Skip to content
Nullgen AI Blocker

BlogIT and security

How to prevent ChatGPT data leaks at work: where pasted company data goes and how to stop it

Most company data that reaches an AI tool is not stolen. It is pasted, by an employee doing their job, into a consumer account nobody manages. Here is where that data goes once it leaves the clipboard, the channels it travels, six layers that stop it in the right order, and what none of them cover.

The Nullgen team

13 min read

The ChatGPT data leak most companies will suffer does not look like a breach. It looks like a support lead pasting a ticket thread into a free account to draft a reply, an analyst uploading a spreadsheet to “summarize the trends,” or an engineer asking an assistant to debug a function with the production credentials still in it. Nobody broke in. The data walked out through the clipboard.

This guide is the practical version of the question security teams are asking: how do we stop employees leaking data to ChatGPT and the tools like it without banning something the business now depends on? It covers the channels data actually travels, what happens to a prompt once it leaves the device, the six controls that stop the leak in the order they pay off, and the gaps none of them close.

Six ways company data reaches an AI tool

The volume is not hypothetical. A 2025 browser-telemetry study across enterprise users found that 77 percent of employees who use generative AI paste data into it, 82 percent of those pastes come from personal accounts the company cannot see, and about a fifth contain personal or payment-card data. Uploads are worse: roughly 40 percent of files sent to AI sites contained that kind of data. The paste is the leak, and these are the forms it takes.

  • The paste

    Contract clauses, customer lists, source code, meeting notes. Clipboard to prompt box in one keystroke, with no file for a download control to catch.

  • The upload

    “Summarize this” with a spreadsheet, a PDF, or a slide deck attached. Whole documents leave at once, including the columns nobody meant to share.

  • Screenshots and photos

    A screenshot of a dashboard, a photo of a whiteboard, a picture of a printed page. Text controls never see it because it is an image.

  • Connectors and plugins

    Email, drive, and calendar integrations grant an assistant standing access to everything the user can read, long after the first question.

  • Browser extensions and sidebars

    “Summarize this page” extensions read every page the user opens, including internal tools, and send the text to whichever model they were built on.

  • The personal account

    A work prompt in a personal login lands under a consumer privacy policy, outside every contract and admin control the company has.

Notice what these have in common: none of them generates a file transfer, a new domain, or a login your identity provider sees. Classic data loss prevention was built for attachments and uploads. Most of these channels never produce one.

What happens to a prompt after you press Enter

Where the data ends up depends almost entirely on which account it was typed into. The same question in a consumer account and in a managed business workspace follows two different paths, and most employees do not know which one they are on.

Is the prompt used to train models?

Consumer account (free or personal paid)
By default on ChatGPT and Gemini, and on Claude if the user accepts the prompt to allow it. Opting out is a per-account setting the company cannot see.
Managed business or education workspace
Not by default on ChatGPT Business, Enterprise, and Edu, Gemini for Workspace, Claude for Work, or the APIs. Set by contract.

Can a person read it?

Consumer account (free or personal paid)
Possibly. Google says a subset of Gemini chats is read by reviewers, and reviewed chats are kept for up to three years even if the user deletes them.
Managed business or education workspace
Governed by the agreement and admin settings; abuse monitoring may still apply.

How long is it kept?

Consumer account (free or personal paid)
Months to years. Gemini keeps activity for 18 months by default; Claude keeps training-enabled chats for five years; a 2025 court order made OpenAI keep consumer chats it would otherwise have deleted.
Managed business or education workspace
Admin-controlled retention, with zero-retention options for API use and workspace-level deletion.

What can the company do about it?

Consumer account (free or personal paid)
Nothing. It cannot see, export, or delete the account’s history, and off-boarding an employee does not reach it.
Managed business or education workspace
Single sign-on, audit logs, retention settings, workspace export and deletion, and a data processing agreement.

Can it end up public?

Consumer account (free or personal paid)
It has. In 2025 ChatGPT’s share links could be marked discoverable, and reporters found thousands of them in Google results before the option was removed.
Managed business or education workspace
Sharing scoped to the workspace.
Consumer account versus managed business workspace, as the major vendors document them

The vendors publish these rules themselves. OpenAI states that content from its services for individuals may be used to train its models unless the user turns that off, and that Business, Enterprise, Edu, and API data is excluded by default. Google’s Gemini Apps privacy notice says activity is used to improve its models while the setting is on, that a subset of chats is reviewed by people, and that reviewed chats are retained for up to three years. Anthropic’s 2025 terms update asked Free, Pro, and Max users to choose whether their chats train future models, with five-year retention if they agree, and excluded Claude for Work and API use.

Then there is what nobody plans for. In 2025 a court order in a copyright case required OpenAI to retain consumer ChatGPT conversations it would otherwise have deleted, for months, while business plans were excluded. In March 2023 a bug showed some users the titles of other users’ conversations and exposed payment details of about 1.2 percent of Plus subscribers. In August 2025 OpenAI removed a “make this chat discoverable” option after shared conversations, some containing confidential material, turned up in search results. And the Samsung engineers who pasted source code into ChatGPT in 2023 did not do anything the tool warned them against. A prompt is a disclosure to a third party. Treat it as one.

Six layers that stop the leak, in the order they pay off

No single control covers every channel. The sequence below starts with the cheapest control that removes the most risk and ends with the one most teams skip, which is the one that actually changes behavior at the keyboard.

  1. 1

    Give people a sanctioned tool with the right contract

    License a business or enterprise tier of at least one assistant, behind single sign-on, with training off by contract and retention you control. Most pasting into personal accounts happens because the company offered nothing. This step alone moves the majority of prompts under an agreement you can audit.

  2. 2

    Write the data rule in one sentence

    “If the tool is not on the approved list, the data is public.” Pair it with three or four named data classes people can recognize at a glance: customer data, source code, financials, anything under NDA. Keep the whole policy to one page.

  3. 3

    Block the paste on every managed browser

    Policy covers the people who remember it. For everyone else, a browser extension that blocks typing and pasting into AI prompt fields on unapproved tools stops the leak at the moment it happens, without reading what was typed, and without a proxy or certificate rollout. Approved tools stay open; everything else goes dark.

  4. 4

    Cover the phone

    Consumer AI apps on a managed phone sit outside app protection policies and the corporate network. Block known AI apps and websites on the device through your MDM, so the shortcut is not simply moved from the laptop to the pocket.

  5. 5

    Point DLP at the uploads

    Where DLP and CASB earn their keep is the file channel: uploads of labeled documents to unapproved domains, large pastes containing card numbers or keys, OAuth grants to AI connectors with broad scopes. Tune those rules; do not expect them to catch a paragraph of prose.

  6. 6

    Make the exception path faster than the workaround

    A blocked tool with no way to ask becomes a personal phone. Route requests to a named approver with a time limit, so a researcher who needs Perplexity for an afternoon gets it in minutes and loses it on schedule. Watch the request log; it tells you which tool to approve next.

Layers one and two are policy and procurement; our acceptable use policy guide has a one-page template. Layers five and six are tuning. Layers three and four are where most programs have a hole, because they require a control at the device rather than at the network, and that is new for many teams; the managed mobile guide covers the phone side with Intune, Jamf Pro, and Iru. The shadow AI guide explains why network and DLP controls miss prompt-based leakage. The short version is that the data never looks like a file.

Where prompt blocking fits

Nullgen’s browser extension blocks the prompt box itself on ChatGPT, Claude, Gemini, Perplexity, Copilot on the web, and the 100+ other AI tools in its catalog, in Chrome, Edge, Firefox, and Safari. The page loads, the input stops accepting typed or pasted text, and nothing the employee tried to enter is sent anywhere, including to Nullgen. Tools you have approved are allowed by policy, for everyone or for the teams that need them.

The mobile app does the same job on managed iPhones and iPads by blocking known AI apps and websites on the device, and Android is next on the same enrollment. Everything links to one dashboard, where approvers handle requests and policies sync to devices in real time.

On a managed browser the prompt box stops accepting typed or pasted text. The rest of the page, and the approved assistant, keep working.
A request for a blocked tool reaches the approver you name, with a duration. Approve for an hour, a project, or permanently.
  • Force-install through Intune, Jamf, Google Workspace, or Group Policy, so browsers enroll on their own and employees cannot remove it.

  • Allow and deny policies per person, per team, or company-wide, from the same catalog on browsers and phones.

  • Owner, Admin, Approver, and Viewer roles, so a team lead can approve requests without administering users or devices.

  • Laptops, phones, and tablets side by side on the Devices page, assigned to the people who use them.

Nothing anyone types is read or stored. The extension recognizes a prompt field and blocks input to it; it does not inspect the text, keep browsing history, or send page content to Nullgen. That matters for the works council conversation as much as for the privacy review.

What this does not solve

Be precise about the boundary, because an overstated control is the kind that gets switched off after the first exception.

  • AI inside tools you already license

    Copilot in Office, Gemini in Workspace, and the assistant in your CRM share hosts with the product itself. Govern those by contract and admin settings; blocking them would break the product.

  • Personal devices you do not manage

    A personal laptop or an unenrolled phone is out of reach. Policy, the sanctioned tool, and a culture where asking is easy are what cover it.

  • Voice, photos, and memory

    A question spoken to an assistant on a personal phone, or a photo of the screen, leaves no clipboard to block. Training and the approved path do the work here.

Nullgen blocks known AI tools and the list grows continually, but it is a list, and new tools appear weekly. The approval log is your early warning: a request for a tool you have never heard of is usually the first time you hear of it.

A 30-day plan

Most teams can get from nothing to a working control in a month, and the first three weeks need no procurement cycle.

  • Week one: pull proxy, DNS, and identity logs for the top AI domains, and ask three teams what they actually use. Pick the sanctioned tool and start the business-tier contract.

  • Week two: publish the one-sentence data rule and the approved list. Install the free extension on your own team’s browsers and try to paste something into a blocked tool.

  • Week three: pilot prompt blocking with the team that complained loudest about the ban, with a named approver and a one-day default on exceptions. Read every request.

  • Week four: force-install through your MDM, add managed phones, tune DLP for uploads to unapproved domains, and schedule a monthly review of the request log and the approved list.

Key takeaways

  • Company data reaches AI tools through pastes, uploads, screenshots, connectors, and extensions, mostly from personal accounts. Most of those channels never create a file for DLP to catch.

  • A consumer account trains on prompts by default, may show them to reviewers, keeps them for months or years, and gives the company no controls. A business workspace does none of that, by contract.

  • Stop the leak in order: sanctioned tool, one-sentence data rule, prompt blocking on managed browsers, the same on phones, DLP for uploads, and a fast exception path.

  • The browser is where the paste happens, so it is where the control belongs. It needs no proxy and no certificates, and it works off the corporate network.

  • AI built into licensed products, unmanaged personal devices, and spoken or photographed prompts are governed by contract and culture, not by a block.

Frequently asked questions

  • If we buy ChatGPT Enterprise, is the problem solved?

    It solves the problem for prompts typed into that workspace. It does nothing about the free accounts employees already have, or about the other tools they use. Pair the sanctioned tool with a control that keeps work data out of everything else.

  • Why not just block the AI domains at the firewall?

    A domain block covers the office network and nothing else, and it pushes people to phones and home Wi-Fi. It also blocks the approved tool along with the rest. Prompt blocking on the managed browser follows the device and leaves approved tools open.

  • Does prompt blocking mean we read what employees type?

    No. The extension recognizes an AI prompt field and prevents input to it. It does not read, store, or transmit the text, keep browsing history, or send page content anywhere.

  • What about Copilot in Microsoft 365 or Gemini in Google Workspace?

    Those run under your existing contracts and admin controls, and they share hosts with the products themselves, so Nullgen does not block them. Decide in policy which data classes may go into them, as you would for any licensed tool.

  • Do we really need to cover phones?

    Yes, if you manage them. The ChatGPT app on a managed iPhone is one tap from the same customer list, on a cellular connection your proxy never sees. The mobile app blocks known AI apps and websites on managed iPhones and iPads, and Android is next.

  • How long does a rollout take?

    The free extension installs in minutes on one machine. A managed rollout through Intune, Jamf, Google Workspace, or Group Policy is typically a week of pilot and a week of fleet-wide push. Enterprise starts with a 30-day trial with no card.

Further reading

  1. The Register, “Employees regularly paste company secrets into ChatGPT,” on the LayerX Enterprise AI and SaaS Data Security Report, October 2025
  2. OpenAI Help Center, “How your data is used to improve model performance”
  3. Google, Gemini Apps Privacy Hub
  4. Anthropic, “Updates to Consumer Terms and Privacy Policy,” August 2025
  5. OpenAI, “How we’re responding to The New York Times’ data demands in order to protect user privacy,” 2025
  6. OpenAI, “March 20 ChatGPT outage: Here’s what happened,” March 2023
  7. The Register, “OpenAI removes ChatGPT self-doxing option,” August 2025
  8. TechCrunch, “Samsung bans use of generative AI tools like ChatGPT after April internal data leak,” May 2023

Close the paste this month

Install the free extension on your own laptop and try to paste a customer record into a chatbot. Then start a 30-day Enterprise trial with no card and push the same control through the MDM you already run, phones included.