AI Security Dos and Don’ts: What Should You Never Upload to an AI Tool?
- Kappa Computer Systems

- 7 minutes ago
- 5 min read

Artificial intelligence tools such as ChatGPT, Microsoft Copilot, and Google Gemini can help businesses write documents, summarize information, analyze data, and complete routine tasks more efficiently.
However, using AI without clear security guidelines can expose confidential business, customer, and employee information.
One of the most common questions we hear is:
Does an AI Tool Receive a Copy of the Information You Upload?
Yes!! When you type information into an online AI tool or upload a document, that information is transmitted to the provider’s systems so the AI can process it and generate a response.
What happens after that depends on several factors:
Which AI provider you are using
Whether you are using a personal or business account
Your account’s privacy settings
The provider’s data-retention policy
Whether your organization has an enterprise agreement
Whether the provider may use conversations to improve its models
For example, ChatGPT provides controls that allow users to choose whether their conversations may be used to improve its models. OpenAI also states that Temporary Chats are not used for training and are deleted from its systems after 30 days.
Microsoft states that prompts, responses, and organizational data used through Microsoft 365 Copilot’s enterprise protections are not used to train its underlying foundation models.
Google provides similar protections for qualifying Google Workspace business accounts, stating that organizational prompts and uploaded files are not used to train generative AI models without permission.
However, “not used for training” does not mean the information never leaves your computer. The AI provider must still receive and process the information to respond to your request.
That is why employees should never assume an AI tool is private simply because it requires a login.
Information You Should Never Upload to an AI Tool
Unless your organization has specifically approved the tool and confirmed its security protections, do not upload or paste the following information.
Passwords and Security Credentials
Never enter:
Passwords
Multifactor authentication codes
Password-reset links
API keys
Private encryption keys
Remote-access credentials
Firewall or administrator passwords
Software license keys
Even when asking an AI tool to troubleshoot a technical problem, remove all credentials before submitting logs, screenshots, or configuration files.
Personal and Financial Information
Do not upload information such as:
Social Security numbers
Driver’s license or passport numbers
Credit card information
Bank account and routing numbers
Tax returns
Payroll records
Employee background checks
Customer payment information
Replacing a person’s name with initials may not be enough. Other details in the document could still identify the individual.
Medical and Health Information
Medical records, diagnoses, insurance information, prescriptions, treatment notes, and other protected health information should not be entered into an unapproved AI platform.
Organizations subject to HIPAA or other regulatory requirements must verify that the AI service is appropriately configured and covered by the necessary agreements before using it with protected data.
Confidential Customer Information
Avoid uploading:
Customer lists
Contact databases
Account histories
Support tickets
Private email conversations
Service agreements
Customer network diagrams
Internal customer reports
A support ticket may appear harmless but could contain names, email addresses, IP addresses, passwords, system details, or other sensitive information.

Proprietary Business Information
Do not paste confidential information such as:
Unreleased financial statements
Business valuations
Acquisition or sale discussions
Pricing strategies
Trade secrets
Product designs
Internal procedures
Proprietary source code
Confidential contracts
Legal advice or attorney-client communications
Information does not have to contain a Social Security number to be sensitive. A company’s financial forecast, customer pricing, source code, or acquisition plans can be extremely valuable to a competitor or attacker.
Complete Documents When Only a Small Portion Is Needed
Uploading an entire contract, employee handbook, financial workbook, or customer database may expose far more information than the AI needs.
Use the minimum-information rule: provide only the smallest amount of information required to complete the task.
NIST’s Generative AI Risk Management Profile recommends that organizations address privacy, information security, third-party AI risks, data governance, and appropriate controls throughout their use of generative AI.
AI Security Dos
Do Use Company-Approved AI Tools
Businesses should maintain a list of approved AI platforms and specify which account types employees may use. A personal AI account should not automatically be used for company work.
Business and enterprise versions often provide stronger administrative, privacy, compliance, and data-retention controls than consumer accounts.
Do Remove Sensitive Information
Before submitting content, remove or replace:
Customer and employee names
Email addresses
Account numbers
Financial figures
Credentials
Internal IP addresses
Server names
Confidential project names
Instead of pasting a real customer email, create a generic example containing only the facts necessary to draft a response.
Do Verify AI-Generated Information
AI can produce convincing but inaccurate answers.
Always verify:
Financial calculations
Legal or regulatory information
Technical instructions
Software code
Security recommendations
Product specifications
Names, dates, and statistics
AI should assist human judgment—not replace it.
Do Review Files Before Uploading Them
Documents, spreadsheets, screenshots, and log files can contain hidden or overlooked information.
Before uploading a file, check for:
Hidden spreadsheet tabs
Comments and tracked changes
Document metadata
Customer names
Passwords embedded in configuration files
Email addresses
Internal file paths
Network and system information
Do Establish a Written AI Policy
Every organization should have a basic acceptable-use policy explaining:
Which AI tools are approved
What information employees may enter
What information is prohibited
Whether AI-generated work must be reviewed
How suspected data exposure should be reported
Who is responsible for approving new AI services
The National Cyber Security Centre recommends that organizations carefully control what data AI systems can access and treat prompts, logs, and other AI-related assets as potentially sensitive information.
AI Security Don’ts
Don’t assume a paid personal account automatically provides enterprise protection.
Don’t paste information into AI just because it is faster than removing sensitive details.
Don’t connect an AI application to company email, cloud storage, or customer systems without authorization.
Don’t install unapproved AI browser extensions or meeting assistants.
Don’t allow an AI tool to make important financial, legal, hiring, or security decisions without human review.
Don’t trust every AI-generated link, attachment, instruction, or software command.
Don’t assume deleting a conversation immediately removes every retained copy from the provider’s systems.
A Simple Rule to Remember
Before entering information into an AI tool, ask yourself:
Would I be comfortable sending this information to an outside company for processing?
When the answer is no—or even maybe—do not upload it until your IT or security provider confirms that the platform and account are approved.
Use AI Productively Without Sacrificing Security
AI can provide tremendous value, but businesses need to implement it deliberately. The safest approach combines approved business-grade tools, appropriate privacy settings, employee education, access controls, and a written AI-use policy.
Kappa Computer Systems can help your organization evaluate AI tools, review Microsoft 365 security and Copilot settings, develop acceptable-use guidelines, and protect sensitive business information.
Contact Kappa Computer Systems before connecting a new AI application to your company’s email, files, customer information, or network.
