AI & Automation · October 1, 2026 · Seed & Society®
What Not to Put in AI at Work: Five Data Safety Rules
Five practical rules for protecting customer, employee, contractor, and business information while using AI tools at work.
Put Context Training™ into practice.
Get the Book
What should you never put into AI at work? Customer records, employee information, internal strategy, financial data, passwords, and confidential files all require more judgment than a quick copy and paste.
The safest starting point is to give an AI system the least information and access it needs to complete an approved job. That rule protects people and business assets while keeping the technology useful.
This article was developed by the Seed & Society A.I. blog employee from an approved podcast episode. Makeda approved the source episode, but did not personally review this article line by line.
What is shadow AI?
Shadow AI is the use of AI tools for work without the organization knowing about, approving, or managing those tools. It often begins with someone trying to solve a problem and move faster.
An employee may paste customer information into a personal account. A manager may upload a document without noticing that it contains private information. A founder may connect an AI tool to an inbox, calendar, or drive because the feature is available without deciding whether the system should be able to reach everything inside it.
This is not limited to employees. Virtual assistants, freelancers, agencies, and contractors may use tools that are outside the organization's direct control. The business still controls what information and access it provides.
A policy sitting in a folder will not solve the problem if the people doing the work do not know what the policy means while they are pasting, uploading, connecting, approving, or sending information.
What is the difference between AI privacy, security, and safety?
Privacy concerns the information
Privacy asks what is being collected, why it is being used, who can reach it, how long it remains, and what rights the people represented in the information have over what happens next.
Security concerns protection and access
Security asks who can enter the account, reach the files, use connected tools, or act inside related systems. It includes stolen passwords, shared links, excessive permissions, and connections that expose more than the job requires.
Safety concerns possible harm
Safety asks whether an output or action could affect someone's money, health, employment, rights, education, relationship, or reputation. It also asks whether a system could act on a bad answer before a qualified person checks it.
You do not need to become a privacy lawyer or security engineer before AI can help with a draft, public research, or a contained problem. You do need to know which rules govern the work and when a specialist should enter the decision.
Five rules for handling business information in AI
Rule 1: Know whose information you are using
Your rough notes are different from an employee record. A public annual report is different from an internal financial forecast. A fictional customer example is different from a support ticket containing a name, email address, account number, or private complaint.
The fact that information appears on your screen does not automatically make it yours to place in another system.
Before you paste, upload, or connect anything, ask whether the information is yours to use for this purpose. If it belongs to a customer, employee, client, student, patient, partner, or employer, identify the permission and policy that apply. If you do not know, stop and find out.
Rule 2: Use the approved tool and the right workspace
Personal, free, and organization-managed AI accounts can have different contracts, retention rules, training practices, administrative controls, and connected features.
A setting that limits whether new conversations improve a model can matter. It does not create permission to upload information that the organization never approved for that tool.
Turning off model training is a data control, not a company policy, confidentiality agreement, or security review.
For work involving sensitive information, “I use ChatGPT” is not a complete answer. Which account is being used? Who owns the workspace? What did the organization approve? What can an administrator control? What does the tool retain? Which other applications or files are connected?
Rule 3: Give the system the least information it needs
An AI system rewriting a customer email may need the purpose, relevant policy, tone, decision, and next step. It may not need the customer's full name, phone number, account history, payment information, or every prior message.
Remove identifiers when they do not change the task. Use categories instead of unnecessary details. Use synthetic records while learning or demonstrating a workflow. Keep sensitive files separate from a general business foundation.
This is data minimization in ordinary language: do not hand over ten things when the job needs two.
The same rule applies when working with employees and outside support. If a virtual assistant needs email access, create a separate business address instead of opening a personal inbox. If the person needs files, create a specific folder or workspace instead of opening an entire drive. Provide the context and access required for the job without handing over unrelated business information.
Rule 4: Decide what the AI may do
Reading a calendar is not permission to change it. Drafting an email is not permission to send it. Finding a product is not permission to buy it. Summarizing a folder is not permission to delete or reorganize the files inside it.
Give the system the smallest access that can complete the job. Add more only when the result genuinely requires it.
Makeda learned this in her own business with Em Bee, an AI clone that can use her face and voice. Some early videos were close enough to what she meant that it was tempting to accept them without the review her identity deserved. She took them down and changed the rule. Anything published with her face, voice, or name as the author receives a human yes before it ships.
Use two questions to place approval: Does this work represent a person? Would a mistake be expensive or hard to take back? When either answer is yes, name the qualified person who has to review it.
Rule 5: Make the system stop when information is missing
AI systems are designed to produce an answer. That can make an incomplete answer sound finished.
Tell the system what it must never guess, which current source governs, what to do when sources disagree, and which missing information should stop the work.
Use only the approved policy and the fictional employee scenario in this folder. Do not infer a diagnosis, protected characteristic, motive, or legal conclusion. If the policy does not answer the question, identify the gap and stop for HR review. Draft the response, but do not send it.
That instruction defines what the system knows, what it may use, what it may not decide, and where a person enters the work.
Use AI to review terms and privacy-policy updates
When a new tool asks you to accept updated terms or a privacy policy, copy the public link or text into an AI tool that is appropriate for the material and ask:
Is there anything egregious, super concerning, unusually broad, or out of the ordinary in here? Give me the high-level things I should pay attention to before I agree.
AI is not a lawyer. This prompt helps identify clauses that deserve closer human or legal review before you click accept.
Makeda used this approach after CapCut changed its privacy policy. She had already paid for a year. The review surfaced language broad and concerning enough for her that she deleted the app from her phone and stopped using it. Other policy reviews have led to a different decision. The value is knowing what deserves attention instead of signing blindly.
How leaders can reduce shadow AI without slowing the work
Give people an approved environment, examples of acceptable work, plain-language rules, and a clear place to ask when a task falls outside those rules.
Train around real business tasks. A customer-service team needs examples involving customer information. A state agency may need synthetic resident records for a workflow test. An HR team needs explicit stopping rules for employee information and decisions. A founder working with contractors needs specific folders, accounts, and context boundaries.
The goal is practical judgment. People should be able to recognize whose information they are holding, which environment is approved, how much context is necessary, what the system may do, and when the work must stop.
That is what Context Training workshops help organizations practice. Participants build a reusable role foundation, set rules for a real task, work inside an approved environment, check the result, and preserve the correction for the next attempt.
Listen to What Not to Put in AI at Work: A Beginner's Data Safety Guide for the complete episode.
Frequently Asked Questions
What should you never put into AI at work?
Do not enter customer, employee, financial, confidential, regulated, or personally identifying information unless the purpose, tool, account, permission, and organizational policy explicitly support that use.
What is shadow AI?
Shadow AI is work-related AI use that happens outside the organization's awareness, approval, or management. It can involve employees or outside partners using unreviewed tools with business information.
Is turning off AI model training enough to protect business data?
No. It is one data control. It does not replace organizational approval, contract terms, retention review, access controls, confidentiality obligations, or applicable law.
How does data minimization apply to AI?
Data minimization means giving the AI only the information required for the approved task. Remove unrelated details and identifiers, and limit connected access to the smallest useful scope.
Can AI review a privacy policy?
AI can summarize a public policy and flag unusually broad or concerning clauses for closer attention. It does not replace qualified legal advice or the person's responsibility to decide whether the terms are acceptable.
How should businesses handle AI use by contractors?
Businesses may not control every tool in a contractor's workflow, but they can control the information, accounts, folders, and access they provide. Use separate business accounts and task-specific workspaces instead of sharing personal passwords or entire drives.
This article is adapted from Season 3, Episode 12 of the Seed & Society podcast. Explore more practical writing in The Connectors Market.
Go deeper
Teach A.I. your world, not another prompt.
Context Training™ is the complete method for giving A.I. the context, examples, standards, and corrections it needs to work like it knows you.
Get the BookMore from The Connectors Market™
AI & Automation
ChatGPT Work vs Codex vs Claude Cowork for Business
September 23, 2026
Business Design
What AI-Native Business Access Really Requires
September 16, 2026
Time & Capacity
How to Use AI to Save Time Without Filling It With More Work
September 9, 2026