Generic drafting keeps the interaction low risk because the prompt contains little or no sensitive content. Using ChatGPT with confidential internal data changes the exposure profile because the model receives information the organisation may want to keep restricted, retained, or undisclosed. The key difference is not the task, but the sensitivity of the context being shared.
Why the Exposure Profile Changes
Generic drafting and drafting with confidential internal data may look similar as a user experience, but they are not the same security event. The first stays close to low-sensitivity language and ordinary productivity use. The second changes the trust boundary because the content may include restricted business information, regulated data, source material, or operational details the organisation would not want copied into a third-party system.
That distinction matters because the risk is created by the context shared, not by the fact that ChatGPT is being used at all. Even if the task is only summarisation or rewriting, confidential inputs can increase disclosure, retention, access-control, and downstream reuse concerns.
What Changes Operationally When Confidential Data Is Included
Once internal data enters the prompt, the interaction becomes part of the organisation’s information-handling process. That means the team has to think about classification, approved-use rules, and whether the content can be sent to a model at all under policy, contract, or regulatory constraints. The same drafting task can move from routine productivity to a controlled handling decision.
Practically, the higher the sensitivity of the material, the more important it is to treat the prompt as an information transfer rather than a casual query. That is especially true for customer data, credentials, incident material, legal text, merger activity, unreleased financials, or anything that would create harm if exposed outside the intended boundary.
- Use generic drafting for public or low-sensitivity text where disclosure would not change the organisation’s risk posture.
- Use stricter review, redaction, or an approved internal tool when the content includes restricted business, legal, security, or customer information.
- Assume that a prompt containing confidential material needs the same discipline as any other controlled data-handling step.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Controls who may handle confidential content in approved tools. |
| 13 — Data Protection | Addresses protecting sensitive information shared with external services. | |
| Recommendation — Restrict confidential prompts to approved access paths and enforce least privilege. Classify and protect sensitive prompt content before sending it to an AI service. | ||
| NIST CSF 2.0 | PR.DS — Data Security | Covers safeguarding data in use, transit, and storage when drafting from internal material. |
| PR.AC — Identity Management, Authentication and Access Control | Supports restricting who can use AI tools with sensitive internal data. | |
| GV.RM — Risk Management Strategy | Fits the need to define when confidential data may or may not enter a model. | |
| Recommendation — Apply data-security controls to limit exposure of confidential inputs and outputs. Limit access to AI tooling based on the sensitivity of the data being handled. Define explicit rules for which data classes may be used in generative AI tools. | ||
| OWASP Agentic AI Top 10 | A2 — Sensitive Data Exposure | Relevant because confidential prompts can expose restricted internal information to AI systems. |
| A7 — Excessive Agency and Data Overexposure | Applies when a tool receives more internal context than needed for the task. | |
| Recommendation — Redact sensitive content before sending prompts to external AI systems. Minimise the data shared with AI tools to the smallest workable context. | ||
| NIST AI RMF | GOV — Govern | Supports organisational policies for acceptable AI data use and oversight. |
| MAP — Map | Helps inventory where confidential data may enter AI workflows and why. | |
| Recommendation — Set governance rules for confidential-data use in generative AI workflows. Map high-sensitivity use cases before allowing them into AI-supported drafting. | ||
Practitioner Guidance
What to verify: Before using ChatGPT on internal material, verify whether the data is classified, restricted by contract, or subject to retention and disclosure rules. If the answer is unclear, do not treat it as safe merely because the task is “just drafting.”
Decision rule: If the prompt can be written without confidential details, strip them out first. If the confidential details are essential to the output, use the approved workflow for that data class rather than improvising in a general-purpose chat session.
What practitioners underestimate: The main risk is often not a dramatic breach, but gradual oversharing, where employees normalize sending sensitive context into tools that were never intended to be the system of record.
Practitioner takeaway: The security question is not whether the model is drafting text, it is whether the prompt itself contains information the organisation must still control after it leaves the user’s screen.
Related resources from NHI Mgmt Group
- What is the difference between using public certificates and private certificates for internal Kubernetes traffic?
- What is the difference between storing identity data on a public blockchain and using a hybrid identity ledger model?
- What is the difference between storing security data centrally and using cross-cluster search for remote Wazuh clusters?
- What is the difference between loading all admin data at once and using progressive disclosure for identity workflows?