Data leakage through AI tools: the policy every company needs

Staff paste customer data into AI tools daily. Where it goes, what can go wrong, and the one-page policy that stops it without a ban.

3 minread 738words last updated

The short answer

Every day, in companies of every size, someone pastes a customer’s email into an AI tool to draft a reply, a contract to get a summary, a spreadsheet of names to clean it up, or a block of code to find a bug. The intentions are good and the productivity is real. The problem is where that data goes. On consumer plans, the terms may allow the provider to retain inputs and use them for training, and no processor agreement exists. On business plans with the right agreement, the same actions are usually fine. The policy that fixes this fits on a page, and it does not ban anything; it provides approved tools and a sanctioned assistant, names what never goes in, and gives people someone to ask.

Where the data goes

Tool tierTypical termsWhat it means
Consumer, freeInputs may be retained and used to improve models; no processor agreementCompany and customer data leaves your control with no contract
Consumer, paidOften opt-out of training available; still no business agreementBetter, still not a processor relationship
Business or enterpriseNo training on your data, defined retention, processor agreement, admin controlsThe tier a company should be on
AI features inside existing toolsVary by vendor and feature; often a separate settingMust be checked individually
Company assistant built on your own indexData stays in your accounts; only passages go to the model under business termsThe place for anything involving company data

The one-page policy

  1. Approved tools, by name, on business plans the company pays for, with two-factor and admin visibility.
  2. Never enter, into any external tool: personal data of customers or staff, credentials and keys, financial and payment details, contracts and confidential documents, unreleased plans, source code of client systems, unless the tool is explicitly approved for that category.
  3. Use the company assistant for anything involving company data; it is built to keep the data in your accounts.
  4. AI features in existing tools: which are enabled, which are not, and why.
  5. Verification: anything sent to a customer or used for a decision is reviewed by a person.
  6. Who to ask, by name, and a promise that asking is never a problem.
  7. Review date, twice a year, because the tools change.

Making it stick

Provide the approved tools before publishing the policy, so the first thing people read is what they can use. Build or buy the company assistant for company data. Explain the why in one paragraph: contracts, customers’ trust, the law. Put the never-enter list where people paste: a short reminder in the tools themselves where possible. Check adoption after a month by asking, not by surveillance. Update when a new tool or feature arrives, which is often.

What this means for you

Assume company and customer data is already flowing into AI tools on personal accounts, because in practice it is. Do not ban; provide. Approved tools on business plans, a company assistant for company data, a short list of what never goes in, and a person to ask, on one page. The productivity stays; the leakage stops; and when a customer or auditor asks how you handle AI, you have an answer.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Is it really a problem if someone pastes a customer email into an AI tool?

On a consumer plan whose terms allow retention and training, personal data has left your control to a third party without a processor agreement, which is a compliance problem on its own, and it may surface in ways you cannot predict. On a business plan with the right agreement, the same action is usually fine. The problem is not the pasting; it is which tool and which plan.

Should we block AI tools on the company network?

No. Blocking moves the behaviour to phones and personal laptops, where you see nothing. Provide approved tools on business plans, a company assistant for anything involving company data, a clear list of what never goes in, and an easy way to ask. Adoption of the sanctioned route is the control that works.

What about AI features inside tools we already use?

They count. Email clients, office suites, CRMs and design tools now include AI features that send content to a provider. Check each vendor's terms for those features, decide which to enable, and include them in the policy. The feature that summarises your inbox is processing every email in it.