What never gets pasted into AI, and what happens when it is anyway

A shield blocking a stream of document and folder icons from flowing into a chat bubble, representing sensitive information kept out of an AI tool

A task that would take forty minutes by hand, and an AI tool that could do it in four. A file is open on their screen that has no business anywhere near that tool. Somebody on your team is going to hit this exact moment, and they are not thinking about compliance. They are thinking about getting home for dinner.

Our one-page policy template covers what belongs on the never list. Customer personal information, payroll and HR records, anything under an NDA, passwords and keys, unreleased financial information, and regulated data. Six items, one line each, easy to copy onto a page and hand out. What that page does not have room for is why each one earns its place. This piece covers that: what actually happens once something on that list gets typed into a chat window anyway.

A rule without a reason gets skipped under pressure

Most people follow a rule they understand faster than one they were just handed. “Don’t paste customer data” sounds like an instruction from someone who has never had a deadline. “Don’t paste customer data, because you cannot get it back and you may not even know it happened” sounds like a reason. Same rule, very different odds it survives contact with a Tuesday afternoon.

Here is the reasoning behind each item, in the order our shadow AI guide lists them.

What actually happens when each one leaks

Customer personal information

Personally identifiable information, or PII, is anything that ties back to a specific person. A name next to an address, an account number, a date of birth, or a phone number attached to a customer file all count. The moment that information leaves your systems and lands in an AI tool your company does not control, you have created a copy. You cannot inventory it, delete it on request, or produce it if a customer or a regulator ever asks where their information has been. That copy will not show up on any list you can hand over, because nobody wrote it down anywhere in the first place.

Payroll and HR records

Payroll files carry Social Security numbers, bank details, salary figures, and often medical or leave information tied to named employees. When someone reformats a spreadsheet or drafts a sensitive letter using a personal AI account to save time, that data stops living inside HR’s normal access controls. It sits instead in a chat history HR does not manage and cannot close out when that employee changes roles or leaves. People hand this information to your business on the understanding that it stays inside a small, accountable circle. A chat log outside that circle breaks the understanding, whether or not anything else ever happens to the data.

Anything under an NDA

A nondisclosure agreement names who is allowed to see the protected material, and an AI vendor is almost never on that list. That means the breach happens at the moment the information is typed in, not later if something goes wrong on the vendor’s end. Most people would treat NDA material with real caution around a competitor or a reporter. Few treat a chat box with the same caution, and the agreement does not know the difference.

Passwords and keys

This category is different from the other five. The others are information about something. This is the thing that lets someone in. A password or an API key typed into an AI tool for help troubleshooting is compromised the instant it is typed. That is true regardless of what the tool does with it afterward, because the entire security model behind a login assumes only authorized people know the secret. Once that assumption breaks, deleting the chat does not fix anything. Rotating the credential is the only real fix, the same as if it had turned up anywhere else it should not be.

Unreleased financial information

Numbers that have not gone public yet carry value because only a small group can see them. That covers a draft board deck, a cash position ahead of a financing conversation, or projections tied to a deal that has not closed. Pasting that material into a tool to reformat it puts a copy outside that group at the exact moment its value depends on staying inside it. If a deal falls through and confidentiality still matters, there is no way to confirm the copy is gone. There was never any visibility into where it went in the first place.

Regulated data

Health records, legal files, and certain financial data carry handling rules specific to the industry. Often that includes a deadline for notifying regulators or affected individuals if something goes wrong. Those rules generally do not distinguish between an outside attack and an employee pasting a record into a chatbot to save twenty minutes. The obligation that follows is the same either way. Businesses in these categories usually already know the rules exist. What is easy to miss is that the rules apply to a chat box exactly as much as they apply to a filing cabinet, and nobody checks which one was used before the deadline clock starts.

The pattern connecting all six

Every category above fails the same way. A normal, well-intentioned task creates a copy of protected information somewhere the business does not control and cannot produce later.

Compare that to how most data problems announce themselves. A stolen laptop gets reported. A hacked email account triggers a password reset and usually an alert.

Pasting something into a chat box triggers nothing.

No error message, no log entry anyone reviews, no moment where the system flags what happened. That silence is the real risk sitting underneath all six categories, more than any single item on the list, and it is exactly why writing the never list down and explaining it beats hoping people work it out on their own.

A quick check before you paste

Not every borderline case maps cleanly onto one of the six categories above. When someone is not sure, run the text past these five checks. A match on any single one means it stays out of anything except the tools your business has actually approved.

  • The text would identify a specific customer, patient, or employee by name or account number.
  • You would not want this exact text to show up in a lawsuit or a regulator’s request for records.
  • It is covered by a signed agreement, a login that belongs to someone else, or a law tied to your industry.
  • This text alone could get someone into an account or a system.
  • This number, deal, or document has not been made public yet.

That is also the moment to ask someone, not the moment to guess and move on.

Common questions

Does this apply to business AI accounts, or just free ones?

The never list applies everywhere, business account or not. A business tier changes what the AI vendor does with the data after you send it, generally keeping it out of model training and giving you administrative controls. It does not change whether an NDA was violated, whether a password is now exposed, or whether a regulator’s notification rules were triggered. The account tier affects the vendor’s side of the risk. The never list covers yours.

What if an AI tool is connected to our files instead of something someone typed in?

That is a related but separate problem. Connecting an AI tool to SharePoint, a shared drive, or an email inbox means the tool can potentially reach whatever that connection has permission to see. That is true whether or not anyone meant to share it. The never list is about what a person actively pastes. A connected tool’s reach depends on your permission settings, which is a conversation worth having with whoever manages your file access.

Is it actually illegal to paste customer information into an AI tool?

It depends on what the information is and what agreements or regulations cover your business, which is a question for your attorney rather than a blog post. What holds true across most situations is simpler. The obligations already attached to that information, whether from a contract, a privacy law, or an industry regulation, do not pause just because the disclosure happened through a chat box instead of an email.

What do we do if someone already pasted something on the never list?

Find out three things without making the person defend themselves: what the information was, which tool received it, and whether the account was a business account or a personal one. That last answer changes what comes next. We walked through the full response process in our shadow AI guide, including when the right answer is calling your attorney rather than deleting the chat and moving on.

How do we get our team to actually follow the never list?

Write it down, explain the reason behind each item, and put a named person’s contact information next to it for anything unclear. A list nobody can explain gets treated as a suggestion. A list people understand gets treated as a rule.

Where this leaves you

The never list itself takes about thirty seconds to read. Understanding why each line is there is what makes someone stop and think before they paste, instead of nodding along in a meeting and forgetting it by Thursday.

If your team already has a policy in place, read this out loud at your next meeting instead of just linking to it. If you do not have one yet, start with our one-page AI acceptable use policy template. It has the never list, the ground rules, and a place for a named contact built in.

Our team is also happy to look at what AI features are already active in the software you pay for. We will flag anything that touches the categories above before it becomes a problem instead of after. That conversation is free and usually takes about half an hour.