Cybersecurity Artificial Intelligence

What data you should never share with an AI

The worst headline a company can face: "Company leaks customer data to an artificial intelligence". While we talk about productivity, automation and content generation, there is a less visible question we also need to address: what information are we sharing with these tools.

What data not to share with an AI

The Spanish Data Protection Authority recommends not entering personal data, sensitive information, confidential professional information or third-party data into AI tools without first assessing how it will be processed. So what data should we never paste into a chat?

1.

Personal data of clients and employees

Names, phone numbers, addresses, ID numbers or email addresses all require special care. The recommendation is to avoid entering this type of information and, where possible, to use fictitious cases or remove identifying data.

How it can happen without bad intent

An employee copies a conversation with a client and asks the AI how to respond to a complaint, or uploads a spreadsheet with customer data to detect patterns.

The problem is that, along with the question, they are also sharing all the information it contains.

2.

Contracts, reports and internal documents

AI can summarise a contract or draw conclusions from a report, but that does not mean we can upload any document. It is expressly recommended not to include confidential professional information — contracts, reports, strategies — or confidential employee and client data.

A common example

An employee copies a full contract into a public chatbot to identify the most unfavourable clauses. Productivity improves, yes. But information may have left the company that should never have done so.

3.

Financial, strategic information and credentials

Financial statements, margins, commercial forecasts or launch strategies also require protection.

⚠ Passwords, API keys, tokens or credentials should never be entered into an AI chat.
How it can happen unintentionally

Someone describes a connection error and pastes the entire configuration alongside the message, or attaches a full ERP export to analyse results.

The AI solves the problem. The issue is everything it needed to see in order to do so.

Before sharing any data, one simple rule applies: if you would not send it to a third party without first checking how they will handle it, you should not paste it into a public AI either.

AI can be an extraordinary tool for any company. The risk is not in using it — it is in using it without knowing what we are sharing.

When data is sensitive, the environment matters

It is not about stopping the use of AI. It is about using it responsibly. When working with truly sensitive data, the best option is to do so through on-premise AI or private platforms such as Minte, where the technology adapts to the security requirements of the business.

Get in touch