Ask a room of small business owners whether they worry about data security with AI, and most will say yes. Ask the same room whether anyone has pasted a client contract, a payroll spreadsheet, or a customer list into ChatGPT this month, and the hands go up anyway. That gap between concern and behaviour is where the real risk lives — not in dramatic hacking scenarios, but in ordinary staff doing ordinary work a little too quickly.
This guide is the practical version of that conversation. No fear-mongering, no compliance jargon. Just what actually happens to the data you paste, which categories genuinely matter, and a one-page rule you can give your team this week that they will actually follow.
Why this is not a theoretical risk
The most common failure mode in an SMB is not a breach. It is what security people call shadow AI: employees using free, personal-account AI tools for work because the sanctioned tools are slow, expensive, or non-existent. Surveys across 2025 and 2026 have consistently put the share of knowledge workers pasting work data into unapproved AI tools somewhere north of half. In a ten-person company, that is five or six people making judgement calls with no guidance.
The damage, when it arrives, is rarely cinematic. It looks like a client discovering their confidential pricing ended up in a third-party system that was never named in your contract. It looks like a GDPR data processing agreement you cannot honour because you never knew a subprocessor existed. It looks like a due diligence questionnaire from an enterprise prospect that you have to answer honestly, and the honest answer costs you the deal.
One useful reframe: the question is not "is this AI tool secure?" It is "would I be comfortable if this data ended up with a vendor I have no contract with?" That question is answerable by anyone on your team without a security background.
What actually happens to the data you paste
There are three separate things people conflate, and separating them removes most of the confusion.
Training. Does the provider use your input to improve its models? On consumer free and personal paid tiers, the default has historically been yes, usually with an opt-out buried in settings. On business, team, and enterprise tiers from the major providers, the default is no — your content is not used for training. This is the single biggest difference between a €0 personal account and a €25 per-seat business account.
Retention. Even when data is not used for training, it is usually stored for a period — commonly 30 days for abuse monitoring, longer if you keep the chat history. Stored data can be subpoenaed, breached, or exposed through an account compromise. Retention is a separate setting from training, and turning off one does not turn off the other.
Human review. A small fraction of conversations may be reviewed by staff or contractors for safety and quality. This is normal across the industry and disclosed in the terms, but it surprises people who assumed their chats were read by nobody.
None of these are scandals. They are contractual facts, and they are the reason the plan you are on matters more than the brand you chose.
The seven things you should never paste into a consumer AI tool
These are the categories where the downside is legal or contractual rather than merely embarrassing. On a personal or free account, treat all seven as off-limits.
- Identifiable customer or patient data. Names plus anything else — email addresses, order histories, health notes, case details. Under GDPR this is personal data, and your AI provider becomes an undisclosed processor.
- Employee records. Salaries, performance reviews, disciplinary notes, sickness records, national insurance or tax numbers.
- Anything covered by an NDA. Client strategy documents, unreleased product plans, merger discussions. The NDA almost certainly does not permit disclosure to a third-party processor you never named.
- Credentials and keys. Passwords, API keys, database connection strings, access tokens. Developers paste these into debugging prompts constantly. Assume any key that touches a chat window is burned and rotate it.
- Financial account details. Bank account numbers, card data, full payroll files. Card data in particular drags PCI DSS obligations into a place they do not belong.
- Source code you do not own. Client codebases, licensed third-party code, anything with restrictive licence terms.
- Legal matters in progress. Litigation strategy, regulatory correspondence, anything where privilege matters. Privilege can be harder to defend once a document has been shared with an outside party.
Notice what is not on that list: your own marketing copy, your public pricing, a job description, a meeting agenda, a draft blog post, an anonymised process description. Most day-to-day AI work involves exactly this kind of low-risk material, which is why a blanket ban backfires — it pushes people into secrecy rather than caution.
Build a simple three-tier data classification
Enterprise data classification schemes run to five levels and forty pages. For a business under 100 people, three tiers on one page is enough, and it is the version people remember.
Green — use freely. Anything already public or that you would happily publish. Marketing copy, published pricing, public documentation, generic industry questions, your own draft ideas. No approval needed, any tool, any plan.
Amber — business account only. Internal but not sensitive. Process documents, anonymised data, internal meeting notes, draft strategy that contains no client names, aggregated numbers. Allowed only on the company's paid business-tier account with training disabled.
Red — never, without written sign-off. The seven categories above. If a genuine business case exists — say, running client documents through an AI tool as part of your service — it needs a named owner, a vendor with a signed data processing agreement, and a note in your privacy policy.
The practical trick is to anonymise your way from red to amber. "Client Acme Ltd is three months late on a €40,000 invoice" becomes "a client is three months late on a five-figure invoice." You get the same quality of advice with none of the exposure. Teach that one habit and you have solved most of the problem.
Settings and plans that change the risk profile
A handful of concrete moves do more than any policy document.
Pay for business tiers. Roughly €20–30 per user per month across the major providers buys you: no training on your data, admin controls, centralised billing, and a real contract. Compared with the cost of one contractual breach, this is not a close call. For a five-person team that is about €1,500 per year.
Turn off training and chat history on any personal accounts that remain. Every major tool has this in settings. It takes two minutes and should be part of onboarding.
Check where data is stored. If you are EU-based and handle EU personal data, ask the provider about data residency and confirm the transfer mechanism. Several providers now offer EU data processing on business tiers.
Get a data processing agreement signed before any customer data touches the tool. Most providers publish a standard DPA you can accept in the admin console. If a vendor cannot produce one, that tells you what you need to know — our guide on how to choose an AI vendor covers the full checklist.
Be careful with browser extensions and unofficial apps. The riskiest AI tools in most SMBs are not the big-name assistants; they are the free extensions and note-taking add-ons someone installed that quietly read every page and every meeting. Audit what is actually installed.
Write a one-page rule your team will actually follow
Long policies do not change behaviour. A short rule stuck in the team channel does. Here is a template you can adapt in ten minutes:
Our AI data rule. Use AI for work only through the company account — the log-in is in the password manager. Never paste customer names, employee records, client-confidential material, passwords or keys, financial account details, or legal matters into any AI tool. If you need AI help with something sensitive, remove the names and numbers first and describe it generically. If you are unsure, ask in #ai-help before pasting. Nobody is in trouble for asking; we would much rather answer the question.
That last sentence is doing real work. The most dangerous policy is one that makes people hide mistakes. Pair the rule with a fifteen-minute team session showing three good redaction examples and one bad one — our piece on training your team to use AI sets out a simple format. If you need something more formal for clients or insurers, the AI policy guide expands this into a full document, and the GDPR guide covers the legal obligations in detail.
What to do if something sensitive has already been pasted
Assume it has. The useful response is calm and procedural, not disciplinary.
Delete the conversation and, where the provider supports it, request deletion of the underlying data. Rotate any credential that appeared, immediately and without debate. Write down what was exposed, when, and to which provider — you may need this later. Then assess: if identifiable personal data was involved and there is a risk to those individuals, you may have a notifiable incident under GDPR, with a 72-hour clock. Most pastes will not meet that bar, but the assessment should be made deliberately rather than assumed away.
Finally, fix the cause. If someone pasted a client contract because the approved tool did not handle PDFs well, the real fix is a better tool, not a stern email.
The bottom line
AI data security for a small business comes down to three decisions, and none of them require a security team. Pay for business tiers so your data is not training anyone's model. Classify your data into three tiers so people know where the line sits. Teach one habit — strip the names and numbers before you paste — so the line is easy to stay behind.
Do those three things and you have eliminated the overwhelming majority of realistic risk, without the blanket ban that would cost you the productivity you adopted AI for in the first place. Security and usefulness are not opposites here. The businesses that get this right are simply the ones that decided the rules on purpose, before an incident decided for them.
Where does your business stand on AI?
Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.
Take the Free Quiz →