Work Secrets Paste-Stop Card
Use with Do Not Paste Work Secrets Into a Consumer AI Account.
Before you paste anything into AI, check for these six categories
- Source code from an unreleased or proprietary system
- Financial figures not yet publicly disclosed
- An unannounced product, feature, or business plan
- A security detail — a vulnerability, credential, or production architecture
- Anything covered by a signed NDA or confidentiality clause
- Anything your employer has specifically told you is a trade secret or confidential
- Personal, regulated, customer, employee, or special-category data
If any box is checked: stop. Do not paste into a personal or unapproved account.
What to do instead
- Check whether your employer has approved the exact tool, tenant/account, configuration, purpose, and data class — see the workplace AI policy read card.
- If no approved tool exists, ask your manager or IT/security whether an exception process exists. Do not decide alone.
- If you only need to ask about a general pattern, strip identifying details first (generic names, rounded numbers, abstracted logic) — and honestly check whether the abstraction actually removes the secret, not just the discomfort of pasting it.
Why this is not just a courtesy
Trade-secret protection and confidentiality duties depend on applicable law and the facts, including the measures used to keep information secret. An unauthorized third-party disclosure can create legal, contractual, security, and incident-response risk. Deleting a chat afterward does not retract the transmission or establish what was retained. Follow employer policy and obtain legal advice for the specific consequences; treat the paste as effectively irreversible before you make it.
If you already pasted something you shouldn’t have
- Tell your manager or IT/security now, in writing, rather than waiting for it to surface elsewhere.
- Note what was pasted, into which tool, and when — this is the information they need to assess exposure.
- Preserve relevant evidence and follow the employer’s incident process; do not delete records if policy or responders require them.
- If credentials, tokens, or access links were included, use the authorized security route to revoke or rotate them promptly.
- Do not repeat the mistake while waiting for a response.