AI tools are in nearly every employee's workflow now, whether IT approved them or not. ChatGPT, Gemini, Claude, and Microsoft Copilot can drive real productivity gains for businesses across New York and the broader tri-state area. But they also introduce data risks that most employees are not thinking about.
Nevtec works with businesses throughout the region to build secure, well-managed IT environments. That means helping your team understand not just which tools to use, but how to use them without putting sensitive business data at risk. Here is what every employee needs to know.
What These AI Tools Do With Your Data
Most employees assume that typing something into ChatGPT or Gemini is no different from running a Google search. It is not. When you enter a prompt into an AI tool, that input is often processed by external servers, and depending on the account type and privacy settings, it may be used to train future versions of the model.
The account tier matters more than most people realize:
- ChatGPT Free and Plus accounts default to using conversation data for model training. ChatGPT Team and Enterprise accounts offer stronger data protections and opt-out controls.
- Google Gemini on a personal account is governed by Google's consumer privacy policy. Gemini for Google Workspace is covered by enterprise data processing terms.
- Microsoft Copilot for Microsoft 365 (the enterprise version) applies Microsoft's commercial data protection commitments and does not use customer data to train foundation models. The free Copilot experience does not carry the same protections.
- Claude.ai personal accounts operate under Anthropic's consumer terms. Claude for Work (Teams and API) provides enterprise-grade data handling.
The core principle: anything typed into an AI prompt could leave your organization if the wrong account or tool is being used. This is not hypothetical. It is already happening at businesses that have not established clear AI usage policies.
If Nevtec manages your Microsoft 365 environment, you may already have access to Copilot for Microsoft 365 with enterprise data protections built in. Contact Nevtec to find out what is available in your current environment.
What Employees Should Never Put in an AI Prompt
These categories of information should never be entered into a consumer-tier AI tool. In many cases, entering this data could trigger regulatory obligations or create liability under HIPAA, state data privacy laws, or client contracts:
- Customer personally identifiable information (names, email addresses, Social Security numbers, account numbers)
- Patient health data or anything covered under HIPAA
- Internal financial data, contracts, or pricing information
- Passwords, API keys, or access credentials of any kind
- Proprietary business processes, trade secrets, or unreleased product details
- Confidential employee performance information or HR records
- Legal correspondence or privileged communications
Quick test: Before pasting anything into an AI prompt, ask yourself whether you would be comfortable seeing that input appear in a data breach notification. If the answer is no, do not include it.
Practical Rules for Safe AI Use at Work
These are the baseline practices every employee should follow when using AI tools on work devices or with work accounts:
- Use only employer-approved AI accounts and platforms. Avoid personal Gmail-linked Gemini, personal ChatGPT accounts, or any AI tool that has not been reviewed by IT.
- Never paste full documents into a consumer AI tool for summarization. Even if you remove names, document structure and context can reveal confidential information.
- Paraphrase or anonymize data before using it as AI context. Describe the situation in general terms rather than inputting the actual records or files.
- Do not use AI to draft external communications that contain confidential client details without human review and approval.
- Treat AI-generated output as a first draft, not a final answer. This applies especially to anything involving legal language, financial calculations, compliance requirements, or medical guidance.
- Log out of personal AI accounts when using work devices. Browser sessions can persist and blur the line between personal and professional data.
- Do not use AI browser extensions that claim to enhance ChatGPT or Copilot unless IT has explicitly approved them. These are a common malware delivery vector.
Nevtec can help your business establish a formal AI acceptable use policy as part of your broader cybersecurity and compliance framework.
Red Flags That Signal an AI Security Risk
Cybercriminals have been quick to exploit the popularity of AI tools. Employees should know how to recognize when something is off:
- An AI tool asking for login credentials or multi-factor authentication codes. Legitimate AI tools never request this.
- Phishing emails spoofing AI platforms. Fake ChatGPT billing alerts, Copilot account suspension notices, and counterfeit Gemini invitations are all active phishing campaigns.
- AI-generated deepfake audio or video impersonating company leadership. This is an evolution of business email compromise (BEC) and is already being used in financial fraud schemes targeting businesses of every size.
- Unsolicited AI tool recommendations or free trial offers sent via email. These are frequently credential harvesting attempts.
If something feels off, report it to IT before clicking anything. Nevtec clients can reach the Nevtec support team directly for guidance.
How to Build an AI Acceptable Use Policy for Your Business
Every business that allows employees to access AI tools at work needs a written policy. You do not need a lengthy legal document. You need a clear, practical set of rules that employees will follow.
A basic AI acceptable use policy should cover:
- Which tools are approved for work use and which are not
- What categories of data are prohibited from AI prompts
- Whether personal AI accounts may be used on work devices
- How AI-generated content should be reviewed before use
- Who employees contact when they have a question or spot a potential risk
Ownership of the policy should sit with IT, HR, and leadership together. IT identifies the risk. HR communicates the expectations. Leadership enforces the standard.
Nevtec helps businesses in the New York metro area build and implement security policies that account for the way employees work today, including the AI tools they are already using. If your organization does not have an AI use policy yet, now is the right time to build one.
Make Sure Your Team is Using AI Safely
If you are not sure whether your employees' AI usage is putting your business at risk, Nevtec can help. From acceptable use policy development to Microsoft 365 Copilot deployment and security configuration, Nevtec works with businesses throughout New York and the surrounding region to close the gaps before they become incidents.
We will review your current environment and get a clear picture of where your AI risk exposure stands.
Frequently Asked Questions About AI Safety at Work
1. Is Microsoft Copilot for Microsoft 365 safe to use with sensitive business data?
Microsoft Copilot for Microsoft 365 is built on Microsoft's commercial data protection commitments. It does not use your organization's data to train foundation models, and it respects your existing Microsoft 365 permissions and data governance policies. The free version of Copilot does not carry these same protections. If you are unsure which version your organization has, contact Nevtec.
2. Can my employer see what I type into ChatGPT on a work computer?
Depending on your organization's network monitoring and endpoint management tools, yes. Many businesses log web traffic and endpoint activity, which can include AI tool usage. More importantly, data entered into consumer-tier AI tools is processed by third-party servers outside your employer's control. What you type may be visible to your employer and potentially retained by the AI provider.
3. What is the difference between a personal and enterprise AI account?
Personal accounts are governed by consumer privacy policies, which typically allow the provider to use your inputs to improve the model. Enterprise accounts are covered by data processing agreements that restrict how your data is used, often prohibiting use for model training and requiring data residency or deletion capabilities. The distinction matters significantly for compliance and liability.
4. Should my business ban AI tools entirely?
Blanket bans are difficult to enforce and often counterproductive. Employees will use AI tools regardless of policy if they find them useful. A more effective approach is to identify approved tools with appropriate enterprise data protections, establish clear usage rules, and provide employee training. Nevtec can help structure that program for your team.
5. How do I know if an AI tool is storing my data?
Review the provider's privacy policy and data processing terms. Look specifically for language about training data, data retention periods, and whether you can opt out. For enterprise accounts, these terms are typically covered in a Data Processing Agreement (DPA). If you cannot locate or understand these terms, that is a signal to consult with IT or a trusted technology partner before using the tool for work purposes.