Ask your staff — politely, and only if you can handle the answer — this question: "Where do you type when you need to quickly draft a difficult email, summarise a contract, or work through a problem?" If you have fewer than fifty people, the honest answer is increasingly likely to be a public AI chatbot. And the data they're typing in? It's yours, and more often than you'd think, it's your clients'.

The problem with pasting client data into ChatGPT — and Gemini, Claude, and the rest — isn't that staff are careless. It's that the tool is convenient, it's free, and it works so well that nobody stops to think: "I'm about to send this client's confidential information to a server I've never seen, run by a company I don't contract with, in a country I can't point to on a map."

What actually happens to the text you paste

Here's the part most people get wrong: using a public AI tool isn't like using a search engine. The words you type don't just come back as an answer. What happens, according to the vendors' own data policies, is this:

  • Your text is processed on the vendor's servers, not on your computer. For the major tools that means datacentre infrastructure in the United States, regardless of where your business sits.
  • On free and consumer accounts, that content may be used to train the models that power the tool. OpenAI's free and Plus plans do this by default, and the opt-out is a toggle buried in Settings ("Improve the model for everyone"). Most users have never found it, let alone switched it off.
  • On paid Team and Enterprise plans, content is not used for training — but it is still retained (typically for 30 days), still processed overseas, and still visible to the vendor's own safety and abuse-review staff in some circumstances.
  • Google's Gemini works the same way in principle: consumer history is saved and may be used to improve Google's products unless the user turns history off, while Gemini in a business or enterprise Workspace is excluded from model training and covered by Workspace admin controls.
The key distinction isn't "free vs paid". It's your tenant vs their tenant. When staff use a personal account, your data enters their ecosystem with none of your controls — no retention rules you set, no DLP policy, no audit trail, no contract.

Notice what's missing from a personal account: there's nothing stopping that pasted client invoice, patient note, or draft legal letter from being retained, reviewed, or folded into training data. You have no agreement with the vendor, no right to ask what was captured, and no breach-notification obligation running back to you.

Why should you care?

Three reasons, in increasing order of pain.

  1. The data was never yours to give away. If you hold client personal information — and every small business does, from contact details to bank details to health and legal information — pasting it into a public AI tool is a disclosure to an unvetted third party, typically an offshore one. Under Australia's Privacy Act, organisations are accountable for how personal information is handled by the processors they use. You didn't choose this processor. You don't know it's your processor. That's a gap in your accountability, and it's exactly the kind of gap the Privacy Act reforms currently moving through parliament (higher penalties, a statutory tort for serious invasions of privacy, and a data-breach compensation regime) are designed to make expensive.
  2. One incident is enough. You don't need a breach in the news. You need a client to discover their details in a model's output, in a support conversation, or in a competitor's prompt. The reputational damage to a small business that lives on client trust is not recoverable, and the "but we only used it once" defence is not a good one.
  3. Nobody will tell you it happened. This is the part that makes it different from almost every other threat I write about. A phishing email is at least an event — you can see it, log it, and train on it. A data leak through a personal AI account produces no event at all. There's no alert, no log in your admin centre, no email to report. By the time you find out, it's usually because a client told you.

Why it's happening (and why "just say no" doesn't work)

The tools are genuinely good, they're one click away, and in a lot of small businesses the person who'd be most productive using them is also the person least likely to read a policy memo. Surveys keep confirming the pattern: the large majority of employees are already using AI tools at work, and the majority of employers have no policy covering it. That's not a staff morale problem. It's a governance problem — and governance problems are solved with rules and guardrails, not with hope.

What "safe AI use" actually looks like

You don't have to ban the tools. You need four things, in this order:

  1. A one-page AI usage policy. Plain English, no legal fog. It says: what data must never leave the organisation (client names, contact and payment details, contracts, anything marked confidential); which tools are approved; and what to do when in doubt (don't paste — redact first, or ask). One page, read by everyone, signed off. Staff comply with short rules. They ignore long ones.
  2. An approved path that's at least as convenient as the personal one. For a Microsoft 365 business, that usually means a commercial AI licence with an agreement — content excluded from training, retention you can manage, and admin controls that let you apply DLP rules so sensitive content is flagged before it leaves. Convenience beat a prohibition every time; beat it with a better door.
  3. A redaction habit for anything else. If someone must use a public tool, the rule is: strip identifiers before you paste. Replace "client" with "a client in the region", delete the invoice numbers, cut the names. It takes thirty seconds and it's the difference between your data and a training example.
  4. A way to find out if it's happening. No admin centre shows you personal-account usage — that's the honest truth. What you can do is ask (seriously, in a meeting, without ambush), and set up monitoring and incident readiness so that when a client raises a concern, your first hour is a plan, not a panic.

Where I come in

This is the most common gap I see in small-business security reviews, and it's usually fixable in an afternoon rather than a project. The work looks like this:

  • AI usage policy and team briefing — the one-pager, plus a 30-minute session so staff actually understand why, including the redaction habit and the "ask before you paste" rule.
  • Commercial AI setup — the right Microsoft 365 licence for your size, configured so AI content is excluded from training, retention is managed, and DLP catches sensitive categories before they go anywhere.
  • Ongoing monitoring and incident readiness — so a client complaint about their data becomes a handled event, not a fire.

If you've ever caught a staff member mid-paste and thought "that can't be right", you're not behind. You're right on time. Get in touch and I'll walk you through your AI exposure in a conversation — no jargon, and no blame.