Illustrated article hero image for What Business Information You Should Never Paste Into AI Tools.

Technical article

What Business Information You Should Never Paste Into AI Tools

Practical, owner-friendly guidance for What Business Information You Should Never Paste Into AI Tools.

AI tools are useful for drafting, summarising, brainstorming, and turning rough notes into clearer language. The risk is not "AI is bad"; the risk is pasting information into a tool before the business has decided what is safe to share. For a small team, the practical rule is simple: if the information would create harm if it appeared in the wrong inbox, do not paste it into a public or unmanaged AI tool.

This checklist is written for ordinary New Zealand SME work: emails, quotes, customer records, website copy, contracts, accounts, and internal notes. It is not legal advice. It is a safer operating habit you can use before staff, contractors, or owners ask an AI tool to help with business admin.

Never paste

Information that should stay out of AI prompts

Some information is too sensitive to paste into a general-purpose AI tool. Keep it in your own systems, or remove identifying details before asking for help with wording or structure.

Customer and patient details

Names, addresses, phone numbers, email addresses, case notes, appointment notes, health details, complaints, or anything that identifies a person.

Credentials and access details

Passwords, MFA codes, recovery codes, API keys, private links, admin URLs, cPanel details, DNS logins, or mailbox forwarding rules.

Commercially sensitive work

Unpublished pricing, margin calculations, quotes, tenders, supplier terms, payroll details, board papers, or private strategy notes.

Legal, HR, and conflict material

Employment disputes, disciplinary notes, settlement wording, legal letters, incident reports, or anything that should remain privileged or tightly controlled.

Safer prompts

How to ask for help without exposing private data

You can still use AI productively. The trick is to separate the task from the sensitive facts. Ask for a structure, checklist, tone rewrite, or generic draft, then add the real details inside your own system.

Good use cases

Business tasks where AI is usually lower risk

AI is safer when the input is generic and the output is reviewed by someone who understands the business. Treat it like a draft assistant, not a private record-keeping system.

First-draft templates

Ask for a generic appointment reminder, quote follow-up, complaint acknowledgement, or handover checklist without customer-specific details.

Plain-English rewrites

Paste a non-sensitive paragraph and ask for simpler wording, shorter sentences, or a more helpful structure.

Internal checklist ideas

Ask for a starting checklist for onboarding, website launch, password handover, device setup, or email migration, then adapt it privately.

Public website drafts

Use AI to outline service-page sections or FAQs, then rewrite them so they match the real business and do not invent claims.

Team rule

A simple AI safety policy for an SME

A policy does not need to be long. It needs to be easy to remember while someone is busy. Start with this: AI tools may be used for structure, summaries, and draft wording, but staff must not paste personal data, credentials, customer records, private commercial information, legal/HR material, or confidential screenshots into unmanaged AI tools.

Add one owner for the policy, one place where approved tools are listed, and one process for asking before a new tool is used. If the business handles sensitive customer information, make the default answer "do not paste" unless someone has checked the tool, account settings, and data-handling terms.

NZ privacy context

Personal information still counts when it is inside a prompt

For a New Zealand business, the privacy question is not whether the tool is clever or convenient. The practical question is whether the prompt includes information about an identifiable person, whether the business has a lawful reason to use it that way, and whether the tool provider may retain, disclose, train on, or process that information outside the business's control.

Identify the information

If the prompt includes names, contact details, photos, emails, IP addresses, account notes, or enough context to identify someone, treat it as personal information.

Check the purpose

Ask whether using the information in an AI tool fits the reason it was collected. If the answer is unclear, use a fictional example instead.

Keep it secure

Prompts, uploaded files, screenshots, and generated outputs should be treated like business records when they contain sensitive details.

Review before acting

AI output can be wrong, biased, or too confident. A person should review anything that affects a customer, staff member, invoice, account, or legal position.

Tool approval

Questions to ask before approving an AI tool

an SME does not need an enterprise governance programme to make better choices. It does need a short approval checklist so staff know which tools are allowed, what they can be used for, and what must never be pasted into them.

Prompt decision tree

A 30-second check before pasting anything

Use this as the everyday rule at the keyboard. If any answer is uncomfortable, stop and rewrite the prompt with placeholders or ask for a generic template instead.

Could this identify someone?

If yes, remove identifiers or avoid the tool unless the business has approved that exact use and checked the provider terms.

Would this harm the business if leaked?

If yes, keep it out of the prompt. That includes pricing strategy, disputes, payroll, supplier terms, credentials, and unpublished plans.

Can a placeholder do the job?

Most drafting tasks work with invented names, fake dates, approximate categories, and generic scenarios.

Will a human check the answer?

Do not rely on AI output for customer commitments, account recovery, legal wording, technical changes, or payment instructions without review.

Overseas and provider risk

Cloud tools can create disclosure and retention questions

Many AI tools are operated by providers outside New Zealand or process data across multiple systems. That does not automatically make them unusable, but it does mean the business should understand whether personal information is being disclosed, retained, used for the provider's own purposes, or protected by comparable safeguards.

Low-risk pattern

Use prompts that contain no personal, confidential, credential, customer, pricing, legal, HR, or commercially sensitive details.

Higher-risk pattern

Uploading emails, documents, screenshots, contracts, CVs, complaints, call notes, or support tickets with real identifiers.

Business control

Prefer managed accounts, approved tools, clear retention settings, access controls, and a process for removing staff or contractors.

Evidence trail

Keep short notes on why a tool is approved, what settings were checked, and which prompt categories are allowed or banned.

Recovery

What to do if sensitive information was pasted

Do not panic, but do treat it like an incident. Record what was pasted, which tool was used, who used it, and whether credentials or personal information were involved. If passwords, API keys, tokens, or recovery codes were pasted, rotate them immediately and check account activity.

Related reading

AI safety often overlaps with account security: mailbox access, MFA, password recovery, and admin ownership. These pages connect the AI checklist to the wider support cluster.

Official references

NZ privacy guidance to cross-check

These official Privacy Commissioner resources are useful when a business is deciding whether a tool is safe enough for personal information, confidential business information, or customer-facing decisions.