What counts as confidential material?
"Confidential" is too broad a word to act on. I sort what an executive handles into four classes, because each class gets a different rule.
| Class | Examples | Where it can go | Default rule |
|---|---|---|---|
| Open | Published articles, public filings, drafts of your own marketing | Any AI account | Paste freely |
| Internal | Meeting notes, internal plans, routine email | A business or enterprise account your organization controls | Paste, with names reduced to roles |
| Sensitive | Board papers, financial models, deal terms, customer lists, HR matters | A business account, with approval from whoever owns the risk | Redacted excerpts only |
| Restricted | Credentials, privileged legal advice, regulated health or financial records, NDA material that bars third parties, material nonpublic information about public companies | Not in a chat tool unless counsel or compliance has approved that tool and that use | Stays out by default |
If your organization already has a data classification policy, use its words and treat the table as a starting point.
Does a business account change what happens to my data?
Often yes, and the vendors say so in writing. The table below summarizes what each vendor's own published page said when I checked on October 1, 2026. These terms change often, so check the current page before you rely on any row.
| Vendor | Business or enterprise plans | Personal plans |
|---|---|---|
| OpenAI | By default, content from ChatGPT Enterprise and ChatGPT Business is not used to train its models. Enterprise owners can set a workspace retention policy, with a minimum of 90 days (OpenAI Academy). | On a personal workspace (Free, Plus, Pro), sharing content to improve models is on by default and can be switched off in Data controls (OpenAI Help). |
| Anthropic | Commercial products such as Claude for Work and the API are not used for training by default, unless you submit feedback or choose to share. Deleted conversations leave back-end storage within 30 days (privacy center, retention). | For Free, Pro and Max, new models are trained on your data when the setting is on, and retention can extend to five years for people who allow it (Anthropic, August 28, 2025). |
| Workspace with Gemini: content is not human reviewed or used for generative AI model training outside your domain without permission (Workspace privacy hub). | Consumer Gemini Apps: a subset of chats is reviewed by human reviewers, reviewed chats can be kept for up to three years, and Google asks you not to enter confidential information (Gemini Apps privacy hub). | |
| Microsoft | Work accounts: prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. Interactions are stored, and administrators can set retention in Purview (Microsoft Learn). | The Microsoft page covers work accounts only. Check the consumer Copilot terms separately. |
Two reading rules. First, "not used for training" is a narrower promise than "not stored, logged or visible to administrators." Microsoft's page says interactions are stored and administrators can search and retain them. Second, a paid personal plan is still a personal plan. In the OpenAI and Anthropic pages above, Plus, Pro and Max sit on the personal side.
What does a business plan still not protect?
- Storage and access. Your content sits with the vendor, and your administrators can usually see, export and delete it.
- Feedback buttons. Anthropic's page says that explicit feedback, such as a thumbs up or down, can let it use that chat for training, even on commercial products (privacy center).
- Connected apps and agents. Each carries its own terms. Microsoft tells administrators to check an agent's privacy statement before enabling it.
- Privilege. In United States v. Heppner (S.D.N.Y., February 17, 2026), a federal judge held that a defendant's conversations with a public AI platform were not protected by attorney-client privilege or work product, partly because the platform's privacy policy allowed data collection and disclosure to third parties (Harvard Law Review). It is one trial-court ruling, and the commentary calls it too categorical. I am not a lawyer. If privilege matters to you, ask counsel before legal material goes near an AI tool.
What should I never paste into an AI tool?
- Passwords, API keys, recovery codes and anything else that works as a credential.
- Full personal records of customers or employees, such as government ID numbers, health information or account numbers.
- Privileged communications with your lawyer, unless counsel has approved the tool.
- Material under an NDA that bars sharing with third-party processors.
- Material nonpublic information about a public company, and anything a regulator requires you to handle in a set way.
If you are unsure, the answer is no until the person who owns that risk says yes.
How do I redact before I paste?
- Paste the passage you need, not the whole file.
- Replace names with roles: "Counterparty A," "the CFO," "our lender."
- Replace exact figures with ranges or placeholders when the numbers are not what you are asking about.
- Strip metadata, comments and tracked changes. Hidden text lives there.
- Read the final prompt once. If you would not email it to an outside adviser, do not paste it.
- Keep the key (who "Counterparty A" is) in a local note and put the facts back yourself in the output.
Redaction is imperfect. Context can still identify a deal or a person, so it reduces risk and does not remove it.
What goes in a one-page personal AI policy?
Write it once, date it and put your name on it. This is a template to adapt. It is not legal advice, and your organization's own policy outranks it.
My AI use policy ([name], [date])
- Purpose. I use AI to speed up drafting, summarizing and preparation. I stay responsible for every output I use.
- Approved tools. Only [tool, plan and account] that I or my organization controls. No personal accounts for work material.
- Classes. Open and internal material may be used. Sensitive material only after redaction and only in [approved tool]. Restricted material never, unless [counsel or compliance] approves in writing.
- Never paste. Credentials, personal records, privileged material, NDA material and material nonpublic information.
- Redaction. Roles for names, ranges for figures, excerpts instead of files, metadata stripped.
- Settings. Training and history settings checked on [date]. Feedback buttons not used on sensitive chats.
- Connections. No connection gets permission to send, delete or share. I review every draft before anything leaves.
- Review. I recheck vendor terms and this policy every quarter. Exceptions are written down with the name of whoever approved them.
What stays risky even with good habits?
- Terms move. Anthropic's 2025 consumer update is an example of a vendor changing training and retention for personal plans. Recheck on a schedule.
- People. Staff using personal accounts for work is the most common gap, and no vendor setting closes it. A short policy and a sanctioned tool do.
- Documents can carry instructions. A file or email you ask an assistant to read can contain text aimed at the assistant. See the approval gate guide.
- Copies. Chat history, exports and screenshots are copies of your material. Treat them with the same class as the original.
For regulated material, such as health, financial, legal or government data, I am not the right person to ask. Bring your counsel or compliance officer the vendor's current terms and the specific use. In coaching I help executives set up the tools and the habits for their own work, which is policy design and tool setup, not legal advice. You can read how that works on the executive AI coaching page, and the wider governance picture in AI governance for non-technical CEOs. A company-wide version of this policy is governance work of the kind described on the fractional CAIO page.
Sources
- OpenAI Academy, Data governance and compliance (checked October 1, 2026). By default OpenAI does not use business customer content from ChatGPT Enterprise and ChatGPT Business to train its models; Enterprise owners can set workspace retention with a minimum of 90 days.
- OpenAI Help, Data controls in ChatGPT (checked October 1, 2026). Sharing content to improve models is on by default for Free, Plus and Pro personal workspaces and can be turned off; OpenAI does not train on Team, Enterprise or Edu content by default.
- Anthropic Privacy Center, Is my data used for model training? (page dated August 18, 2026). Commercial products are not used for training by default; explicit feedback or choosing to share can change that.
- Anthropic Privacy Center, How long do you store my organization's data? (page dated July 1, 2026). Deleted conversations are removed from back-end storage within 30 days; usage policy violations can be retained for up to two years.
- Anthropic, Updates to Consumer Terms and Privacy Policy (August 28, 2025). Free, Pro and Max data can be used for training when the setting is on, with retention extended to five years for those who allow it; Team, Enterprise and API are exempt.
- Google, Generative AI in Google Workspace Privacy Hub (last updated August 14, 2026). Content is not human reviewed or used for generative AI model training outside your domain without permission.
- Google, Gemini Apps Privacy Hub (last updated June 29, 2026). A subset of chats is reviewed by humans and retained for up to three years; users are asked not to enter confidential information.
- Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot (page dated July 9, 2026). Prompts, responses and Microsoft Graph data are not used to train foundation models; interactions are stored and administrators can set retention.
- Harvard Law Review blog, United States v. Heppner (March 2026). Summarizes the February 17, 2026 S.D.N.Y. ruling that a defendant's AI chats were not privileged, and critiques it as too categorical.