Last reviewed 2026-07-01 · ~9 min read

Before your team pastes customer data into a chatbot

Somewhere in your company, today, someone pasted something into an Artificial Intelligence (AI) chatbot to get their work done faster. A draft contract. A customer complaint, name and all. A snippet of code with a connection string still in it. They did not ask permission, because there was no one to ask and no rule that said they should.

This is not a hypothetical, and it is not a scandal. It is what adoption of a genuinely useful tool looks like inside a small company: fast, informal, and invisible. The problem is not that your team is using AI. The problem is that nobody has decided — out loud, in writing — what may go into these tools and what may not. That decision takes one afternoon. This piece is the shape of it.

Why banning it fails

The instinctive first policy is a ban. It is also the policy most likely to make things worse.

A ban does not stop the behaviour — the tools are too useful, and they are a browser tab away. What a ban does is push the behaviour onto personal accounts and personal devices, where you have no visibility, no contract, and no way to answer the question "did any of our customer data go into that tool?" when a customer, an auditor, or a regulator asks. An unenforceable rule is worse than no rule, because it converts ordinary work into hidden work.

The teams that handle this well do the opposite: they name a small set of approved tools, put the riskiest use beyond doubt, and make the safe path the easy path.

The four kinds of data that should not go into a public chatbot

Most AI-use policy fits in one sentence: use the approved tools freely, and keep four kinds of data out of the unapproved ones. The four kinds:

1. Customer and employee personal data. Names, emails, addresses, account details, support conversations — anything that identifies a person. Under the General Data Protection Regulation (GDPR) and similar laws, pasting personal data into a third-party tool is a disclosure to that outside company. If the tool is a free consumer service you have no agreement with, that disclosure is very hard to defend. Health, financial, and other sensitive categories carry stricter rules still.

2. Credentials and keys. Passwords, application programming interface (API) keys, access tokens, connection strings. These end up in prompts mostly by accident — pasted inside a config file or an error log. Treat a credential that has been pasted into an external tool the way you would treat one posted publicly: rotate it.

3. Other people's confidential material. Anything you hold under a non-disclosure agreement or a customer contract: their roadmap, their pricing, their code. Your own appetite for risk does not cover material you promised to protect. Many business-to-business contracts now ask directly whether confidential material is shared with AI tools, and "we don't know" is a poor answer in a renewal.

4. Your own crown jewels. Unreleased financials, deal terms, security details, proprietary source code. Not because a chatbot will leak them tomorrow, but because you lose control of where they are stored, for how long, and who at the provider can see them.

Everything else — drafting, summarising public material, explaining an error message, brainstorming, rewriting your own prose — is the productive bulk of AI use, and a good policy leaves it alone.

What "trains on your data" actually means

The phrase that causes the most confusion in this conversation is "the model trains on your data." It helps to separate three different questions.

Is your input used to train future models? On free consumer tiers, often yes by default, sometimes with an opt-out buried in settings. On paid business tiers, the major providers generally commit not to train on your data. This single difference is most of the argument for paying for a business tier rather than tolerating free personal accounts.

Is your input stored, and for how long? Separate from training, providers typically retain conversations for some period — for abuse monitoring, for the history feature, or because you never deleted them. Retention on a business tier is usually configurable; on a consumer tier it usually is not.

Can humans at the provider read it? Some providers allow human review of flagged conversations. Business agreements typically narrow this. The practical rule: assume anything pasted into a consumer-tier tool could, in principle, be read.

None of this makes the tools unsafe to use. It means the account type matters more than the model. The same prompt can be a routine business use on one contract and an uncontrolled disclosure on another.

The one-afternoon AI-use policy

You do not need a twenty-page policy. You need a page that answers five questions, written down and told to everyone:

Which tools are approved? Pick a small set — typically one general assistant on a business tier, plus whatever AI is already built into tools you have vetted. Named tools, named account type. "Approved" means you have read the data terms and turned off training where you can.

What must stay out? The four categories above, stated plainly with examples from your own business. This is the paragraph people will actually remember.

Who pays and who administers? Personal accounts for work use are the thing you are trying to end. Put the approved tools on company billing and company sign-on, so that offboarding a person also offboards their access.

What about AI inside the tools you already have? Your customer-relationship-management system, your email suite, your meeting notetaker — much of your AI exposure arrives silently inside software you already pay for, each with its own data setting. Inventory these. The meeting notetaker that joins sales calls is a favourite blind spot: it may be recording customers who never agreed to it.

What happens when someone slips? The honest answer is "tell us, so we can fix it" — rotate the credential, note the disclosure, adjust the examples in the policy. If a slip is punished, the next slip will be hidden, and hidden slips are the ones that surface in an incident.

Write it, circulate it, and put a review date on it — quarterly is right for something moving this quickly. A policy from last year that names tools nobody uses any more teaches your team that the policy is decoration.

Where the law is heading

Regulation is arriving in phases rather than all at once. In the European Union, the AI Act's bans on certain practices and its AI-literacy duties have applied since early 2025, and obligations for general-purpose AI models since mid-2025; an amending package agreed in mid-2026 moves most of the remaining high-risk obligations out to December 2027 and August 2028. You do not need a regulatory programme to use a chatbot. You do need to be able to say what tools are in use and what data goes into them — which is exactly what the one-page policy and the inventory give you. Keeping that inventory current is the cheapest piece of future-proofing available.

Start from what is true, not what is written

The order matters: find out what your team actually uses first, then write the policy around the truth. A quick, blame-free survey — "what AI tools do you use for work, and for what?" — will surprise you, and every surprise is a disclosure path you did not know about. A policy written before the survey describes an imaginary company.

Handled this way, the whole exercise is an afternoon of work and one team meeting. The alternative — silence — is also a policy. It just delegates the decision about your customers' data to whoever is in a hurry today.


When you want this ready to use

Sylvan Assurance's AI Security Assessment toolkit turns this into a working programme: the AI-use policy templates, the tool-inventory worksheet, the vendor data-handling questions, and the maturity assessment across governance, data, and vendor controls — in editions for a solo operator, a team running the programme together, or an organisation formalising AI governance, from $49. The companion Sylvan Press field guide, AI Security, covers the full discipline in three volumes.

The free AI security readiness check at sylvanassurance.com/free/ai-security scores where you stand across the areas above in a few minutes. It runs entirely in your browser. Your answers are never transmitted.

Prefer the long form? The companion Sylvan Press title, AI Security, covers the same ground in depth.

See where you stand

Wondering how much shadow AI you actually have? The free assessment walks the governance, data, and vendor questions above and returns a scored readiness picture. It runs entirely in your browser — your answers never leave your device.

Take the free AI security readiness check