AI Safety, Privacy & Verification

What You Should Never Share With AI Tools

The CourseFluent TeamFebruary 1, 20267 min read
MOFUsensitive data and chatgptai confidentiality ruleswhat to avoid putting in chatgpt

What you should never share with AI tools boils down to a short, memorable list: customer personal information, financial data that isn't yet public, anything under NDA or legal privilege, credentials of any kind, and employee HR data. Beyond that specific list, a good general rule is: if you wouldn't paste it into a public forum, don't paste it into a consumer AI tool either - because, depending on the account and settings, that's closer to what's actually happening than most people realize.

This isn't about distrusting AI or avoiding it - it's about knowing exactly where the line is so your team can use these tools confidently for everything else. Here's the specific list, with real examples of what it looks like in practice.

Category 1: Customer Personal Information

This is the highest-stakes category and the one most likely to create real legal exposure. Avoid pasting:

  • Full names combined with contact details, order history, or account information
  • Financial information (payment details, account numbers, credit information)
  • Health-related information of any kind
  • Any data covered by a privacy regulation your business is subject to (see our AI compliance basics guide)

What to do instead: describe the situation generically. Instead of "Sarah Thompson at 555-0123 is disputing a $4,200 charge on invoice #8821," write "a customer is disputing a charge of roughly $4,000 on a recent invoice." The AI tool doesn't need the real identifying details to help you draft a response.

Category 2: Unreleased Financial Information

Company financials that haven't been publicly disclosed - quarterly results, forecasts, fundraising details, pricing changes - carry real risk if they end up retained somewhere outside your control, especially for public companies or businesses under an active deal.

What to do instead: use rounded or placeholder figures when the exact numbers aren't necessary for the task ("revenue grew by roughly 20%" instead of the precise figure), or restrict real-figure work to a business-tier tool your finance team has explicitly cleared.

Anything under an NDA, active litigation, or contract negotiation should be treated as strictly off-limits without explicit legal sign-off. This includes:

  • Draft contracts under negotiation
  • Details of active disputes or litigation
  • Anything a client or partner has explicitly asked to be kept confidential
  • Attorney-client privileged communications

What to do instead: if you need AI help with legal-adjacent writing, work with a genericized or hypothetical version of the situation, or check with legal counsel about whether an approved, contracted AI tool is appropriate for the specific matter.

Category 4: Credentials and Security Information

This category is easy to overlook because it doesn't always feel like "sensitive data" in the moment, but it's some of the highest-risk information to expose:

  • Passwords, API keys, or access tokens
  • Internal system architecture or security configuration details
  • VPN details, internal URLs, or admin credentials

What to do instead: never paste real credentials into any AI tool, even "just to check the format." If you need help debugging something that involves a credential, replace it with an obviously fake placeholder first.

Category 5: Employee Personal and HR Data

Performance reviews, compensation details, disciplinary matters, and personal employee information carry the same sensitivity as customer PII, and the same privacy regulations often apply.

What to do instead: if you're using AI to help draft a performance review or HR communication, work from a genericized version of the situation and add the real specifics yourself afterward, outside the AI tool.

A Simple Test When You're Not Sure

For anything not obviously on the list above, ask yourself two questions:

  1. Would I be comfortable if a colleague or my manager saw exactly what I typed?
  2. Would this be a problem if it were somehow retained or seen outside the company?

If either answer is "no" or "I'm not sure," redact the specifics or don't share it. This quick gut-check catches most edge cases the formal list doesn't explicitly cover.

Redaction: The Habit That Solves Most of This

The single most useful habit for staying safe isn't avoiding AI for anything sensitive-adjacent - it's redacting before you type. In practice, this means:

  • Replacing real names with generic placeholders ("Client A," "Employee 1")
  • Rounding or generalizing exact figures when precision isn't needed for the task
  • Describing a situation's substance without its identifying specifics
  • Adding the real details back in yourself, after the AI has helped with structure or wording

Most tasks people bring to AI - drafting, summarizing, brainstorming, rewriting - work just as well with redacted placeholders as with real data, because the AI is helping with structure and language, not verifying facts about your specific customer.

Why This List Matters More Than It Seems

Every one of these categories represents a genuinely realistic scenario, not a hypothetical edge case - a support agent pasting a customer's full ticket into ChatGPT to draft a reply, a finance analyst asking AI to "clean up" a spreadsheet with real client figures, an HR coordinator drafting a difficult conversation with real names attached. None of these happen out of carelessness so much as nobody ever drawing the line clearly. That's exactly what this list - and a written AI acceptable use policy - is for.

Make This List Second Nature for Your Whole Team

A list like this only works if people actually remember it in the moment, under time pressure, mid-task - which takes more than reading it once. CourseFluent builds this exact judgment into every course, with realistic, redacted examples from your own industry and a knowledge check that confirms the habit has actually formed, tied together with our safe AI use checklist.

Start your free CourseFluent account and make "what not to share with AI" second nature across your whole team - see our features page for how it fits into the full training path.

FAQ

Is it ever okay to share customer names with AI tools?

Generally, avoid it unless the tool is a vetted business-tier account with an appropriate data processing agreement and there's a genuine business need. For most everyday drafting and brainstorming tasks, a placeholder works just as well and carries far less risk.

What if I already pasted something sensitive into ChatGPT by accident?

Most AI tools let you delete individual conversations, which removes it from your visible history, though retention policies vary by plan. Report it to whoever owns your AI policy internally so the team can assess and respond appropriately - treat it the same way you would any other accidental data exposure.

Does this list apply the same way to business-tier AI accounts?

The risk is generally lower on business-tier accounts (no training data usage, contractual protections), but the same categories still deserve caution - a data processing agreement reduces risk, it doesn't eliminate the value of redaction and good judgment.

Written by The CourseFluent Team

Free AI training plan

Get your team fluent in AI

CourseFluent builds a free, personalised AI training plan for your business - sign up and invite your team in minutes.

Start free

Related reading

More on this topic