LJE ITIT outside the box

Using AI chatbots at work safely

Home › Blog › Using AI chatbots at work safely

AI chatbots like the large language models available to the public are now common in workplaces. A staff member pastes a customer email into a chatbot to draft a reply. Someone uploads a spreadsheet to ask the tool to reorganise it. A manager asks an AI to summarise meeting notes. The temptation is strong because these tools are free, easy, and often surprisingly useful. But small businesses and charities need to understand the data protection and security risks before allowing staff to rely on them.

What data should never go into an AI chatbot

The fundamental rule: never paste personal data, customer information, financial records, or confidential business information into a public AI chatbot.

Personal data – If your message contains someone’s name, email address, telephone number, bank account, or any detail that identifies them, that data enters the AI’s training pipeline. For charities and small businesses working with vulnerable people—children, refugees, clients in crisis—sending personal details to a chatbot violates UK GDPR and your duty of care. Data protection law requires that you control where personal data flows.

Client and customer information – A customer email, an invoice, or details of a transaction should never be pasted into a public AI tool. If you need to draft a response to a customer query, anonymise the message first: remove names, account numbers, and identifying details, then paste the anonymised version. “A customer asking about a refund” is safe; “Jane Smith, order 12345, requesting a refund” is not.

Business confidentiality – Trade secrets, pricing, strategic plans, staff information, or unpublished financial results should stay internal. If a competitor watches your chatbot history (possible if you use a free tier where conversations train the model), your confidential information becomes theirs.

Best practices for AI chatbots in the workplace

Safe use of these tools involves several key measures:

Business tiers offer better data protection. Free versions of public chatbots may use your inputs to train future versions. Business or enterprise subscriptions typically include commitments that conversations won’t train models and data won’t be retained. The cost is modest for small teams—many business tiers cost less than a single standard software subscription.

Anonymisation before sharing. When working with customer or client information, identifying details should be removed first. “A customer asked how to reset their password” is appropriate; “John Doe, email [email protected] , asked how to reset his password” is not. This practice prevents sensitive information from entering training pipelines.

Verification of outputs. AI tools can generate plausible-sounding but false information with confidence. When an AI writes a summary of legal requirements or quotes statistics, independent verification is essential. For any content customers see, fact-checking and editing before publication protects both accuracy and reputation.

Policies and governance. Organisations that use these tools should document acceptable use. Personal data, customer files, and confidential information should not be pasted into public chatbots. Staff training on these restrictions helps prevent accidental data exposure. Where AI-generated outputs are used, review and fact-checking before publication ensures they represent the organisation accurately.

Security risks in AI systems

Beyond data protection, the National Cyber Security Centre (NCSC) highlights security vulnerabilities in AI itself:

Prompt injection – An attacker can craft a message to manipulate the AI into ignoring its safety guidelines or revealing information. If your staff member asks an AI for advice and the AI has been compromised by injected instructions, the response might be misleading or harmful.

Data poisoning – An attacker can corrupt the training data that teaches an AI, causing it to produce biased or incorrect outputs. This is mainly a risk for organisations training their own models, but it illustrates the broader risk that AI systems can be subverted.

Supply chain attacks – If your business relies on an AI tool and that tool’s creator is compromised, malicious code or data exfiltration could affect your organisation.

These risks are less acute for small businesses using public chatbots than for organisations running their own AI systems. But they reinforce the principle: do not treat AI outputs as authoritative without verification.

The balance: adopting AI thoughtfully

AI chatbots are powerful tools. They accelerate brainstorming, streamline routine writing, and help staff work faster. Yet they remain imperfect, untrustworthy for sensitive content, and fundamentally designed to operate outside an organisation’s privacy boundary. Treat them as you would a public search engine or a conversation in a café: useful for general, non-confidential inquiry, but unsuitable for confidential matters.

A small business that bans these tools entirely may lose productivity gains and competitive advantage. Conversely, a business that allows unrestricted use—staff pasting customer data into free chatbots without thought—risks regulatory fines and reputation harm when data breaches occur.

The sustainable path sits between these extremes: a documented policy that defines acceptable use, business-tier subscriptions that include data protection features, regular training that helps staff recognise what should not be shared, and a habit of checking AI outputs for accuracy and bias before they represent the organisation publicly. This approach acknowledges that AI is now part of everyday work, while building guardrails that protect both data and trust.

Key points

  • Never paste personal data, customer information, or confidential business details into public AI chatbots; use anonymised, general versions of your query instead.
  • For business use, invest in a business-tier subscription that includes data protection guarantees and prevents training on your conversations.
  • Always verify AI-generated information independently; AI tools can confidently produce false information.
  • Establish a clear company policy on what AI tools can and cannot be used for; train staff to recognise what should stay internal.
  • Data protection frameworks apply to how organisations handle personal data through AI, whether intentionally or by accident. Know where sensitive information goes.

Related: Guides