What Should We Do if an Employee Accidentally Shares Sensitive Information With an AI Tool?
23 August 2026
What Should We Do if an Employee Accidentally Shares Sensitive Information With an AI Tool?
The moment matters less than the response. Contain it, work out exactly what was shared and where it went, decide within hours (not days) whether it meets the threshold for an ICO report, and treat the incident as evidence your AI usage policy needs updating rather than as one careless employee's fault.
What to Do in the First Hour
The instinct is to panic or to quietly hope nobody notices. Neither helps. The first hour has four jobs, in this order.
First, stop the bleeding. If the employee is still mid-conversation with the tool, get them to stop typing further sensitive detail into it, but do not close the chat or delete it yet. You need that chat as evidence of exactly what was shared, not as something to make disappear.
Second, write down precisely what went in. Not roughly. Precisely. Was it a client's name and email, or their name, date of birth, home address and a contract value? Was it a spreadsheet of payroll figures, or a screenshot of someone's medical note? The scale of your response depends entirely on this detail, so get it in writing while it is fresh, ideally with a timestamp.
Third, check what tool it went into and under what account. A free personal ChatGPT account with no enterprise data protection agreement is a very different risk to a business Microsoft 365 Copilot account where your organisation already has a data processing agreement with Microsoft covering that exact use. If it is a consumer-grade account, assume the data may be used to train future models unless the specific product's settings say otherwise, and check that setting immediately.
Fourth, tell someone senior. In a small business with no IT department, this is usually you, the owner, or whoever holds the data protection responsibility. Cyberhaven's 2025 analysis found that 34.8 percent of corporate data employees now paste into AI tools is sensitive, up from just 10.7 percent two years earlier, and a separate 2025 industry report found 77 percent of employees have shared sensitive company data through AI tools at some point. This is not a freak event. It is common enough that you need a named person who owns the decision, not a group chat working it out by committee.
Do You Have to Report It to the ICO?
This is the question every business owner actually wants answered, and the honest answer is: it depends on what was shared and how likely it is to cause harm.
Under UK GDPR, you are required to report a personal data breach to the Information Commissioner's Office if it is likely to result in a risk to people's rights and freedoms. Since the Data Use and Access Act changes that took effect in August 2025, the reporting clock for PECR-related breaches moved from 24 hours to 72 hours, aligning it with the existing UK GDPR standard: report without undue delay and, where feasible, within 72 hours of becoming aware.
Not every AI mishap clears this bar. A staff member asking a generic AI tool to rewrite a paragraph that happened to include a client's first name is a low-risk, arguably non-reportable event if you act fast and the tool has no persistent training on inputs. A staff member uploading a spreadsheet of 200 customers' names, addresses and outstanding balances into a free consumer AI account with no enterprise agreement is a very different matter, and very likely reportable.
The ICO's own guidance sets out the practical test: assess the likely risk to individuals first, then decide. Ask yourself three questions. Could this data identify someone directly or in combination with other information? Could its exposure cause someone financial loss, distress, discrimination or reputational harm? Is there a realistic chance the AI provider retains, reviews or trains on this input? If the answer to any of these is a clear yes, involve a data protection professional and prepare to report within the 72 hour window. If you decide not to report, you must still log the incident, your reasoning and the outcome in your breach register - the ICO expects that record to exist even for decisions not to escalate.
Why This Keeps Happening, Even in Careful Businesses
It is tempting to treat this as one employee's mistake. It rarely is. A 2025 Chartered Management Institute survey found 59 percent of UK workers use AI tools at work, and most have never been told what is and is not allowed. If your business has never written down a clear rule about what can and cannot go into ChatGPT, Copilot or Gemini, you do not have an employee problem. You have a policy gap, and the employee just found it for you.
The other reason it keeps happening is speed. AI tools are genuinely useful for exactly the kind of task that involves sensitive information: summarising a contract, drafting a reply to a difficult client, tidying up a spreadsheet of figures before a meeting. The tasks where AI saves the most time are often the tasks that touch the most sensitive data, which is precisely why a blanket 'just don't use AI' rule tends to fail. Staff quietly move to personal accounts on personal devices where you have zero visibility, which is worse than the original problem, not better.
There is also a training gap most small businesses have not addressed. Staff generally understand not to email a client's full financial history to a stranger. Far fewer understand that pasting the same information into a free AI chatbot is functionally similar, because it does not feel like 'sending' data anywhere, it feels like typing into a search box. That mental model gap is the actual root cause in most incidents we see, not carelessness.
Building a Response Plan Before You Need One
Once the immediate incident is handled, the actual job is making sure there is never a repeat, and that if there is, the response is faster and calmer than this one.
Write a one-page incident response note. It needs four things: who to tell first (name a person, not a department), what to check immediately (which tool, what data, what account type), the 72-hour ICO decision framework above, and a template for logging the decision either way in your breach register. One page. If it takes longer than five minutes to read under pressure, nobody will use it.
Separately, close the actual gap. If staff do not know what is and is not allowed, that is now your most urgent job, not a nice-to-have for next quarter. A short, plainly written AI usage policy that names approved tools, gives clear examples of banned inputs (client contracts, financial data, health information, passwords, anything under an NDA) and explains why, will stop most repeats. Pair it with one real conversation, not just a document nobody reads: show the team the difference between 'summarise this generic paragraph' and 'summarise this client's medical history,' because that distinction is the one most people have never actually had explained to them.
Finally, consider whether an approved, business-grade AI tool with a proper data processing agreement (Microsoft Copilot under your existing 365 tenancy, or an enterprise ChatGPT Team/Enterprise account, for example) would reduce the temptation to use unmanaged personal accounts in the first place. Banning AI outright rarely works. Giving staff a safer, sanctioned option they can use for the same job usually does.
One more practical step worth taking in the same week as the incident: run a quick, honest audit of who in your team is already using AI tools, and for what. You will almost certainly find more use than you expected, often on personal devices or personal accounts, because staff have been solving their own problems quietly rather than waiting for permission that never came. This is not a trust issue, it is a communication gap, and it is far easier to close once you know the real scale of it. A five-minute conversation with each team or department, asking what they use and why, tells you more than any policy document ever will, and it usually surfaces one or two obvious, low-risk wins you can approve immediately, which builds goodwill for the rules you do need to enforce.
Is This Right For You?
This guide is for you if you run a small or medium UK business, someone on your team has just told you (or you have just discovered) that client details, financial data, health information, contracts or passwords went into a free AI tool, and you are not sure what happens next.
It is not a substitute for legal advice. If the data involved is highly sensitive - special category data under UK GDPR such as health, biometric or criminal records, or if the breach is large in scale, you should speak to a data protection solicitor or a qualified DPO before you decide not to report something. This guide gets you moving in the right direction in the first hour; it does not replace proper legal sign off on genuinely serious incidents.
If nothing has actually happened yet and you are trying to prevent this situation in the first place, read our guide on writing an AI usage policy your team will actually follow instead.
Frequently Asked Questions
Should I discipline the employee who shared the data?
Only if they knowingly broke a clear, existing policy they had been trained on. If your business has never had an AI usage policy, this is a process failure, not a conduct issue, and treating it as a disciplinary matter will just push future incidents further underground.
Can I ask ChatGPT or another AI provider to delete the data that was shared?
You can request deletion, and for enterprise/business accounts (ChatGPT Team, Enterprise, Microsoft Copilot under a 365 tenancy) providers generally honour data processing agreements that limit retention and training use. For free consumer accounts the position is weaker: check the specific provider's current data controls and opt-out settings, and document exactly what you requested and when as part of your incident record.
Does it matter if the data was about an employee rather than a client?
No. UK GDPR applies to personal data about anyone, including your own staff. Payroll figures, HR notes or disciplinary records shared with an AI tool carry the same 72-hour reporting assessment as customer data.
What if we are not sure whether the AI tool retains or trains on our data?
Assume it does unless you can confirm otherwise in writing from the provider's current data policy for the specific account type used. Business and enterprise tiers from major providers typically state they do not train on customer inputs by default; free consumer tiers often reserve the right to unless the user has actively opted out, and settings change, so check the current policy rather than relying on memory of an older one.
How do we know if the breach is 'high risk' enough that we must also tell the affected individuals, not just the ICO?
The ICO's test is whether the breach is likely to result in a high risk to people's rights and freedoms, for example enabling fraud, identity theft, financial loss or significant distress. If in doubt, involve a data protection professional rather than guessing; getting this judgement wrong in either direction (over-notifying panics people unnecessarily, under-notifying is a compliance failure) is a genuinely difficult call worth a second opinion on.
We are a five person business with no IT department. Do these rules really apply to us?
Yes. UK GDPR and the ICO's reporting obligations apply regardless of business size. There is no small business exemption for personal data breach reporting, though the ICO's own guidance for small organisations is written with limited resources and no dedicated compliance team in mind, and is worth reading directly.
Is it enough to just tell staff 'don't put client data into AI tools' verbally?
It is a start but it will not hold up as evidence of a proper policy if something does go wrong later, and verbal-only guidance is rarely consistent across a team. A short written policy that staff acknowledge, even a single page, closes this gap properly.