Direct answer
Never enter credentials, authentication secrets, private keys, restricted security information, or data you are not authorized to disclose. Keep customer, employee, health, financial, legal, contractual, proprietary, and regulated information out of unapproved public tools. Use sensitive data only in an approved environment with a defined purpose, minimum necessary input, reviewed terms, permissions, retention, and legal controls.
Data-boundary trainer
Practice the stop, check, or proceed decision
Credentials and secrets
Never enter
Passwords, API keys, private keys, authentication codes, and security answers should stay out of prompts and uploads.
Classification is only the first control. The approved tool and business purpose still matter.
Stop
Some information should not enter a prompt or upload
| Category | Examples | Action |
|---|---|---|
| Credentials | Passwords, API keys, tokens, private keys, recovery codes | Never enter |
| Restricted security | Vulnerability details, access maps, incident secrets | Never enter without a specifically authorized security workflow |
| Unauthorized third-party data | Information received under confidentiality or limited-purpose terms | Stop until authority and purpose are confirmed |
| Regulated or highly sensitive data | Health, financial, government identifiers, children's data | Use only in an approved architecture with qualified review |
| Privileged or legal material | Attorney communications, litigation strategy | Stop and obtain legal direction |
Check
Confidential business information requires an approved environment and purpose
- Customer and prospect records
- Employee and applicant information
- Non-public pricing, financials, forecasts, and strategy
- Contracts, proposals, and negotiation terms
- Source code, product plans, designs, formulas, and trade secrets
- Internal policies, investigations, and security documentation
- Any information whose disclosure would violate a promise, policy, or law
Proceed carefully
Public information can still create accuracy and rights problems
Published web copy, approved product information, public filings, and material created for broad distribution are generally lower risk. Employees still need to verify facts, respect copyright and license terms, avoid false claims, and use approved accounts and purposes.
Removing a name does not automatically make a record anonymous. Context and combinations of fields can still identify a person or reveal confidential information.
Before approval
Review the environment, not only the model name
| Question | What to verify |
|---|---|
| Account | Consumer, business, enterprise, or API service tier |
| Data use | Whether inputs or outputs are used for training or service improvement |
| Retention | Storage duration, deletion, and temporary processing |
| Access | Identity, roles, sharing, administrative control, and logs |
| Location and subprocessors | Where data is processed and which parties receive it |
| Contract | Confidentiality, security, incident, compliance, and termination commitments |
If data was entered
Respond as an incident, not as an embarrassment
Stop
Do not continue the conversation or upload more material.
Preserve facts
Record the tool, account, time, information type, and actions taken without spreading the data further.
Report
Contact the designated manager, security, privacy, or legal owner promptly.
Contain
Delete where available, revoke exposed credentials, and follow provider and company procedures.
Learn
Assess notification duties, close the control gap, and update training without blaming the reporter.
The value point
After this page, you should be able to decide:
Whether information must stop, requires an approved controlled system, or may proceed with ordinary accuracy and rights review.Your working output should be a stop-check-proceed boundary, data categories, response steps, and employee training scenarios.
Questions business leaders ask
Frequently asked questions
Is it safe to enter business data into an enterprise AI tool?+
It may be appropriate when the exact service, contract, configuration, data type, purpose, permissions, and retention have been approved. Enterprise branding alone is not sufficient.
Can employees paste customer data after removing names?+
Not automatically. Other fields or context may identify the person, and contracts or laws may still restrict use. Follow approved de-identification and data-handling rules.
Are public AI tools always unsafe?+
They can be useful for lower-risk public material, but consumer and anonymous accounts may have different data terms and controls. Company policy should define approved uses.
What should an employee do after entering sensitive data?+
Stop, record what happened, report it promptly, follow containment instructions, and rotate any exposed secret. Early reporting improves the company's ability to respond.
Research anchors
Primary and authoritative sources
- FTC: Privacy and confidentiality commitments for AI companies↗
- NIST Generative AI Profile↗
- U.S. Small Business Administration: AI for small business↗
Examples and planning ranges are clearly labeled. Source terms, provider behavior, and regulations can change; verify current requirements for your organization and jurisdiction.
Prepared and reviewed by the Future Made Useful systems editorial team. Material guidance reviewed July 17, 2026.