Resources · 13 July 2026

What data is safe to put into AI tools? A plain-English guide (UK)

By the Operating Bench Team · Last reviewed 13 July 2026

The most useful question about using AI safely is not “which tool?” but “what am I allowed to put into it?” Get that right and most of the risk disappears. Here is the plain-English answer for anyone in a UK organisation, with one rule you can teach in a sentence.

The one gut-check

Before you paste anything into an AI tool, ask yourself:

Would I be comfortable if this appeared in public, and does it name or identify a real person?

If it could be public and names nobody, you are almost certainly fine. If it identifies a real person, or it is confidential, stop. That single check catches the large majority of mistakes.

Why it matters

Two things make this more than caution. First, as the NCSC warns, queries you send to a public AI tool can be stored by the provider and used to develop the model, so anything you type in may leave your control. Second, if that information identifies a living person, it is personal data under UK GDPR, and putting it into an unapproved tool can be a breach. The convenience is real, but so is the exposure.

The four levels of data

Most organisations can sort their information into four simple levels. Think of it as a traffic light with one extra stop.

1. Public — green. Anything already published or intended to be: your website copy, public marketing, published reports. Fine to use in approved AI tools.

2. Internal — still green, with care. Day-to-day material that is not sensitive: draft communications, general notes, non-confidential templates. Fine in approved tools that do not train on your inputs. Strip out any names first.

3. Confidential — amber. Commercially sensitive information: financials, contracts, tender material, board papers, anything covered by a duty of confidence. Only in tools specifically approved for confidential data. Never in a free or personal tool.

4. Personal and special-category — red, and sometimes never. Anything that identifies a living person: names, contact details, client and customer records, staff data. This is personal data under UK GDPR and only belongs in tools approved for it, under a proper agreement. The most sensitive kind, health, safeguarding, children’s data, or anything about a vulnerable person, should generally never go into a general AI tool at all.

If your team can place a piece of information on this ladder in a few seconds, they will make good decisions without needing to ask every time.

Turning it into a habit

Knowing the levels is one thing; getting a busy team to use them is another. Three moves make it stick:

Get the one-page version free

We have packaged exactly this into a free download. The AI Starter Kit gives you a one-page guide to what data is safe to put into AI tools, alongside a short set of AI ground rules you can share with your team today. No cost, and it is the fastest way to turn the gut-check above into something everyone can follow.

If you want the complete system, the AI Safe-Use Pack includes a full Data Classification Guide with worked examples for your sector, plus the acceptable use policy, approved-tools matrix and risk register that put it into practice. You can look inside it first.

Either way, the message to your team is simple: use AI, and keep anything that names a person or gives away a secret well out of it.


This article is general information, not legal advice. For advice on your specific circumstances, consult a suitably qualified professional.

Frequently asked questions

What data is safe to put into AI tools?
Public and non-sensitive internal information is generally safe: published content, general drafts, and anything you would be comfortable seeing shared. What is not safe is personal data, client or customer data, and anything confidential, which should never go into a consumer AI tool. When in doubt, leave it out and ask whoever owns your AI policy.
Is it safe to put personal data into ChatGPT?
No, not the free or consumer version. Personal data is protected under UK GDPR, and the NCSC warns that queries sent to public AI tools can be stored and used to develop the model. Only use tools formally approved for personal data, under a data processing agreement that does not train on your inputs.
What is the simplest rule for using AI safely?
One line covers most of it: if it names or identifies a real person, or you would not be happy to see it made public, do not put it into an unapproved AI tool. Everything else in a good AI policy builds on that single gut-check.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.