6Putting your name on AI work without getting burnedYour Responsibility

Which AI tools are safe to paste client data into

5 min read994 words

Not All AI Tools Are Created Equal

Throughout this course, we have focused on what AI can do for you. Now it is time to think carefully about what you might be giving AI in return.

Every time you type a prompt into an AI tool, you are sharing information. Sometimes that information is trivial — a request to brainstorm holiday destinations or rewrite a paragraph about gardening. But sometimes, without quite realising it, you are handing over something far more significant: a client's financial details, a student's personal circumstances, your organisation's strategic plans, or a colleague's private communication.

Here is the uncomfortable truth: not all AI tools handle your data in the same way. Some tools use your inputs to train future versions of their models. Some store your conversations indefinitely. Some share data with third parties. And some — particularly enterprise-grade tools — offer robust privacy protections and clear data boundaries. The difference matters enormously, and it is your responsibility to know which category your chosen tool falls into.

Three Questions Before You Share

Before you paste any information into an AI tool, pause and ask yourself three questions:

1. Who owns the data I input?

This sounds straightforward, but the answer varies widely between tools and pricing tiers. With some free AI chatbots, the terms of service grant the provider broad rights to use your inputs. With paid enterprise plans, you typically retain full ownership and the provider commits to not using your data for training. Read the fine print. If you cannot find a clear answer, treat that as a red flag.

2. Could my input be used to train future models?

Many AI providers use conversations from free-tier users to improve their models. This means that the sensitive information you share could, in theory, influence responses given to other users in the future. Most reputable providers now offer clear opt-out mechanisms or separate tiers where training on your data is explicitly excluded. Know which arrangement applies to you.

3. Is this compliant with my organisation's policies?

Increasingly, workplaces have specific policies about which AI tools are approved, what data can be shared with them, and what workflows require human oversight. If your organisation does not yet have such a policy, that does not mean anything goes — it means you need to exercise even greater personal judgement.

Sensitive Data Categories

Some types of information should make you pause every single time, regardless of which tool you are using:

Personal information includes names, addresses, email addresses, phone numbers, health details, financial information, and anything that could identify a specific individual. In many jurisdictions, sharing personal data with an AI tool without proper safeguards could breach data protection regulations such as the UK GDPR.

Proprietary business data covers trade secrets, unreleased product details, financial projections, strategic plans, internal communications about mergers or restructures, and anything your organisation would not want a competitor to see. Even if an AI provider promises not to train on your data, consider whether the risk of a data breach — however unlikely — is one you are comfortable taking.

Confidential communications includes private messages, legal discussions, HR matters, whistleblower reports, and any correspondence shared with you in confidence. The person who trusted you with that information almost certainly did not consent to it being processed by a third-party AI system.

The Driving Analogy

Think back to our driving analogy from earlier in the course. AI fluency, like driving fluency, is not just about getting from A to B as quickly as possible. A truly fluent driver does not simply know how to operate the vehicle — they understand the rules of the road, they are aware of other road users, and they take responsibility for driving safely.

The same applies here. A truly fluent AI user does not simply know how to get impressive outputs. They understand the data landscape, they are aware of the risks, and they take responsibility for using AI tools in a way that protects themselves, their colleagues, and the people whose information they handle.

Practical Steps for Tool Evaluation

Before adopting any new AI tool, spend ten minutes reviewing the following:

  • Terms of service: Look specifically for clauses about data retention, data usage for training, and third-party sharing. If the language is vague or evasive, proceed with caution.
  • Privacy policy: Check how long your data is stored, where it is stored geographically (this matters for regulatory compliance), and what happens to it if you delete your account.
  • Data processing agreements: For professional use, check whether the provider offers a formal data processing agreement. This is particularly important if you handle client data or work in a regulated industry.
  • Security certifications: Look for recognised certifications such as SOC 2, ISO 27001, or sector-specific standards. These are not guarantees of perfection, but they indicate that the provider takes security seriously.
  • Your organisation's approved tools list: If one exists, start there. If it does not, consider raising the issue with your IT team or line manager. You might be doing everyone a favour.

The goal is not to become paralysed by caution. It is to make informed choices. Most AI tools are perfectly fine for most tasks. But "most" is not "all," and the exceptions are where reputations and regulations come into play.

Key Takeaways

  • 1Not all AI tools handle your data the same way — some train on your inputs, some store them indefinitely, and some offer strong privacy protections.
  • 2Before sharing any information with an AI tool, ask who owns the data, whether it could be used for training, and whether it complies with your organisation's policies.
  • 3Personal information, proprietary business data, and confidential communications should always trigger extra caution regardless of the tool.
  • 4Spend ten minutes reviewing a tool's terms of service, privacy policy, and security certifications before adopting it for professional use.