AI at work: the confidentiality reflexes
Pasting a document into an AI assistant is never trivial at the office. Five simple reflexes to use AI without exposing your data or your clients'.
Updated on

An AI assistant is a formidable accelerator. But at the office, every text you paste into it leaves your machine. Before it becomes a reflex, adopt these five precautions — then check, with the short checklist at the end, what your tool really does with your data.
What counts as sensitive data, exactly?
Many leaks come from underestimation: you think you are sharing “nothing important.” Yet data does not need to be secret to be protected. Three categories should trigger your vigilance:
- Personal data: anything that identifies someone, directly or not — name, e-mail, client number, but also a cluster of clues (“the CFO of such-and-such Lyon SME”). That is the scope of the GDPR.
- Sensitive data in the strict sense: health, opinions, orientation, union membership. Their processing is especially regulated.
- Confidential company data: non-public figures, contracts, code, strategy. No GDPR here, but a very real competitive risk.
The common thread: as soon as one of these categories appears in what you are about to paste, the reflexes below apply.
1. Assume that anything you paste may be processed elsewhere
Depending on the tool and the plan, your inputs may travel through third-party servers, or even be used to improve the service. That is not necessarily a problem, but it is the starting point: treat every input as data that leaves your premises.
2. Never paste sensitive data without a guarantee
Clients’ personal data, health information, trade secrets, credentials: by default, you do not put them in a consumer assistant. This is particularly true for meeting transcription tools, which capture often-sensitive exchanges. If you need to, you need a professional offering with clear commitments on data handling.
Some sectors are more exposed than others: healthcare (patient data), legal (professional secrecy), human resources (employee files) handle, by nature, information whose leak has direct consequences. In these fields, the consumer assistant is off-limits for real data — and depending on the use, the European AI Act already sets obligations.
3. Distinguish free from professional offerings
Professional versions generally offer guarantees the free versions lack: your data not used for training, controlled hosting, access management. For use at work, that is often the minimum condition.
This table sums up the differences that matter most at the office. The exact labels vary from one vendor to another: it is a reading grid, to compare against your tool’s actual policy.
| Criterion | Consumer plan (free) | Professional plan |
|---|---|---|
| Are your inputs used for training? | Often yes, unless set otherwise | Generally no by default |
| Written commitment on processing (DPA) | Rarely | Yes, contractual |
| Data hosting / location | Little or not documented | Specified and controlled |
| Access management (who sees what) | Individual | Administrable by the company |
| Suitable for real client data | No | Yes, under conditions |
The reading is simple: until you have a written commitment, assume your inputs may be reused.
4. Anonymise whenever possible
You can often get useful help without handing over real data. Replace names, amounts and identifiers with fictitious examples. The model reasons just as well on an anonymised case.
A concrete example. You want help replying to a complaint, without exposing the client:
- Before (do not paste): “Ms Dupont, client no. 44127, is disputing the €2,480 invoice of 12 March for the work on her house on rue des Lilas in Lyon.”
- After (anonymised): “A client is disputing an invoice of [AMOUNT] dated [DATE] for a [TYPE] service. Write a calm reply that proposes a meeting.”
The request keeps its full meaning; the identifying data never leaves. You reinsert the real values at the end, in your word processor.
5. Check your organisation’s position
Many companies have a policy on AI use, sometimes a list of approved tools. Before industrialising a use, find out. In France, the CNIL publishes useful benchmarks to frame these practices, and in any case the GDPR rules apply the moment personal data is involved.
The checklist: where to find what a tool does with your data
Before adopting an assistant for professional use, look for these four pieces of information. They are found in the privacy policy and, for a professional offering, in the data processing agreement (DPA):
- Training: are your inputs used to improve the model? Look for the word “training” or “service improvement.”
- Opt-out setting: is there a switch to disable that reuse? Where, and is it on by default?
- Hosting: where is the data stored, and for how long?
- Deletion: can you request the erasure of your histories, and how?
If any of these answers cannot be found, treat it as unfavourable: a transparent vendor displays this information.
Key takeaway
AI at work is not forbidden, it is to be framed. One principle is enough to avoid most slip-ups: only entrust to an assistant what you would accept seeing leave your organisation. For the rest, anonymise, use a professional offering — and check, policy in hand, what the tool really does with your data.
Sources
Frequently asked questions
Can you paste confidential data into an AI assistant?
By default, no: clients' personal data, health information, trade secrets or credentials do not belong in a consumer assistant. If you need to, you need a professional offering with clear commitments on data handling.
Are the free and professional versions equivalent for confidentiality?
No. Professional versions generally offer guarantees the free tier lacks: your data not used for training, controlled hosting, access management. For use at work, that is often the minimum condition.
How do you use AI without exposing real data?
Anonymise whenever possible: replace names, amounts and identifiers with fictitious examples. The model reasons just as well on an anonymised case.
A simple principle to avoid mistakes?
Only entrust to an assistant what you would accept seeing leave your organisation. For the rest, anonymise or use a professional offering — and check your company's AI policy.
Where do you check what a tool does with my data?
In its privacy policy and, for professional use, in its data processing agreement (DPA). Look for three points: are your inputs used for training, is there a setting to disable it, and where is the data hosted. If the info cannot be found, assume the answer is unfavourable.
Is anonymisation enough to settle everything?
No, but it settles most office cases. Replacing names, amounts and identifiers with fictitious examples is enough when you are looking for help with reasoning or writing. For real sensitive data (health, HR, legal), anonymisation does not replace a controlled professional offering.