Module 2.1
Before You Paste
Pasting information into an AI system is an action with consequences. What you put in may be stored, logged, used for training, or seen by others depending on the tool, account type, and organizational agreement — and once it is out, it generally cannot be taken back.
Most everyday material is fine to paste. The care applies to a specific set of high-stakes categories — not to routine work.
Generally safer to paste
- Public information
- Your own already-published writing
- Generic drafts and boilerplate
- Synthetic or anonymized examples
- Code with no secrets or credentials
- Non-confidential text already cleared for external sharing
Not safe without approval
- Personal & regulated: personal, financial, or regulated data
- Confidential or proprietary: secrets, proprietary material, compliance records
- Legal, medical & HR: legal filings, medical records, HR decisions
How to verify
Look for the vendor’s privacy policy, data processing agreement, or help documentation — and your organization’s approved AI guidance, which may be more restrictive. The answers change — these questions do not:
- Is my data used to train the model?
- How long are prompts and outputs retained?
- Who has access to them?
- Is there an opt-out, and where is it?
To turn this into a repeatable habit, the Data Classification Worksheet in the Template Kits gives you a reusable form for deciding what is safe to share.
EU AI Act resources provide regulatory context on data handling obligations for organizations operating in or serving European markets. See the Appendix for the primary source and a readable summary.