An Employee Put Confidential Data Into an AI Tool: What Do I Do Now?
A calm first-hour response to confidential data entered into an AI tool: establish the facts, contain the exposure, assess notification duties, close the gap.
Establish exactly what was shared, into which tool and under which account. Check the supplier’s data-handling terms for that tier. Assess whether personal data was involved and whether the UK GDPR breach threshold is met. Contain: rotate exposed credentials and request deletion. Record the incident and the decisions you took.
This page is written for the person handling the first hour. It sets out the facts to establish, the notification duties to assess and the control gap the incident exposes.
An employee put confidential data into an AI tool. What do I do now?
Establish the facts first, contain second, assess your notification duties third, close the control gap fourth. Spend the first thirty minutes on evidence, because a vague report often proves either less serious than feared or far broader than a single paste. The undeclared tool use this exposes is Shadow AI, and Shadow AI Discovery maps which tools are in use and under which accounts.
What exactly should I establish in the first hour?
Six facts, in this order. Ask directly and calmly, because a punitive first conversation means later incidents go unreported.
- The tool, with its exact URL or app name.
- The account type: personal free, personal paid or an organisational tenant you control.
- The content: what data, how much and whose.
- The timing: when, and whether it happened once or repeatedly.
- Whether any output was shared onward, into a document, email or client deliverable.
- Whether the employee still has the session or chat history available.
If the answers point to a wider pattern, our answer on finding which AI tools employees already use covers the discovery work.
Does the type of account change how serious this is?
The account type is the single biggest factor. Consumer tiers of major AI tools have historically used submitted conversations to improve models unless the user disables that setting, though these policies change and vary between suppliers. Business and enterprise tiers typically commit contractually not to train on customer content and offer data-processing terms suitable for UK GDPR processor arrangements. The same paste of the same client file can be a manageable internal error on a contracted tenant and a reportable disclosure on a personal free account.
Is data shared with an AI tool automatically a GDPR breach?
No, but it may be one. Under UK GDPR a personal data breach is a security incident leading to accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data. If no personal data was involved, you have a confidentiality or contractual problem rather than a data protection one. The assessment turns on risk to the individuals rather than embarrassment to the organisation: sensitivity, numbers affected, potential for fraud or harm, recoverability.
When do we have to notify the ICO, and how fast?
If the incident is a personal data breach likely to result in a risk to the rights and freedoms of those affected, notify the ICO without undue delay and within 72 hours of becoming aware of it. The clock starts at awareness, not when you finish investigating. If you cannot supply full details in time, notify with what you have and supplement afterwards. Contractual obligations run in parallel, and many client agreements require notification sooner than 72 hours.
Can the data be deleted from the AI tool?
Partly, and less completely than most people expect. You can usually delete individual conversations, request account deletion and rely on the supplier’s published retention process. What you cannot reverse is any influence the content has already had on a trained model, or any copy held in supplier logs during their stated retention window. Treat deletion as containment rather than remediation, and rotate immediately any credentials, API keys or access tokens that were included.
Should we discipline the employee?
Usually not, at least not as the first response. Most of these incidents happen because a capable person was trying to work faster and no one had told them where the line sat. If your organisation has never published guidance on approved tools and prohibited data types, a disciplinary response punishes the employee for a governance failure. Deliberate exfiltration or repeated breaches of an acknowledged policy are different, and your existing HR process should handle them.
How do we stop this happening again?
Publish a short list of approved AI tools and an explicit list of data types that must never be entered into any of them. Provide a sanctioned alternative so the productivity need is met rather than driven underground. Add technical controls where proportionate, such as browser or DLP-based blocking of consumer AI endpoints on managed devices. Then verify, because policy without verification produces confident non-compliance.
AI Security Gap Analysis covers the control gaps this incident exposes, and AI Behaviour Verification tests whether the controls you believe are in place hold. Both sit within AI governance and are formalised in ISO 42001. On the wider question of tolerating or blocking consumer AI, see should we ban ChatGPT.
This page is general guidance, not legal advice. Breach classification and notification duties turn on your specific facts, so take advice from your DPO or qualified counsel before deciding on your own incident. If you want a second view on the breach assessment, contact us.
A second view on the assessment
If you are mid-incident, we can review the breach assessment and the control gap it exposes.