English · 3 min read
What business data should you keep out of AI tools? A plain-English checklist
A practical checklist for small business owners: what not to paste into AI tools, what needs a business-grade setup, and how to use AI without losing control of sensitive information.
AI can save a small business real time, but it is not a magic private notebook. Before you paste a document, customer message, or spreadsheet into an AI tool, pause long enough to ask one useful question: would I be comfortable sending this information to an outside service?
That question will not solve every privacy decision, but it prevents the most common mistake: treating a consumer AI chat like an internal company system.
Keep these out of ordinary AI chats
Unless you have confirmed a business agreement, the right account settings, and a clear reason to share the information, do not paste these into a general AI tool:
- Customer passwords, payment card details, bank details, government IDs, or authentication codes.
- Full medical, legal, payroll, tax, or disciplinary records.
- Confidential contracts, deal terms, source code, security details, or private product plans.
- A full customer export when a short anonymised summary would do.
- Information about children or anyone whose data needs special protection.
This is not about avoiding AI. It is about giving it the smallest amount of information needed for the job.
Use a simple traffic-light rule
You do not need a forty-page policy to start making better decisions. Give your team three buckets.
Green: generally safe to use. Public website copy, a blank email template, an anonymised customer question, a meeting agenda, or a list of product features already published on your site.
Amber: use only with care. A customer email with names removed, internal process notes, a quote where private details have been replaced, or a spreadsheet with identifying columns removed. Use an approved tool and review the output.
Red: do not paste into a general chat. Passwords, payment data, IDs, private health or legal records, confidential contracts, security credentials, and any information that would seriously harm someone if exposed.
When in doubt, treat it as amber or red until someone responsible has checked the tool and the purpose.
Do not let AI make the final sensitive decision
Even when data is handled properly, AI should not make the final call on a loan, hiring decision, medical matter, legal conclusion, disciplinary action, or other high-impact outcome. It can help organise information or prepare a draft. A qualified person must decide and verify the result.
The same rule applies to customer-facing promises. AI can prepare a reply, but a person should approve pricing, refunds, delivery commitments, and anything that could create a dispute.
Check the tool before you connect it
Before you connect AI to your email, CRM, cloud drive, or support inbox, answer these practical questions:
- Which exact account and plan are we using?
- Are our inputs used to train the provider's models, and can that setting be changed?
- Who in our business can connect data or export it?
- What information will the AI actually be able to see?
- Where is human approval required before anything is sent or changed?
- How do we remove access if a staff member leaves or we stop using the tool?
If you cannot answer those questions, do not connect the system yet. Start with a smaller workflow using approved, non-sensitive examples.
Make safe use the easy option
Write a one-page rule your team can actually follow. Include the green, amber, and red examples above; name the approved tools; and give people an easy way to ask before sharing something unclear. A good rule is more useful than a policy nobody can find.
Then start with low-risk work: draft public marketing copy, turn an anonymised meeting summary into tasks, prepare a reply from approved FAQs, or summarise a non-confidential document. You can widen the scope only after the team understands the boundaries.
For a broader overview of how Dapols treats connected workflows, read our security and data privacy page. If you want a plan that identifies the data boundary and human checks before recommending tools, try the free AI plan finder.