GuideResearch-backed

Privacy-Safe AI at Work: What You Should Never Put Into a Model

Decide what data may enter an AI system by mapping purpose, sensitivity, authorization, provider handling, retention, access, and safer substitutes.

The AI Data Admission Gate. A seven-question admission matrix for purpose, authority, sensitivity, minimization, provider terms, retention, and downstream access. Download the SVG asset.
Direct answer

Never put information into an AI system when you lack authority to disclose it or cannot verify how the system may collect, retain, use, secure, and expose it. That includes secrets, credentials, protected personal data, confidential client or employer material, and another person's data unless an approved system and purpose explicitly permit the use.

The dangerous verb is disclose not type

Pasting text into a model can feel like using a calculator. Operationally, it may disclose information to a provider, subprocessors, logging system, workspace administrator, connected tool, or later user. The relevant boundary is not the chat box; it is the complete data flow.

The NIST Privacy Framework organizes privacy risk around identifying, governing, controlling, communicating, and protecting data processing. privacy, gai, oecd, context NIST's generative-AI profile includes data privacy among cross-cutting risks. gai OECD principles emphasize human rights, transparency, robustness, and accountability. oecd

This guide provides a conservative operating method. It cannot interpret your law, contract, or employer policy.

Categories that require a stop

Unless an authorized purpose and approved system clearly cover them, do not enter:

  • passwords, API keys, tokens, private keys, or recovery codes;
  • government identifiers, financial account details, or health information;
  • confidential legal, client, research, personnel, or commercial material;
  • unpublished product designs, source code, security findings, or deal terms;
  • children's data or another person's private communications;
  • data under a nondisclosure, licensing, residency, deletion, or sector rule;
  • combined fragments that can re-identify a person even after names are removed.

The list is illustrative, not exhaustive. “Publicly accessible” also does not automatically mean reusable for every purpose.

The seven-question data gate

Before any upload, ask:

  1. Purpose: What necessary work will this data enable?
  2. Authority: Who owns it, and what permission allows this disclosure and use?
  3. Sensitivity: What harm follows from exposure, inference, or misuse?
  4. Minimum: Can the task work with less, synthetic, redacted, or local data?
  5. Handling: Which provider, model, tools, subprocessors, and regions receive it?
  6. Retention and learning: What is stored, for how long, who can delete it, and can it be used to improve systems?
  7. Access and effect: Which humans or tools can retrieve it or act on an output derived from it?

If any answer is unknown for consequential data, stop and escalate. Do not fill the gap with assumptions about an “enterprise” label.

Evidence inside the case boundary: the AI Data Admission Gate

Evidence snapshotHigh confidence

Authoritative frameworks and contextual-integrity research support judging data flows by purpose, actors, information type, transmission rules, governance, and accountability. They do not declare one AI product safe or supply a universal prohibited-data list. The admission gate translates those principles into a worker-level decision.

privacy, gai, oecd, context

Claim sources: privacy, gai, oecd, context

Redaction is a transformation not a guarantee

Removing a name may leave employer, location, rare diagnosis, timestamps, writing style, or linked facts that identify a person. Summaries can preserve secrets. Screenshots can expose data in backgrounds and metadata. Source code can contain embedded credentials or proprietary algorithms.

Prefer a hierarchy of safer options:

  1. Do not use the data.
  2. Use a fabricated example with the same structure.
  3. Minimize to the fields necessary for the task.
  4. Transform or aggregate under an approved method.
  5. Use an approved local or isolated system with defined controls.
  6. Use identifiable or confidential data only under explicit authority and safeguards.

Inspect the product configuration

Terms and controls vary across consumer, team, enterprise, API, and self-hosted offerings. Before use, verify current documentation for:

  • training or improvement use;
  • retention and deletion;
  • administrator visibility;
  • connected apps and tools;
  • regional processing and subprocessors;
  • encryption and access controls;
  • incident handling;
  • contractual commitments.

Record the exact product tier and verification date. A colleague's memory of a setting is not a control.

Apply the seven-question data gate

Take a proposed use—such as summarizing customer calls—and create two versions. Version A uses representative synthetic transcripts. Version B names the real fields needed. Route B through the data owner, privacy/security process, and approved environment. Compare whether the benefit requires the added exposure.

Test the admission decision as a workflow

Build a representative test set of proposed inputs: harmless public text, internal operational data, combined quasi-identifiers, a document under contract, secrets embedded in code, and a borderline case with unclear authority. Evaluation should ask whether the gate routes each case correctly, explains the reason, and escalates uncertainty without copying the sensitive payload into another unapproved system.

Name an accountable decision owner for admission and a human checkpoint for ambiguous or high-consequence data. The reviewer needs the purpose, authority, product configuration, retention terms, recipients, and safer alternative. Record the decision without reproducing unnecessary personal data. A false negative can create disclosure; a false positive can block useful work. Both are failure conditions, but they are not symmetric. Set conservative blockers from the more serious consequence and verify time-sensitive provider terms immediately before the authorized use.

Build accountability from AI Literacy for Adult Learners, model hostile content paths with Prompt Injection Explained, and assign the admission decision through AI Workflow Design.

Privacy shortcuts that fail under inspection

  • “I removed the name.”
  • “The company is reputable.”
  • “The output, not the input, is what matters.”
  • “The conversation is private because only I can see it.”
  • “The data was already online.”
  • “We will delete the chat later.”
  • “It is only a prototype.”
  • “The model promised not to remember.”
Limits and counterevidence

Privacy, confidentiality, secrecy, intellectual-property, employment, and sector obligations vary by jurisdiction and agreement. Provider practices and product settings change. This article cannot authorize a disclosure, certify anonymization, or replace current official documentation and qualified legal, privacy, security, and data-owner review.

When information matters, convenience is not consent. Admit data only when the purpose, authority, flow, and consequence can all be defended.

Named sources

Evidence and further reading

  1. NIST Privacy Frameworkofficial · accessed 2026-07-28
  2. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profileofficial · accessed 2026-07-28
  3. OECD AI Principlesofficial · accessed 2026-07-28
  4. Privacy as Contextual Integrityresearch · accessed 2026-07-28
Publication record

Published July 29, 2026. No substantive revision has been recorded. Evidence last verified July 28, 2026.