top of page

KAPPA TECHNOLOGY BLOG 

AI Security Dos and Don’ts: What Should You Never Upload to an AI Tool?

AI Security Dos and Don’ts: What Not to Upload

Artificial intelligence tools such as ChatGPT, Microsoft Copilot, and Google Gemini can help businesses write documents, summarize information, analyze data, and complete routine tasks more efficiently.


However, using AI without clear security guidelines can expose confidential business, customer, and employee information.


One of the most common questions we hear is:


Does an AI Tool Receive a Copy of the Information You Upload?


Yes!! When you type information into an online AI tool or upload a document, that information is transmitted to the provider’s systems so the AI can process it and generate a response.


What happens after that depends on several factors:


  • Which AI provider you are using

  • Whether you are using a personal or business account

  • Your account’s privacy settings

  • The provider’s data-retention policy

  • Whether your organization has an enterprise agreement

  • Whether the provider may use conversations to improve its models


For example, ChatGPT provides controls that allow users to choose whether their conversations may be used to improve its models. OpenAI also states that Temporary Chats are not used for training and are deleted from its systems after 30 days.


Microsoft states that prompts, responses, and organizational data used through Microsoft 365 Copilot’s enterprise protections are not used to train its underlying foundation models.


Google provides similar protections for qualifying Google Workspace business accounts, stating that organizational prompts and uploaded files are not used to train generative AI models without permission.


However, “not used for training” does not mean the information never leaves your computer. The AI provider must still receive and process the information to respond to your request.

That is why employees should never assume an AI tool is private simply because it requires a login.


Information You Should Never Upload to an AI Tool

Unless your organization has specifically approved the tool and confirmed its security protections, do not upload or paste the following information.


Passwords and Security Credentials

Never enter:

  • Passwords

  • Multifactor authentication codes

  • Password-reset links

  • API keys

  • Private encryption keys

  • Remote-access credentials

  • Firewall or administrator passwords

  • Software license keys


Even when asking an AI tool to troubleshoot a technical problem, remove all credentials before submitting logs, screenshots, or configuration files.


Personal and Financial Information

Do not upload information such as:

  • Social Security numbers

  • Driver’s license or passport numbers

  • Credit card information

  • Bank account and routing numbers

  • Tax returns

  • Payroll records

  • Employee background checks

  • Customer payment information


Replacing a person’s name with initials may not be enough. Other details in the document could still identify the individual.


Medical and Health Information

Medical records, diagnoses, insurance information, prescriptions, treatment notes, and other protected health information should not be entered into an unapproved AI platform.


Organizations subject to HIPAA or other regulatory requirements must verify that the AI service is appropriately configured and covered by the necessary agreements before using it with protected data.


Confidential Customer Information

Avoid uploading:

  • Customer lists

  • Contact databases

  • Account histories

  • Support tickets

  • Private email conversations

  • Service agreements

  • Customer network diagrams

  • Internal customer reports


A support ticket may appear harmless but could contain names, email addresses, IP addresses, passwords, system details, or other sensitive information.


AI Security Dos and Don’ts: What Not to Upload. Orlando IT Support for Business


Proprietary Business Information

Do not paste confidential information such as:

  • Unreleased financial statements

  • Business valuations

  • Acquisition or sale discussions

  • Pricing strategies

  • Trade secrets

  • Product designs

  • Internal procedures

  • Proprietary source code

  • Confidential contracts

  • Legal advice or attorney-client communications


Information does not have to contain a Social Security number to be sensitive. A company’s financial forecast, customer pricing, source code, or acquisition plans can be extremely valuable to a competitor or attacker.


Complete Documents When Only a Small Portion Is Needed

Uploading an entire contract, employee handbook, financial workbook, or customer database may expose far more information than the AI needs.


Use the minimum-information rule: provide only the smallest amount of information required to complete the task.


NIST’s Generative AI Risk Management Profile recommends that organizations address privacy, information security, third-party AI risks, data governance, and appropriate controls throughout their use of generative AI.


AI Security Dos

Do Use Company-Approved AI Tools

Businesses should maintain a list of approved AI platforms and specify which account types employees may use. A personal AI account should not automatically be used for company work.

Business and enterprise versions often provide stronger administrative, privacy, compliance, and data-retention controls than consumer accounts.


Do Remove Sensitive Information

Before submitting content, remove or replace:

  • Customer and employee names

  • Email addresses

  • Account numbers

  • Financial figures

  • Credentials

  • Internal IP addresses

  • Server names

  • Confidential project names


Instead of pasting a real customer email, create a generic example containing only the facts necessary to draft a response.


Do Verify AI-Generated Information

AI can produce convincing but inaccurate answers.


Always verify:

  • Financial calculations

  • Legal or regulatory information

  • Technical instructions

  • Software code

  • Security recommendations

  • Product specifications

  • Names, dates, and statistics


AI should assist human judgment—not replace it.


Do Review Files Before Uploading Them

Documents, spreadsheets, screenshots, and log files can contain hidden or overlooked information.


Before uploading a file, check for:

  • Hidden spreadsheet tabs

  • Comments and tracked changes

  • Document metadata

  • Customer names

  • Passwords embedded in configuration files

  • Email addresses

  • Internal file paths

  • Network and system information


Do Establish a Written AI Policy

Every organization should have a basic acceptable-use policy explaining:


  • Which AI tools are approved

  • What information employees may enter

  • What information is prohibited

  • Whether AI-generated work must be reviewed

  • How suspected data exposure should be reported

  • Who is responsible for approving new AI services


The National Cyber Security Centre recommends that organizations carefully control what data AI systems can access and treat prompts, logs, and other AI-related assets as potentially sensitive information.


AI Security Don’ts

  • Don’t assume a paid personal account automatically provides enterprise protection.

  • Don’t paste information into AI just because it is faster than removing sensitive details.

  • Don’t connect an AI application to company email, cloud storage, or customer systems without authorization.

  • Don’t install unapproved AI browser extensions or meeting assistants.

  • Don’t allow an AI tool to make important financial, legal, hiring, or security decisions without human review.

  • Don’t trust every AI-generated link, attachment, instruction, or software command.

  • Don’t assume deleting a conversation immediately removes every retained copy from the provider’s systems.



A Simple Rule to Remember

Before entering information into an AI tool, ask yourself:

Would I be comfortable sending this information to an outside company for processing?

When the answer is no—or even maybe—do not upload it until your IT or security provider confirms that the platform and account are approved.



Use AI Productively Without Sacrificing Security

AI can provide tremendous value, but businesses need to implement it deliberately. The safest approach combines approved business-grade tools, appropriate privacy settings, employee education, access controls, and a written AI-use policy.


Kappa Computer Systems can help your organization evaluate AI tools, review Microsoft 365 security and Copilot settings, develop acceptable-use guidelines, and protect sensitive business information.


Contact Kappa Computer Systems before connecting a new AI application to your company’s email, files, customer information, or network.

bottom of page