Just over one-third (36%) of us had used artificial intelligence (AI) tools, like ChatGPT, Claude, or Gemini, in the workplace at the start of this year.
And while only 21% said the tools actually made them more productive, the trend doesn’t seem to be dying down any time soon.
According to the same survey, 61% of workers want to know how to keep their information “safe and private” when using AI.
But what does that actually look like?
Experts previously told HuffPost the kind of information they recommend keeping off of large language models (LLMs), including sensitive details like your address or phone number.
But what about work information? We asked Tomas Stamulis, the chief security officer at digital privacy company Surfshark, what to avoid uploading.
The work information an expert thinks you should never upload to AI
According to the cybersecurity pro, the problem with uploading sensitive information to AI tools is that it “could be retained or used by the AI provider, depending on its terms and conditions”.
If disclosed, he added, this information might be “damaging” to you or “valuable” to your competitors.
Some information he says to keep away from AI tools are:
1) Entire email chains
In general, Stamulis said, uploading more information than you really need to disclose for the task is “one of the easiest mistakes individuals can make”.
For instance, someone might “paste an entire email chain into ChatGPT to help draft a response”, when they only really wanted a reply to one message.
That might “inadvertently” expose sensitive business strategies or other protected information.
2) Customer spreadsheets
Maybe a worker wants to “analyse trends” across their customer base. But the problem with uploading whole lists like these is similar to the issue with entire email chains: it makes sharing “personal details” all too possible, Stamulis advised.
3) Confidential meeting notes
In your quest for a handy “summary”, the online security expert suggested, you might actually be sharing more information with a third party than you or your company would be happy with.
4) Documents with hidden sensitive information
Just because you can’t clearly see sensitive information on a sheet or table, doesn’t mean it’s not there – or that some AI tools couldn’t access it, Stamulis shared.
“Even if a document seemingly contains no passwords or financial account details, hidden tabs and tracked changes could reveal far more information than anticipated,” he told us.
5) Any business operation information you’d rather keep under wraps
This might include “unpublished business plans, pricing strategies, upcoming product launches and client proposals,” the security officer said.
6) Sensitive information that an AI tool which acts on your behalf can access
OK, this technically isn’t an upload. But, as Stamulis explained, that’s kind of the problem. “AI agents that can perform actions on a user’s behalf introduce further risks,” he commented.
“Depending on the permissions they’re given, an incorrectly configured agent could accidentally delete files or send confidential information to the wrong recipient, potentially disrupting business operations.”
7) Private data AI browser extensions can see
Again, the expert said this shows that “the risks extend beyond what users deliberately upload”.
He claimed: “AI browser extensions may have permission to access browsing history or content displayed on websites.” The advice is to vet them carefully.
How can I lower my odds of uploading the wrong work information to AI?
Start by asking yourself whether you really need to include the amount of information you’re uploading, Stamulis said.
“In many cases, anonymised examples or dummy figures will achieve the same result.”
You should also “check whether [your] employer has approved [your AI tool/s] for handling sensitive information, review its terms to understand how long data is retained and whether it is shared with third parties”.
He stated that data protection arrangements can vary between personal and business accounts, so what applies in one context might be completely different in the other.
What if I’ve already shared sensitive work information with an AI tool?
If this happens, report it to your company’s IT team “promptly rather than assume deleting the conversation resolves the issue,” Stamulis ended.
“If passwords or access credentials were involved, these should be changed or revoked immediately.”



Bengali (Bangladesh) ·
English (United States) ·