News

How do I stop staff putting sensitive data into AI tools?

Written by Ross Ansell | Jul 29, 2026, 6:00:00 AM

AI tools are quickly becoming part of everyday work. Whether it’s drafting emails, analysing data or creating content, your team is already finding ways to use tools like ChatGPT, Copilot, and others to work faster and smarter.

But alongside that opportunity comes a very real concern: how do you stop people (accidentally or not) putting sensitive business data into AI tools?

The honest answer is this: you can’t solve this problem by simply blocking access. And more importantly, you shouldn’t try to.

The real solution is to guide, protect and enable your team so they can use AI safely and confidently, without putting your (or your customer’s) data at risk.

Why this happens in the first place

Before looking at solutions, it’s important to understand the behaviour.

Your team isn’t trying to put your business at risk. They’re trying to do their jobs better, faster and with less frustration. AI tools offer exactly that, so people naturally start experimenting. Often without formal approval or guidance.

This is where something called “Shadow AI” comes in, where employees use AI tools outside of official company systems or policies.

The risk: what actually counts as “sensitive data”?

One of the biggest challenges is that many employees don’t always recognise what counts as sensitive.

This can include:

  • Customer details and contact information
  • Financial data or pricing structures
  • Internal documents or reports
  • Login credentials or system details
  • Commercially sensitive conversations

The issue isn’t that people don’t care; it’s that the boundaries aren’t always clearly defined. Without guidance, it’s easy for someone to paste information into a public AI tool without realising where that data goes or how it could be used.

If your team can't use AI safely through office channels, they will find their own way to use it.

Why just blocking AI tools doesn’t work

It might feel like the safest option - to restrict access completely, but in reality, this often creates a bigger problem.

When AI tools are blocked:

  • Employees look for workarounds (personal devices, external tools, mobile apps)
  • Visibility is lost, so risk becomes harder to manage
  • Innovation slows down, putting you behind competitors

More importantly, it sends the message that AI is something to avoid, rather than something to use responsibly.

Blocking AI doesn't remove risk, it just pushes it somewhere you can't see or control.

The smarter approach: enable safe AI use

Instead of trying to stop people using AI, the goal should be to help them use it safely and productively.

Here’s how that looks in practice:

1. Give your team an approved, secure AI tool to use

If you want people to stop using unapproved tools, you need to provide a better alternative. That’s where solutions like Microsoft Copilot come in. Unlike public AI platforms, Copilot operates within your existing Microsoft 365 environment, meaning:

  • Your data remains governed by your existing Microsoft 365 security, compliance and access controls
  • Security and permissions are maintained
  • Information isn’t used to train external models

When people have access to a trusted tool, they’re far less likely to turn to unknown or risky alternatives.

2. Set clear, simple guidelines

Policies don’t need to be complicated to be effective. In fact, the simpler they are, the more likely people are to follow them.

Focus on clear principles, such as:

  • What can and cannot be entered into AI tools
  • Which tools are approved for use, with what type of account (e.g. free or premium)
  • When to double-check outputs before using them

3. Train people, don't just warn them

Telling people what not to do is only half the picture. They also need to understand:

  • How AI tools work
  • Where risks come from
  • How to use AI effectively in their role

Training sessions, quick guides and real-life examples are far more effective than blanket restrictions.

When people understand the “why” behind the rules, they make better decisions.

4. Build awareness around data sensitivity

A small shift in thinking can make a big difference.

Encourage your team to ask a simple question before using AI: “Would I be comfortable sharing this externally?”

If the answer is no, it probably shouldn’t be entered into a free or public AI tool. Over time, this builds good habits without slowing people down.

Safe AI isn’t about restricting people – it’s about helping them make better decisions

5. Put the right safeguards in place

Alongside training and tools, there are technical measures that can support usage, such as:

  • Data loss prevention (DLP) policies
  • Access controls and permissions
  • Monitoring and reporting

These work quietly in the background, adding protection without disrupting day-to-day work.

The opportunity: doing AI properly

It’s easy to focus on the risks, but it’s just an important to recognise the opportunity.

When AI is introduced properly, businesses see:

  • Increased productivity across teams
  • Faster decision-making
  • Reduced admin and repetitive tasks
  • More engaged, empowered employees

The difference comes down to how it’s implemented.

If AI is controlled through fear and restriction it creates resistance and workarounds. If it’s introduced with clear approved tools (with the right security), clear guidance, the right tools, and a supportive approach, it becomes a powerful advantage.

A final thought…

You don’t stop staff putting sensitive data into AI tools by saying “no”. You stop it by giving them a better, safer way to say “yes”. That means providing secure tools like Copilot or premium ChatGPT licenses, setting clear expectations, and helping your team understand how to use AI responsibly. When you get that balance right, you don’t just reduce risk – you unlock the full potential of AI across your business.