Keeping company data out of AI training sets
The question is not whether your team can use AI safely. They already are, or they will be soon. The real question is whether they have a safe default, or whether everyone is making up their own rules in personal accounts.
Most data problems do not start with someone trying to be careless. They start with normal work. A customer sends an email that is too long to summarize by hand. A vendor quote needs to be compared against last year's price list. A spreadsheet has a weird row and someone wants help writing the formula.
So the employee opens the easiest AI tool they know, pastes the thing in, and asks for help. From their side, that feels practical. From the owner side, it feels like a data leak waiting to happen.
The fix is not a 30-page policy nobody reads. It is a safe default that is easier to use than the risky workaround.
Start with the account, not the policy
The first move is boring and important: pick one sanctioned AI tool for work. Not five. One. Give people a place to go that the business actually controls.
That matters because consumer accounts and business accounts can have different data controls, retention settings, admin visibility, and training defaults. The exact settings vary by vendor and plan, so the rule is simple: before employees use it for work, someone should read the admin/data settings and decide what is allowed.
If that sounds obvious, good. A lot of small businesses skip it. They talk about "AI policy" in the abstract while half the team is already using personal accounts because nobody gave them anything better.
The three buckets
I like a three-bucket rule because people can remember it while they are working.
- Public or already-shareable material. Website copy, public product descriptions, generic job descriptions, draft social posts. Usually fine.
- Internal working material. Process notes, anonymized examples, internal templates, non-sensitive spreadsheets. Often fine in the sanctioned tool, but not automatically fine everywhere.
- Restricted material. Customer-identifying data, private employee information, credentials, contract-controlled data, regulated data, and anything you would not email to an outside consultant without thinking hard first.
The middle bucket is where most teams get stuck. If the policy only says "do not paste sensitive data," every person has to decide what sensitive means under pressure. That is how you end up with twenty different policies in one company.
Give examples, not just prohibitions
A useful policy has examples in both directions.
Bad: "Do not paste customer data into AI."
Better: "Do not paste a customer name, address, email, account number, order history, or support thread into AI unless the tool has been approved for that category. You may paste a rewritten version that removes identifying details."
That last sentence matters. If you only say no, people will either stop using the tool or work around you. If you show them how to transform the material into something safe, you keep the productivity without making the data problem worse.
What safe use looks like in practice
Say an employee has a customer complaint and wants help drafting a reply. The risky version is pasting the whole email thread, including the customer's name, address, order number, and private details.
The safer version looks like this:
A customer ordered the wrong part because our website compatibility note was unclear. They are frustrated but polite. Draft a reply that apologizes, explains that we will update the listing, and offers either a return label or a replacement. Do not invent policy details.
No identifying data. Same business value. Better prompt, too.
Owner checklist
If you run a small business, I would start here:
- Pick one sanctioned AI tool for work.
- Review the plan's data handling and training settings.
- Turn off training on company data where the plan allows it.
- Write a one-page acceptable-use policy with examples.
- Teach people how to anonymize a prompt instead of just telling them no.
- Decide who employees ask when they are not sure.
That is enough for most small teams to move from improvising to operating with some discipline.
The takeaway
The safest practical AI policy is not "never use it." It is one sanctioned tool, clear data settings, and a short list of what never gets pasted. People need a safe default they can actually follow.
Need the one-page version for your team?
I help small businesses set practical AI rules people can actually use while they work.