gantryai
All articles

Security & Governance

What Not to Paste into ChatGPT at Work: A Practical Guide for Business Teams

Employees are sharing sensitive data with ChatGPT at alarming rates. Here's what your team should never paste, why it matters, and how to get value from AI without the risk.

Gantry AI7 min read

Your team is probably already using ChatGPT. Whether or not you gave them the green light, employees across every industry are pasting work content into AI tools to draft emails, summarize documents, write code, and speed up their day. Most of the time, the intent is good. The problem is what they are pasting in along the way.

The core principle is simple: if something should not appear on a public website, it should not go into ChatGPT. That one rule, applied consistently, would prevent nearly every AI data incident that has made headlines over the past two years.

The scale of the problem

This is not a hypothetical risk. The numbers have gotten worse, not better, as AI adoption has accelerated.

~34.8%
of employee inputs to ChatGPT contained sensitive data in 2025, up from ~11% in 2023
Concentric / Metomic, 2025

That means more than one in three prompts from employees includes information the business would not want shared publicly. And in most cases, the employee does not even realize it.

If your business is just getting started with AI, this is one of the first things to get right. The tools are powerful, but only if your team knows the boundaries.


The "never paste" list

Some categories of data should never go into a consumer AI tool. Full stop. Here is the list every team should know.

Personal Identifiable Information (PII)

Names, addresses, phone numbers, Social Security numbers, dates of birth. If it can identify a specific person, it does not belong in ChatGPT. This applies to employee data, customer data, and vendor data alike.

Client financials

Revenue figures, bank account details, tax returns, financial statements, billing records. Pasting a client's P&L into ChatGPT to "get a quick summary" creates a data exposure your client never agreed to.

Contracts and legal documents

NDAs, partnership agreements, terms of service drafts, litigation materials. These documents often contain confidential terms, pricing, and obligations that are legally protected.

Credentials and access keys

Passwords, API keys, database connection strings, login tokens. This one sounds obvious, but it happens more often than you would think. Developers paste configuration files. Admins paste error logs that contain credentials. One careless prompt can expose the keys to your entire infrastructure.

Proprietary source code

Internal code, algorithms, trade secrets, product designs. In 2023, Samsung engineers pasted proprietary source code into ChatGPT on at least three separate occasions, exposing confidential semiconductor data and internal meeting notes. The incident became a case study in what not to do, and Samsung responded by banning the tool entirely for a period (TechCrunch, 2023).

Health and medical data

Patient records, diagnoses, treatment plans, insurance information. For businesses in healthcare or those handling employee health data, this carries serious regulatory consequences under laws like HIPAA.

The simple test: Before pasting anything, ask: "Would I be comfortable if this appeared on the front page of our local newspaper?" If the answer is no, do not paste it.

What actually happens when it goes wrong

This is not abstract. Here is what a single careless paste can set off.

Your data trains someone else's AI. On free-tier plans, anything you submit can be used to improve the model. That means your client's financials, your contract terms, or your internal strategy could surface in responses to other users. Not word for word, but patterns, phrasing, and details can bleed through.

Regulatory fines. If your business handles health data (HIPAA), financial data, or operates under privacy laws like GDPR or CCPA, pasting protected information into an unauthorized tool is a compliance violation. Fines can run into the hundreds of thousands of dollars, and the investigation alone costs time and legal fees.

Client trust disappears overnight. If a client finds out their confidential data was fed into a public AI tool, the relationship is over. It does not matter that nobody meant any harm. The breach of trust is enough. And depending on your contract, it could mean litigation.

Leaked credentials = full access. A pasted API key or database password does not just sit there. Automated scrapers monitor public data sources, including AI training datasets. A credential leak can lead to unauthorized access to your systems within hours.

The Samsung incident mentioned above cost them a company-wide ban on the tool, a PR crisis, and an internal investigation. That was a large company with resources to absorb the hit. For a smaller business, one incident like that can be existential.


Free vs. business tiers: why the difference is fundamental

One of the biggest misunderstandings is that all versions of ChatGPT work the same way under the hood when it comes to your data. They do not.

Free and Plus tiers (consumer plans): By default, OpenAI can use the content you submit to train and improve its models. You can opt out in your settings, but most employees never do. Even with the opt-out, your data still hits OpenAI's servers and is subject to their retention policies.

ChatGPT Team, Business, and Enterprise tiers: OpenAI states that it does not train on data submitted through these plans. You also get admin controls, audit logs, and data retention policies that are designed for business use. These plans offer a fundamentally different privacy model.

The gap between these tiers is not just a feature difference. It is a legal and compliance difference. On a free account, your employee's prompt is, practically speaking, a contribution to a public AI model. On an enterprise account, it stays within a controlled environment.

This matters for any business that handles client data, operates under regulatory requirements, or simply does not want its internal operations feeding someone else's AI.


Safe ways to still get value

None of this means your team should stop using AI. It means they should use it smartly. Here are four practical approaches.

Sanitize before you paste

Remove names, account numbers, and identifying details before submitting a prompt. Instead of "Summarize this contract between Acme Corp and Widget Inc for $2.4M," try "Summarize this contract between Company A and Company B for [amount redacted]." You still get useful output. You just do not hand over the sensitive details.

Use approved, business-grade tools

If your team needs AI regularly, invest in a business-tier plan with proper admin controls. The cost is minimal compared to the risk of a data leak. Many providers now offer plans specifically designed for workplace use, with data processing agreements and compliance certifications.

Build internal guidelines

Create a short, clear list of what is and is not acceptable to share with AI tools. Keep it to one page. Post it where people will actually see it. The best policy is the one your team can remember without looking it up.

Train your team, not just your tools

Most data leaks through AI tools are not malicious. They happen because an employee was trying to work faster and did not stop to think about what they were sharing. A 30-minute training session can prevent incidents that would take months to remediate.

The business-grade difference: Consumer AI tools and enterprise AI tools may look identical on screen, but they are governed by completely different data policies. Knowing which version your team is using is not optional. It is a basic security requirement.


A simple rule of thumb for your team

Complicated policies do not get followed. Give your team something they can remember.

Treat ChatGPT like a smart stranger. You would ask a smart stranger for advice on how to write a better email. You would not hand them your client list, your financials, or your passwords.

That mental model covers about 90% of the judgment calls your team will face. For the other 10%, that is where a clear policy and proper training come in.

Here is what a practical, one-line rule looks like for different teams:

Sales: Never paste CRM exports, deal terms, or prospect contact details.

Finance: Never paste bank statements, tax documents, or payroll data.

Legal: Never paste contracts, case files, or privileged communications.

HR: Never paste employee records, performance reviews, or compensation data.

Engineering: Never paste proprietary code, infrastructure configs, or access credentials.

The pattern is the same across every department. Use AI for the thinking, not for the data. Ask it to help you structure a proposal, not to analyze the actual numbers in one. Ask it to improve your writing, not to process your client's confidential report.


Frequently asked questions

What should you never paste into ChatGPT at work?

Keep personal identifiable information, client financials, contracts and legal documents, passwords and access keys, proprietary source code, and health or medical data out of ChatGPT. A simple test: if it should not appear on a public website, it should not go into an AI tool.

Is ChatGPT safe to use for work?

It can be, with the right habits. Remove sensitive details before pasting, use business-grade tools that do not train on your data, and give your team clear guidelines. The risk comes from what people paste in, not from using AI itself.

What is the difference between free and business versions of AI tools for data safety?

Free consumer tools may use your inputs to improve their models and offer fewer data controls. Business and enterprise tiers typically keep your data private, exclude it from training, and add administrative controls, which makes them a safer default for company use.

Getting this right from the start

The businesses that get the most value from AI are not the ones that move fastest. They are the ones that move with clear guardrails. A team that knows what not to share will use AI more confidently, more frequently, and more effectively than one operating in a gray area.

If your team is using AI tools today and you have not set boundaries yet, the time to do it is now. Not after an incident. Not after a client asks. Now.

We help businesses build AI training and enablement programs that cover exactly this, practical guidelines your team will actually follow, paired with the tools and workflows to use AI safely. Let's talk about what that looks like for your team.