What Not to Put Into AI: A Plain-English Guide to Protecting Sensitive Data

It usually starts with a deadline.

Someone pastes a spreadsheet into ChatGPT to save twenty minutes. It works, so they do it again next week, and by the time anyone thinks to ask, months of company information have gone through a tool nobody vetted.

Nothing was hacked. Nobody broke a rule that had been written down.

The short answer: keep customer and member records, login credentials, health information, employee files, and anything covered by a contract or a regulator out of any AI tool your organization has not formally approved.

This happens more often than most owners expect. Cyberhaven’s 2026 AI Adoption and Risk Report found that 39.7 percent of all data movements into AI tools involve sensitive information, roughly once every three days per employee.

The One Question That Settles Most of These Decisions

Before pasting anything into an AI tool, ask this:

Would I email this to an outside vendor we have never signed an agreement with?

If the answer is no, it does not belong in the prompt box either. Pasting into an unmanaged AI tool hands data to a third party. It feels private because it looks like a chat window, and it is easy to forget there is a company on the other end.

That connects to something Montana banks and credit unions already do well. An AI tool your team adopted on their own is a vendor nobody assessed, which raises the same questions you would face if that vendor had a cyber incident.

Is ChatGPT Safe for Work? It Depends on the Account

The confusion comes down to one distinction.

Consumer accounts. Free and personal-tier accounts commonly reserve the right to retain conversations and use them to improve the model. Settings sometimes let you opt out, and most people never change them.

Business and enterprise accounts. Paid business tiers of ChatGPT and Copilot generally exclude your data from model training by contract, keep it inside your tenant, and give administrators real visibility over retention.

Same brand name on the login screen. Very different data handling behind it.

That distinction matters, because a large share of workplace AI use runs on personal logins. Cyberhaven found 32.3 percent of ChatGPT usage happens through personal rather than corporate accounts.

When we look at AI adoption in Montana organizations, exposure usually traces back to a licensing question nobody thought to ask. The person typing cannot tell the difference from the interface.

Seven Things You Should Never Put Into ChatGPT or Copilot

Do not paste Why it matters 
Customer or member records Names paired with account numbers, Social Security numbers, dates of birth, or transaction history. The category regulators care about most. 
Login credentials and keys Passwords, API keys, connection strings, firewall and router configurations. Anything that would let someone else in. 
Health information Patient records, claims, treatment notes. Consumer AI tools do not sign Business Associate Agreements. 
Employee files Payroll detail, performance reviews, disciplinary records, medical accommodations, applicant information. 
Nonpublic financial and strategic material Board packets, unreleased financials, acquisition discussions, loan committee detail, pricing models. 
Anything under NDA or contract Client work product, partner data, negotiated terms. Your obligation to protect it does not pause when the tool is convenient. 
Controlled or classified categories CUI and ITAR material for DOD contractors, criminal justice information for government agencies. These carry explicit rules about where data may be processed. 

Even people whose job is data security get this wrong. In January 2026, Politico reported that the acting director of CISA, the agency responsible for defending US critical infrastructure, had uploaded contracting documents marked for official use only into the public version of ChatGPT, triggering automated security alerts and a Department of Homeland Security review.

Can Bank and Credit Union Employees Use ChatGPT?

For regulated organizations this stops being a best practice and becomes an examinable one.

Under GLBA, customer information stays inside your information security program even after it leaves your building, and even if you never assessed where it went. NCUA’s 2026 supervisory priorities, issued January 14, 2026, name vendor management and protecting member data among examination focus areas. An AI tool processing member information is a vendor relationship, even if it never went through procurement.

In our experience the gap that shows up at exam time is inventory. An examiner asks which AI tools your staff use, and there is no answer on file. That is worth solving before your next credit union or bank examination.

AI, HIPAA and CUI: What Regulated Data Changes

Healthcare organizations face a specific obstacle. Consumer AI platforms will not execute a Business Associate Agreement, which makes patient information in a consumer tool a disclosure you cannot paper over afterward.

DOD contractors have the parallel problem with controlled unclassified information. There is no de-identified version of CUI, so the only answer is an approved tool with the right agreement behind it.

The Gray Areas

Most day-to-day AI use sits between obviously fine and obviously not, and the answer is rarely to refuse.

Strip the identifiers. A loan officer drafting a payment reminder for a borrower 45 days past due gets the same output with or without the actual account attached.

Use an example instead of the real file. A construction firm building a bid template does not need to paste the live bid. Made-up numbers in the same structure produce the same formula.

What To Do If Sensitive Data Is Already in ChatGPT

Most organizations reading this will realize it already has. In every AIStack Challenge we have run, we have found at least one AI account in use that leadership did not know about.

Work it in order.

  1. Find out what was submitted. Ask without blame. People tell you if the conversation is about fixing it, and go quiet if it is not.
  2. Determine the account tier. A business-tier submission with an agreement in place is a very different situation from a personal login.
  3. Delete history and disable training where settings allow. This limits ongoing exposure. It does not undo what was already processed.
  4. Document the review, then escalate. Whether this is a reportable disclosure depends on the data category and your regulator, which is a decision for compliance or counsel, not IT.

Then approve a business-tier alternative. Remove the tool without replacing it and the behavior moves onto personal phones.

Once you know what to keep out, the next step is writing it down. Our guide to the one-page AI policy your team will actually follow covers what that document needs to say, and our piece on implementing AI without security risks covers the governance side for owners and executives. If you would rather assess this yourself before talking to anyone, the AI Integration Checklist walks through ten questions in five minutes.

Frequently Asked Questions

Is ChatGPT safe to use for work?

ChatGPT is safe for work when your team uses it through a paid business or enterprise account, which carries contractual protections against your data being used for model training, plus administrative controls. Free and personal accounts often do not, so the account tier matters more than the brand.

Can I put customer information into ChatGPT if I remove the names?

Removing names reduces risk but does not eliminate it, because combinations of remaining details can still identify a person. For customer, member or patient data covered by GLBA or HIPAA, use an approved business-tier AI tool rather than relying on redaction alone.

Can bank or credit union employees use AI tools with member data?

Only through a tool the institution has approved and assessed as a vendor. GLBA obligations follow member data wherever it goes, and NCUA examiners are reviewing vendor management and member data protection in 2026.

What if our team is already using AI without approval?

Start by finding out which AI tools are in use and why, rather than issuing a ban. Then approve business-tier versions of the tools that are genuinely helping. A prohibition with no approved alternative pushes AI use onto personal phones, where nobody can see it.

Get It Touch

Don't hesitate to contact us any time.

Whether you have questions, need support, or are ready to explore new IT solutions, our team is here and eager to help. Reach out to us anytime—we’re just a call or message away!

More Like This

Business Email Compromise: The Wire-Fraud Banks Miss

Business email compromise, known as BEC, is a scam where an attacker impersonates a trusted contact, often by email, to trick someone into wiring money or sharing sensitive data. It does not require breaking into your network, which is exactly why it is harder to catch, and for many community banks, more expensive than ransomware.

Read More

Your Vendor Had a Cyber Incident. Now What?

If a vendor you rely on has a cyber incident, your first job is finding out exactly what data or systems of yours that vendor could reach. Don’t wait for an official notification letter to start looking. Most community banks and credit unions in Montana don’t have a documented answer to that question until an examiner asks for one.

Read More

Let's Work Together

Schedule a discovery meeting with one of our Advanced Cybersecurity Experts to discuss how First Call can help you start YOUR Security Transformation!