What staff are really pasting into free AI tools, and the one rule that fixes it
18 July 2026 · 6 min read · Optimum IT Solutions

Nobody in your business is trying to leak anything. They are trying to get a task finished faster, and the quickest route happens to involve pasting something confidential into a website you have never assessed.
Start from the honest position: your staff are already using AI tools. Not in a pilot you approved, and not necessarily on equipment you control. They found something that turns an hour of writing into five minutes, and they used it, the same way people started using cloud file sharing years before anyone wrote a policy about it.
This is not a discipline problem, and treating it as one makes it worse. It is a supply problem. People will always route around a slow process to get their work done, and the answer is to give them a safe route rather than to pretend the demand is not there.
What actually goes in
When we look at what is being pasted, it is rarely exotic. It is the ordinary material of a working day, which is exactly what makes it sensitive.
- Client documents and contracts, dropped in to be summarised or simplified.
- Customer lists and spreadsheets, to be sorted, cleaned or turned into a mail merge.
- Long email threads, pasted so the tool can draft a reply that reflects the history.
- Job applications and staff records, to be summarised or compared.
- Financial figures, quotes and pricing, to be reformatted or checked.
- Photographs and screenshots of invoices, delivery notes and forms, uploaded to have the numbers pulled out.
- Sections of code, configuration and, occasionally and memorably, connection details containing live credentials.
Why it matters, without the drama
The risk is not that a robot reads your contract. It is more mundane and more real than that.
Free and consumer versions of AI tools often reserve the right to use what you type to improve their systems, and the terms differ from the paid business versions of the very same product. Almost nobody reads which one they are on. Content you submit may also be retained in a chat history tied to a personal account, and may be reviewed by people for quality and safety purposes. None of that is sinister, and all of it means the information has left your control.
Then there are the ordinary failures. The personal account with a reused password and no second factor, where months of pasted client material sits waiting. The tool that turns out to be a thin wrapper around something else, run by a company you cannot name. The colleague who leaves and takes their chat history, and its contents, with them.
And there is the obligation you already have. If personal data about customers, patients or staff goes into a service you have not assessed, you have made a decision under UK data protection law without knowing you made it. The uncomfortable part is not usually the breach. It is being asked afterwards who approved it and having no answer.
Why banning it does not work
The instinctive response is to prohibit the tools, and it reliably fails. The work still needs doing and the tool still saves an hour, so usage moves to personal phones and home laptops where you cannot see it, cannot support it and cannot advise on it.
A ban converts a manageable risk into an invisible one, and it costs you the benefit as well. It also puts your most conscientious staff in an awkward position while doing nothing about the ones who were never going to ask permission.
The businesses that handle this well do the opposite. They decide which tools are acceptable, make those easy to reach, and are clear about the line. That way usage comes back into the open, where it can be improved rather than merely worried about.
The one rule
You can write pages of AI policy that nobody reads. Or you can give people one sentence they can hold in their head at the moment of the decision, which is what actually changes behaviour.
Here is the rule: if it names a person or a client, or you would not be comfortable seeing it read aloud outside the business, it does not go into an AI tool we have not approved.
That works because it is checkable in two seconds by the person doing the pasting, and it targets the material that causes almost all of the harm. It also does not stop the useful uses, which is important. Rewriting a sentence, drafting a job advert, explaining a formula, planning an agenda, none of that requires anything confidential, and that is where most of the value is anyway.
The rule only works if you also answer the obvious follow up: so what should I use? Name the approved tool. Make sure it is a business account rather than a personal one, with your data excluded from training, signed in through your normal work login, and covered by the same access controls as everything else. A rule with no sanctioned alternative is just a ban with extra steps.
Making it real in a fortnight
This does not need to be a project. For most small businesses it is a handful of short, concrete steps.
- Find out what is actually being used. Ask the team openly and without consequences, because the fastest route to an accurate answer is making it safe to give one.
- Pick one approved tool and pay for the business version of it. Paying is often what moves you onto terms where your content is not used for training.
- Write the rule on one page, with three examples of fine and three examples of not fine drawn from your own work. Specific beats comprehensive.
- Spend twenty minutes with the team walking through it. Show the approved tool doing a real task from their week, so the safe route is also the convenient one.
- Cover the exits. Make sure AI accounts are part of your leavers process, and that people are not signed in with personal accounts for work.
- Revisit it in six months. This area moves quickly, and a policy written once and never reviewed drifts out of date faster here than anywhere else.
The point of all this
The aim is not to make people nervous about AI. Used sensibly it genuinely saves time, and the businesses that get comfortable with it early tend to be glad they did. The aim is to make sure the time saved is not paid for later with a conversation you would rather not have with a client, a regulator or an insurer.
If you want to know what is really in use across your business before you write any rules, an AI audit will tell you, plainly and without obligation. Sometimes the finding is that everyone is being sensible already, and that is a perfectly good result to have in writing.
Want a straight answer on this?
Tell us the job that is costing you the most time. We will look at it and tell you honestly what, if anything, is worth doing about it. The first conversation is free.
Get a quote
