Security & RiskDepartment managersEngineering / ITAll staff

Which Company Data Should Never Be Uploaded to Generative AI?

Classify data by sensitivity to clarify what needs anonymization, an enterprise account, or should never be uploaded at all.

6 min read · Last updated 2026-07-17

What you'll learn

  • Understand the four levels of data sensitivity.
  • Know above which level public AI tools should not be used.

Step-by-step guide

The four sensitivity levels

L1 Public information → free to use. L2 General internal information → recommend using an enterprise AI plan. L3 Sensitive (customer lists, personal data, financials) → requires anonymization or should not be uploaded. L4 Confidential (unpublished contracts, sensitive financials, trade secrets) → never upload, especially not to public AI tools.

Common mistakes

Pasting an entire customer list into AI for analysis; dropping a full contract in to ask questions; handing an employee salary table to AI for sorting.

How to anonymize

Replace company names, personal names, amounts, and addresses with codes; keep only the fields needed for analysis; ask questions in batches.

Enterprise-level practices

Draft an 'AI usage policy' that clearly defines what's allowed, prohibited, and requires review; provide enterprise accounts and log usage.

Good example / Bad example

Good practice

Replace the customer's name with 'Customer A' and remove the last 6 digits of any ID number before uploading.

Bad practice

Drag an Excel file straight into a public AI tool for analysis.

Common mistakes

  • Assuming that removing names alone counts as anonymization.

Cautions

  • Must comply with personal data protection laws, GDPR, or data-handling clauses in customer contracts.

Related prompts

Related articles

Last updated 2026-07-17

Need help customizing this for your company and industry?

AEGIS provides enterprise AI adoption, process assessment, and systems integration consulting to help you turn prompts and AI tips into reliable internal workflows.