Keywordswhat not to paste into chatgptBlogai for workai at workworkplace aiai for professionalshow to use ai at workai productivity
Related searcheswhat not to paste into chatgptis chatgpt safe for workconfidential data chatgptchatgpt data classificationsecrets in chatgpthow to use what not to paste into chatgpt
Classification comes before the paste, every time
The fastest way to get ChatGPT wrong at work is not a bad prompt. It is a paste. People drop a customer thread, a salary table, an unpublished forecast, or a counsel email into a box that feels private because it is a conversation. It is not a filing cabinet. Do not paste secrets, customer data, unpublished numbers, or legal advice into ChatGPT unless your organisation has approved that workspace and that data class. The model will still be helpful. Helpful is irrelevant if you have moved a restricted file into a tool that is not allowed to hold it. A named person still owns the classification. The chat does not.
If you cannot name the data class, the approved tool, and the person who owns the file, do not paste. You are still hoping the box is private.
Four classes that stay out of the box until someone says otherwise
Secrets: passwords, keys, tokens, and anything that grants access. Customer and staff personal data: names with context, contact details, IDs, health, and HR case files. Unpublished numbers: forecasts, unreleased results, deal prices, and anything a market or a rival should not see early. Legal and advice: counsel email, draft positions, and anything covered by privilege you do not intend to waive. ChatGPT can still help on public text, on synthetic examples, and on files in a workspace that is contracted and classified for that use. Give it only what the policy allows. If the policy is silent, the answer is no paste, not a clever redact you invented on the train.
| Data class | Example | Default rule |
|---|---|---|
| Secrets | Keys, passwords, tokens | Never paste. Rotate if you did. |
| Personal data | Customer thread, staff file | Approved workspace or do not use AI |
| Unpublished numbers | Forecast, deal, unreleased result | Approved tool and a named owner |
| Legal advice | Counsel email, draft position | Counsel decides, not the chat box |
Classify, redact, or stay in the approved system
Before you open the chat, name the artefact and its class. If it is restricted, use the approved enterprise workspace or do not use a model. If you only need structure, rebuild the example with fake names and rounded figures you have permission to use. If you need a rewrite of a public page, paste the public page. Ask the model to list what it thinks you pasted that might be sensitive, then check that list against what you actually sent. Keep a one-page class list on the team's wall: public, internal, restricted, secret. Onboarding should include it. A prompt library that ignores classification is a leak with good intentions. The method is boring on purpose.
Role: You are helping me classify a paste before I send work to a model.
Task: Say whether this artefact belongs in public chat, an approved workspace, or neither.
Context: I will describe the artefact, the data class I think it is, and the tool I planned to use.
Constraints:
- If classification is unclear, recommend neither and say what a human owner must decide.
- Do not ask me to paste the sensitive content in order to classify it.
- Prefer no paste over a clever redact I have not been trained to do.
Output: Class, allowed tool, and what to strip if anything may go in.
Quality checks: What I might still have leaked if I paste a so-called anonymous version.If the answer is neither, you have already been saved a bad paste. That refusal is the point of the prompt. Save the class list in a shared note so the next person does not invent a redact on the train. Keep the version that survived contact with security, and retire the habit of dropping the thread in because the rewrite would be faster. Five rules the team uses beat a private exception.
The little paste, the screenshot, and the thread you forgot was full
The little paste is the common failure. A single customer surname plus a complaint is still personal data. A single unreleased percentage is still an unpublished number. Screenshots are worse: they look like pictures and they are still the file, often with a sidebar of other people's mail. The third failure is the long thread. You meant to paste the last reply and you took twelve messages of pricing, health, and a lawyer. Fluency in the rewrite does not undo the transfer. If you pasted a secret, rotate it. If you pasted personal data into an unapproved tool, tell the owner your policy names. Hoping nobody will look is not a control.
| Mistake | What it looks like | What to do instead |
|---|---|---|
| Just this once | A little customer thread | Class first, or do not paste |
| Anonymous enough | Fake names, real details | Rebuild, or approved workspace |
| Screenshot habit | A picture of the file | Still the file, still classified |
| Whole thread | Twelve messages of price | One public sentence, or nothing |
A rewrite is not worth a leak. If the class is restricted and the tool is not approved, the professional move is to type it yourself.
Related reading on StudyGrid
Read next: Risk, Security and Governance GDPR and ChatGPT at Work Workplace AI Policy for Small Teams. Those essays sit beside this one. Use them when you need the neighbouring skill, not as a substitute for the check you still have to make.
What to do this week
Take five artefacts you almost pasted this week. Write the class beside each. Move two of them to the approved tool or to no model at all. Share the class list in the same place as onboarding. Keep the habit if nobody needed to report a paste, and ask one colleague to classify a file with you. Drop the just-this-once exception. That is how what not to paste into ChatGPT becomes a rule instead of a scare.