What you can and can't paste in: handout

One slide per page with speaker notes. Choose "Save as PDF" in the print dialog.

Back

your AI programme · Session 3

What you can and can't paste in

Using your AI assistant confidently without leaking what you shouldn't.

enablementlead.com1

Notes · slide 1

Before this session, do your homework, because people will ask specific questions. Find out: whether your company has an AI or acceptable use policy and where it lives; which tools and accounts are approved; what the approved your AI assistant setup does with the data you give it, in the words of your IT or legal team, not a guess; and who people should contact if they make a mistake. If there's no policy, say so honestly and use this session to show what sensible defaults look like while one is written. Open by saying: "This isn't a session to scare you off. Most people don't use AI as much as they could because they're not sure what's allowed. The aim is to make you confident, not nervous."

What we'll cover

  • Where your words go when you paste them
  • Three questions before you paste
  • Green, amber and red
  • Stripping out what's sensitive
  • Exercise: traffic-light your own inputs
  • What to do if you get it wrong
enablementlead.com2

Notes · slide 2

30 seconds. Mention that you'll finish with where to find your company's actual rules, so people know this is about their workplace, not general advice from the internet.

Most people aren't breaking the rules. They just don't know them.

enablementlead.com3

Notes · slide 3

When people are asked what they're allowed to put into AI tools, a lot of them aren't sure. Some respond by not using it at all; others paste in everything. Both are problems. If you've interviewed people at your company about AI use, quote what you heard, anonymised. If not, ask the room: "Hands up if you've ever hesitated before pasting something in because you weren't sure it was allowed." Then: "Hands up if you've ever pasted something in and wondered afterwards." Keep it light; nobody's in trouble here. One minute.

Where your words go

  • Pasted text leaves your screen and goes to a service
  • What happens next depends on the tool and the account
  • The approved your AI assistant at your company is set up for work
  • Personal accounts and free tools are not
enablementlead.com4

Notes · slide 4

Keep this factual and specific to your company. Explain in your IT or legal team's words what the approved setup means: for example, whether conversations are retained, who in the company can access them, and whether the provider may use them. Do not state product facts you haven't confirmed; tools and contracts differ and change. The key behavioural message is simple: use the work account for work, never a personal account or a random free website, even if it seems quicker. Likely question: "Is it safe to paste anything into the approved one?" Good answer: "It's safer, not unlimited. Some data shouldn't go into any tool without a specific reason and approval; that's the red category we're about to cover." Two minutes.

Three questions before you paste

  1. 01Which tool?Approved, on your work account?
  2. 02What's in it?People, customers, money, secrets?
  3. 03Would it be all right if this reached the wrong person?
enablementlead.com5

Notes · slide 5

These three questions cover most situations without anyone needing to memorise a policy. The first is about the tool. The second is about what's actually in the text, including bits you might not notice, like an email signature or a customer number buried in a spreadsheet. The third is a gut check: if this ended up somewhere it shouldn't, would it embarrass someone, harm a customer, or break a promise your company made? If yes, stop and strip it down, or don't use it. Two minutes.

Green, amber, red

enablementlead.com6

Notes · slide 6

Transition. Say: "Here's a simple way to sort things. Your policy has the final word; this is the everyday version."

A simple way to sort it

  1. 01Greenpublic information, your own drafts, general questions
  2. 02Amberinternal documents and customer situations, with details removed
  3. 03Redpersonal data, passwords, unreleased financials, legal or confidential matters
enablementlead.com7

Notes · slide 7

Three minutes. Green is the large majority of everyday use: rewording your own email, summarising a published report, asking how to structure a presentation. Amber is where people need judgement: an internal strategy document might be fine in the approved tool but not in a free one; a customer complaint is fine once names and order numbers are taken out. Red should not go in without explicit approval: anything identifying a person's health, performance, pay or grievance; passwords, API keys and access codes; financial results before they're published; anything under legal privilege or a non-disclosure agreement. Important: adjust these to match your company's policy. If your policy is stricter or looser, use its categories, and say so. Likely question: "What about my own performance review?" Good answer: "Your own information is yours to decide about, but anything about other people, like feedback on a colleague, is red."

What that looks like by team

  • Sales CRM export, red. Anonymised deal summary, fine
  • HR grievance notes, red. Policy wording, green
  • Finance unpublished results, red. Dummy figures, green
  • Support a ticket with names and order numbers removed, amber
enablementlead.com8

Notes · slide 8

Pick the examples relevant to your audience. The pattern in each pair: the same task can be safe or unsafe depending on what's in the input. Sales people can still get help writing a follow-up; they just describe the prospect as "a mid-sized logistics firm, finance director, worried about cost" rather than pasting the CRM record. Finance can still get help structuring a variance commentary using made-up or rounded numbers, then put the real figures in by hand. Two minutes.

Strip it, don't skip it

  • Swap names for roles: "the customer", "Manager A"
  • Remove IDs, emails, phone numbers and signatures
  • Round or replace sensitive figures
  • Describe the situation instead of pasting the record
enablementlead.com9

Notes · slide 9

This is the practical skill that unlocks most amber cases. It usually takes a minute. Demonstrate it live if you can: take an anonymised or invented support email with a name, order number and address, and edit it down in front of the room. Point out that the AI's answer is just as useful without the personal details, because it doesn't need them to write a good reply; you add them back at the end. Warn people about the bits they won't think to check: email signatures, quoted earlier messages at the bottom of a thread, and hidden columns in spreadsheets. Two minutes.

I didn't think of the spreadsheet as customer data. It was just the file I was working on.

A sales coordinator, explaining an export they'd pasted in
enablementlead.com10

Notes · slide 10

Illustrative, not a real quotation. This is the most common way sensitive data ends up in AI tools: not someone deliberately sharing secrets, but someone in a hurry pasting the file in front of them. Spreadsheets and long email threads are the usual culprits because they contain far more than the part you're thinking about. Ask the room: "What's the file you most often have open that would be a problem?" You'll get answers like the CRM export, the payroll file, the ticket queue. That's the list to be careful with. One minute.

Less obvious things that count

  • Screenshots, which show more than you think
  • Meeting transcripts and recordings
  • Long email threads, with everyone's details
  • Code or config files containing keys
  • Attachments you upload, not just text
enablementlead.com11

Notes · slide 11

People think about the text they type and forget everything else. A screenshot of a dashboard might include customer names in the corner. A meeting transcript includes what everyone said, including the off-hand remark about a colleague. Uploading a document counts the same as pasting it. If your AI assistant at your company is connected to email, documents or chat, explain what it can see and what that means; check this with IT first. One to two minutes.

What comes out matters too

  • You're responsible for anything you send or publish
  • Check facts before they reach a customer
  • Follow your company's rules on saying when AI helped
  • Don't put AI text into contracts without review
enablementlead.com12

Notes · slide 12

Data safety isn't only about inputs. If AI writes something wrong and you send it to a customer, that's your company's mistake, not the tool's. Find out whether your company has a position on disclosing AI use, for example in customer communications or published content, and tell people what it is. If there isn't one, say so and tell people to use judgement and ask their manager. Legal and contractual wording always gets a qualified human review. One minute.

Exercise · 10 minutes

Exercise: traffic-light your own inputs

  • List three things you'd like help with from your AI assistant
  • Mark each input green, amber or red
  • Pick one amber and rewrite it until it's green
enablementlead.com13

Notes · slide 13

Timing: 10 minutes. Four minutes alone: people list three real tasks and write down what they'd need to paste in for each, then mark the colour. Three minutes: they take one amber item and write the stripped-down version, describing the situation, removing names and identifiers. Three minutes: share with a neighbour or in breakout rooms and check each other's work, asking "is there anything left that could identify someone?" Walk around. Expect questions about edge cases; if you don't know the answer, write it down and promise to check with whoever owns the policy. Those questions are valuable: they show where the policy is unclear. If online, ask people to post one before-and-after in the chat, without any real data.

What did you find?

  • Which tasks were harder to classify than you expected?
  • Did stripping the details make the task impossible?
  • What question do you still have?
enablementlead.com14

Notes · slide 14

3 minutes. The second question is the important one: usually the answer is no, the task still works fine without personal details. Where it genuinely doesn't, for example someone needs to analyse real customer feedback at scale, that's a conversation for their manager and whoever owns data at your company, not something to work around. Collect the open questions and commit to answering them in your follow-up email.

If you get it wrong

  • Tell someone quickly: speed matters more than blame
  • At your company, that's: [contact or channel]
  • Note what was shared, where, and when
  • Don't try to fix it quietly
enablementlead.com15

Notes · slide 15

Fill in the real contact before the session, usually the data protection lead, IT security or a specific mailbox. Edit the slide text to include it. Stress the culture point: people who report a mistake quickly should be thanked, not punished, because it's the only way the organisation can respond properly. If people fear blame, they hide mistakes, and that's far worse. If you're not sure how your company handles this, ask before running the session. One minute.

Before you paste

  • Approved tool, on your work account
  • No names or details that identify a person
  • No passwords, keys or access codes
  • No unreleased financial or legal information
  • No customer identifiers
  • Fine if it reached the wrong person
enablementlead.com16

Notes · slide 16

The one-page version of this session. Suggest people keep it pinned near their desk or in their chat sidebar for a few weeks. If your company has its own checklist, use that instead and tell people where it is. Thirty seconds.

Where to find the rules at your company

  • The policy: [link]
  • Approved tools: [link or list]
  • Questions: [person or channel]
enablementlead.com17

Notes · slide 17

Replace the placeholders on this slide with real links before you present. If there's no policy yet, say so plainly: "We don't have a written policy yet. Until we do, follow the traffic lights and the checklist, and ask me if you're unsure." Then follow up with whoever should own one; the questions from today's exercise are good evidence for what it needs to cover.

Recap

  • Use the approved tool, on your work account
  • Green, amber, red: most everyday use is green
  • Strip details out instead of skipping the task
  • Report mistakes fast
enablementlead.com18

Notes · slide 18

One minute, then questions. Common question: "Can I use it on my phone?" Good answer: depends on your company's setup; tell them what's approved. Another: "What about tools built into other software we use?" Good answer: those count too, and the same three questions apply; check with IT if unsure.

This week

Find your company's AI policy, read it once, and pin the checklist where you'll see it.

enablementlead.com19

Notes · slide 19

Small and concrete. Send the link and a one-page version of the checklist in your follow-up email so there's no excuse. Ask people to reply with any question the policy didn't answer. Thank them, and remind them that the aim is confident use, not less use.