What Should You Never Paste Into an AI Tool?
Business Partner · 31 July 2026
AI, thought through.
An AI tool can help write a difficult email, summarise a document or explain a set of figures. The empty text box makes it feel as ordinary as typing a note to yourself.
It is not.
The moment you paste information into an online AI tool, you are giving that information to another service. Whether it is stored, reviewed, used to improve the service or shared with another provider depends on the tool and the agreement behind it.
The useful rule is simple:
Do not give an AI tool information unless you are entitled to share it and understand what the provider will do with it.
Start with what is never worth the risk
Some information should not be entered into an AI tool at all:
Passwords, one-time PINs, security answers and private access keys
Online banking credentials or card details
Copies of identity documents that are not specifically required by an approved service
Information that would give someone access to a system, account or payment
AI does not need a real password to explain how a password policy should work. It does not need a real bank account to draft a payment instruction. Replace the sensitive detail with a description or an invented example.
Customer information is still your responsibility
A debtor ledger may contain customer names, email addresses, invoice references, balances and payment histories. A customer complaint may reveal a phone number, address or private circumstances.
That information may be useful to the task, but usefulness does not make it yours to disclose wherever you choose.
Under South Africa's Protection of Personal Information Act, a business remains responsible for protecting personal information under its control. When another provider processes that information for the business, the purpose, authority, confidentiality and safeguards still matter.
Before using customer information, ask:
Does the tool need the customer to be identifiable?
Am I entitled to provide this information for this purpose?
Does the provider say whether it stores the information?
Can the information be used to train or improve another service?
What happens to it when the task is finished?
If those answers are unclear, do not upload the information.
Payroll belongs in a smaller circle
Payroll records bring several risks together. They can contain salaries, bank details, identity numbers, tax information, leave records and sometimes health or disciplinary information.
Do not paste a payroll file into a general AI tool to ask for a summary.
If the question is general, remove the people. Ask with job titles, broad salary bands or invented figures. If the real records are necessary, use only a service approved for that information and provide only the fields required for the task.
The same applies to employee assessments, disciplinary correspondence, medical information and private conversations. Making the names anonymous may not be enough if the surrounding details still identify the person.
A contract can carry someone else's confidence
Contracts, tenders and proposals often contain information belonging to several parties: pricing, methods, intellectual property, settlement terms and commitments made in confidence.
Before asking AI to summarise a contract, check whether you are allowed to submit it to another provider. A confidentiality clause does not stop applying because the recipient is software.
Where possible, ask about the principle rather than supplying the document:
What should a small business look for in a limitation-of-liability clause?
That is different from uploading a signed customer agreement containing names, prices and negotiated terms.
AI can help you understand what to look for. It should not quietly become an undisclosed reader of the agreement.
Correspondence is not harmless because it is already in your inbox
An email chain or WhatsApp conversation may be the easiest way to give AI the full story. It may also include everything the other person assumed would remain between you.
Remove names, contact details, signatures, account numbers and unrelated history. Keep only the words needed to answer the question.
The UK's National Cyber Security Centre gives a useful test for public AI tools: do not submit sensitive information, or a query that would cause difficulty if it became public. That is a sensible business rule, even when a provider offers stronger protections.
Not every AI tool is the same
The conclusion is not that AI must never work with real business information.
A purpose-built service may have clear terms, an agreed purpose, confidentiality obligations, defined retention and security safeguards. A general public tool may have different settings and conditions. Those differences matter more than the word "AI" on the label.
Before approving a tool for business information, establish:
What information it needs
Why it needs it
Whether the information is stored
Who may access it
Whether it is used for training
How it can be exported or deleted
What the provider must do if something goes wrong
If a provider cannot answer plainly, the owner should not have to guess.
The practical rule
If you would hesitate to forward the information to a supplier you have never met, do not paste it into a general AI tool.
Remove what identifies people. Use an invented example where the real detail is unnecessary. Where real business information is essential, use a service whose purpose, authority and treatment of that information are clear before you provide it.
AI should reduce the amount an owner has to carry.
It should not create a new risk the owner never agreed to take.