How to Use AI on Confidential Documents as an Executive

By Avihay Zanetti Published 2026-10-01 Updated 2026-10-01 AI Governance

What counts as confidential material?

"Confidential" is too broad a word to act on. I sort what an executive handles into four classes, because each class gets a different rule.

ClassExamplesWhere it can goDefault rule
OpenPublished articles, public filings, drafts of your own marketingAny AI accountPaste freely
InternalMeeting notes, internal plans, routine emailA business or enterprise account your organization controlsPaste, with names reduced to roles
SensitiveBoard papers, financial models, deal terms, customer lists, HR mattersA business account, with approval from whoever owns the riskRedacted excerpts only
RestrictedCredentials, privileged legal advice, regulated health or financial records, NDA material that bars third parties, material nonpublic information about public companiesNot in a chat tool unless counsel or compliance has approved that tool and that useStays out by default

If your organization already has a data classification policy, use its words and treat the table as a starting point.

Does a business account change what happens to my data?

Often yes, and the vendors say so in writing. The table below summarizes what each vendor's own published page said when I checked on October 1, 2026. These terms change often, so check the current page before you rely on any row.

VendorBusiness or enterprise plansPersonal plans
OpenAIBy default, content from ChatGPT Enterprise and ChatGPT Business is not used to train its models. Enterprise owners can set a workspace retention policy, with a minimum of 90 days (OpenAI Academy).On a personal workspace (Free, Plus, Pro), sharing content to improve models is on by default and can be switched off in Data controls (OpenAI Help).
AnthropicCommercial products such as Claude for Work and the API are not used for training by default, unless you submit feedback or choose to share. Deleted conversations leave back-end storage within 30 days (privacy center, retention).For Free, Pro and Max, new models are trained on your data when the setting is on, and retention can extend to five years for people who allow it (Anthropic, August 28, 2025).
GoogleWorkspace with Gemini: content is not human reviewed or used for generative AI model training outside your domain without permission (Workspace privacy hub).Consumer Gemini Apps: a subset of chats is reviewed by human reviewers, reviewed chats can be kept for up to three years, and Google asks you not to enter confidential information (Gemini Apps privacy hub).
MicrosoftWork accounts: prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. Interactions are stored, and administrators can set retention in Purview (Microsoft Learn).The Microsoft page covers work accounts only. Check the consumer Copilot terms separately.

Two reading rules. First, "not used for training" is a narrower promise than "not stored, logged or visible to administrators." Microsoft's page says interactions are stored and administrators can search and retain them. Second, a paid personal plan is still a personal plan. In the OpenAI and Anthropic pages above, Plus, Pro and Max sit on the personal side.

What does a business plan still not protect?

  • Storage and access. Your content sits with the vendor, and your administrators can usually see, export and delete it.
  • Feedback buttons. Anthropic's page says that explicit feedback, such as a thumbs up or down, can let it use that chat for training, even on commercial products (privacy center).
  • Connected apps and agents. Each carries its own terms. Microsoft tells administrators to check an agent's privacy statement before enabling it.
  • Privilege. In United States v. Heppner (S.D.N.Y., February 17, 2026), a federal judge held that a defendant's conversations with a public AI platform were not protected by attorney-client privilege or work product, partly because the platform's privacy policy allowed data collection and disclosure to third parties (Harvard Law Review). It is one trial-court ruling, and the commentary calls it too categorical. I am not a lawyer. If privilege matters to you, ask counsel before legal material goes near an AI tool.

What should I never paste into an AI tool?

  • Passwords, API keys, recovery codes and anything else that works as a credential.
  • Full personal records of customers or employees, such as government ID numbers, health information or account numbers.
  • Privileged communications with your lawyer, unless counsel has approved the tool.
  • Material under an NDA that bars sharing with third-party processors.
  • Material nonpublic information about a public company, and anything a regulator requires you to handle in a set way.

If you are unsure, the answer is no until the person who owns that risk says yes.

How do I redact before I paste?

  1. Paste the passage you need, not the whole file.
  2. Replace names with roles: "Counterparty A," "the CFO," "our lender."
  3. Replace exact figures with ranges or placeholders when the numbers are not what you are asking about.
  4. Strip metadata, comments and tracked changes. Hidden text lives there.
  5. Read the final prompt once. If you would not email it to an outside adviser, do not paste it.
  6. Keep the key (who "Counterparty A" is) in a local note and put the facts back yourself in the output.

Redaction is imperfect. Context can still identify a deal or a person, so it reduces risk and does not remove it.

What goes in a one-page personal AI policy?

Write it once, date it and put your name on it. This is a template to adapt. It is not legal advice, and your organization's own policy outranks it.

My AI use policy ([name], [date])

  1. Purpose. I use AI to speed up drafting, summarizing and preparation. I stay responsible for every output I use.
  2. Approved tools. Only [tool, plan and account] that I or my organization controls. No personal accounts for work material.
  3. Classes. Open and internal material may be used. Sensitive material only after redaction and only in [approved tool]. Restricted material never, unless [counsel or compliance] approves in writing.
  4. Never paste. Credentials, personal records, privileged material, NDA material and material nonpublic information.
  5. Redaction. Roles for names, ranges for figures, excerpts instead of files, metadata stripped.
  6. Settings. Training and history settings checked on [date]. Feedback buttons not used on sensitive chats.
  7. Connections. No connection gets permission to send, delete or share. I review every draft before anything leaves.
  8. Review. I recheck vendor terms and this policy every quarter. Exceptions are written down with the name of whoever approved them.

What stays risky even with good habits?

  • Terms move. Anthropic's 2025 consumer update is an example of a vendor changing training and retention for personal plans. Recheck on a schedule.
  • People. Staff using personal accounts for work is the most common gap, and no vendor setting closes it. A short policy and a sanctioned tool do.
  • Documents can carry instructions. A file or email you ask an assistant to read can contain text aimed at the assistant. See the approval gate guide.
  • Copies. Chat history, exports and screenshots are copies of your material. Treat them with the same class as the original.

For regulated material, such as health, financial, legal or government data, I am not the right person to ask. Bring your counsel or compliance officer the vendor's current terms and the specific use. In coaching I help executives set up the tools and the habits for their own work, which is policy design and tool setup, not legal advice. You can read how that works on the executive AI coaching page, and the wider governance picture in AI governance for non-technical CEOs. A company-wide version of this policy is governance work of the kind described on the fractional CAIO page.

Sources

Frequently Asked Questions

Is it safe to put confidential documents into ChatGPT?

It depends on the account and the document. A business plan with training off by default and administrator controls is a different thing from a personal account with sharing on. Even then, use document classes and keep restricted material out unless counsel or compliance has approved the tool.

Does turning off training make a personal account safe for confidential work?

It changes one thing: whether your content may be used to train models. Your content is still stored for a period, and the vendor's other terms still apply. For sensitive or restricted material I would still use an approved business account.

Can I use AI on board materials?

Board materials are at least sensitive. Use an approved business account, redact names and figures you do not need, and ask your general counsel or corporate secretary whether your governance policy allows it.

Who should I ask about regulated data?

Your counsel or compliance officer. Bring the vendor's current terms and a description of the use. This guide is not legal or compliance advice.

Private executive AI coaching

If this is on your desk, a 30 minute conversation is the easy next step. Executive AI coaching is private and one to one, on video, built around your own work, with real tools built in the sessions.

Prefer to write first? Send a note.

Not ready for a call? Take the 8 question AI leadership snapshot. No email needed.