Data leakage through AI tools: the policy every company needs
Staff paste customer data into AI tools daily. Where it goes, what can go wrong, and the one-page policy that stops it without a ban.
The short answer
Every day, in companies of every size, someone pastes a customer’s email into an AI tool to draft a reply, a contract to get a summary, a spreadsheet of names to clean it up, or a block of code to find a bug. The intentions are good and the productivity is real. The problem is where that data goes. On consumer plans, the terms may allow the provider to retain inputs and use them for training, and no processor agreement exists. On business plans with the right agreement, the same actions are usually fine. The policy that fixes this fits on a page, and it does not ban anything; it provides approved tools and a sanctioned assistant, names what never goes in, and gives people someone to ask.
Where the data goes
| Tool tier | Typical terms | What it means |
|---|---|---|
| Consumer, free | Inputs may be retained and used to improve models; no processor agreement | Company and customer data leaves your control with no contract |
| Consumer, paid | Often opt-out of training available; still no business agreement | Better, still not a processor relationship |
| Business or enterprise | No training on your data, defined retention, processor agreement, admin controls | The tier a company should be on |
| AI features inside existing tools | Vary by vendor and feature; often a separate setting | Must be checked individually |
| Company assistant built on your own index | Data stays in your accounts; only passages go to the model under business terms | The place for anything involving company data |
The one-page policy
- Approved tools, by name, on business plans the company pays for, with two-factor and admin visibility.
- Never enter, into any external tool: personal data of customers or staff, credentials and keys, financial and payment details, contracts and confidential documents, unreleased plans, source code of client systems, unless the tool is explicitly approved for that category.
- Use the company assistant for anything involving company data; it is built to keep the data in your accounts.
- AI features in existing tools: which are enabled, which are not, and why.
- Verification: anything sent to a customer or used for a decision is reviewed by a person.
- Who to ask, by name, and a promise that asking is never a problem.
- Review date, twice a year, because the tools change.
Making it stick
Provide the approved tools before publishing the policy, so the first thing people read is what they can use. Build or buy the company assistant for company data. Explain the why in one paragraph: contracts, customers’ trust, the law. Put the never-enter list where people paste: a short reminder in the tools themselves where possible. Check adoption after a month by asking, not by surveillance. Update when a new tool or feature arrives, which is often.
What this means for you
Assume company and customer data is already flowing into AI tools on personal accounts, because in practice it is. Do not ban; provide. Approved tools on business plans, a company assistant for company data, a short list of what never goes in, and a person to ask, on one page. The productivity stays; the leakage stops; and when a customer or auditor asks how you handle AI, you have an answer.
Frequently asked questions
Is it really a problem if someone pastes a customer email into an AI tool?
On a consumer plan whose terms allow retention and training, personal data has left your control to a third party without a processor agreement, which is a compliance problem on its own, and it may surface in ways you cannot predict. On a business plan with the right agreement, the same action is usually fine. The problem is not the pasting; it is which tool and which plan.
Should we block AI tools on the company network?
No. Blocking moves the behaviour to phones and personal laptops, where you see nothing. Provide approved tools on business plans, a company assistant for anything involving company data, a clear list of what never goes in, and an easy way to ask. Adoption of the sanctioned route is the control that works.
What about AI features inside tools we already use?
They count. Email clients, office suites, CRMs and design tools now include AI features that send content to a provider. Check each vendor's terms for those features, decide which to enable, and include them in the policy. The feature that summarises your inbox is processing every email in it.