AI assistants have become everyday work tools: drafting an email, summarising a contract, analysing a spreadsheet, preparing a presentation. The instinct is natural — paste the document into the chat. That is also where the risk begins. A customer’s name, a bank account number, a login or a confidential clause pasted into an assistant leaves the company. The good news: you can enjoy these tools without exposing your data by combining the right plans, the right settings, clear rules and, where useful, an anonymisation tool.

What happens to your data when you write to an AI

When you send a request to an AI assistant, its content is transmitted to the provider’s servers to be processed by the model. Depending on the plan and the settings, it may then be:

  • kept in the conversation history, for a variable length of time;
  • reviewed in some cases (abuse detection, for example), under the provider’s terms;
  • used to train future models, notably on some consumer plans depending on the user’s settings.

The risk is not theoretical: information that has been sent cannot be “recalled”. And in many companies, staff use free personal accounts outside any framework.

Rule one: business plans

The major providers draw a clear line between their consumer offerings and their business offerings (enterprise subscriptions and API access). The latter generally come with contractual commitments: no model training on your data by default, a GDPR-compliant data processing agreement, defined retention periods and central account management.

For example, Anthropic’s commercial terms state that it may not train models on its business customers’ content. Other major providers make comparable commitments on their enterprise plans. In every case, read the contract, not just the product page, and check where the data is processed.

Giving staff a properly governed business tool is also the best way to stop them using personal accounts.

Rule two: checked settings

Even on a business plan, a few settings deserve an administrator’s attention:

  • the retention period of conversations and the ability to delete them;
  • the connectors allowed (access to email, files, calendars): enable only the useful ones;
  • sharing of conversations and projects between users;
  • account authentication (two-factor, sign-in through the company directory).

Rule three: don’t send what isn’t needed

The best-protected data is data that is never sent. Before pasting a document, ask a simple question: does the AI need this name, this number, this amount to do the job? Very often, the answer is no.

Type of information Example Good practice
Identity A customer’s name, address, phone number Replace with “Customer A”
Banking data Account number, card number Never send
Technical secrets Passwords, API keys, tokens Never send
Health or HR data Sick leave, appraisal Avoid, or anonymise strictly
Strategic information Purchase prices, acquisition plans Keep to approved tools

The trouble with this rule is that it relies on everyone’s vigilance, on every single request. In practice, it is soon forgotten.

Rule four: automate anonymisation

That is why tools now automate this step. The principle: intercept the request on the workstation, detect sensitive data, replace it with decoys before it is sent, then restore the real values in the reply on screen. The AI works on fictitious data; the user reads an accurate answer.

That is how our software AIGuard works:

  • it intercepts requests sent to ChatGPT, Claude, Gemini, Copilot, Mistral’s Le Chat or Perplexity, in the browser and in desktop apps alike;
  • it replaces email addresses, IBANs, numbers, logins and secrets with reversible tokens or fictitious names;
  • it blocks a file containing sensitive data from being attached, with a one-click temporary unblock for false positives;
  • it logs every exchange (who, when, which service, which types of data were protected) for your GDPR obligations, without storing the sensitive content.

Going further: an AI that works on your premises

Beyond conversations, more and more businesses want to hand entire processes to AI: bank reconciliations, customer files, documents to sort. Those uses raise a further question: must you upload all your documents to a provider for the AI to use them?

Not necessarily. Our software AIKeep runs on the company’s own workstations: it opens files where they already are, keeps its history and memory encrypted on the machine, and sends the model only the extract needed for the current instruction, stripped of sensitive data by AIGuard. Storage does not leave; only the useful extract travels.

What about technical secrets?

Technical teams are particularly exposed: a developer pasting a configuration file or a log extract to get help can unknowingly transmit an API key, a database password or an access token. These secrets must be detected and masked as rigorously as personal data, and any key exposed by mistake must be revoked straight away.

Making the safe route the easy route

Rules only work if following them is easier than ignoring them. In practice, that means giving staff a business AI tool that is genuinely good, pre-configured with sensible settings, with anonymisation running automatically in the background rather than relying on memory. When the approved tool is the most convenient one, shadow use of personal accounts largely disappears on its own.

A ten-line usage policy

A short written rule that everyone knows beats a long policy nobody reads:

  1. Use only the AI tools provided by the company.
  2. Never enter a password, key or login.
  3. Never enter banking details.
  4. Anonymise the names and contact details of customers and staff.
  5. Do not attach confidential documents to an unapproved tool.
  6. Always check answers before using them.
  7. Never take a decision about a person on the strength of an AI alone.
  8. Label AI-generated content when it is published.
  9. Report any incident (data sent by mistake) immediately.
  10. Take the AI training offered by the company.

This policy also contributes to the AI literacy obligation under the EU AI Act, covered in our article on AI, the GDPR and the AI Act.

Frequently asked questions

Should free AI assistants be banned?

For business data, in most cases yes: they lack the contractual commitments of an enterprise plan, and whether conversations are used for training depends on each user’s settings.

Does anonymisation reduce answer quality?

Rarely. To draft a letter or summarise a contract, the AI does not need the customer’s real name: a consistent fictitious name is enough, and the real value is restored on screen.

Does Copilot in Microsoft 365 raise the same questions?

Yes, with one particularity: it can access the documents and emails the user can access. Tidy sharing permissions are therefore a prerequisite before rolling it out.

How can I find out which AI tools my staff already use?

Ask them, simply, and look at how work actually gets done. A blame-free inventory often reveals genuine needs, which can then be met with a governed tool.

Step By Step, a software and AI studio based in Ajaccio, Corsica, publishes AIGuard and AIKeep and helps businesses use AI with confidence. Let’s talk about your use cases.