Almost nobody covers this topic plainly, so let me. You should use AI on real work, that is where the value is, but you should do it with a deliberate view of what goes in. Here is the system I use and recommend, none of which requires a security team. The usual caveat applies: this is practical guidance, not legal advice, and regulated industries have obligations on top of it.
Think in three classes of data
Green: paste freely. Public information, general questions, your own drafts and ideas, anonymised examples, anything already on your website. This is most of daily use, and hesitating here just costs you productivity.
Amber: paste deliberately. Commercially sensitive material, financials, strategy, client identifiable information, staff matters. This is where real work lives, so the answer is not "never", it is "on the right account with the right settings", covered below. Two good habits: de identify when identity adds nothing ("a client" instead of the name), and share the minimum slice that the task needs rather than the whole file.
Red: never on a personal account, and rarely anywhere. Passwords and credentials, full payment card numbers, government identifiers like TFNs and Medicare numbers, and other people's health or sensitive personal information without a proper basis for handling it. Nothing you are doing in a chat window needs a password in it. If a task seems to, the task is designed wrong.
Account hygiene beats vigilance
The biggest practical upgrade is boring: separate work from personal, and know your settings.
- Use a business account for business data, not a free personal login shared with your teenager's homework
- Check the provider's data controls: whether your conversations are used for training, what retention looks like, and turn the dials to match your risk appetite. Reputable providers make these settings accessible, and business tiers exist precisely for stronger commitments
- For regulated or client heavy work, ask the grown up questions of any AI vendor: where is data stored, is Australian residency available, is my data isolated from other customers, is it retained by the model provider? At D3ploy these are design requirements on every build, zero data retention arrangements with model providers, Australian hosting, and hard isolation between clients, and you should demand the same standard from anyone you buy from
- Give your team a one page policy. Literally the three classes above, translated to your business, with two examples each. Most data incidents are not malice, they are the absence of a rule anyone can remember
Special notes for regulated fields
If you are in health, legal, or finance, your professional obligations already govern client information, and AI does not change them, it just adds a new place they apply. Industry playbooks are coming to this page later with the specifics, but the headline is consistent: these industries benefit enormously from AI, and they are exactly where you buy or build properly rather than improvising on consumer tools.
The balance to strike
I want to land this carefully, because the failure I see most is not recklessness, it is over caution. Businesses ban the tools, staff use them anyway on personal phones, and you get all the risk with none of the governance. The winning move is the opposite: sanction the tools, set the three class rule, sort the accounts, and then push real work through with confidence.
Locked in? Good. The next article is the fun one, putting AI to work on hours of research while you make a coffee.