Module 2.1

Before You Paste

Pasting information into an AI system is an action with consequences. What you put in may be stored, logged, used for training, or seen by others depending on the tool, account type, and organizational agreement — and once it is out, it generally cannot be taken back.

Answers: Data Exposure →

Most everyday material is fine to paste. The care applies to a specific set of high-stakes categories — not to routine work.

Generally safer to paste

  • Public information
  • Your own already-published writing
  • Generic drafts and boilerplate
  • Synthetic or anonymized examples
  • Code with no secrets or credentials
  • Non-confidential text already cleared for external sharing

Not safe without approval

  • Personal & regulated: personal, financial, or regulated data
  • Confidential or proprietary: secrets, proprietary material, compliance records
  • Legal, medical & HR: legal filings, medical records, HR decisions
Rule: If you would not post it in a public forum, do not paste it into an AI system until you understand the vendor, account type, data retention policy, and your organization’s approved use.
Maintenance note: Vendor data-handling policies change. Verify current policy directly with your vendor before relying on any opt-out procedure.

How to verify

Look for the vendor’s privacy policy, data processing agreement, or help documentation — and your organization’s approved AI guidance, which may be more restrictive. The answers change — these questions do not:

  • Is my data used to train the model?
  • How long are prompts and outputs retained?
  • Who has access to them?
  • Is there an opt-out, and where is it?

To turn this into a repeatable habit, the Data Classification Worksheet in the Template Kits gives you a reusable form for deciding what is safe to share.

EU AI Act resources provide regulatory context on data handling obligations for organizations operating in or serving European markets. See the Appendix for the primary source and a readable summary.