At home, when we have a question, many of us [raises hand] now choose to ask AI instead of Google. At the same time, AI has created a new workplace habit: whenever we encounter something tedious, confusing or awkwardly composed (by ourselves), we paste it into an AI tool.
Long email? Summarize it. Awkward paragraph? Rewrite it. Spreadsheet? Analyze it. Meeting notes? Turn them into action items. Twenty-page contract? Tell me what I actually need to know. This is enormously useful and what makes AI seem like a modern-day blessing.
But it’s also worth remembering that every time you paste something into an AI tool, you’re giving that tool information. And sometimes that information probably shouldn’t be there. A case of AI “TMI“.
Before You Paste, Look at What You’re Pasting
There’s a big difference between asking ChatGPT to make an announcement friendlier and dropping in a spreadsheet containing employee salaries. The same goes for donor information, customer records, passwords, financial data, personnel issues, confidential board discussions, legal documents, medical information and anything else your organization wouldn’t normally hand to an outside company without thinking about it first.
The tricky part is that using AI doesn’t necessarily feel like sharing data. It feels more like asking a very smart coworker for help. You paste something into a box, get an answer and move on with your day.
But in this case, our very smart coworker isn’t a human being. It’s a technology service, and your organization – and every member of its staff – needs to understand what happens to information submitted to it.
Not All AI Tools Are the Same
There’s a big difference between using an approved business AI service with appropriate security, privacy and administrative controls and an employee signing up for a random free AI tool they discovered online. Even familiar AI products may have different protections depending on the version or account type. Organizations should understand which tools are approved, what employees can put into them and what privacy and data-handling protections apply.
Otherwise, “We’re using AI” can actually mean 25 employees are using nine different AI services under nine different sets of rules.
AI Doesn’t Need Everything
There’s also a surprisingly simple solution: don’t give AI information it doesn’t need.
If you want help rewriting an email to a customer, maybe the customer’s full name and account number aren’t necessary. If you’re asking AI to analyze a policy, perhaps you can remove confidential names or details first. And if you need help creating an Excel formula, AI probably doesn’t need the entire spreadsheet containing your organization’s financial history.
Think of it as the AI version of “need to know.” Give the tool enough information to do the job, but not necessarily everything you have.
Give Employees Rules They Can Actually Follow
Telling employees “don’t put sensitive information into AI” sounds reasonable, but it leaves an enormous amount open to interpretation. What’s sensitive? Which AI? What about Copilot? What about ChatGPT? What about the meeting transcription tool somebody installed last Tuesday?
I provided some simple guidelines for writing an AI policy recently. Bottom line is that a useful AI policy doesn’t have to be a legal masterpiece. Employees mainly need to know which tools are approved, what information is off-limits and who to ask when they’re unsure. The goal shouldn’t be to scare people away from AI. Organizations should want employees experimenting with these tools and finding ways to save time and work better. They just need a few guardrails.
Copy, Pause, Paste
So by all means, paste that terrible paragraph into AI and ask it to fix it. Have it summarize the report. Let it help untangle that Excel formula that’s been ruining your afternoon.
Just take a quick look at what you’re about to paste first.
Because sometimes Ctrl+C deserves a second thought before Ctrl+V.
For over forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!




0 Comments