Authorship Debt: When AI Finishes Your Work
AI agents no longer draft your work, they complete it. That moves the risk from quality to accountability. A ten-minute discipline pays it down.
You've been told not to paste confidential data into AI, and nothing more. A plain decision map for what's fine, what to redact, and what never goes in.
Someone at your company handed you the rule and then walked off: don’t paste confidential data into AI. It sounds responsible until you sit down to actually use the thing, because now every prompt comes with a small anxious pause. Is a job description confidential? What about the survey comments you’re trying to summarize, or the draft policy with the CEO’s name in it? If you’re the person who got told to “roll out AI” without being told what that means in practice, the prohibition isn’t a guardrail. It’s a shrug dressed up as a policy.
The reason it feels impossible is that “confidential” was never the useful line. Most of what you want to do with AI at work sits in a middle zone that a blanket ban and a blanket green light both get wrong. What you need is a map with more than one road on it, so here is the one I’d give a colleague on their first day.
Sort anything you’re about to paste into one of three buckets before you hit enter.
Green, paste as-is. Anything already public, or that has no real person or number attached. A rewrite of text that’s on your public careers page, a first draft of a blog post, brainstorming ten angles for a campaign, explaining a concept back to you, cleaning up your own rough notes that name nobody. If it could sit on a whiteboard in the lobby without anyone flinching, it’s green.
Amber, redact first. Anything whose shape is useful to an AI but whose specifics aren’t its business. This is where most real work lives, and it’s the bucket people skip because redacting feels like effort. It isn’t much. Say you want help summarizing engagement-survey comments. You don’t paste “Maria in Finance says her manager Tom plays favorites.” You paste “Employee says their manager shows favoritism.” The model does the same summarizing job on the anonymized version, and you kept two names and a department out of a system you don’t control. Strip the identifiers, keep the structure, and the amber task becomes safe without becoming useless.
Red, never, even redacted. Some things don’t get anonymized into safety. Regulated personal data such as health details, financial records, or government ID numbers. Anything you’d need legal permission to email to an outside vendor: unreleased financials, contracts under negotiation, security credentials or API keys. And a whole category people forget, which is other people’s data you were only trusted with because you’re inside the company. Redaction can’t fix red, because the problem is the substance rather than the label on it.
The honest test for a borderline paste: would you be comfortable if this exact text showed up in a stranger’s chatbot answer next year? If not, it’s amber at best.
The part almost nobody tells the person doing the rollout is that the same sentence can be safe or a leak depending on the account it’s typed into. On consumer ChatGPT, the free and Plus tiers, your conversations are used to train future models by default, and turning that off is a per-person setting buried in preferences that you can’t enforce across a team (OpenAI’s own privacy pages spell this out). On the business tiers, ChatGPT Team, Business, and Enterprise, your content is not used for training by default, with Enterprise backing that by contract rather than a settings toggle.
That gap is why “just don’t paste anything sensitive” quietly fails in real companies. Security research keeps finding that the large majority of risky pastes happen through unmanaged personal accounts that bypass whatever controls the company thought it had (The Register’s write-up of the Cyberhaven data is a good rundown). An amber task done in a company Enterprise seat is genuinely fine. The identical task done in someone’s personal free account on their lunch break is how confidential data ends up training a model. If your organization has a paid business seat, use it and route everyone through it. If it only has the free tier, treat everything as if it’s one bucket stricter than it looks.
The whole map collapses into one fifteen-second habit: before you press enter, reread the prompt and ask what a stranger could do with it. Names, numbers, and anything that points at a specific person or deal get swapped for a role or a placeholder. You’ll find that nine times out of ten the AI didn’t need the real details to do the work, which means you were never trading usefulness for safety in the first place. Once the “is this safe” question stops eating your attention, you can put it toward the more useful one of how to work with the tool well, which we break into four practical modes here.
This is also the thing to bring to the “should I even admit I’m using AI” question, which is its own tangle worth reading separately (we covered it here). The confident answer to a nervous manager isn’t “I never use it” or “I paste whatever.” It’s “I use it for the drafting and thinking, and I strip anything private before it goes in.” That sentence is what a real AI policy sounds like, and you can say it whether or not anyone above you has written one down. If they haven’t, and you’re the one expected to, our note on learning AI when your employer won’t pay for the tools or the training covers building that muscle on your own.
None of this requires you to become a security specialist. It requires one map and one reflex, applied to work you’re already doing. The prohibition you were handed was never wrong, exactly. It was just half a sentence, and now you have the other half.
Take the next real task you'd use AI for and write the prompt out before you send it. Do one redaction pass: swap every real name for a role ("the manager," "a client"), every exact figure for a rounded or generic one, and delete anything you'd need permission to email outside the company. Send the redacted version and check the answer is just as useful. That single pass is the whole habit, and it turns most of your daily "is this allowed?" pauses into a two-second yes.