Artificial intelligence (AI) tools can be extremely useful at work.
But before you paste information into one, it’s worth asking a simple question:
Would I be comfortable giving this information to an external service before I understood how it would be stored, used and protected?
If the answer is no, stop and check.
If you're unsure whether information is safe to use with an AI system, our data protection and commercial solicitors can help you understand the legal and contractual risks before sensitive information leaves your control.
Contents:
AI tools aren't all the same
The term ‘AI tool’ covers a very wide range of products.
Some organisations have approved enterprise AI environments with contractual, technical and organisational safeguards around the way information is stored and processed.
At the other end of the spectrum are consumer tools where your business may have little control over what happens to information after it has been entered.
Free and paid tools can both create risks depending on their terms, settings and technical architecture. On 17 August 2026, the Solicitors Regulation Authority (SRA) warned the solicitors and law firms it regulates that confidential information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place.
So, ‘I pay for it’ should not be treated as the same thing as ‘my business has approved it for confidential information’.
Be particularly careful with legal advice and privileged material
Take particular care before putting previous legal advice, correspondence with your solicitor or documents connected with obtaining legal advice into an AI tool.
Some communications and documents may be protected by legal professional privilege. Not everything involving a lawyer is automatically privileged, and deciding whether privilege applies can be technical.
Sharing privileged material with an external AI service can create a risk that privilege is waived or lost, depending on the circumstances and the safeguards around the system.
Unless the particular system has been approved for that material and the implications have been considered, the safer approach is to keep previous legal advice and potentially privileged documents out of the AI workflow and share them directly with your lawyer instead.
Be careful with personal information about other people
The information does not have to belong to your business to create a problem.
Employee records, customer details, candidate information and correspondence involving identifiable individuals all need careful handling. Some information needs particular care: health information, for example, is special category personal data and is subject to additional protections.
Removing a name doesn't necessarily make information anonymous. If someone can still be identified from the remaining information, either on its own or together with other information that is reasonably available, you may still be dealing with personal data.
Using AI doesn't remove your existing data protection obligations. Think about whether you need to use the personal data at all, and if you do, limit it to what is necessary for the task.
Commercially sensitive information deserves the same care
You may also have information that is not personal data or legally privileged but would still cause a problem if it were disclosed.
That could include pricing models, acquisition plans, product roadmaps, source code, unpublished financial information, investor discussions or the detail of a confidential negotiation.
You may also owe contractual or other confidentiality obligations to somebody else, so the fact that information belongs to your business doesn't necessarily mean you are free to put it into a third-party system.
Before uploading it, understand what protections actually apply.
What if I have already shared something?
Act promptly if information has already been shared.
You will need to work out exactly what was entered, which system was used, when it happened and which account or settings applied. Check what options exist to delete the material or limit further use, but don't assume that pressing ‘delete’ necessarily answers every question about retention or previous processing. The provider's terms and technical arrangements matter.
Depending on the material involved, speak to the appropriate people within your business, which may include your legal, IT, security or data protection teams.
If personal data was disclosed, your organisation should also consider whether the incident amounts to a personal data breach. Not every breach has to be reported to the Information Commissioner's Office (ICO), but you should assess the risk and keep an appropriate record. Where a breach is likely to result in a risk to people's rights and freedoms, the ICO generally needs to be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.
If previous legal advice or material relating to an ongoing legal matter has been uploaded, tell your lawyer promptly. They can help assess any confidentiality or privilege implications rather than assuming privilege has automatically been lost.
How to use AI without sharing sensitive information?
The answer isn't to avoid AI. It's to know which tools your business has approved, what information each tool is suitable for and when you need a more secure route.
AI is very good at working with structure. In many cases, you can get much of the benefit by using high-level information, placeholders or genuinely anonymised information, then adding sensitive detail yourself afterwards or sharing it directly with your lawyer through your usual secure channels.
That allows you to make use of AI without giving it more information than it actually needs.