What Information Should Never Be Put Into Public AI Tools?
Generative AI can be extremely useful for drafting, summarising, research and analysis. The risk begins when users treat an AI prompt box like a private workspace without understanding what information is being submitted, how it may be retained, or which contractual protections apply.
For Family Offices, private enterprises and not-for-profit organisations, the safest starting point is simple: do not put sensitive organisational information into an unapproved public AI service.
Key takeaways
- Not all AI subscriptions provide the same privacy, retention or administrative controls.
- Public or personal AI accounts should not be assumed suitable for confidential business information.
- Family Offices should define prohibited information in plain language.
- Approved enterprise AI can reduce risk, but configuration, permissions and use case still matter.
- Third-party gateways, unofficial access services and browser tools can create an additional disclosure path.
The issue is not the brand name
Users often ask whether “ChatGPT”, “Claude” or “Copilot” is safe. That is not quite the right question.
The relevant questions include:
- Which product and subscription tier are being used?
- Is the account personal or organisational?
- What contractual terms apply?
- How are prompts and uploaded files handled?
- Can administrators control users and settings?
- Is organisational data used to improve or train models?
- What retention settings exist?
- Are third-party gateways or integrations involved?
The same provider may offer materially different protections across consumer, business and enterprise services.
Information Family Offices should treat as high risk
Every office should create its own rules, but common categories include:
- Family and principal information: personal correspondence, family relationships, private schedules and sensitive personal matters.
- Financial and investment information: portfolios, transactions, valuations, bank details and investment committee material.
- Trust, entity and tax records: structures, ownership information, tax documents and related advice.
- Legal and privileged material: legal opinions, disputes, contracts and confidential negotiations.
- Board and council papers: minutes, strategy papers, risk reports and governance documents.
- Credentials and security information: passwords, API keys, access tokens, network information and security configurations.
- Health and sensitive personal information: medical, counselling or other deeply personal information.
- Deal information: acquisitions, disposals, negotiations or transactions that are not public.
- Third-party confidential information: information received under NDA, professional duty or contractual confidentiality.
Australian privacy guidance supports a cautious approach
The Office of the Australian Information Commissioner has advised organisations to conduct due diligence before using commercially available AI products and has recommended, as a best-practice position, that personal information — particularly sensitive information — should not be entered into publicly available generative AI tools.
That is a useful baseline even where the information falls outside a specific privacy-law obligation. Family Offices often hold information whose sensitivity is driven as much by discretion and trust as by regulation.
Public AI and enterprise AI are not the same
Moving to an approved enterprise or business AI environment can materially improve governance through features such as:
- organisational account management;
- single sign-on and multi-factor authentication;
- administrator controls;
- enterprise contractual terms;
- stronger data-use commitments;
- retention and deletion controls;
- audit and activity information;
- managed integrations.
But enterprise licensing does not remove the need for governance. A user can still submit information that the organisation does not want processed by AI, and an AI integration can still be granted excessive access.
Beware of unofficial and gray-market access
AI access does not always come directly from the model provider. Third-party gateways may proxy requests to popular models, sometimes offering discounted or unofficial access.
Recent security research has highlighted that such intermediaries may be able to see prompts because requests pass through their infrastructure. This introduces a simple rule: know who is actually receiving your data.
Family Offices should avoid unofficial AI gateways for sensitive work and should assess any intermediary, integration or reseller that sits between the user and the model provider.
Meeting assistants deserve the same scrutiny
AI transcription and meeting-assistant tools can be useful, but they may receive some of the most sensitive information in an organisation: spoken discussion.
Before approving a meeting bot, consider:
- whether participants are informed;
- where recordings and transcripts are stored;
- who can access them;
- whether they are retained indefinitely;
- whether the provider uses content for model improvement;
- whether confidential board or adviser meetings are excluded.
Give users a simple traffic-light model
Policies are more useful when people can apply them quickly. One option is:
- Green: public information or content specifically approved for the selected AI service.
- Amber: internal information that may be used only in approved organisational AI under defined conditions.
- Red: information that must not be entered into AI without explicit approval, such as credentials, legal privilege, highly sensitive personal information or confidential deal data.
The exact categories should reflect the Family Office’s risk appetite.
What if sensitive information has already been entered?
Treat it as a potential information-security incident rather than assuming nothing can be done.
- Record what information was submitted and to which service.
- Identify the account and subscription type.
- Review provider retention and deletion options.
- Change any exposed credentials or secrets immediately.
- Assess legal, contractual and privacy implications.
- Determine whether notification or escalation is required.
- Update policy, training or technical controls to prevent recurrence.
Make safe AI use easier
The most effective control is not simply telling people what not to do. It is giving them an approved way to obtain the benefit they need.
DSC helps organisations assess AI platforms, define sensitive-data rules, implement approved AI environments and address Secure AI Governance and Shadow AI. For Family Offices, these controls sit within the broader technology and privacy environment described in our Family Office technology services.