Most AI mistakes involving customer data are not dramatic. They are ordinary: someone pastes a support thread containing a name and an address into a tool nobody has checked.
Establish this before anything else
- Which tools has your organisation actually approved, and on which plan?
- Does that plan train on your inputs, and can you turn it off?
- Where is the data processed, and does that satisfy your obligations?
- Who has access to the conversation history?
These answers differ between the free and paid tiers of the same product, which is where people get caught out.
Reduce before you paste
Most tasks do not need the identifying details. A support reply can be drafted from the problem without the customer name, account number or address. Removing them takes seconds and removes the question entirely.
Write it down
A short written rule that names the approved tools and the data that must never be pasted will prevent more incidents than a training session. Put it where people work, not in a policy folder.
This is not legal advice
Requirements vary by jurisdiction and by industry, and they change. Have someone qualified review your approach rather than relying on a general article, this one included.