Appearance
Understanding Which AI Tools Are Safe to Use at Work
Applies to: All devices, all AI tools (ChatGPT, Gemini, Copilot, Claude, Perplexity, etc.)
Article Type: Informational
Last Updated: 2026-07-09
Summary
AI tools like ChatGPT, Gemini, and Copilot can save you hours of work — but pasting the wrong information into the wrong tool can expose company data. This guide explains which AI tools are generally safe for work, what data to never share with them, and how to tell the difference between a personal account and an enterprise-protected one.
Prerequisites
- No special requirements — this is a reference guide for all employees
Instructions
1. Understand the Two Types of AI Access
There's a critical difference between using an AI tool through your company account versus your personal account.
| Company / Enterprise Account | Personal Account | |
|---|---|---|
| Data privacy | Your company has a contract that prevents the AI provider from training on your data | The AI provider may use your inputs to improve their models |
| Who controls it | Your IT team manages the tool, its settings, and its data retention | You control it — but so does the AI provider |
| Examples | Microsoft Copilot (through M365), ChatGPT Enterprise/Team, Gemini for Google Workspace | Free ChatGPT, personal Gemini, free Claude, Perplexity free tier |
WARNING
The key rule: If you're using a personal account (the free version you signed up for at home), do not paste work data into it. The AI provider may store and use that data for training, which means your company's information could influence responses given to other users.
2. Know What's Approved at Your Organization
Your company may already have an approved AI tool list. Here's how to find out:
- Check your company intranet or IT portal — search for "AI policy," "approved tools," or "generative AI."
- Look for Microsoft Copilot in your M365 apps — if it's there, your organization has licensed it and it's safe to use with work data.
- Ask your manager or IT team — a quick message asking "Are we approved to use ChatGPT/Gemini for work?" takes 30 seconds and prevents a data incident.
3. Learn the "Never Paste" List
Regardless of which AI tool you use, never paste or upload the following into any AI tool that isn't explicitly approved by your company:
| ❌ Never paste this | Why it's risky |
|---|---|
| Customer names, emails, or personal data | Violates privacy laws (GDPR, HIPAA) and could trigger a data breach |
| Financial data, revenue figures, or forecasts | Could leak competitive intelligence |
| Source code or proprietary algorithms | Could be incorporated into the AI model and exposed to others |
| Internal strategy documents or roadmaps | Competitive advantage lost |
| Passwords, API keys, or access tokens | Direct security threat — treat these like a house key |
| Legal documents or contracts | Attorney-client privilege could be waived |
4. Use the "Newspaper Test"
Before pasting anything into an AI tool, ask yourself:
"Would I be comfortable if this text appeared on the front page of a newspaper with my company's name on it?"
If the answer is no, don't paste it.
5. What You CAN Safely Use AI For
When using an approved, enterprise AI tool, these tasks are generally safe:
- Drafting emails, reports, and meeting summaries (with non-sensitive content)
- Brainstorming ideas, outlines, and project plans
- Summarizing long documents (that contain no restricted data)
- Writing formulas for Excel or Google Sheets
- Generating templates, checklists, and how-to guides
- Proofreading and improving the clarity of your writing
6. Verify Success
You're in good shape if you can answer yes to all three:
- ✅ I know whether my company has an approved AI tool list.
- ✅ I know the difference between my personal AI account and an enterprise one.
- ✅ I know what data I should never paste into an AI tool.
Troubleshooting
WARNING
If you've already pasted sensitive data into a personal AI account, report it to your IT or security team immediately. Most organizations have an incident response process that can contain the exposure. Acting quickly limits the damage.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| "I already pasted company data into ChatGPT" | Used personal account for work | Report to IT immediately; delete chat history in the AI tool's settings |
| "I don't know which AI tools are approved" | No visible AI policy | Ask your manager or IT team; check the company intranet |
| "Copilot is available but I'm not sure it's official" | Copilot may be a trial | Check with IT to confirm your license covers enterprise data protection |
| "A coworker shared an AI tool I've never heard of" | Potential shadow AI | Verify with IT before using; unknown tools may not have data protection agreements |