Glossary

Cortexa AI Glossary · Your data, rights, and the rules

Is it safe to paste work information into AI?

From Cortexa Learn, by Cortexa Consulting. Last checked .

A chatbot could tidy your report in a minute. Which account you use decides whose rules apply.


Late, with a deadline

It's late, the report is due in the morning, and a chatbot on your phone could tidy it in a minute. Before you paste it in, there's one quiet question to ask. Which account are you signed into, and whose rules cover what you're about to share?

Where it goes

When you paste text into an artificial intelligence (AI) chatbot, it's sent to the company that runs the tool, and it may be stored there. Depending on the product and your settings, some consumer tools may also use chats to help train future models. Topic 13, "Is what I type used to train AI?", covers those settings. It's a bit like forwarding a work file to your personal email. At work there's a bigger question: has your workplace agreed to share that information with that company?2

Personal and work accounts

The same chatbot can come with very different terms. Business plans usually come with a contract that covers how the company stores and uses your data, and many promise not to train on it. OpenAI, for one, says that by default it doesn't train its models on data from its business plans. A personal account on the same tool has none of your employer's agreement behind it, and that agreement is what your workplace's rules are built on.4

A name for the habit

Using AI tools at work without the company's approval has a name: shadow AI. It's common. In a 2024 survey of more than 7,000 people by CybSafe and the National Cybersecurity Alliance, 38 percent of workers who used AI said they had shared sensitive work information with it without their employer knowing.13

Why it happens

People rarely do this to cause trouble. They want to get the work done faster, and the approved tool may be missing, slower, or one nobody told them about. The same survey found that more than half of the working people it asked had never had any training on using AI safely. So if you've pasted something before, you're far from alone. You can start doing it differently today.3

What stays out

Whatever tool you use, three kinds of information need a clear yes from your workplace first.

  • Client and company secrets, such as contracts, plans, or code.
  • Passwords, keys, and anything else that opens a system.
  • Other people's personal details, such as names, addresses, or health records.

Those are the things that can do real harm once they're in the wrong place.12

Ask first

Many workplaces now have, or are writing, a short list of approved AI tools and what each one is cleared for. If you don't know yours, ask your manager or the people who run your company's technology. It's an ordinary question, and the answer often turns up a tool you can use on your work account. When you're unsure in the moment, take out names and numbers before you paste, or wait until you can ask.1

Tomorrow's question

So which tools has your workplace approved, and for what? If you're not sure, that's a good first question to bring in tomorrow.

Works cited

  1. IBM, "Does your business have an AI blind spot? Navigating the risks of shadow AI." (checked )
  2. IBM, "Governing data exposure in the age of generative AI." (checked )
  3. CybSafe, "Study: Almost 40% of workers share sensitive information with AI tools, without employer's knowledge" (2024) (checked )
  4. OpenAI, "Enterprise privacy at OpenAI." (checked )