AI chatbots like ChatGPT, Gemini, Copilot, and Claude are gaining popularity. However, research from Stanford University indicates that, by default, conversations can be used by developers to train models. Some data is also retained long-term. Cybersecurity expert George Kamide states that users often underestimate the potential for data storage and reuse.
Cybersecurity experts advise users to exercise caution with the following five groups of data:
Personally identifiable information
Personally identifiable information (PII) includes full names, addresses, phone numbers, passport details, or national ID cards. Information security expert George Al-Koura explains that sharing this data with chatbots increases the risk of users becoming targets for identity theft or fraud. When asking AI to edit a resume, users should remove unnecessary identifying information before uploading the file.
Personal confidential information
Ashley Casovan, Executive Director of the AI Governance Center at the International Association of Privacy Professionals (IAPP), notes that people often chat freely with chatbots. A growing number of individuals view AI as a therapist or a "confidant". However, disclosures about mental states or personal relationships are not protected in the same way as discussions with real psychological professionals.
Health information
A 2024 survey by health policy organization KFF shows that one in six adults consults AI chatbots for health advice monthly. Dr. Ravi Parikh at Emory University highlights that popular chatbots are not bound by the Health Insurance Portability and Accountability Act (HIPAA), unlike doctors. Users should not upload medical records to AI. If assistance is needed, remove names, addresses, and patient identification numbers.
![]() |
Illustrative photo: AI. |
Confidential work data
Employees should not input internal reports, customer data, source code, or documents under non-disclosure agreements into AI. According to Al-Koura, this information can be recorded by the system to train models. "A prompt containing sensitive data can also violate employment contracts," he says. Users should conceal company and project names, providing only core facts.
Financial information
The University of Kentucky (US) advises against sharing payslips, bank accounts, investment portfolios, credit cards, or tax returns with AI. If exposed, this data can easily be exploited for blackmail or fraud.
What to do if data has been shared
George Kamide states that once data has been used for training, it is difficult for users to fully retrieve it. However, deleting chat history helps limit risks if an account is compromised by hackers.
Al-Koura suggests users ask themselves a question before hitting send: "Would I be comfortable if this content appeared in a family or company chat?" Instead of providing specific details, use anonymization. For example, change "patient at Hospital X" to "a customer in the healthcare sector."
Users should also proactively check privacy settings and select features that prevent AI from using personal data for model training.
Nhat Minh (According to Huffpost)
