Before You Paste — What Shouldn’t Go Into the Chat
Removing people’s names is not the same as making information safe to share. Match the tool tier to what you’re allowed to paste — ZDR doesn’t skip judgment.
Task: Prepare a safer practice version of a work document or decide what to paste into which tool.
You’re mid-task: the doc is open, your AI chat tool is open in another tab, and pasting the whole thing would be faster than explaining the context. Pause. Convenience is not the same as permission.
A common false comfort: “I’ll just delete the surnames.” Names alone were never the only sensitive part. Filenames, client codes, pricing, headcount, internal URLs, ticket IDs, unpublished roadmaps, and margin comments still travel with the paste. If you’d regret seeing it forwarded — or in a system you don’t control — it may not belong there.
At work, the question isn’t only “Is AI allowed?” It’s which tool, for which data, under which policy. Some companies now offer enterprise AI with contractual protections and modes such as zero data retention (ZDR), where the provider doesn’t keep prompts for training or long-term storage. That reduces some retention and training risk. It does not erase policy, need-to-know, redaction judgment, or “would I regret this forwarded?”
Practice on synthetic or authorised material. This article is not legal advice. It is a practical habit so your first useful AI workflows don’t start with a data spill.
Try it safely — fictional work snippet
Imagine someone is about to paste this into a public AI chat:
Filename:
Acme_Renewal_Pricing_Mar2026_CONFIDENTIAL.xlsxnotes
“Maya Chen (Acme) unhappy with 12% uplift. Our margin on Plan Enterprise is 34%. Offer 8% if they sign by 28 Mar. Internal URL: https://intranet.example/deals/acme-88421. Ticket INC-99201. Headcount on support pod: 6 → maybe cut to 4 after renewal. Unpublished: sunsetting Product X in Q3 — don’t tell customer yet.”
Even with “Maya Chen” changed to “Person A,” you might still leak the customer, margin, deadline strategy, ticket ID pattern, headcount plan, and a stealth sunset. That’s why “remove names” fails as a safety strategy.
Tool tiers at work (pick the right lane)
Three rough lanes — labels vary; match these to your policy:
-
Consumer / unapproved chat — personal accounts, free web chat, anything IT hasn’t cleared. Synthetic or clearly non-sensitive practice only. Don’t paste live work data “just to try a prompt.”
-
Lighter workplace assistants — e.g. Copilot-class tools in email or docs. They feel “work-approved,” but policy may still restrict client data, HR notes, pricing, or regulated content. When in doubt, redact or ask.
-
Company-approved enterprise AI — contracted tools with higher confidentiality modes, data-processing terms, and sometimes ZDR or similar. You may paste more of a real artifact if policy allows — but still only what the task needs.
ZDR and similar protections help with retention and training concerns. They do not mean every paste is fine — chats can still be forwarded or mis-scoped. The checklist stays useful on every tier.
The method — 2-minute safer-practice checklist
- Name your tool tier (consumer, lighter workplace assistant, or approved enterprise). If unsure, treat it as tier 1 until you check.
- Copy into a throwaway draft (not the original file).
- Replace organisations, people, products, and places with placeholders when the tier doesn’t allow the real ones: Acme → Client A; Maya Chen → Person A; Product X → Product Blue.
- Strip attachments, screenshots, and tables you don’t need for this task — even on an approved enterprise tool.
- Scrub leftovers: filenames, signatures, intranet links, ticket IDs, invoice numbers, exact margins, personal data — unless policy clearly allows them there.
- Ask the regret test: “Would I regret this if it were forwarded tomorrow?” If yes — stop, redact further, or switch tiers.
Copy-paste helper prompt (especially useful when practising, or on a weaker / less-approved tool):
Help me prepare a safer practice version of the text below for an AI writing exercise.
Replace real-looking names, organisations, products, URLs, IDs, money figures, and headcount with obvious placeholders.
List everything you replaced in a short table (original pattern → placeholder).
Do not invent extra confidential detail.
Then give me the redacted text only.
Text:
[paste]You still review the redaction. Models miss things. On a fully approved high-confidentiality system, you may paste more of the real artifact if policy allows — the helper is optional then; the checklist still catches oversharing beyond the task.
What often still leaks
Filenames and headers; pricing, margins, salaries, headcount; internal URLs, ticket/deal IDs, unpublished plans; HR or health notes about real people; anything you’d regret in a provider’s logs or a Slack forward — even with ZDR.
Convenient paste ≠ careful paste. Approved lane ≠ unlimited paste.
Check before you paste
- You know which tool tier you’re in, and policy allows this content there
- This is synthetic, authorised, or going into an approved work tool for this data class
- Placeholders replaced more than surnames (when redaction is required)
- Only what’s needed for the task remains (no spare attachments/tables)
- Regret-if-forwarded test passed
- If unsure → don’t paste to “just try the prompt”; clarify first
Essential check: Approved tool ≠ “I deleted the surnames.” ZDR ≠ “I can skip judgment.” Removing names alone does not prove information is safe to share.
Make it yours / when to stop
Adapt: Build a personal “never paste / which tier” list for your role. Keep synthetic samples for practice. Use the redaction helper on weaker tools or when practising; on a fully approved system, still ask whether the whole artifact is needed.
Stop and escalate when: You need regulated or confidential data and lack an approved channel; someone asks you to paste credentials, private keys, or full ID documents; or redaction would gut the task — then use a human with proper access, not a cleverer prompt.
Your challenge
Take one fictional paragraph (or a real doc you’re allowed to use) and run the 2-minute checklist — including naming the tool tier. Note the category of what you removed or kept — not the confidential detail itself.
Did this produce something you could use, and what did you have to correct?
Save the checklist. Next: Brief AI like a colleague (5-line template). New here? /start-here · /brief
After you try it
Did this produce something you could use, and what did you have to correct?
Email a reply, or keep a note for yourself. The useful part is the correction — that is the skill, not the first draft.
Email hello@ainewbie.org