Public AI tools are useful. They are also leaky. The danger is rarely a hacker. It is a good employee, in a hurry, pasting the wrong thing into the wrong box. In 2023, Samsung engineers pasted secret source code into ChatGPT to save time. The code was gone, and the company restricted the tools soon after.
You do not need a ban. You need a few habits and controls that keep private data where it belongs. Here is how to keep your data out of public AI tools.
Know how public tools use your data
Start with the basic fact. Many free AI tools keep what you type and may use it to train their models. That means a contract, a client list, or a patient note can become part of a system you do not control. Once it is in, there is no delete button that reaches everywhere.
Write down what is off-limits
People cannot follow a rule they have never seen. Put it in writing. Name the data that must never go into a public tool: Social Security numbers, financials, health records, deal terms, and passwords. Make it plain, and repeat it — at onboarding and again a few times a year.
Move work to business accounts
Free accounts are the leak. Business plans are the fix. Tools like ChatGPT Team, Copilot for Microsoft 365, and Google Workspace agree in their contracts not to train on your data. Moving your team to paid, business-grade accounts removes most of the risk in one step. This is a core piece of sound AI governance.
Add a safety net with DLP
People make mistakes, so add a backstop. Data loss prevention (DLP) tools watch for sensitive data leaving your systems. Modern options — like Microsoft Purview or browser-level controls — can spot a credit card number or a client file heading into a chatbot and stop it before it lands.
Train for the real risk
The threat is habit, not hacking. Short, real training works better than a long memo. Show people what a leak looks like, and teach one simple move: strip names and numbers out before you ask an AI for help. Make staff part of the defense, not the weak point.
Check the logs
Trust, then verify. If you use business accounts, the admin dashboard shows how AI is being used. A quick monthly look tells you what is normal and what is not. The goal is to fix gaps and coach — not to blame.
Keeping data out of public AI comes down to one idea: give people a safe, fast path, then back it up. Move to business accounts so your data is not used for training. Write down what is off-limits. Add a DLP net for the honest mistakes. Train for the habit, not the horror story. Do those four things and you get the speed of AI without handing your business to a system you cannot control.
A few fair questions
Is it safe to use ChatGPT for work at all?
Yes, on a business plan and with clear rules. The paid business tiers do not train on your data. The problem is the free version plus sensitive input — not AI itself.
What is the fastest fix if we have done nothing yet?
Move everyone to business accounts and send one short note listing what must never be pasted into a public tool. That single step removes most of the risk while you build the rest.
Do insurers care about this?
More every year. How you handle data now shows up at renewal time. Our cyber-insurance renewal checklist walks through what insurers actually ask.
If you want a straight read on where your data could be leaking, book fifteen minutes with me — Wayne Libonati, PCI’s CEO. Bring the tools your team uses, and we will find the gaps together.