The one idea
There are two things you can give away without noticing, and only one of them is data.
The first is information. Once you paste something into a tool you do not control, you no longer control it. Whether it is retained, who might see it, and what it is used for are governed by an agreement you probably have not read.
The second is judgement. This one is quieter and costs more. You can hand over the deciding, the checking and the thinking, and still have your name on the output — keeping the accountability while giving away the capability. That trade is always bad, and easy to make gradually.
Do not paste things that are not yours to share. Do not hand over decisions you will have to defend.
Know which tier of tool you are using and what its terms say about retention, human review and training. Assume nothing about a consumer account.
Data handling differs by product tier and configuration. Consumer accounts commonly allow retention, human review of samples, and use for improving services; business and enterprise agreements usually restrict this contractually. The difference is the contract, not the interface.
The never-paste list
| Category | Examples | Why |
|---|---|---|
| Employer or client confidential | Contracts, unreleased strategy, financials, source code, internal documents | Not yours to share. Usually a contractual breach, not just a policy one |
| Other people's personal data | Names with medical, financial, HR or performance details; CVs; customer records | They did not consent. Data protection law may apply regardless of your intent |
| Credentials and secrets | Passwords, API keys, tokens, account numbers, OTPs | No legitimate reason ever exists to paste these |
| Unreleased information | Results before announcement, unannounced products, deal terms, layoffs | Consequences can extend to securities and employment law |
| Anything under NDA | Whatever the NDA covers | You signed something specific about this |
| Your own sensitive material | Medical history, financial position, legal problems | Allowed — but decide knowingly, not by habit |
The last row is a choice, not a prohibition. Plenty of people get real value from AI help understanding a diagnosis or a legal notice. Make it a decision rather than a reflex, and know it may be retained.
Consumer versus enterprise
This distinction matters more than anything else here, and most people do not know which one they are using.
| Consumer account | Business or enterprise account | |
|---|---|---|
| Who agreed to the terms | You, by clicking | Your employer, by contract |
| Typical training use | Often allowed, sometimes opt-out | Usually contractually excluded |
| Human review | Samples may be reviewed | Restricted or excluded by agreement |
| Retention | Set by the provider | Set by the agreement |
| Who is liable if it goes wrong | You | Your employer |
The interface can look identical. A personal and a company account can sit in the same browser, distinguished by a small label.
The practical rules:
- Find out what your employer has approved, and whether the account you are logged into is that one. Ask; do not assume.
- If there is no approved tool, assume work material is not allowed. "Nobody said no" is not permission, and it is a poor thing to say afterwards.
- Check which account you are in before pasting anything from work.
- Do not route around a restriction by pasting work content into a personal account on a personal device. That is the specific thing the restriction exists to prevent, and doing it deliberately is much worse than doing it ignorantly.
You want help rewriting a difficult email to a client. The email names the client, references contract terms, and mentions an internal dispute.
The workable version: strip it. Replace the client with "the client", remove the contract clause, describe the situation generically — "we missed a deadline, the relationship is strained, I need to acknowledge fault without accepting liability". You get the same help on the hard part, the wording, and have shared nothing. Most confidential-paste situations dissolve like this.
You are asked to analyse a spreadsheet of employee salaries. Pasting it shares other people's compensation data — personal data carrying real obligations in most jurisdictions, and something your employer will treat as a serious breach whether or not the law does.
What works: describe the structure and ask for the method. "I have a sheet with department, grade and salary. How do I find the median by department and flag anything more than 20% from it?" You get the method; the data never moves.
The second thing: what not to outsource
Data leaks are the risk everyone talks about. This one does more quiet damage.
| Never outsource | Why | What to do instead |
|---|---|---|
| Judgement | Weighing options against things only you know — politics, history, who will be upset | Use it to lay out options and trade-offs. You choose |
| Responsibility | Your name is on it. "The AI said so" is not a defence anyone accepts | Own the output completely or do not send it |
| Verification | It cannot check itself, and asking makes more text of the same kind | Check facts at the source yourself |
| Original thinking | The first thing it gives you is the average of what exists | Think first, then use it to stress-test |
| Decisions you must defend | You will be asked why, in a room, without the tool | Be able to explain the reasoning as your own |
| Relationships | The apology, the difficult feedback, the condolence | Draft with it if you must. Send words you mean |
The order matters. Think first, then use the tool, then decide. Most people invert this — ask first, receive the average, and end up defending a position they did not arrive at. It is hard to have an original thought about something after reading a fluent answer about it, and you cannot tell it has happened.
The check before you paste
1 of 6Ask whose information this is. Yours, your employer's, a client's, or another individual's? Anything but the first needs permission you probably do not have.
Try this
Which of these are safe to paste into a consumer AI account? For the unsafe ones, what would you do instead?
- A public job description you are applying to.
- Your team's unreleased quarterly numbers, for help writing the commentary.
- A LinkedIn message from a recruiter, asking how to reply.
- A colleague's medical certificate, to summarise for an HR form.
- An error message from your company's internal system.
Your challenge
Level 3 · IndependentFind out, this week, what your employer's or institution's actual position is on AI tools. Not what people assume — what is written down.
You have succeeded when you can state: whether there is an approved tool, whether it is a business or consumer account, what categories of information are prohibited, and who to ask when it is unclear.
If there is no policy, that is a finding. Write down the rules you will follow yourself, and be ready to explain them. When a policy does arrive, being the person who already had a defensible position is a good place to be.
What people usually get wrong
- Assuming a chat is private because it feels private. A text box that looks like a message to a friend is a submission to a service.
- Not knowing which account you are logged into. The commonest way work material ends up in a personal account.
- Thinking deletion undoes it. Deleting a conversation may not remove data already retained or reviewed. Check the provider's actual policy.
- Believing "I removed the name" is anonymisation. Enough surrounding detail identifies a company or person without any name.
- Treating no policy as permission. It means nobody has decided yet, and you will be the test case.
- Letting it make a decision you will have to defend. You keep the accountability either way.
- Sending an apology you did not write. People can tell, and the damage exceeds the awkwardness you avoided.
How someone experienced does it
Experienced professionals run a two-part test before pasting: whose information is this, and what is the worst plausible place it could surface? Not the worst imaginable — the worst plausible: a support ticket, a reviewer's screen, a retained log produced in litigation. It takes three seconds and it settles almost every case.
On the judgement side, the discipline that separates people is this: they can always explain their reasoning without mentioning the tool. If the only account they can give of why they recommended something is that the AI suggested it, they treat that as a signal they have not done the work yet — not as an efficiency.
The failure they watch for in themselves is gradual. Nobody decides to stop thinking. They start by checking every output, then most, then the ones that look odd, then none — and each step feels reasonable because the tool has been right so often. The people who stay sharp keep one category they always verify by hand, regardless of how reliable it has seemed. It is a deliberately maintained habit, not a judgement call, precisely because judgement is what erodes.
When not to use this
This caution is not an argument for avoiding AI tools. Refusing to use them at all is its own cost, and "I do not use those" is not a professional position.
The boundary is specific: not other people's confidential information, and not the parts of your work you are accountable for. Everything else — your own drafts, public material, generic problems, your own learning — is open. That is most of the work.
Why 'it was only a summary' does not help
People reason that pasting a document for a summary is different from sharing it, because the output was just a summary.
The exposure is the input, not the output. The document was transmitted, processed and possibly retained the moment you pasted it. What you did with the result is irrelevant to whether the sharing occurred.
This matters because confidentiality obligations are usually written as restrictions on disclosure — on transmitting information to a third party — not on publication. A clause saying you will not disclose client information to third parties without consent is engaged by the paste. Your intention, and the fact that nothing bad happened, do not change what took place.
Which is why the check has to happen before the paste. No version of it works afterwards.
Prove it
Write your own one-page rule set: three categories you will never paste, three kinds of decision you will never delegate, and the one thing you will always verify by hand no matter how reliable the tool has been.
Keep it where you can see it. In two years the tools will be much better and the line will be harder to hold, because it will feel unnecessary. That is exactly when having written it down is worth something.
Keep learning this
Paste this into any AI assistant. It turns the assistant into a tutor that tests you instead of just answering you.
Act as an experienced practitioner who is good at teaching. I have just learned what information is unsafe to share with AI tools and why. Assume I am intelligent but relatively new to this — treat me as intermediate level. Work through this in order, and wait for my reply at each step: 1. Ask me 5 questions that test whether I actually understood what information is unsafe to share with AI tools and why. Do not reveal the answers yet. 2. After I answer, tell me which parts I got right, which I got wrong, and which I only half-understand. Explain only what I misunderstood — do not re-teach what I already know. 3. Give me one practical challenge based on something I could genuinely encounter at work or in daily life. Do not solve it for me. 4. Evaluate my solution the way an experienced person would judge it, including what a professional would have done differently. 5. Tell me what to learn next, and why that comes next. 6. Give me trustworthy sources for deeper study — prefer official documentation, primary research or standards bodies over blogs and videos. Rules for you: no buzzwords. No motivational filler. Say "I'm not certain" when you are not certain, and tell me which parts of your answer I should verify myself. Clearly separate facts from your recommendations and your opinions.
Become independent at this
Use this when you want a path from where you are to actually good, with checkpoints you can test yourself against.
I want to become independently capable at setting your own boundaries with AI tools — not permanently dependent on AI, tutorials or step-by-step guides. Design a progression for me with five stages: Beginner, Guided practice, Independent practice, Real-world application, Professional level. For each stage tell me: - what I must know - what I must be able to do without help - the mistakes people make at this stage - one practical challenge - one real project that would prove I reached this stage - one way I can test myself honestly Then tell me the signals that I am ready to move to the next stage, and the signals that I have skipped ahead too early. Keep the theory to the minimum I actually need. Focus on ability I can transfer to situations you and I have not discussed.