Your team is almost certainly using AI already. The question is no longer whether to adopt it, but whether sensitive information leaves your control every time someone pastes a client file, internal spreadsheet, or meeting transcript into a chat box.
That risk is not theoretical. Analysis of one million employee prompts and twenty thousand file uploads to generative AI tools found that 22% of uploaded files and 4.37% of prompts contained sensitive data — customer records, employee PII, credentials, and proprietary source code (Harmonic Security, 2025). You do not need to ban AI to protect your business. You need to understand where data goes, what can go wrong, and how to make safe use easier than unsafe use.
Why cloud LLMs are different
When someone uses a cloud large language model, they are not just storing a file. They are transmitting content to an external system that may retain it, log it, and route it through subprocessors in other jurisdictions. Depending on the product tier, that content might also influence future model behaviour.
Three things make this distinct from ordinary cloud risk:
-
The input is the product. LLMs are designed to absorb information and produce useful output. An employee pasting a client contract to "summarise the key terms" can be an unauthorised transfer of confidential information — even when the intent is innocent.
-
Consumer and enterprise tiers are not the same. Business plans from major providers generally do not train on customer data and offer stronger contractual protections (OpenAI business data policies). Consumer accounts — the ones people sign up for with a personal email — typically do not. Yet shadow AI research consistently shows employees using personal accounts for work.
-
You cannot reliably delete a prompt. OpenAI's consumer FAQ has long warned: "We are not able to delete specific prompts from your history. Please don't share any sensitive information in your conversations." That matters when someone realises, too late, that they pasted the wrong paragraph.
This is general guidance, not legal advice. Regulators are clear that existing data protection law applies to generative AI without exemption (ICO, December 2024).
What actually goes wrong
The pattern repeats across industries. A capable tool arrives. Productivity jumps. Sensitive material follows.
Samsung (2023): Within weeks of allowing ChatGPT for work, engineers entered proprietary semiconductor source code, equipment testing data, and a confidential meeting transcript into the consumer chatbot (TechCrunch). Samsung's internal memo captured the problem: once content is entered, it is transmitted to an external server and cannot be retrieved. The company banned external generative AI — then, by 2026, reintroduced enterprise versions behind mandatory security training and access controls.
Amazon: Internal proprietary code reportedly appeared in ChatGPT responses to other users' prompts — code that Amazon employees had previously submitted seeking programming help (Aon analysis).
Law firms: Confidential client information entered into consumer AI tools raises duties of confidentiality and questions about professional privilege (Law.com). UK data breach specialists have warned that firms "over-excited" by AI productivity gains risk inputting sensitive client material without adequate safeguards (Legal Futures).
Platform incidents: In March 2023, a caching bug caused some ChatGPT users to see fragments of other users' conversations and, in rare cases, payment details (OpenAI postmortem). Even careful users depend on vendor security they do not control.
The through-line is consistent: people use AI because it works. The failure mode is not carelessness alone — it is the absence of a safer default.
A practical protection framework
Classify your data. Define what may never go into public or unsanctioned AI (client files, contracts, HR records, financials, credentials, regulated personal data), what may go into approved business tools with care, and what is generally safe. Three zones — green, amber, red — give people a decision they can make in ten seconds. We cover this approach in How to Write an AI Policy Your Team Will Actually Follow.
Match the tool to the data.
- Consumer cloud LLMs: fine for genuinely non-sensitive tasks. A poor default for client-related work.
- Enterprise cloud LLMs: appropriate for many amber workflows when you have reviewed contracts, retention settings, and access controls.
- Private or local AI: the right answer for red data that should not leave your environment. As we outlined in Why Businesses Should Choose Private AI Over Cloud API Services, the question is not whether the model is capable — it is whether the data path is acceptable to your clients and regulators.
Put guardrails in place. Policy alone does not stop a tired employee on a deadline. Pair rules with approved tools on corporate SSO, browser or endpoint controls that warn before sensitive pastes reach external AI services, and audit logging on enterprise accounts.
Do vendor due diligence. Before approving a tool, confirm in writing: is customer content used for training? How long is data retained? Where is it processed? What happens on termination? Then check the settings after procurement — a capable enterprise product with training opt-in enabled by mistake is a common gap.
Plan for mistakes. People will paste the wrong thing. Your response plan should include how to report without blame, when to notify clients, and a review that improves the system rather than just disciplining an individual.
What to do this week
- Ask the team which AI tools they use and what they put into them.
- Define red, amber, and green data with three concrete examples from your business.
- Approve one enterprise or private path for sensitive work.
- Add a one-page "before you paste" checklist to your intranet or team channel.
- Assign an owner for AI tool approvals and policy updates.
Cloud LLMs are genuinely powerful, and enterprise tiers have matured. The danger is treating convenience as a security model — assuming that because a tool is popular, it is automatically appropriate for client files or proprietary know-how. The firms that get this right will use AI more, not less, because their teams will stop hiding the workflows that matter most.