Answer
What data should you never put into an AI tool?
Anything you hold on someone else's behalf, and anything you could not explain having sent to a third party.
Anything held on someone else's behalf — client files, patient information, staff records, another company's confidential material — and any credential. The question is whether it was yours to send, not whether the tool is safe.
The framing that causes trouble is whether a tool is safe. That is a supplier question and it is partly answerable. The prior question is whether the data was yours to send, and for a great deal of what a small business handles the answer is no — not because the tool is untrustworthy but because sending it anywhere is a disclosure the business was not authorised to make.
Information held on someone else's behalf is the main category and it is broader than people assume. A client's documents. Patient information. Employee records. A supplier's or customer's confidential material received under an agreement. In each case the business is a custodian, and confidentiality obligations do not distinguish between a disclosure to a person and a disclosure to a service. In regulated professions the obligation is stricter still, and in some the fact of the relationship is itself protected.
Credentials and keys are the second category and the rule is simply never. Passwords, API keys, access tokens, anything that grants entry. They frequently arrive by accident — pasted inside a configuration file or a log while asking for help with something else — which is why the practical control is a habit of stripping them before pasting, rather than an intention not to include them.
The third is anything that would be embarrassing or damaging in a context you do not control: an unresolved dispute, a personnel matter, commercially sensitive plans, a draft of something whose existence is confidential. The test is not whether the supplier is likely to misuse it. It is whether you could explain, to the person concerned, having sent it to a third party — and if the answer requires a paragraph of justification, it belongs outside the tool.
What determines how much of this a business can safely do is the account arrangement rather than the model. Consumer accounts and business accounts typically differ in whether inputs may be used to improve a model, how long data is retained, and who at the supplier can access it — and those terms are published, change over time, and are the actual control surface. Establishing which arrangement you are on is a five-minute task most businesses have never performed, and it can move a substantial amount of work from prohibited to permitted.
The workable policy is short enough that people follow it. Never credentials. Nothing held on a client's or patient's behalf unless the agreement in place explicitly permits it. Anonymise before asking about a real situation — the tool rarely needs the name to answer the question. And when in doubt, ask the question without the document, which is usually possible and almost always sufficient.
Pasting a client's document into a tool is a disclosure to a third party, and it is a disclosure whether or not anything bad ever comes of it.
Answer Production Engine, Context Theory
Related questions
Is a paid business account enough to make client data acceptable?
It is necessary and frequently not sufficient. A business agreement with appropriate terms addresses the supplier relationship; it does not address whether you were permitted to disclose the material at all, which is governed by your agreement with the client and by any professional rules. Both have to be satisfied, and businesses commonly resolve the first and assume it settled the second.
What about using it on our own internal documents?
Generally fine and worth doing, with two exceptions. Documents containing employee personal information carry obligations to the individuals concerned rather than to the business. And material subject to legal privilege should be handled on advice, since the consequences of a mistake there are unlike those elsewhere and are not reversible by deleting anything.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| Buyers preferring a rep-free purchase path | two-thirds | Category-wide |
| Share of the buying journey completed before contacting a vendor | 60% | Category-wide |
| Firms that never responded to a web enquiry at all | 23% | Category-wide |
Gartner · March 2026 · verified
2026 B2B buyer surveys · verified
Oldroyd, McElheran & Elkington, "The Short Life of Online Sales Leads", Harvard Business Review (March 2011) · 1.25M inbound leads across 2,241 US firms · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Constraint | Confidentiality obligations over information held on another party's behalf do not distinguish between disclosure to a person and disclosure to a service, so submitting such material to a tool is a disclosure regardless of outcome. | The confidentiality clause in the agreement under which the material was received, or the applicable professional conduct rule. |
| Software | Consumer and business accounts with the same supplier typically differ in whether inputs may be used for model improvement, retention period and internal access, which makes the account arrangement rather than the model the control surface. | The supplier's published terms for the specific plan the business is on, checked for training use and retention. |
| Workflow | Credentials and access tokens most often enter a tool incidentally inside configuration files or logs pasted while asking about something else, which makes a stripping habit the effective control rather than an intention. | A review of recent pasted material for embedded keys, tokens or connection strings. |
| Constraint | A supplier agreement with appropriate terms addresses the supplier relationship but not whether the business was permitted to disclose the material, which is governed separately by its client agreement and any professional rules. | The client engagement terms on subcontracting and disclosure, read alongside the supplier's data processing agreement. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one