How much personal information should you give an AI system?
← Back to blog

How much personal information should you give an AI system?

Artificial Intelligence Informational article

Distinguish useful context from sensitive details that the task does not require.

A chat window may feel friendly, but messages enter a service's data-processing system. That is not the same as a private conversation with a friend. Storage and use vary by provider, product and settings.

Ask what the task genuinely needs

Editing an appointment email usually does not require an identity number, full address or detailed health history. Replace real names with examples and reduce exact dates or locations. However, removing a name alone does not automatically anonymise a document.

Protect other people's information

Client notes, children's details and colleagues' private messages should not be uploaded simply for convenience. Professional confidentiality and organisational rules still apply. Fictional examples are enough for many drafting tasks. If real records are necessary, clarify authority and appropriate processing conditions first.

Read policies and settings

Check official information about storage, deletion, training use and third-party sharing. Do not infer complete privacy protection from a feature name. “Free” or “private” does not automatically mean suitable for confidential health data.

If you share something accidentally

Follow the provider's official deletion and reporting steps. If a password or API key was exposed, deleting the conversation may not be enough; the relevant access may need to be replaced. This article is not a legal compliance assessment. The basic principle is to send no more sensitive information than necessary.

Sources and further reading

NIST — Generative Artificial Intelligence Profile (AI 600-1)

https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence