Insights · Stay Protected

What not to paste into ChatGPT

Some business data is safe to paste into AI, some needs a check, and some must never go in raw. A plain guide for owners on where to draw the line.

A confidential financial document with a person's name and account number dissolving into pixels as it transfers to a laptop running a secure AI chat, illustrating sensitive data being anonymized before it reaches an AI tool.

Some business information is safe to put into an AI tool, some needs a check first, and some should never go in raw. The difference is not obvious, most owners have never been shown it, and getting it wrong is the fastest way to turn a useful tool into a liability. This guide draws the lines in plain language.

Why this matters now

AI tools are genuinely useful for a small business. They summarize, draft, categorize, and analyze in seconds. So owners paste things in: a customer list to clean up, a bank statement to categorize, a staff schedule to reorganize, a patient inquiry to draft a reply to.

Here is the part that gets missed. When information goes into a public AI tool, it leaves the business. Depending on the tool and its settings, it may be retained, reviewed, or used in ways the owner never intended. For a business that handles other people's information, that is not a technicality. A pharmacy pasting patient details, an accountant pasting client financials, a lawyer pasting case records: each of those can be a privacy breach, and in regulated fields it can carry real consequences under laws like PHIPA and PIPEDA.

The answer is not to avoid AI. The businesses getting value from these tools are not the ones abstaining. They are the ones that know what can go in and what cannot.

The three levels

Kozentis classifies business information into three levels. The classification is simple enough to write on a sticky note, and it covers almost every case.

Level one: information AI can use freely. Anything already public or containing nothing about a real person. Your published prices. Your marketing copy. Your store hours. A blog draft. General questions about how to do something. Paste away.

Level two: information that needs a person to check it first. Internal business information that identifies no customer, patient, or client but that you would not post publicly. Sales totals. Inventory levels. A supplier negotiation. Staff scheduling. The risk here is lower, but it is not zero, and the check is simple: would you be comfortable if this exact text appeared outside the business? If yes with the sensitive parts removed, remove them first.

Level three: information that must never go in raw. Anything identifying a real person or their affairs. Customer names attached to purchases. Patient information of any kind. Client financials. Employee records, including resumes with contact details. Account numbers, health card numbers, social insurance numbers. If a document contains these, it does not go into a public AI tool as-is. Full stop.

The mistake almost everyone makes

The common error is not pasting a customer list into a chatbot on purpose. It is pasting a document that contains level-three information without noticing. A bank statement carries counterparty names. An email thread carries the customer's address in the signature. A spreadsheet has a name column the owner forgot was there.

The document is the unit of risk, not the field. Before anything goes in, the question is not whether this document is sensitive but whether anything inside this document identifies a person.

What careful businesses do instead

There is a technique for this, and it is not new: anonymization. Sensitive values are replaced with consistent stand-ins before the document ever reaches an AI tool, so the tool sees the structure and the patterns but never the real names, numbers, or dates that matter. The analysis still works. The trend is still visible. The person is protected.

Done properly, the same person gets the same stand-in every time, so month-over-month analysis holds together. Done improperly, with a find-and-replace or a free browser tool, things get missed, and the misses are exactly the items that mattered.

This is the work Kozentis does for owner operated businesses under Stay Protected: classifying what the business holds, masking what must never leave, and setting up AI the owner can defend using. The first three files are free, which is usually enough for an owner to see what their own documents look like with the sensitive parts handled.

The one-line version

If it identifies a person, it does not go in raw. Everything else, think for one second about whether you would say it outside the business. That single habit prevents most of the trouble.

Kozentis Advisory & Systems is an AI visibility and advisory firm for owner operated businesses in the Greater Toronto Area and across Canada. Try Stay Protected free on three files at kozentis.com/stay-protected.

Back to insights