The First Rule of AI Club
Chatbots are not confidential. When you paste something into a free AI tool, you're sending it to a company's servers - and in many cases, it can be used to train the next model. Assume everything you type is semi-public. That assumption costs nothing and protects you from everything.
The Three Things Never to Paste Into AI
- Passwords, security codes, or account details - no AI tool needs your password. Ever. If a prompt asks for it, you're in a scam.
- Financial identifiers - credit card numbers, bank accounts, tax IDs. There is no legitimate AI task that requires these.
- Sensitive personal data about other people - customer lists, medical records, employee details. Beyond the risk to you, sharing others' data can be a legal problem.
For work tools (Microsoft Copilot, Google Gemini in Workspace, enterprise plans), the rules are usually different - those often have stronger privacy guarantees. Check your employer's policy. For free consumer tools, assume the worst.
How to Use AI Without Leaking Everything
- Anonymise first: change names to "[Client A]", addresses to "[City]", figures to "a number roughly this size"
- Use enterprise versions for real business data when available
- Check the settings: many tools let you turn off training on your data
- Delete conversations you regret, and know that deletion isn't guaranteed everywhere
- When in doubt, don't - if you'd be embarrassed to see it on the front page, it doesn't go in the prompt
The Scam Landscape (It's Getting Weird Out There)
AI makes scams cheaper and more convincing. The classics, now with robot upgrade:
- Deepfake family calls - "Grandma, I'm in trouble, send money" but the voice is a perfect clone. Set a family code word. Seriously.
- AI voice phishing - scammers clone a voice from three seconds of social media audio
- Fake customer service - convincing AI chatbots that are really phishing for credentials
- AI-written spear phishing - emails with perfect grammar targeting you personally
The Family Safety Kit (Do This This Week)
- Pick a secret family word that is never written down anywhere
- Agree: any call asking for money or urgent help gets a callback on the known number
- Teach older relatives: "If it's urgent and asks for money, it's a scam. Hang up and call back."
- Turn on two-factor authentication everywhere that offers it
- For anyone who will listen: videos and voice notes are easy to fake now, so verify before you trust
Try This Today
Find the settings in your main AI tool and look for the data / training toggle. Turn it off if it exists. That's a five-minute win that most people never do.
The One-Line Summary
Treat every prompt as a postcard, keep the family word secret, and verify before you send money.