← All posts
AI & Email Compliance

The new insider risk: what your team pastes into ChatGPT, Gemini, and Copilot

August 28, 2026 · 6 min read

A paralegal has a 40-page supplier contract and a deadline. She pastes the whole thing into a public chatbot with one instruction: “rewrite clause 7 in plainer English.” Ten seconds later she has a clean paragraph and a solved problem. She was helpful, fast, and completely well-intentioned. She also just moved a confidential third-party agreement, with its parties, pricing, and indemnity terms, onto an external service governed by someone else’s retention policy, and she did it without sending a single email to anyone.

That is the shape of the risk almost nobody has a control for yet. Your DLP watches attachments. Your archiving tool captures what people send. Your supervision queue reviews messages that have a recipient. The paste into ChatGPT, Gemini, or Copilot has no recipient, produces no sent item, and slips past all three.

Why a paste with no recipient is still an exposure

The instinct is that if nothing was sent to a person, nothing happened. That instinct is wrong under most confidentiality and data-protection regimes, because the duty attaches to the disclosure of the information, not to the existence of a named counterparty.

Three concrete duties make the paste itself the event:

  • Contractual confidentiality. A standard NDA restricts disclosure to “third parties” and requires you to control how the information is processed. A public AI tool is a third party. Pasting protected text into it can be a breach on its own terms, whether or not a human ever reads the output.
  • Data protection (GDPR). Putting personal data into a public tool is a processing operation and often a transfer to a processor you have not assessed, with no lawful basis and no data-processing agreement. Under Article 83, serious infringements carry fines up to EUR 20 million or 4 percent of global annual turnover, whichever is higher.
  • Trade-secret protection. Legal protection for a trade secret depends on having taken “reasonable steps” to keep it secret. A pattern of staff pasting source code or a customer list into consumer AI tools undercuts the argument that you took those steps at all.

The precedent here does not need to be about AI to be instructive. In the off-channel recordkeeping sweep, the SEC and CFTC levied over USD 2 billion in penalties across firms whose employees moved work onto unmonitored channels. Regulators did not need to prove the content was harmful. The failure was structural: business communication left the perimeter of what the firm could see and govern. A public AI paste is the same structural failure, one text box further along.

The usable part: what should never be pasted, and a safer workflow

Give your team something concrete. “Be careful with AI” changes no behavior. A short, memorable rule of what never goes into a public tool does. Below is a starting taxonomy you can adapt to your own data classification and circulate as a one-pager.

Never paste into a public AI tool

  • Signed or draft contracts, term sheets, and NDAs, including the counterparty names and commercial terms.
  • Personal data of customers, employees, or candidates: names tied to health, pay, performance, disciplinary, or contact details.
  • Customer or user lists, account numbers, and anything that identifies a specific client relationship.
  • Source code, credentials, API keys, and internal system details.
  • Unreleased financials, board material, and deal information before public disclosure.
  • Anything marked confidential, privileged, or restricted under your own classification scheme.

The safer workflow, three steps

Step Do this Why
1. Strip Remove names, numbers, and identifiers before you paste. Ask about “clause 7” using a redacted or synthetic version. The tool can help with structure and language without ever holding the protected data.
2. Contain Route real confidential work to an enterprise AI tier with a data-processing agreement, retention controls, and no training on your inputs. Moves the same task inside a boundary you have actually assessed.
3. Log Give people a clear “when in doubt, ask” path and record what tools are approved for what data class. Turns a silent habit into a governable one, and supports the “reasonable steps” defense later.

If you build one artifact from this post, make it that table plus the “never paste” list. It fits on a page, and a compliance officer can hand it to 200 employees on Monday.

Where a pre-send check fits (and where it does not)

A policy on a page still relies on people remembering it at the exact moment they are rushing. That gap is where a browser-level check earns its place. VerbaPulse includes an AI Guard capability that watches when someone pastes into a web AI tool (ChatGPT, Gemini, Copilot) and advises, before the data leaves the browser, when the text looks like it carries confidential or personal information. It is a quiet nudge at the point of the paste: “this looks like a customer list, are you sure?”

Be clear about what this is. It is an advisory prompt for the careless line, the well-meaning paste an employee never registers as risky. Here is the kind of phrase-level flag it surfaces:

  • Flagged: “Here is our full customer export, please summarize the churn risks” → Suggested: remove the export, paste the aggregate figures only.

It is not an adversarial security wall. It will not stop a determined insider who wants to exfiltrate data, and it is not a defense against a prompt-injected agent. Treat it as the front-end shield that catches the accidental cases early, so fewer of them ever reach your archiving, DLP, and supervision queues (the Smarsh and Proofpoint layers that AI Guard sits in front of, rather than replaces). The goal is a smaller pile of incidents downstream, caught while they are still just a paste and not yet a disclosure.

The takeaway

Do two things this quarter. First, publish the “never paste” list and the three-step workflow, and name which AI tools are approved for which data class, because most teams have never actually said so out loud. Second, decide whether an advisory nudge at the moment of the paste is worth having, given that the paste is invisible to every tool you already run. The exposure is not hypothetical, and it is compounding with every quarter your team gets more fluent with these tools.

If you want to see the browser-level nudge against your own workflows, the VerbaPulse 30-day Proof-of-Value Pilot runs up to 10 seats for EUR 120, credited to your plan if you continue. For the wider governance context, our EU AI Act resource hub maps where this sits alongside your other obligations.

This is general information, not legal advice. Check specific duties against your own contracts, jurisdiction, and data classification.

See it on your own emails

VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.

Start a pilot

Up to 10 seats. EUR 120, credited to your plan if you continue.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The Reference Reply That Creates Defamation Risk The Cost of One Sentence: What a Dozen Real Cases Reveal About Communication Risk →