What to Do If an Employee Pastes Confidential Data Into AI

A minute-by-minute runbook for the hour after you learn an employee pasted sensitive data into ChatGPT, Claude, or another AI tool, from containment to the fix that stops it happening again.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
15 August 20261 min read

An employee just told you, or you found out on your own, that they pasted a customer list, a contract, or a set of financial figures into ChatGPT, Claude, or another AI chat tool. The question that matters right now is not whose fault this is. It is what to do in the next hour, the rest of today, and the following week to limit the exposure and stop it happening again. That is what this runbook covers, in order.

This is a minute-by-minute incident response for that one moment, not another policy explainer. Posts elsewhere on this blog cover how to prevent this before it happens, including a short written AI usage policy and the wider problem of unmanaged AI tool use running through a business. This one assumes the mistake already happened and walks through the response, not the prevention.

The first ten minutes: get the facts, not the blame

Before doing anything else, get three facts from the employee, calmly and without accusation. A defensive employee gives you less accurate information at the exact moment you need more of it.

  • Which tool. Consumer ChatGPT, Claude.ai, Gemini, a browser extension, or an AI feature built into another product. The tool determines which levers are available to you next.

  • Which account tier. Free and Plus-style consumer tiers commonly default to using conversations for model training unless someone opts out, with retention windows that can run long on that default. Paid business tiers, such as Team, Enterprise, or Claude for Work, typically exclude conversations from training by default and carry shorter, contractually defined retention. The tier tells you whether you are dealing with a contained business account or open consumer terms.

  • What was actually typed in. Ask for the exact text or a close paraphrase, not a category. "Some customer info" and "the accounts payable file with forty client bank details" call for very different responses.

Write the three answers down with a timestamp. You will need them for every step below, and a decision made from memory an hour later will be wrong in some detail that turns out to matter.

Contain what you can, right away

  • Have the employee stop the conversation and delete that specific chat if the interface allows it. Deletion removes it from visible history. It does not by itself guarantee removal from a vendor's backend systems within a training or debugging retention window, so do not treat a deleted chat as a closed case.

  • If the account is personal, on a personal device, there is no admin console to reach into. The response is limited to what the account exposes: deleting the conversation, checking data controls for a training opt-out, and using the vendor's support channel to request deletion for anything sensitive.

  • If the account is company-managed, check whether your plan gives an administrator visibility into conversation logs or a way to purge a specific item. Many business tiers do, which is one practical reason those tiers exist over consumer accounts.

  • Rotate anything that can be rotated. If the pasted content included a password, API key, or access token, that credential is compromised the moment it left the building regardless of what the AI vendor does with the chat. Rotate it before anything else on this list.

Who needs to know, and when

Whether you have a formal notification duty depends on what kind of data left and which jurisdiction your customers or employees are in. That determination belongs with whoever handles your legal or compliance obligations, not a general rule of thumb. A few things hold true across most situations.

  • Tell your own leadership immediately. An incident someone mentions a day later, once they have decided it is worth bringing up, is far harder to contain than one flagged in the first hour.

  • If the data belongs to a customer, contract terms, NDA language, and breach notification law, GDPR-style rules in the EU and UK, state-level laws in the US, may create a formal duty with a deadline attached, often measured in days. Loop in legal or compliance before that clock becomes the story.

  • If the data includes employee personal information, the same logic applies through employment and data protection law rather than a customer contract.

  • If nothing sensitive actually left, say so and close the loop. Not every AI paste is an incident, and treating a harmless one as a crisis teaches people to under-report the next real one.

Reduce the exposure over the following days

  • Use the vendor's formal deletion or privacy request channel, separate from the in-chat delete button, for anything genuinely sensitive, and follow their published retention policy rather than assuming a specific mechanic. Deletion rules vary by vendor and by tier and change over time, so check current documentation rather than what you recall from a previous incident.

  • If the pasted content included customer data and your contract or applicable law requires notifying those customers, prepare that communication factually: what happened, what was involved, what you have done, what they should watch for. A plain account reads better than vague reassurance.

  • Check whether this employee, or others, have been doing this routinely rather than once. One paste is an incident. A pattern is a sign of shadow AI, tools nobody approved being used because the approved option was slower or did not exist, and that calls for a structural fix rather than one conversation.

The fix that stops the next one

Everything above is triage. It addresses this specific incident. It does not stop the next employee from doing the same thing next month, because the usual cause is not carelessness, it is the absence of a fast, obvious, approved way to get AI help without making a judgment call under deadline pressure. This scenario sits inside the wider set of AI risks facing small businesses, and three things are worth putting in place this week rather than repeated here in full.

  • A short written AI usage policy that names approved tools and states plainly what never goes into a prompt.

  • A habit of keeping an audit trail of AI use so you know which tools people actually touch, rather than guessing after an incident forces the question.

  • An honest check on whether unmanaged tool use is already common in the business. The account-tier question from the first ten minutes usually answers that too, a personal free-tier account on a work laptop is a symptom, not a one-off.

This incident is about an employee's input, what they typed in. A related but different problem is what to do if an AI tool leaks your data through its own vulnerability or misconfiguration rather than through what someone pasted, and that scenario calls for a different first set of steps.

The reason bans keep failing is the same reason this incident happened in the first place: staff will find a way to get AI help regardless of the rulebook. Getting your team to actually use approved AI tools well, so the sanctioned option is also the fast one, is part of the fix rather than a separate project.

Questions people ask

Is one instance of an employee pasting data into AI a breach I have to report?

Not automatically. Whether a legal reporting duty exists depends on what data was exposed and which jurisdiction's rules apply, and that determination should come from whoever handles your legal or compliance obligations rather than a general rule of thumb. Treat "was this reportable" as its own question to answer quickly, separate from containing the exposure itself.

Should I discipline the employee?

Usually not for a first instance, and not before asking what made the unapproved route easier than an approved one. If there was no approved tool, no policy, and no training, the gap is organizational. Repeat instances after a policy and a clear conversation exist are a different, ordinary conduct matter.

Does deleting the chat actually remove the data?

Deleting a conversation removes it from the visible interface. It does not on its own guarantee removal from every backend system within a vendor's retention or training window, since that depends on the vendor's specific policy and the account tier. Check the vendor's current published retention terms for the exact product, and use their formal deletion or privacy request channel for anything genuinely sensitive rather than relying on the in-app delete alone.

What is the single fastest thing to do in the first ten minutes?

Get the three facts, which tool, which tier, what exact content, written down with a timestamp, and rotate any credential that was in the pasted text. Everything else depends on those answers, and a credential left unrotated is the one item here with a clock that will not wait for anyone's decision.

How do we stop this from happening again?

Give people a fast, approved way to use AI so the unapproved route stops being the easy one, put the handful of never-paste-this categories in writing, and check periodically what is actually being used instead of assuming the policy is being followed on its own.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.