Data and risk
Is it safe to put customer data into an AI tool?
Somebody in your business has already pasted a customer email into an AI tool. Not maliciously — to draft a reply faster. The question is not whether to allow it, because it is happening. The question is whether it is going into an account where that is fine, or into one where it is not, and almost nobody has checked which.
The short answer
It can be perfectly safe, and it can be a problem you have to disclose. Which one you have is decided by three things you can check this afternoon: whose account it is, what the plan says about training, and how long the vendor keeps it.
Not by which brand of tool it is. Two people using the same product on different plans can be in genuinely different positions.
Check one: whose account is it?
This is the one that decides most of the outcome, and it is the one nobody asks.
A personal free account, signed up with a personal email, on a personal phone, is outside your business entirely. You have no administrative control over it, no visibility of what has been put into it, no ability to remove anything, and no contractual relationship covering the data. If a customer asks you what happened to their information, you cannot answer.
A business or team account under your own domain, with an administrator, is a different situation in every one of those respects. Same underlying technology, materially different risk — and typically the paid business tiers also carry different data commitments than the consumer ones.
If you do one thing from this article, do this: find out which accounts your staff are actually using. Ask directly and without consequence, because the honest answer is what you need and people will not give it if it sounds like an accusation.
Check two: does it train on what you send?
Some plans use what you type to improve the underlying system. Others contractually do not. Which category you are in is written in the vendor's documentation, and on several products it is also a switch in the settings.
Do not guess and do not rely on what someone told you eighteen months ago; these policies have changed repeatedly and differ between the free, paid and business tiers of the same product. Open the account you actually use, find the data controls, and read what it says today.
Then write the answer down somewhere your team can see it, with the date you checked. Re-check when you change plans.
Check three: how long is it kept, and who can see it?
Even where nothing is used for training, conversations are usually stored for some period — for abuse monitoring, for support, or simply as your history. Find out the retention period, and find out whether an administrator in your business can read other people's conversations.
That second question matters more than people expect. If your team account lets an administrator read everything, that is a reasonable governance feature, and staff should be told it exists rather than discovering it.
Send less, and most of this stops mattering
The strongest control available is not a policy. It is noticing how much of what you paste is not needed for the task at hand.
To draft a reply about a delayed delivery, the model needs the situation and your policy. It does not need the customer's surname, address, phone number, order number or payment details. Those exist in the email because that is how the email arrived, not because the drafting task requires them.
- Strip names, addresses, phone numbers and account numbers before pasting. Put them back into the draft yourself.
- Never paste card numbers, bank details, passwords or API keys anywhere, into anything. This is not an AI rule, it is a general one, and AI tools are just the newest place it gets broken.
- Health information, anything about children, and anything a customer told you in confidence deserve a higher bar than convenience.
- If a spreadsheet is going in, ask whether the columns that identify people are needed for the question you are asking. Usually two of eleven are.
The one-page rule to give your staff
Long policies do not get read and do not change behaviour. Four lines do.
- Use the company account, not your personal one. If you do not have access, ask — it takes a minute to set up.
- Remove personal details before pasting: names, addresses, phone numbers, account numbers.
- Never paste passwords, card or bank details, or anything from the payroll or HR files.
- Read before it goes out. Anything drafted by AI is a draft until a person has checked it.
Print it. Put it where people work. Add one sentence saying who to ask if something is unclear, and mean it — a rule that punishes questions gets routed around within a fortnight, and then you have the same behaviour with none of the visibility.
Where the regulator comes into it
If you handle personal data belonging to people in the UK or EU, your existing obligations do not pause because a new category of tool appeared. Broadly, you need a lawful basis for the processing, you need to tell people what you do with their data, and you remain responsible when a supplier processes it on your behalf.
In practice this means an AI vendor holding your customers' information should appear in your records of processing and, where required, be covered by the appropriate contractual terms — the same treatment your email provider and CRM already get. Business tiers commonly offer the relevant agreements; consumer accounts generally do not, which is another reason the first check is the account.
This is general information, not legal advice. If the data you handle is sensitive, or you are in a regulated sector, the sensible spend is an hour of someone qualified rather than a longer article.
If it has already happened
Assume it has, because it almost certainly has, and treat it as something to correct rather than something to investigate.
- Find out what has gone in and roughly how much. Ask; do not audit devices.
- Move everyone onto a business account under your domain, and check the training and retention settings on it.
- Where the tool allows deletion of history, delete what should not be there.
- Write the four-line rule and circulate it.
- Judge the seriousness by what was sent. A drafted reply about a delivery date is not the same as a customer list, and treating them the same either overreacts or, more often, means the serious one gets waved through with the trivial ones.
One line to keep
The risk is not that your staff are using AI. It is that they are using it on accounts you cannot see, with more information than the task needs — and both of those are fixable in an afternoon by someone who decides to ask.