0:00
/
0:00
/
Preview

Your company blocked ChatGPT for sensitive files. Grab the guide to strip the name, the address, and the price, and the block stops mattering.

"DoN’t UpLoAd SeNsItIvE FiLeS to AI." Okay, well now what? The hard part is deciding what a model needs to know, and who should have to make that decision.

Your manager says: do more with AI, get more done. Your IT department says: you can’t use that, and you can’t upload that. Both are presented as requirements of the job. The deadline keeps moving closer.

In practice, people obey the manager. The manager evaluates their performance and controls whether they get promoted.

It did not always work this way. For most of the past twenty years, I have sat through more IT presentations about data and privacy than I can count. The people giving them were serious, and the issue was serious, but I also watched most of the room roll its eyes. People were not hoping customer information would leak. Privacy did not feel like the problem in front of them. It was another obligation to remember while trying to finish the work they had actually been asked to do.

Over the last two years, that changed. Every IT administrator I talk to now worries about shadow IT because AI tools are moving into daily work faster than most organizations can evaluate, approve, or control them. At the same time, the individuals using those tools do not feel casual about the risk. They feel tremendous stress because they are receiving two instructions from different parts of the same company, and both are presented as requirements of the job.

The privacy risk is real, but the consequence of disappointing the manager is immediate, personal, and easy to understand.

That puts employees directly in the crosshairs. Use the strongest tool on the real material, and they may violate a rule they were told to follow. Avoid it, or flatten the task into something generic, and they may miss the gains their manager now expects. Either way they lose. The person with the least authority to resolve the conflict is being asked to carry it, then judged on the result.

The employee is no longer being asked merely to follow the policy or use AI; they are being asked to decide, file by file, which information can move, what must stay behind, and which tool is acceptable. That is a privacy process, whether the company designed one or not. In many companies, the employee is inventing it.

You can see the conflict in a question an auditor asked other accountants late last year. Every conference and webinar seemed to be telling them the same thing: use AI to streamline the work. The opportunities were obvious. A capable model could read client process documents, internal-control manuals, checklists, and summaries, then help the auditor find gaps or turn the material into something another person could understand.

The trouble was that the useful material lived inside client files. Uploading those files would be “a game changer,” the auditor wrote, “but I also have a responsibility to protect their data.” The products that seemed safest created a different compromise: they had “far less intelligence” or were “priced astronomically.” The auditor was unwilling to sacrifice either quality or security, which left the work at a standstill.

The auditor does not need to be persuaded to care about privacy. They are trying to satisfy two professional responsibilities at once: safeguard the client and do the work well. The rule names what must not happen. Then it leaves them alone with everything that still has to happen.

“Don’t upload the file” is good advice. It is not an answer to: How should I finish the work?

Here’s what’s inside:

  • Airlock, and what it does not do. The Mac app I built for the repetitive part, what it refuses to touch, and why a clean copy still is not permission.

  • Why the empty chat box stopped being enough. Useful AI work now runs on your real material, and that is what turned privacy from a policy slide into a decision you make file by file.

  • What people are actually doing about it. Real answers from operators who built routing, tiers, and local pipelines instead of trusting themselves to remember a rule at 11pm.

  • The two-minute test for your company’s privacy system. Put the approved path on a clock against the consumer route, because the difference predicts what people under deadline will actually do.

  • Why there is no single “clean” version of a document. Relevance depends on the question you are asking, which is why one sanitized copy cannot be a permission slip for every later task.

Subscribers get the full deep-dive and guide, plus membership to my Slack community!

Listen to this episode with a 7-day free trial

Subscribe to Nate’s Substack to listen to this post and get 7 days of free access to the full post archives.