The next piece of sensitive information you expose may not end up on a phishing site. You may paste it directly into an AI chatbot.
AI assistants have made it almost effortless to paste in a document, a screenshot, a block of code, or a personal problem and ask for help. Still, that convenience can encourage users to hand over information they would never give to a stranger.
Security guidance from Norton and other sources specifically warns against sharing certain kinds of information with general-purpose chatbots.
To help you understand the kinds of information you should keep off AI platforms, we have outlined specific data kinds you must never give an AI tool while also providing an easy way to judge whether a piece of information should find its way into an AI platform.
A rule of thumb to always remember
If you wouldn’t want a stranger reading it, don’t put it into an AI chatbot.
However, you can use three simple categories to decide what can be pasted as-is, what needs editing first, and what should be left out entirely.
- Paste as-is: The information is already public or poses little risk if someone else sees it. For example, uploading a PDF report for summarization.
- Edit before you paste: This is information that may be useful to an AI tool but could contain details it doesn’t need. Work documents, screenshots, source code, contracts, research, and customer-related information may fall under this category. Redact sensitive details before submitting.
- Never paste it: This is for information that could cause serious harm if exposed or misused. If the information contained there is often sought for malicious intent, that is a good sign not to input it into an AI tool.
If you are still unsure whether to upload or redact, it is better not to upload at all.
What you shouldn’t upload to an AI
Passwords and login credentials
Never paste any credentials or one-time codes into a general-purpose AI chatbot. These secrets can provide direct access to accounts, applications, systems, or data.
The same applies to credentials embedded in screenshots or error logs.
Bank and payment information
Keep bank account numbers, credit card details, PINs, tax information, and other financial credentials out of AI conversations. They can identify financial accounts or facilitate fraud if exposed.
Government identification numbers
A chatbot doesn’t need your passport number, driver’s license number, Social Security number, or any other government-issued identifier to answer questions. The same applies to combinations of your date of birth, home address, and phone number.
While individual details may seem harmless, together they can create a useful trail for privacy violations..
Confidential company information
Internal financial results, customer records, product plans, business processes, and unreleased information should not be submitted to unapproved AI services.
The risk is not necessarily that a chatbot will publish the information. It is that sensitive company data may be processed outside the systems and controls your organization has approved.
For work-related information, use only AI tools permitted by your employer and follow company rules on what data can be uploaded.
Private source code and secrets
Developers should be particularly careful with source code submitted to AI tools. Codebases and configuration files can contain API keys, database passwords, authentication tokens, private URLs, customer identifiers, or proprietary algorithms.
A seemingly routine debugging session can therefore expose credentials, infrastructure details, or intellectual property unrelated to the bug itself.
Sensitive medical information
AI can answer general health questions, but users should be careful about giving a general-purpose chatbot highly sensitive medical information. Diagnoses, test results, medication lists, treatment histories, and other health records can reveal deeply personal information.
Personally, I will be more cautious about using AI tools for medical purposes because medical matters can be complicated. Given AI’s tendency to hallucinate, it could provide wrong answers whose applications can be highly consequential.
Confidential legal documents and intellectual property
Contracts, lawsuits, employment agreements, proprietary research, unreleased product designs, inventions, business plans, and unpublished manuscripts can contain information with serious legal, commercial, or competitive value.
Submitting this material to an AI service raises a simple question: who controls the information after it leaves your systems? The answer is unlikely to favor the person behind the upload interface.
Other people’s private information
Having access to someone’s information doesn’t mean you should send it to an AI system.
That matters especially for businesses, where a single document may contain personal information belonging to hundreds or thousands of people.
The point isn’t that every AI conversation is public, or that every provider handles data the same way. Users should remember that a chatbot is a service that processes the information they submit, not a private diary stored entirely on their device.
More must-read AI coverage
- SS&C Intralinks DealCentre AI vs. Datasite: Which platform is built for the future of dealmaking?
- SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
- Why Data, Not Models, Determines AI Success
- The Rise of the AI-Native Factory: How Physical AI Is Transforming Manufacturing
Why you shouldn’t share personal information with an AI chatbot
While there has not been a confirmed case of a major AI platform being breached specifically to steal users’ private chatbot conversations, the possibility remains.
There is also a legal-access issue. AI conversations generally lack confidentiality protections, and government agencies may require providers to disclose user data. OpenAI, for example, says it may disclose personal data to government authorities when legally required.
The safest assumption is not that every AI chatbot is insecure. It is that anything you submit is being processed by a service whose privacy, retention, access, and security rules may differ from your own expectations.
Before pasting sensitive information, ask one question: does the chatbot actually need this detail to help me?
If the answer is no, remove it.
Other news: Vara received European clearance for an autonomous breast-screening system that can report some mammograms as normal without requiring a radiologist to review every case.