woman in wheelchair at work place

ADA – EMPLOYMENT

September 21, 2026

Protecting Confidential Information While Using AI

September 28, 2026

Cheri D. Andrews, Esq.

AI has become an incredibly useful business tool. We ask it to summarize things, brainstorm ideas, improve emails, analyze information, take notes during meetings, draft marketing content, and help us work through problems. We’ve all gotten remarkably comfortable pasting things into AI. But it comes with concerns about confidential information. Have you ever stopped to think about what you’re actually giving it?

There’s a question we don’t ask nearly often enough:

What confidential information are we giving AI in return?

Every time you type information into an AI tool, upload a document, connect an AI tool to another business application, or allow an AI notetaker into a meeting, you may be sharing confidential information outside your business.

And sometimes that information isn’t yours to share.  Sharing it may even violate ethical and regulatory provisions in your profession

Before You Paste Anything Into AI… consider where it ends up.

Imagine you’re trying to respond to a complicated client email. It would be so much easier to paste the whole thing into an AI tool and say, “Help me respond to this.”  Or perhaps you’d like AI to summarize a contract, analyze a spreadsheet, review customer feedback, or turn your meeting notes into a follow-up email.

The problem isn’t necessarily using AI to perform those tasks.

The question is what confidential information you’re providing in order to get the answer.

Depending on your business, that might include:

  • Client or customer names and contact information
  • Financial information
  • Employee information
  • Health information
  • Contracts and other confidential documents
  • Customer lists
  • Proprietary business processes
  • Unreleased products or programs
  • Passwords, account credentials, or other security information

Before putting any of that confidential information into an AI tool, you should understand what happens to it.

Does the provider retain your prompts or uploaded files? Is the information used to improve or train its models? How long is it stored? Who can access it? Can you delete it? Are different protections available with a paid business account?

The answers vary considerably from one tool – and sometimes one subscription level – to another.

And even if you think you are being careful… You May Be Sharing Confidential Information Without Typing Anything

A client recently asked me a really good question about AI notetakers in Zoom meetings – and that’s a perfect example of what I’m talking about.

Tools that take meeting notes may listen to the conversation, create a transcript, prepare a summary, identify action items, and store some or all of that information for later use.

That’s convenient.  It gives you a written summary of what happened in the meeting so you don’t have to rely on your notes – if you even took any.

It’s also potentially another repository containing everything discussed during the meeting.

If you’re a bookkeeper discussing financial information, a consultant talking about a client’s internal operations, or an employer discussing an employee matter, that’s worth thinking about.

This is also why I recommend treating AI transcription much like you would treat recording a meeting. Everyone should know that it’s happening and affirmatively consent before the recording or transcription begins. That’s particularly important in states such as Pennsylvania and Maryland, where recording private communications generally requires the consent of all parties. And don’t assume that a pop-up notification alone necessarily solves the problem – if you’re the one doing the recording or transcribing, obtaining an affirmative ‘yes’ is the safer practice.

What About AI That’s Already Built Into Your Software?

This issue isn’t limited to ChatGPT or obvious AI applications.

AI is increasingly being built into software businesses already use – meeting platforms, email programs, CRMs, accounting programs, project management systems, cloud storage, and more.

Sometimes turning on an AI feature means giving that feature access to much more than the particular information you’re working with at that moment.

Before connecting an AI tool to your email, cloud drive, CRM, or other business system, take a minute to learn what it will actually be able to access.

A good rule is simple:

Give an AI tool access only to the information it actually needs to perform the task you’re asking it to perform.

A Simple Question to Ask Yourself

I’m not suggesting that businesses stop using AI. I use it, and it can be a great collaborator.  But convenience shouldn’t replace judgment.

Before entering information, uploading a document, inviting an AI notetaker into a meeting, or connecting AI to another business application, stop for a moment and ask:

What information am I sharing here?  And is this information mine to give?

If it contains someone else’s confidential, personal, financial, proprietary, or otherwise sensitive information, that’s your cue to slow down and determine whether this particular AI tool is an appropriate place for it.

Using AI wisely doesn’t mean avoiding it.

It means knowing what you’re handing over before you hit Enter.

© 2026 Cheri D. Andrews, Esq. This material is informational only and does not constitute legal advice. This material does not create an attorney-client relationship between Cheri D. Andrew, Esq and the reader. Recipient should consult with counsel before taking any actions based on the information contained within this material.
There are no posts on the list.
✕

Free Download:

Safeguard Your Success

Enter your name and email to sign up for the Cheri Andrews newsletter and get the Safeguard Your Success download emailed right to you.