Safety · Hero

What information should not go into AI tools at work

The useful detailsIt depends on two things: which account you're using and what the information is. Some information never goes into any AI tool: passwords, government ID numbers, bank and card numbers, and health information. Client, employee and confidential business information goes only into a business account your organization has approved, for a task it has approved. Everything else should be public, your own non-sensitive writing, or a made-up example.

Step 1: know which account you're in

The same brand can come with very different terms. A free personal account and a company-managed workspace are not the same product.

What you're usingIs your content used to train the vendor's models?What that means at work
ChatGPT Free, Plus or Pro (personal account)Yes by default. You can turn it off: Settings → Data controls → Improve the model for everyoneNot for client or employee information, even with the setting off. Your employer doesn't control the account.
ChatGPT Business (formerly Team) or EnterpriseNo by default, per OpenAI's business termsCan be approved for work. The workspace owner controls access and settings.
Microsoft Copilot with a personal Microsoft accountConsumer terms applyNot for work content.
Microsoft Copilot Chat signed in with your work (Entra) accountMicrosoft says prompts and responses aren't used to train its foundation models. Look for the green shield ("enterprise data protection")Comes with eligible Microsoft 365 business plans at no extra cost. Chats are logged and covered by your organization's retention settings.
Gemini inside Google Workspace with a qualifying business licenceGoogle says your content isn't used to train its models and isn't reviewed by peopleCan be approved for work. Your Workspace admin controls it.
Gemini or other AI apps on a personal Google accountConsumer terms applyNot for work content.
Browser extensions, "free AI" websites, AI note-taker botsVaries, and is often unclearTreat as unapproved until someone has read the terms.

Two cautions. First, "not used for training" doesn't mean "fine for anything". The vendor still stores your content for a while, people in your organization may be able to see it, and your client contracts and privacy duties still apply. Second, these terms change. Check the vendor's current business-privacy page when you approve a tool, then again every six months.

Free downloadSetting rules for your team? Start from the free one-page AI use policy template.

Step 2: sort the information

Use three colours. Write your own examples next to each one. A generic list helps less than "our renewal spreadsheet is red".

Red: never, in any AI tool

  • Passwords, access codes, API keys, security questions, multi-factor codes
  • Social Insurance Numbers, health card, driver's licence and passport numbers
  • Bank account, card and payroll deposit details
  • Health information about any identifiable person
  • Information under legal privilege, or that a contract, court order or regulator says you can't share
  • Details of a live security incident

Yellow: only in an approved business account, for an approved task

  • Client, customer or tenant names together with their details
  • Employee and applicant information (performance, pay, discipline, résumés)
  • Unpublished financials, pricing, forecasts, deal terms
  • Draft contracts and confidential business plans
  • Anything a client gave you in confidence

Green: fine in an approved tool

  • Public information (your website, published reports, public regulations)
  • Your own writing with personal and confidential details removed
  • Templates, checklists, formulas, procedures with no personal details
  • Fictional examples written for practice

If something doesn't clearly fit, it's yellow. Stop and ask the person your policy names.

Step 3: de-identify properly, or don't paste

Deleting the name is often not enough. A date, an amount, a street, a job title and an unusual detail together can identify a person or a deal.

  • Instead of: "Draft a follow-up to Jordan Lee at Northwind Advisory about their $18,400 renewal due March 3."
  • Use: "Draft a follow-up to [CLIENT] about their renewal of about [AMOUNT], due next month. Friendly, under 120 words."

Then add the real details yourself in your email program. A second option is to describe the situation instead of pasting the document: "A client is upset that a report was late. Our policy is to offer a call within one business day. Draft a calm reply." For training and practice, ask the tool to write fictional examples, and don't lightly edit a real file.

Step 4: watch the less obvious ways information gets in

Most leaks don't come from someone typing a SIN into a chat box. They come from:

  • File uploads. One uploaded spreadsheet can hold thousands of records. Check what's in the file, not only the rows you care about.
  • Connectors. "Connect to Gmail / Outlook / Drive / SharePoint" lets the tool read far more than the one document you meant to use. Connecting an AI tool should need approval.
  • AI note-takers. Meeting bots can join calls through calendar invites. In a case Ontario's Information and Privacy Commissioner published in April 2026, an unapproved AI transcription tool linked to a former physician's personal calendar recorded a hospital meeting where patient information was discussed. That was a reportable breach.
  • Browser extensions that read every page you visit, including your email and CRM.
  • Screenshots with names, emails or account numbers in the corner.
  • Memory features that keep details across conversations. Check whether memory is on and what it has saved.

A next stepNot sure what your team already puts into AI tools? An AI security assessment finds out. Start with a free 30-minute call.

The Canadian rules behind this

General information, not legal advice:

  • PIPEDA (federal private-sector privacy law) makes you accountable for personal information you hand to a service provider, AI vendors included. You're expected to protect it with safeguards that match how sensitive it is. Breaches that create a real risk of significant harm must be reported to the Privacy Commissioner of Canada, and affected people must be notified. You must keep a record of every breach for 24 months.
  • Quebec's private-sector law (Law 25) requires a privacy impact assessment before personal information is communicated outside Quebec, which can include a cloud or AI provider.
  • Alberta and BC have their own private-sector privacy laws with similar principles.
  • Ontario health information custodians (clinics, practitioners) fall under PHIPA. The IPC says entering personal health information into an AI tool the custodian hasn't authorized is a privacy breach.
  • Professional confidentiality (lawyers, accountants, engineers, brokers, health professionals) applies on top of privacy law.
  • Canada's federal privacy commissioner and its provincial counterparts have published joint principles for generative AI. Among them: use personal information only where it's necessary and proportionate, and be open about how AI is used.

If someone pastes the wrong thing

Make this easy to report. Hidden mistakes are the expensive ones.

  1. Stop. Don't keep working in that conversation.
  2. Write down what was entered, which tool, which account (personal or business) and when.
  3. Tell the person named in your policy the same day.
  4. Delete the conversation if the tool allows it, and turn off any memory that saved the details. Deleting doesn't undo what the vendor may already have stored, so still report it.
  5. The policy owner decides whether personal information was involved and whether it's a breach to record or report. Ask your privacy adviser if you're unsure, and keep a record either way.
  6. Fix the cause. Was there no approved tool? No template? A connector nobody knew about? Fix that first.

A card to put next to the screen

Print this, fill in the name, and tape it where people work.

Before you press Enter

  1. Am I in our approved work account, not a personal one?
  2. Is anything here red? Passwords, ID numbers, banking, health information. Remove it.
  3. Is anything yellow? Is this an approved task in an approved tool? If not sure, ask [NAME].
  4. Could I explain what I pasted to the client, and to my manager?

Where Hero fits

If you don't know which tools and accounts your team is really using, start there. Hero's AI security assessment maps which AI tools are in use, under whose accounts and with what data, then gives you a ranked list of what to fix first. For the rules themselves, see the AI use policy template.

Sources checked (October 7, 2026): OpenAI Help Center, Data controls in ChatGPT and ChatGPT Business FAQ (Team renamed Business on Aug 29, 2025) · Microsoft Learn, Microsoft Copilot Chat privacy and protections · Google Workspace Help, Gemini for Google Workspace FAQ (Business) · PIPEDA s.10.1 and Breach of Security Safeguards Regulations · Quebec P-39.1 s.17 · IPC Ontario, Artificial intelligence gone wrong (April 27, 2026) · OPC, Principles for responsible, trustworthy and privacy-protective generative AI technologies (December 2023).

A CLEAR NEXT STEP STARTS HERE

Find out what your team already puts into AI.

A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.

Free 30-minute call with our founder · Video call, camera optional