Skip to content

AI Is Not Magic — And It Is Not Private by Default

By Tomasz Lewandowski · 16 Jun 2026 · 5 min read

AI Is Not Magic — And It Is Not Private by Default
Using AI in a Small Business — Data Confidentiality

Before a business worries about clever prompts, it needs to decide what must never be entered into an AI tool.

The Convenient Paste

Many small businesses discover AI in an entirely ordinary moment. A customer has written a long complaint. A supplier has sent a confusing set of terms. A manager has notes from a meeting and no appetite for writing them up. Someone copies the text, pastes it into an AI tool and asks for help.

That may feel harmless. In many cases, it may even be useful. But the moment business information is pasted into an external tool, the question is no longer simply whether the answer is good. The question is what information has just left the business, who may be able to access it, how it may be stored, and whether the person using the tool was authorised to share it in the first place.

AI can be a helpful assistant. It should not be treated as a private notebook by default.

The First AI Rule Is Not About Prompting

Most conversations about AI start with how to write better prompts. That is understandable. Better prompts often produce better answers. Yet for a business, the first rule should come earlier:

Do not paste information into AI unless you are allowed to share it.

That sounds simple, but it is where much of the risk sits. Staff may not think of a customer email as sensitive. A spreadsheet may look like routine admin. A contract clause may feel like a paragraph of text rather than a commercial agreement. A disciplinary note may be copied into a tool merely to improve the wording.

The tool does not know that the information is sensitive. The employee may not pause long enough to ask. The business is still responsible for the consequences.

What Should Never Be Pasted

Every organisation will need its own judgement, but most small businesses should start with a clear list of prohibited material.

Do not paste passwords, access codes, API keys or security information. Do not paste customer personal data, employee records, medical details, financial account information, unpublished accounts, legal disputes, confidential supplier terms, trade secrets, intellectual property, acquisition plans or anything covered by a non-disclosure agreement.

It is also worth treating customer complaints and internal HR matters with particular care. They often contain names, history, opinion and emotion. Asking AI to tidy the language may be tempting, but the convenience does not remove the duty of confidentiality.

A useful test is this: would you be comfortable emailing the same information to an unknown third-party supplier for processing? If the answer is no, it probably should not be pasted into a public AI tool.

Anonymisation Is Helpful, But Not a Magic Cloak

Some information can be made safer by removing names, addresses, account numbers and other identifying details. That is a good habit. It is not, however, a complete answer.

A description may still identify a customer if the situation is unique. A contract clause may still reveal a supplier relationship. A set of figures may still expose margins, pricing strategy or commercial weakness. The same lesson applies to your underlying records: as we argue in AI Will Not Fix Messy Data — It Will Amplify It, a tool only works with what you give it. Anonymisation reduces risk. It does not make judgement unnecessary.

Free Tools Are Not Free of Responsibility

Many AI tools offer free or low-cost access, which makes experimentation easy. That is part of their appeal. It also means that staff may sign up using personal accounts, outside company oversight, with settings that nobody has reviewed.

Before using any AI tool for work, the business should understand the terms well enough to answer a few plain questions. Is the tool approved for business use? Can prompts or files be used to improve the provider’s systems? Can data be deleted? Is there an enterprise or team setting with better controls? Who owns the account if an employee leaves?

These are not technical niceties. They are basic supplier questions.

Practical Steps You Can Take Today

  • Write a simple “never paste” list and share it with the team. Keep it short enough that people will remember it.
  • Create a safer example bank. Give staff sample prompts that use fictional customers, dummy figures and generic scenarios.
  • Decide which AI tools are approved for work. A ban on everything is unlikely to hold if people already see the benefit, but a free-for-all is not much of a policy.
  • Require human review before AI-assisted content is sent to customers, suppliers, regulators, employees or the public.
  • Check whether any staff are already using AI for work. Ask in a non-punitive way: you are trying to understand the current reality, not catch people out.

Control Before Cleverness

AI is useful precisely because it is quick. That is also why it needs boundaries. A business would not give every employee permission to send documents to any outside adviser they fancied. AI should not quietly become the exception simply because it appears in a friendly text box.

The right starting point is not fear. It is control. Once staff know what must not be shared, they can use AI with greater confidence. Safety rules do not stop useful experimentation. They make it possible.

Related reading

How to set AI data-confidentiality boundaries in a small business

  1. Write a simple "never paste" list. Create a short list of information that must never be entered into an AI tool and share it with the team. Keep it short enough that people will remember it.
  2. Create a safer example bank. Give staff sample prompts that use fictional customers, dummy figures and generic scenarios so they can use AI without exposing real data.
  3. Decide which AI tools are approved for work. Choose which tools are permitted. A ban on everything is unlikely to hold if people already see the benefit, but a free-for-all is not much of a policy.
  4. Require human review before content goes out. Make sure AI-assisted content is reviewed by a person before it is sent to customers, suppliers, regulators, employees or the public.
  5. Check who is already using AI for work. Ask staff in a non-punitive way whether they are already using AI. The aim is to understand the current reality, not to catch people out.

Frequently asked questions

Is ChatGPT private?

Not by default. The moment business information is pasted into an external AI tool, the question is no longer just whether the answer is good — it is what data has left the business, who may access it and how it may be stored. AI can be a helpful assistant, but it should not be treated as a private notebook. Before using any tool for work, understand its terms, including whether your prompts can be used to improve the provider's systems.

Can I put customer data into AI tools?

You should not paste customer personal data into public AI tools, and most businesses should make this an explicit rule. Customer complaints and HR matters deserve particular care because they contain names, history, opinion and emotion, and tidying the wording does not remove the duty of confidentiality. A useful test: if you would not email the same information to an unknown third-party supplier for processing, do not paste it into a public AI tool.

Is AI confidential for business use?

Not automatically — confidentiality depends on the tool, its settings and how staff use it. Many free tools let employees sign up on personal accounts, outside company oversight, with settings nobody has reviewed. Decide which tools are approved for work, treat them like any other supplier by asking whether data can be deleted or used for training, and require human review before AI-assisted content reaches customers or regulators.

Share Follow
How to Reduce Hallucinations Without Pretending They Disappear
Using AI in a Small Business

How to Reduce Hallucinations Without Pretending They Disappear

You cannot eliminate hallucinations, but you can design work so they are less likely and easier to catch: provide sources, restrict the task, surface assumptions and verify.

25 Jun 2026 · 5 min read
Give AI Context, Constraints and Examples
Using AI in a Small Business

Give AI Context, Constraints and Examples

Generic AI output usually means the prompt supplied a request without the ingredients. Context, constraints and examples turn a text generator into a useful assistant.

20 Jun 2026 · 5 min read
Start With Low-Risk Tasks, Not Business-Critical Decisions
Using AI in a Small Business

Start With Low-Risk Tasks, Not Business-Critical Decisions

The safest first AI projects are useful but unglamorous: drafting, summarising, organising and turning messy notes into clearer documents. Build confidence before ambition.

18 Jun 2026 · 5 min read