Skip to content

What your team can paste into an AI tool, and what stays out

Three data-classification panels showing unsafe, filtered, and safe content for pasting into AI tools.

A one-page rule with three colors stops most data leaks into AI tools. You don't need a policy binder to get there.

Most small businesses handle this in one of two ways. They ban AI and hope, or they say nothing and hope. Either way, the risk is the same: someone copies a client email into a chatbot at 4:55 on a Friday because it saves ten minutes.

Why a banned-tools list does not stop the paste

A list of approved tools tells people where to work. It says nothing about what they put in. The leak happens at the clipboard, not at the login screen.

People paste because it's fast. So the rule has to be as fast as the paste. If a staff member needs more than five seconds to decide, they will skip the decision.

Three data classes: green, amber, red

Green: paste freely. Anything already public, or anything with no names, numbers or client details. Your published price list. A blank template. A question about how to word a policy.

Amber: clean it first. Real work that contains identifiers you can remove. A quote, a project update, a client email thread.

Red: never paste. Passwords and API keys. Bank, card and tax ID numbers. Health information. HR, pay and disciplinary notes. Anything under an NDA or a regulation you must report on.

This rule assumes a free or consumer AI account. A business plan with a signed data agreement can move some amber work to green. That call belongs to the owner, after someone reads the terms.

Examples from a normal week: quotes, invoices, HR notes, client emails

  • A quote for a kitchen remodel: amber. Remove the client name, address and phone number, then ask for help with the wording.
  • An overdue invoice reminder: amber. Replace the company name and amount with placeholders.
  • Notes from a performance conversation: red. No cleaning makes this safe, because the context identifies the person.
  • A client complaint email: amber. Strip the signature block, the email address and any account number.
  • Your "about us" page: green.

How to strip an amber document so it becomes green

Use the same three steps every time:

  1. Replace names with roles: "Client A", "Supplier B", "Employee 1".
  2. Replace numbers with placeholders: [AMOUNT], [DATE], [ACCOUNT].
  3. Delete signature blocks, addresses and anything below the first reply line.

This takes about one minute for a normal email. When the AI returns a draft, put the real details back in your own system, not in the chat.

Put the rule where the work happens: one page, one owner

Write the three classes and the examples on one page. Pin it in the team chat and link it from the AI tool bookmark. Name one owner who answers "which color is this?" within a business day.

Review the page each quarter. Add every question that came up to the examples list. After two quarters, most questions answer themselves.

What to do when someone pastes red data by mistake

It will happen. Make the response routine, not a punishment, or people will hide it.

  1. Stop and delete the conversation in the tool.
  2. Tell the owner within one hour.
  3. Rotate any password or key that was exposed.
  4. Log what was pasted, when, and into which tool.
  5. The owner decides if a client, bank or regulator must be told.

If you don't know which AI tools your team uses today, start with finding the AI already in your business. Then write the one-page rule this week.


Keep exploring

To see where your data and approvals stand before you write the rule, start the AI Readiness Audit or contact FIT.

Share this post LinkedIn X Email