Skip to content
CodelessOps
Go back

How to use AI at work without leaking data

Your team already uses it. Not in a pilot, not with IT’s blessing, just quietly, on personal accounts, at the point in the afternoon when a deadline stops being negotiable. That is the version of AI adoption most finance functions actually have right now, and it’s the worst one on offer.

Not because the people doing it are reckless. Because nobody ever gave them a rule they could apply in the ten seconds before pasting.

Is it safe to put company data in ChatGPT?

It depends on two things, and neither of them is the model. Which account you’re using, and which class of data you’re pasting. The same sentence typed into two different accounts is a routine productivity gain in one and a disclosure in the other.

The term for what happens while nobody has decided is shadow AI: tools used for company work outside any policy or contract. Read it as unrecorded outsourcing. Every paste hands a piece of your company’s information to a supplier nobody signed with, and creates no record that it happened.

What actually differs between accounts

The useful split isn’t consumer against enterprise. It’s these three things, and you can ask about each one directly.

Retention. How long the provider stores what you typed, and who can see it during that window. This is the question people skip, and it’s the one that decides whether a paste is a moment or an artifact.

Training. Whether your content ends up improving the provider’s models. Consumer tiers have historically defaulted to yes with an opt-out available; business and enterprise tiers generally default to no. Defaults move, and they differ by plan and region, so read the terms attached to the account you actually hold rather than a summary someone posted last year.

Accountability. Whether a contract exists with your company’s name on it. A personal account has terms between the provider and your employee. Not between the provider and your employer. That gap is the whole reason legal gets twitchy, and it survives every reassurance about encryption.

None of this makes the model better or worse at the work. Same brain, different paperwork.

The ladder, which fits on one page

Here’s the decision, in the shape a person can actually run while their cursor is in the box.

flowchart TB
  A[About to paste this] --> B{Would you email it<br/>outside the company?}
  B -->|Freely| C[Paste it]
  B -->|Under NDA| D{Company account<br/>with a contract?}
  B -->|Never| E[Don't paste<br/>describe the shape]
  D -->|Yes| F[Paste it<br/>note the use]
  D -->|No| E

The email test is the part that does the work. Finance people already carry well-calibrated instincts about what can leave the building, built over years of handling things before they were public. The ladder borrows those instincts instead of asking anyone to learn a new framework.

Data class against tool class

Enumerated properly, because “use good judgment” is not a policy. Read down for what you’re holding, across for where you’re about to put it.

What you’re pastingPersonal accountCompany account, contract in placePrivate or self-hosted
Public filings, published guidanceFineFineFine
Method questions with no company dataFineFineFine
Anonymised structures and shapesCautionFineFine
Real figures, pre-releaseNoCaution, check retentionFine
Named customers, staff, salariesNoOnly if the contract covers itFine
Board pack, deal papers, anything price-sensitiveNoNoFine

The right-hand column is why governed systems exist. Everything else is about staying honest regarding which column you’re actually in.

Anonymising, done properly

Most anonymisation fails the same way. People strip the names and leave the arithmetic.

Here’s the version that doesn’t work:

Our Q3 revenue was 4.2m against a budget of 5.1m. Why might the gap sit in the services line?

Removing the company name changed nothing. The figures were the sensitive part, and anyone reading that log now knows a business missed by 900k in a named quarter. If the company is identifiable from the account, the anonymisation was decorative.

Here’s the version that does:

A services business missed a quarterly revenue budget by roughly 18%. What are the usual causes when the gap sits in project revenue rather than recurring licence revenue?

Ratios instead of absolutes. Shape instead of scale. You still get the answer worth having, because what the model is good for here is pattern knowledge, not your specific numbers.

And when you genuinely need a tool to work on the real figures, cited and checkable, that’s the signal you’ve outgrown the chat window. I’ve written separately about why uploading the workbook doesn’t get you there.

Where this still goes wrong

The summary that feels safer. People paste a long document and ask for a summary, on the quiet assumption that asking for less exposes less. The document went in the moment you hit send. What comes back has no bearing on what left.

The screenshot loophole. An image upload is a paste. Teams that have internalised a rule about text will photograph a screen without a second thought, and spreadsheets get pasted as pictures constantly, which is its own problem given how these tools read a spreadsheet.

The audit question nobody rehearses. At some point someone asks which AI tools touched the numbers in the last filing. On personal accounts the honest answer is that you don’t know. That answer costs more than any single paste ever did.

Getting IT to yes

The instinct in most companies is to ban it. Bans produce the quiet version, which is the one with no logs and no contract, so the ban makes the exposure harder to see without making it smaller.

The trade that tends to work is narrow. Ask for one sanctioned tool with a contract, and offer the recording in exchange. A finance team saying “give us an approved account and we’ll note what we use it for” is much easier to approve than one asking for permission in the abstract. You’re not asking IT to trust AI. You’re asking them to swap invisible usage for visible usage, which is a trade they understand.

Then write the one-page rule. The ladder above is most of it. A rule somebody can run in ten seconds beats a policy document that nobody opens twice.

What I’d tell your CFO

Your team is already using this, so the only real decision left is whether the usage is recorded. Buy one sanctioned account with a contract against your company’s name, publish a one-page rule a person can apply in the ten seconds before they paste, and treat pre-release figures and named individuals as things that don’t go into a chat window whatever the account. Then ask, once a quarter, which tools touched the numbers in the last filing. If the room shrugs, the policy isn’t real yet.


This is part of a series explaining AI and the systems around it for finance people, in their own language. I build AI systems for finance teams; the series is what I’ve learned doing it.


Share this post:

Keep reading

All posts →