Scores
  • Premier Cup FT Riverside FC2 Northgate United1
  • Premier Cup LIVE 67' Harbor City1 Westfield Rovers1
  • Premier Cup FT Oakmont0 Lakeside Athletic3
  • Premier Cup 20:45 Port Ashby Kingsbridge
  • Basketball League FT Eastvale Tigers88 Summit Hawks84
  • National League Sat 15:00 Redwood Rangers Silverton Stars

Chatbots at work: what happens to the data employees paste into them?

A survey of 1,200 office workers found that almost half have pasted internal documents into an AI chatbot, often without knowing where the data ends up.

Office worker at a laptop in an open-plan office in the evening, screen glow on the face Higgsfield AI

Almost half of office workers in the country have pasted internal documents, client emails or spreadsheets into an AI chatbot to get help with their work, according to a new survey, and most of them have never been told what their employer allows.

The survey of 1,200 employees, carried out by researchers at Elmbridge University, found that 46 percent had used a popular chatbot for tasks such as summarizing reports, drafting replies or cleaning up data. Only one in five said their company had a written policy on the tools.

Where the text goes

Privacy experts say the main risk is not the chatbot itself but what happens to the information typed into it. Depending on the service and the settings, conversations may be stored, reviewed by staff or used to improve future versions of the system.

Read also

People treat the chat window like a private notebook. Legally and technically, it is often more like sending an email to a third party.

Sofia Brandt, data protection lawyer in Riverton

The survey found that the most commonly shared material was meeting notes and internal emails, followed by customer data and draft contracts. About 8 percent admitted to pasting information they knew was confidential.

Employers are catching up

Several large employers have started to respond. Some have blocked public chatbots on company networks, while others have signed contracts for business versions of AI tools that promise not to keep or reuse company data.

Banning the tools rarely works. Staff just use them on their phones. It is better to give them a safe option and clear rules.

Jonas Ekholm, head of IT security at a Port Alden logistics firm

The country’s data protection authority said this week it would publish guidance for employers before the end of the year. It reminded companies that existing data protection law already applies when personal data about customers or colleagues is entered into any online service.

Practical steps

Experts recommend a few simple rules for employees while companies write their policies:

  • Remove names, account numbers and other personal details before asking for help.
  • Check whether your company offers an approved AI tool.
  • Turn off chat history or training options where the service allows it.
  • When in doubt, ask your manager or IT department first.

The researchers plan to repeat the survey next year to see whether awareness has improved.

Add News to your preferred sources on Google.

Trust and transparency

Published
Updated
Author
Amelia Owens
Revision history
  • — Story updated.
  • — Article first published.

If you spot an error, let us know. We publish corrections clearly and visibly.

Comments 2

Write a comment

Join the discussion

Sign in or create a free account to comment.

Sign in Create free account

  • Mirela T.

    Our company sent a one-line email saying ‘don’t use AI’. Everyone still uses it. A real policy would help.

  • Owen P.

    The tip about removing names first is so simple, but I had honestly never thought about it.

More news

In other news…

More news