Hustlyst

Learn the basics  /  Part 6 of 10  /  8 min read

Using AI at work without getting into trouble

The rules nobody explains at work: what is safe to paste in, what is not, and how to check whether your company already has a policy you are breaking.

Most people using AI at work have never been told what the rules are. They are using a personal account, on a work laptop, with work documents, and nobody has said either yes or no.

That is the situation this guide is for. None of it requires a technical background.

The one rule that covers most of it

Do not paste anything you would not put in an email to a stranger.

That covers customer data, employee records, unreleased financials, anything covered by a contract, credentials, and the document marked confidential in the footer.

It is a blunt rule and it is right far more often than it is wrong.

Consumer accounts and business accounts are not the same product

This is the part almost nobody knows. On the same tool, from the same company:

  • Consumer tiers commonly use your conversations to improve their models by default, with a setting somewhere to turn it off.
  • Business and enterprise tiers commonly do not train on your content at all, and say so in the contract.

So the honest position is not "AI tools are unsafe". It is that a free personal account and the company-provided account carry different terms, and the free one is the one to be careful with.

Find the setting. In most consumer tools it sits under Settings, then Data controls, and it is worth two minutes.

What to check before you paste anything

  1. Ask whether your company has an AI policy. Ask IT or your manager directly, and in writing, so the answer exists somewhere.
  2. Find out which tools are approved. An approved tool you can use openly beats a better one you have to hide.
  3. Check whether training on your content is on, and switch it off if you are on a personal account.
  4. Decide what your own line is for customer names, and hold it. Replacing real names with "the customer" costs nothing and removes most of the risk.
  5. Assume anything you paste could be read by someone at the vendor. Not because it will be, because the assumption produces good habits.

Regulated work has harder rules

If you handle health records, financial data, or personal data of people in Europe, India or California, the rules are not a matter of judgement and you cannot resolve them from a guide.

The practical version: do not be the person who decides this alone. Get it in writing from whoever owns compliance where you work. Being told no is a much better outcome than being the example in the incident report.

The quiet risk nobody mentions

It is not usually a leak. It is being wrong in public.

You paste in a report, ask for a summary, and send it on. The summary contains a number the model rearranged, and your name is on it. The tool made the error, and the mistake is yours.

Check names, numbers and dates in anything you forward. Every time. This is the failure that actually happens to people.

The honest limitation

Following all of this does not make you compliant with anything. It makes you sensible. Compliance is a decision your organisation makes and writes down, and if nobody there has made it yet, the useful thing you can do is ask the question that forces it.

The newsletter

Get the next playbook by email

Each issue is one task from real work, step by step, with the prompt ready to copy. Free, and one click to leave. Reply to any issue with the task you are stuck on.

No spam. Unsubscribe in one click.