Handling Confidential Information: Security Basics When Using AI at Work

AI Navigate Original / 5/16/2026

共有:

Key Points

  • AI input is sent to servers; confidential input ignoring rules/contracts/law causes serious incidents
  • Don't input: customer/unpublished contracts/financial/HR/unpublished specs/IP/credentials/health info
  • 3 checks: training-use terms (differ by plan—check official) / internal rules / law & NDA
  • Mindsets: mask, abstract, approved tools, training-off, logs; on an incident report immediately and preserve history

Using AI at Work = Side by Side with Confidential-Info Risk

When you ask AI, what you input is sent to a server. Inputting confidential information while ignoring internal rules/contracts/law leads directly to serious incidents like leakage or violation. First, the minimum security to hold.

Information You Must Not Input (Typical Examples)

  • Customer info (name, address, phone, email)
  • Unpublished contracts/pricing with partners
  • Unpublished financial data/management metrics
  • Employees' personal info/HR evaluations
  • Unpublished product/technical specs
  • Intellectual property (pre-patent ideas)
  • Passwords/API keys/tokens
  • Medical/health info (personally identifiable)

3 Confirmation Points

1. Terms of Service / Data Policy

Always confirm whether the AI "uses / doesn't use" input data for training (conditions differ by service/plan and can change—check the latest on official pages). General tendencies:

  • Paid individual (ChatGPT Plus, Claude Pro, etc.): may be used for training; often can be turned off in settings

Sign up to read the full article

Create a free account to access the full content of our original articles.