What information should not go into AI tools at work
✳By Hero Published Sept 12, 2026 · Updated Oct 7, 2026
The useful detailsIt depends on two things: which account you're using and what the information is. Some information never goes into any AI tool: passwords, government ID numbers, bank and card numbers, and health information. Client, employee and confidential business information goes only into a business account your organization has approved, for a task it has approved. Everything else should be public, your own non-sensitive writing, or a made-up example.
Step 1: know which account you're in
The same brand can come with very different terms. A free personal account and a company-managed workspace are not the same product.
What you're using
Is your content used to train the vendor's models?
What that means at work
ChatGPT Free, Plus or Pro (personal account)
Yes by default. You can turn it off: Settings → Data controls → Improve the model for everyone
Not for client or employee information, even with the setting off. Your employer doesn't control the account.
ChatGPT Business (formerly Team) or Enterprise
No by default, per OpenAI's business terms
Can be approved for work. The workspace owner controls access and settings.
Microsoft Copilot with a personal Microsoft account
Consumer terms apply
Not for work content.
Microsoft Copilot Chat signed in with your work (Entra) account
Microsoft says prompts and responses aren't used to train its foundation models. Look for the green shield ("enterprise data protection")
Comes with eligible Microsoft 365 business plans at no extra cost. Chats are logged and covered by your organization's retention settings.
Gemini inside Google Workspace with a qualifying business licence
Google says your content isn't used to train its models and isn't reviewed by people
Can be approved for work. Your Workspace admin controls it.
Gemini or other AI apps on a personal Google account
Consumer terms apply
Not for work content.
Browser extensions, "free AI" websites, AI note-taker bots
Varies, and is often unclear
Treat as unapproved until someone has read the terms.
Two cautions. First, "not used for training" doesn't mean "fine for anything". The vendor still stores your content for a while, people in your organization may be able to see it, and your client contracts and privacy duties still apply. Second, these terms change. Check the vendor's current business-privacy page when you approve a tool, then again every six months.
Public information (your website, published reports, public regulations)
Your own writing with personal and confidential details removed
Templates, checklists, formulas, procedures with no personal details
Fictional examples written for practice
If something doesn't clearly fit, it's yellow. Stop and ask the person your policy names.
Step 3: de-identify properly, or don't paste
Deleting the name is often not enough. A date, an amount, a street, a job title and an unusual detail together can identify a person or a deal.
Instead of: "Draft a follow-up to Jordan Lee at Northwind Advisory about their $18,400 renewal due March 3."
Use: "Draft a follow-up to [CLIENT] about their renewal of about [AMOUNT], due next month. Friendly, under 120 words."
Then add the real details yourself in your email program. A second option is to describe the situation instead of pasting the document: "A client is upset that a report was late. Our policy is to offer a call within one business day. Draft a calm reply." For training and practice, ask the tool to write fictional examples, and don't lightly edit a real file.
Step 4: watch the less obvious ways information gets in
Most leaks don't come from someone typing a SIN into a chat box. They come from:
File uploads. One uploaded spreadsheet can hold thousands of records. Check what's in the file, not only the rows you care about.
Connectors. "Connect to Gmail / Outlook / Drive / SharePoint" lets the tool read far more than the one document you meant to use. Connecting an AI tool should need approval.
AI note-takers. Meeting bots can join calls through calendar invites. In a case Ontario's Information and Privacy Commissioner published in April 2026, an unapproved AI transcription tool linked to a former physician's personal calendar recorded a hospital meeting where patient information was discussed. That was a reportable breach.
Browser extensions that read every page you visit, including your email and CRM.
Screenshots with names, emails or account numbers in the corner.
Memory features that keep details across conversations. Check whether memory is on and what it has saved.
PIPEDA (federal private-sector privacy law) makes you accountable for personal information you hand to a service provider, AI vendors included. You're expected to protect it with safeguards that match how sensitive it is. Breaches that create a real risk of significant harm must be reported to the Privacy Commissioner of Canada, and affected people must be notified. You must keep a record of every breach for 24 months.
Quebec's private-sector law (Law 25) requires a privacy impact assessment before personal information is communicated outside Quebec, which can include a cloud or AI provider.
Alberta and BC have their own private-sector privacy laws with similar principles.
Ontario health information custodians (clinics, practitioners) fall under PHIPA. The IPC says entering personal health information into an AI tool the custodian hasn't authorized is a privacy breach.
Professional confidentiality (lawyers, accountants, engineers, brokers, health professionals) applies on top of privacy law.
Canada's federal privacy commissioner and its provincial counterparts have published joint principles for generative AI. Among them: use personal information only where it's necessary and proportionate, and be open about how AI is used.
If someone pastes the wrong thing
Make this easy to report. Hidden mistakes are the expensive ones.
Stop. Don't keep working in that conversation.
Write down what was entered, which tool, which account (personal or business) and when.
Tell the person named in your policy the same day.
Delete the conversation if the tool allows it, and turn off any memory that saved the details. Deleting doesn't undo what the vendor may already have stored, so still report it.
The policy owner decides whether personal information was involved and whether it's a breach to record or report. Ask your privacy adviser if you're unsure, and keep a record either way.
Fix the cause. Was there no approved tool? No template? A connector nobody knew about? Fix that first.
A card to put next to the screen
Print this, fill in the name, and tape it where people work.
Before you press Enter
Am I in our approved work account, not a personal one?
Is anything here red? Passwords, ID numbers, banking, health information. Remove it.
Is anything yellow? Is this an approved task in an approved tool? If not sure, ask [NAME].
Could I explain what I pasted to the client, and to my manager?
Where Hero fits
If you don't know which tools and accounts your team is really using, start there. Hero's AI security assessment maps which AI tools are in use, under whose accounts and with what data, then gives you a ranked list of what to fix first. For the rules themselves, see the AI use policy template.
Sources checked (October 7, 2026): OpenAI Help Center, Data controls in ChatGPT and ChatGPT Business FAQ (Team renamed Business on Aug 29, 2025) · Microsoft Learn, Microsoft Copilot Chat privacy and protections · Google Workspace Help, Gemini for Google Workspace FAQ (Business) · PIPEDA s.10.1 and Breach of Security Safeguards Regulations · Quebec P-39.1 s.17 · IPC Ontario, Artificial intelligence gone wrong (April 27, 2026) · OPC, Principles for responsible, trustworthy and privacy-protective generative AI technologies (December 2023).
A CLEAR NEXT STEP STARTS HERE
Find out what your team already puts into AI.
A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.