Before You Paste It Into AI, Check Who Owns the Information
Companies are giving employees more access to AI productivity tools. Privacy controls only work if users know which information they are allowed to put into them.
AI productivity tools give users more control over privacy than many early workplace tools did. Users can adjust training settings, review connected applications, manage remembered information and control access to location or account data. None of those settings answers the first question an employee should ask before uploading a file: do I have the authority to send this information to the service? A contract does not stop being confidential because the company approved an AI tool. A customer record does not become safe because the employee disables model training. Privacy settings govern what the service does with information after submission; company policy determines whether the information should enter the system at all.
Privacy Settings Do Not Change the Document
Employees often make the decision at the point of use. Someone uploads a customer contract because they want a summary. A colleague pastes an email chain into an AI assistant to prepare meeting notes. A finance team uploads a spreadsheet because the model can explain the figures faster than they can restructure them manually. The task may be legitimate. The information may still carry restrictions. Bank details, payment-card numbers, health information, passwords, login credentials, confidential business documents, personally identifiable information, private workplace files and material covered by a non-disclosure agreement all require tighter handling. Companies need a rule that applies before employees choose the tool.
Four Labels Cover Most Everyday Decisions
A practical company policy can divide information into four categories: public, internal, confidential and prohibited.
Public information has already been released without access restrictions. Published reports, approved marketing material, public webpages and product information usually belong here. Employees can use it without exposing information the organisation intended to keep private.
Internal material belongs inside the company but carries limited sensitivity. Employees should still remove names, account details and identifiers when the task does not require them.
Confidential information needs a different test. Client documents, unpublished financial results, legal correspondence, internal pricing, personnel records, acquisition discussions and proprietary research may carry contractual, regulatory or commercial restrictions. Employees should only enter such information where the organisation has approved both the AI service and the specific type of use.
Prohibited information removes discretion. Passwords, authentication credentials, bank details, highly sensitive personal data and material the employee has no authority to disclose should never enter the prompt. The policy works because the employee does not have to judge the entire risk profile of an AI provider before completing a simple task. They first classify the information.
Redaction Does Not Remove Every Risk
Deleting a name only solves the problem when the name caused the sensitivity. A contract can reveal prices, liability clauses or commercial terms without naming the client. A spreadsheet can expose revenue by customer after someone removes the customer names. Meeting notes can describe a restructuring long before the company announces it. The question is what makes this information sensitive? If the answer is the underlying business fact, redaction does not change its classification. That is why a policy built only around personal data leaves large parts of commercial confidentiality uncovered.
Retention Adds Another Decision
Even correctly classified information can remain in the system after the immediate task ends. AI productivity tools may use conversations for model improvement depending on account settings. Deletion policies can vary, and feedback features may change how long a conversation remains available. Different account types can also offer different privacy controls. A company therefore needs to know which settings employees use, what happens when they delete a conversation and whether the same rules apply across personal, team and enterprise accounts. Employee choice becomes a control weakness when those settings vary widely and nobody checks them.
Shared Conversations Can Expose More Than the Final Answer
Some AI tools allow users to turn a conversation into a shareable link. The final answer may contain nothing sensitive while the earlier conversation contains a customer email, internal comments or pasted financial information. Anyone reviewing the thread can see more than the polished output. Companies should treat the full conversation as the document being shared. Before an employee sends a link, they need to review everything that entered the thread, not only the last response.
Connectors Increase the Cost of a Permission Error
Copying one paragraph gives an AI tool access to one paragraph. Connecting an inbox, browser or file repository can expose far more. The risk no longer sits in one prompt. It sits in the permission. An inbox connector can reach messages the employee never intended to analyse. Browser-based assistants operate across a wider working environment than a pasted extract, while malicious instructions hidden in external content can try to influence what the assistant reads or reveals. Access should match the task. If the assistant needs one file, provide one file. If it needs temporary access to one application, remove the connection when the work ends. Broader permissions should require a clear reason.
Authority Is the Final Test
The four-level policy breaks down when employees classify information according to whether it feels sensitive. Sensitivity is not the same as authority. Removing a client name does not give an employee permission to disclose the client’s commercial terms. Disabling training does not override an NDA. Using an approved AI service does not cancel contractual or data-protection obligations.
The pre-prompt check can remain short:
Public: use it.
Internal: minimise it.
Confidential: use only with explicit approval.
Prohibited: do not enter it.
AI privacy controls can reduce what happens to information after submission. They cannot give an employee permission to share information they were never authorised to disclose.


