobby? Not because the chat box is a noticeboard, but because the question forces the right reflex - you stop assessing the tool and start assessing the content.

How do you anonymise data before using AI?

Most tasks survive anonymisation intact, because the assistant needs the shape of your problem, not the secrets in it. Swap names for roles: "Client A", "our largest supplier", "a team member". Round or rescale numbers: a payment plan for "roughly £40k" gets the same quality of answer as one for £41,750. Strip emails, phone numbers and reference codes. And watch combinations - "our Manchester warehouse client in dairy" identifies someone as surely as a name. A worked example:

Instead of: "Draft a payment reminder to Meadowbrook Farms, who owe £41,750 from invoice INV-2209, contact Sarah Jennings..."
Write: "Draft a firm but warm payment reminder to a long-standing client with a five-figure invoice 30 days overdue. We value the relationship but need a date."

The draft that comes back needs the same personalisation you would add anyway - and nothing directly identifying left the building. This reduces the risk sharply; it does not put the data outside UK GDPR, because anything still traceable back to a person counts as personal data. This one technique unlocks most of email, spreadsheet and document work on even a personal tool. Where anonymisation is impractical - full transcripts, whole datasets - that is the signal the task belongs in an approved tool instead.

Play it as a team sport.

Three habits close most of the remaining gap. First, know your employer's AI policy - and if none exists, asking for one is a contribution, not an admission (here is what a right-sized policy looks like). Second, prefer the approved route where one exists: an enterprise Copilot, Gemini or ChatGPT plan moves most of this risk from your judgement to a contract. Third, be doubly careful with anything that holds standing access - notetakers that join every call, agents wired into your inbox, plugins with drive permissions. Pasting shares a message; connecting shares everything, continuously. Tool-adoption questions live in choosing AI tools for office work.

What if something has already gone in?

It happens in every organisation, usually in week one of enthusiasm. The wrong response is silence. The second-wrong response is tidying up. Tell your manager, IT or data protection lead first - if personal data is involved, your organisation may have assessment and notification obligations with statutory deadlines, and any such deadlines typically run from the point of awareness, not from the moment it is convenient - the ICO's personal data breach guidance is the primary source. Then write down what went where and when: which tool, which account, what was pasted, what time.

Do not delete the conversation until you are told to. It is the only record of what was actually exposed, and your employer needs it to judge the scope and decide whether anything has to be reported. Deleting it removes nothing from the provider's servers, destroys the evidence and reads, afterwards, as concealment - which turns a mistake into a conduct question. Organisations forgive fast honesty; they struggle with slow discovery.

And if you are reading this pre-emptively: open the settings of your personal AI tool, find the option that controls whether your conversations are used to train future models, and switch that training off. Two caveats worth knowing before you do. On Google's Gemini, the same switch also stops chats being saved to your activity history. And it works forwards only - it does not remove anything already sitting on the provider's servers. It reduces one risk. It does not make pasting confidential material safe.

This is general guidance, not legal advice; your employer's own policy and your data protection lead come first.

Frequently asked questions

What should you never put into an AI chatbot at work?

Personal data about identifiable people, client or customer confidential material, unreleased financial figures, passwords and access credentials, anything under NDA, and anything relating to HR, health, legal or disciplinary matters. If exposure would harm a person or the business, it stays out of public tools.

Is it safe to use ChatGPT at work?

It depends on the plan and the data. Consumer versions of AI tools may use your conversations to improve their models unless you opt out; business and enterprise plans typically exclude training and add contractual protections. Safe use means an approved tool for real data, or properly anonymised input on a personal one.

How do I anonymise data before using AI?

Swap names for roles (Client A, our supplier), round or rescale sensitive numbers, strip contact details and identifiers, and remove context that makes a person or deal identifiable in combination. The structure of the task survives; the sensitive substance does not.

What should I do if I pasted confidential data into an AI tool?

Tell someone promptly - your manager, IT or data protection lead - the same as any other data incident. Do not delete the conversation: it is the evidence your organisation needs to assess what was exposed, and any notification deadlines typically run from the point of awareness. Write down which tool, which account, what was pasted and when, and let the people who own the process decide what happens next. Speed matters far more than blame.

Take this with you

The safety rules, pocket-sized.

  • The noticeboard test: if you wouldn't pin it in the lobby, it doesn't go in a public tool.
  • Never list: personal data, client confidences, unreleased numbers, credentials, anything near lawyers.
  • Anonymise by default: roles for names, rounded numbers, no identifiers, no identifying combinations.
  • Approved tools for real data; personal tools for anonymised structure; training switched off everywhere.
  • Standing access (notetakers, agents, plugins) is a bigger decision than any single paste.
  • If something slips: report fast, do not delete the conversation, write down what went where - honesty ages well, discovery does not.

Put AI to work in your own job.

AI at Work is Clerq's practical, hype-free guide to getting real work done with AI - written for people with inboxes, deadlines and meetings, not developers. PDF and EPUB, launching soon.