Staying safe
What happens to text you paste into an AI tool, how to strip out what identifies people first, and what to do if it has already gone.
86% of the 14 organisations surveyed for this project fear sensitive information leaving. It usually leaves by being pasted.
What happens when you paste text in
When you paste something into a hosted AI tool, a website or a phone app or anything that needs an internet connection, that text leaves your device. It goes to a company’s computers, where it is stored at least long enough to produce an answer, and usually longer. While it is there:
- staff at the company may be able to read it, and on free tiers they often deliberately do;
- it may be kept for months, for abuse monitoring or for legal reasons;
- it may be used to train the next version of the model;
- it can be handed over under a legal order in the country where the company operates, which is not the country you are in.
None of this requires anybody to have hacked anything. It is the normal, documented operation of the product.
So “delete” in a chat window removes the conversation from your view, not from the company’s systems. And once a name has been sent, it has been sent.
ChatGPTChatGPTNever for sensitive materialHas a free version: No payment card needed to sign up. Unlimited basic text chats on the free model, but daily limits on file uploads, image generation, voice chat, and access to the more advanced reasoning models.View tool is useful for public material. It is the wrong place for a witness statement. Every tool in the catalogue carries a safety tier and a line saying what to never put into it.
The free tier is the training tier
That is the vendor’s own position, not ours. Google’s published terms for the free tier of the Gemini API, on the Unpaid Services:
Google uses the content you submit to the Services and any generated responses to provide, improve, and develop Google products and services
Human reviewers may read, annotate, and process your API input and output.
Do not submit sensitive, confidential, or personal information to the Unpaid Services.
Source: Gemini API Additional Terms of Service (ai.google.dev/gemini-api/terms). The paid tier of the same product says the opposite: Google states there that it does not use your prompts or the responses to improve its products.
The tier most organisations here can afford is the tier whose terms tell them, in writing, not to submit confidential information. Decide which material never goes into a free tool, and write that decision down before you are in a hurry. If cost is what pushes you onto a free tier, read working with no budget.
Take the identifying details out first
Do this before the text reaches any tool, every time, including tools you trust.
- Names. Victims, witnesses, sources, staff, family members, the accused. Replace each with a role and a letter: “Witness A”, “the lawyer”, “the officer”.
- Exact dates. “14 March 2026” becomes “March 2026” or “the second week of the month”. A precise date plus a place is often enough to identify one person.
- Exact locations. “A village in Nineveh”, not the village name. Never a house, a street, a checkpoint or an office address.
- ID and case numbers. National ID, passport, case file, phone numbers, vehicle plates, bank details, email addresses.
- Distinguishing details. Anything that identifies someone without a name: “the only woman judge in the district”, a rare illness, a specific injury, an unusual job, a distinctive car.
- Small numbers. “3 of the 4 women who reported from that office” identifies people by arithmetic. If a number is small enough to point at individuals, write “a small number” instead.
Keep the key somewhere else. The list that maps “Witness A” back to a real person belongs in a separate document, offline or encrypted, that never goes near an AI tool.
Read the whole thing once more before you paste. Most disclosures are not a decision. They are a paste that carried more than the person meant to send.
If it has already happened
43% of the organisations surveyed have already put sensitive material into an AI tool. You are the ordinary case, not the exception.
- Say it out loud to whoever is responsible, today. Speed matters more than composure, and more than having a full account ready.
- Write down what went in: which text, into which tool, from whose account, and when. You cannot assess a risk you have not described.
- Delete the conversation, and turn off training on your input in the tool’s settings if that switch exists. This undoes nothing, but it can limit what happens next.
- Ask what changed for the people in the text. Is anyone more exposed today than they were yesterday? That question, not the paperwork, decides whether you need to warn someone.
- Fix the process, not the person. 71% of the organisations surveyed have nothing written down, so every person is deciding alone and at speed. One page is enough: write your organisation’s AI rules in one hour.
Nobody should be disciplined for telling you. An organisation that punishes disclosure does not stop having incidents. It stops hearing about them, which is much worse for the people in the files.