Before pasting a document into an AI tool, ask two questions: Am I allowed to share this information with this service? and Does the task need the real information at all? The answer depends on your agreement with the people involved, your organization’s rules, and the specific product and account settings. A paid plan or a reassuring privacy slogan is not a substitute for checking those details.
Choose the smallest useful input
| Material | Safer first move | Extra check before using the real data |
|---|---|---|
| Public text you wrote | Share only the portion needed for the task. | Confirm it is actually public and you have rights to use it. |
| Internal process or draft | Replace names, account details, and unnecessary context with placeholders. | Check your organization’s approved tools and retention rules. |
| Customer messages or contact details | Start with a fictional or de-identified example. | Confirm permission, purpose, access, and any applicable contract or policy. |
| Financial, health, legal, employee, or child-related information | Keep it out of an unapproved tool. Use a controlled process and qualified review. | Confirm the precise service terms, security controls, and required approvals. |
| Passwords, API keys, recovery codes, private tokens | Never put them in a prompt or attached file. | Use the service’s secret-management method; rotate a secret if exposed. |
De-identification takes care. Removing a name may still leave a unique address, invoice number, timestamp, or combination of details that identifies someone. For a draft, a fictional example often works just as well.
Check the actual service and account
Product controls change, so inspect the current settings and documentation for the account you will use. Record the date of the check. In particular, check:
- Where data goes: the product, connected apps, browser extensions, shared workspaces, and any third-party model provider.
- Training and retention: whether inputs or outputs can be used to improve models, how long they are kept, and whether your plan changes those rules.
- People and permissions: who can read the conversation, files, logs, exports, and generated results. Use the smallest access level that completes the task.
- Connected actions: what the AI can read, edit, send, or publish. A drafting task rarely needs permission to send messages or update records.
- Deletion and incident path: how to remove material, what deletion covers, and whom to tell if the wrong data was shared.
Do not assume a private chat is the same as a private deployment. Read the terms for the exact product and configuration. The NIST generative AI risk profile treats privacy and information security as risks that need controls throughout a system’s use.
A quick decision rule
If the task works with placeholders, use placeholders. If it truly requires real data, use only an approved service and the minimum necessary fields. If the sharing permission or service behavior is unclear, stop that input and get the responsible person’s answer before proceeding. You can still run the first AI pilot with invented data, then test a real case after the data decision is settled.