Why underwriters ask about it
cyber insurers explicitly flag employees pasting sensitive data into public AI tools as a privacy exposure they now underwrite.
How to fix it
- Adopt the never-list: Social Security numbers, card numbers, passwords, medical details, full customer files — never entered into any AI tool.
- Use business accounts with model-training turned off (see R5.3) for anything work-related.
- Put the never-list where work happens: in the policy, and pinned wherever staff chat with AI.
Evidence to keep
the never-list in the signed policy.