When ChatGPT is given customer data or proprietary code without safeguards, the organisation can expose confidential information, intellectual property, and regulated records outside its controlled environment. That can trigger privacy violations, weaken contractual protections, and create legal or competitive harm. The safest approach is to use anonymised examples, strict policy controls, and approved review processes.
Why This Matters for Security Teams
Using ChatGPT with customer data or proprietary code changes the trust boundary immediately. The data may leave internal systems, be retained in logs or prompts depending on the service and settings, and be exposed to users who were never intended to see it. That matters because the same prompt can contain regulated records, contractual commitments, source code, API details, or business logic that carries competitive value. In practice, many teams discover the exposure only after the material has already been pasted into a public or loosely governed workflow. A useful benchmark here is that the Ultimate Guide to NHIs notes that 96% of organisations store secrets outside secrets managers in vulnerable locations including code, config files, and CI/CD tools, which shows how easily sensitive material spreads into environments that were not designed to protect it.That same pattern becomes more dangerous with generative AI because the system can reproduce, summarise, or transform what it has been given, making leakage harder to spot and harder to contain.
How It Works in Practice
The main issue is not that ChatGPT is always unsafe, but that it is often used without a data-handling model that matches the sensitivity of the input. If an employee pastes customer records, proprietary source code, or internal incident notes into an unmanaged chat session, the organisation may lose control over where that information is processed, stored, or reviewed. The practical risk increases when users treat the model like a private scratchpad rather than a governed system.- Customer data can be exposed if prompts include personal data, account details, transaction history, or regulated records.
- Proprietary code can leak architecture, logic, credentials, or internal endpoints, especially when developers ask the model to debug production snippets.
- Copied outputs can be reused in tickets, documents, or code reviews, extending the exposure beyond the original session.
- Policy gaps matter when there is no clear rule on what may be shared, what must be redacted, and which approved tools may be used.
Security teams should also distinguish between a public consumer interface, an enterprise-controlled deployment, and an internal AI workflow with logging, retention, and access controls. Those controls tend to break down when users are under time pressure and see the model as the fastest route to an answer, because convenience usually beats policy unless guardrails are built into the workflow.
Common Variations and Edge Cases
Tighter controls often increase friction, so organisations must balance productivity against confidentiality and compliance risk. Not every use of ChatGPT is equally sensitive: anonymised examples, synthetic code, and non-production data can be appropriate in approved workflows, while raw customer data, credentials, and unreleased source code usually are not.Current guidance suggests several edge cases need separate handling. A developer asking for help with a small code fragment may still reveal secret names, endpoints, or business logic. A support agent pasting a customer complaint may unintentionally include personal data that falls under privacy or retention rules. A business user summarising a contract may expose pricing, legal terms, or customer identifiers even if the prompt looks harmless at first glance. The key judgement is whether the input can be reconstructed, reused, or stored in a way the organisation cannot govern.
Where teams rely on approved enterprise AI tools, the question becomes less about whether AI is allowed and more about whether the deployment has clear retention limits, access controls, review expectations, and redaction rules. Without those, the workflow is effectively uncontrolled, even if the interface looks familiar.
Risk and Threat Considerations
The material risk is data leakage, policy bypass, and uncontrolled propagation of sensitive information. Once confidential data or proprietary code enters an unmanaged chat workflow, the organisation may lose confidentiality, reduce auditability, and create downstream legal or contractual exposure.
Failure mechanism: Users paste sensitive material into prompts, the material is processed outside the organisation’s governed environment, and the resulting input or output can persist, be shared, or be reused in ways the original owner did not approve. If secrets, identifiers, or source code are present, the exposure can extend beyond privacy into account compromise, intellectual property loss, or broader system abuse.
Impact: The consequence can include privacy violations, competitive disadvantage, regulatory findings, breach notification obligations, and increased blast radius if code or embedded credentials are exposed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | ChatGPT use with sensitive data depends on controlled access and authorised use. |
| PR.DS — Data Security | Customer data and proprietary code require protection during AI input and output handling. | |
| Recommendation — Restrict AI tool access to approved users and governed workflows. Classify and protect sensitive prompts, outputs, and retained records. | ||
| CIS Controls v8 | 3 — Data Protection | Sensitive data pasted into ChatGPT needs handling rules that prevent uncontrolled disclosure. |
| 6 — Access Control Management | Approved AI use depends on limiting who can submit sensitive information. | |
| Recommendation — Apply data-handling rules to redact or block sensitive AI inputs. Limit AI usage to approved accounts and controlled environments. | ||
| NIST AI RMF | GOVERN — Govern | Governance is needed to set policy for sensitive data use in AI systems. |
| Recommendation — Establish governance for what data may be entered into ChatGPT. | ||
Practitioner Guidance
What to prioritise: Classify the data before people use the tool. If the workflow can touch customer records, source code, or credentials, require an approved environment with documented retention, access, and review controls rather than relying on user judgement alone.
Decision rule: If the prompt would be unacceptable in a ticket, email thread, or shared document, it should usually not go into an unmanaged AI chat either. If the content is sensitive but still useful, replace it with redacted, synthetic, or minimally necessary examples.
What good looks like: Users know which data types are allowed, prompts are filtered or reviewed where needed, and sensitive material is not copied into general-purpose chat tools by default. The strongest sign of control is when teams can answer, quickly and consistently, where the data went and who can see it.
Practitioner takeaway: The real control objective is not to ban AI use, but to prevent sensitive content from entering a workflow that the organisation cannot observe, limit, or later prove it controlled.
Related resources from NHI Mgmt Group
- What happens when customer data is shared without strong safeguards?
- Who is accountable when a security breach exposes source code and customer configuration data from a widely used platform?
- What happens when sensitive data is shared without proper redaction controls?
- What happens when customer data APIs are exposed without enough authorization controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 15, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org