Top 5 This Week

spot_img

Related Posts

10 Things You Should Never Share With AI Chatbots

AI chatbots have quickly become part of everyday life.

People now use tools such as ChatGPT, Gemini, Claude and other AI assistants to write emails, study, prepare reports, understand documents, solve problems and even make important personal decisions.

However, there is one habit every AI user needs to develop:

Think before you type.

An AI chatbot may feel like a private conversation because you type a question and receive an immediate answer. But that does not mean you should treat every AI service like a private diary, password manager or secure banking system.

The safest approach is simple: never give an AI chatbot information it does not actually need to complete your task.

Cybersecurity authorities give similar advice. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), for example, recommends avoiding sensitive, confidential and personal information when using generative AI tools.

Here are 10 things you should think twice about—and generally avoid sharing—with AI chatbots.

1. Your Passwords

Your passwords should remain private, whether you are talking to an AI chatbot, another person or an online support service.

Never type your Gmail password, Facebook password, banking password, Wi-Fi password or workplace login credentials into a chatbot simply because you need help with an account.

The same rule applies to password recovery information.

For example, you can safely ask:

“How do I change my Gmail password?”

But you should not write:

“My Gmail password is ABC123. Is this secure?”

If you want AI to suggest a password structure, ask for an example rather than providing your real password.

Even better, use a reputable password manager to create and store unique passwords.

2. Banking Details and Credit or Debit Card Information

Never use an ordinary AI chat as a place to store or process your complete financial credentials.

Avoid entering your full debit or credit card number, PIN, CVV security code, online banking password or one-time verification code.

The same principle applies whether you live in Pakistan, the United States or anywhere else.

If you want an AI chatbot to explain a bank statement, remove information that can identify you or provide access to your account before uploading it.

For example, you might replace:

Account Number: 123456789

with:

Account Number: XXXXXXXX

You can still receive help understanding charges, fees or financial terminology without exposing information the chatbot does not need.

3. OTPs and Verification Codes

An OTP, or one-time password, may remain valid for only a few minutes.

That does not make it safe to share.

Banks, email providers, social networks and other services use OTPs to confirm that the person attempting to log in or complete a transaction actually controls the account or device.

Therefore, treat every OTP like a temporary password.

Never paste an OTP into an AI chatbot and ask what it means.

You can simply ask:

“I received an unexpected login verification code. What should I do?”

The AI does not need the actual code to answer that question.

This rule also protects you from scams.

If anyone contacts you claiming to represent a bank or technology company and asks for your OTP, do not provide it without independently verifying the request through the organisation’s official channels.

4. Your CNIC, Social Security Number or Other National ID Numbers

Identity numbers are particularly sensitive.

For Pakistani users, this includes your CNIC or NICOP number.

For Americans, it includes your Social Security number (SSN).

The same principle applies to national identification numbers used in other countries.

These numbers can form an important part of identity verification. In the wrong circumstances, exposed identity information can contribute to identity theft, impersonation or fraudulent applications.

If you need help completing a form, you usually do not need to provide your real number.

Instead of typing:

CNIC: 12345-1234567-1

write:

CNIC: XXXXX-XXXXXXX-X

AI can still explain where the information belongs or how a form works.

5. Passport, Driver’s Licence and Immigration Documents

AI can be extremely useful for explaining visa requirements, immigration terminology or travel documents.

However, that does not mean you should automatically upload your entire passport.

A passport contains several pieces of identifying information.

Similarly, a U.S. driver’s licence, Pakistani driving licence, visa document or residence permit may contain your photograph, date of birth, document number and other personal details.

Suppose you want AI to explain a sentence on a visa letter.

Instead of uploading every page of your passport and immigration file, provide only the relevant text after removing identifying details.

The principle is:

Share the minimum information necessary to get the answer.

6. Confidential Workplace Information

This is one of the biggest risks for employees using AI at work.

Imagine your manager sends you a confidential document and asks for a summary.

Uploading the entire document to a consumer AI chatbot may be inappropriate if it contains confidential company information.

Examples can include:

  • Unreleased financial results
  • Customer databases
  • Employee records
  • Internal passwords
  • Business strategies
  • Confidential contracts
  • Product designs
  • Source code
  • Trade secrets
  • Acquisition plans

CISA specifically advises users to avoid putting sensitive or confidential workplace information into AI systems.

The UK’s National Cyber Security Centre has also highlighted the importance of preventing sensitive information from being exposed through AI systems.

Before using AI for work, check your employer’s AI and data-security policies.

Companies using approved business AI services may have different privacy and data-handling arrangements from ordinary consumer accounts.

7. Private Information About Other People

Privacy does not stop with your own information.

You should also think carefully before sharing someone else’s private information.

Suppose you want AI to help write an employee performance report.

You probably do not need to provide the employee’s complete home address, phone number, national ID, personal email address and other unrelated information.

The same applies to customers, students, patients, friends and family members.

Remove names and identifying details whenever they are unnecessary.

Instead of writing:

“John Smith, who lives at [full address], has this workplace problem…”

you can write:

“One of my employees has this workplace problem…”

You will often receive essentially the same useful answer without exposing another person’s identity.

8. Detailed Medical Records With Unnecessary Personal Information

AI tools can help people understand general health terminology, prepare questions for a doctor or make sense of information.

But medical records can contain extremely sensitive information.

A laboratory report may include your full name, date of birth, address, patient number, hospital registration number and other identifying details.

If your goal is simply to understand a cholesterol reading, blood glucose result or another measurement, the AI generally does not need all of that identifying information.

Remove unnecessary details first.

For example, you can ask:

“What can an HbA1c result of X% generally indicate?”

rather than uploading an entire medical record containing your identity and unrelated history.

AI should also not replace qualified medical care when decisions involve diagnosis, medication changes or urgent symptoms.

9. Intimate Photos, Private Videos or Highly Personal Content

People increasingly use AI to analyse and edit images.

That makes another privacy rule important.

Do not casually upload intimate photographs, private videos or highly sensitive personal material to an AI service without understanding how that service handles uploaded content.

This becomes even more important when another person appears in the material.

Their privacy matters too.

Before uploading any personal image, ask yourself:

Does the AI actually need this image to perform the task?

If the answer is no, do not upload it.

If an image is necessary, consider cropping or removing irrelevant identifying information first.

The same principle applies to children’s photographs and documents.

Be particularly careful when the content involves someone who cannot meaningfully consent to how their information is being used.

10. Secrets You Cannot Afford to Expose

This final category covers everything that does not neatly fit into the previous nine.

Before sharing something with an AI chatbot, ask yourself one question:

“What would happen if this information became known to someone else?”

If the answer is:

“I could lose money.”

“I could lose my job.”

“My business could suffer.”

“Someone could access my account.”

“This could seriously embarrass or harm me.”

“This would violate someone else’s privacy.”

then think carefully before entering it into an AI service.

This could include confidential legal strategy, unreleased business information, private relationship conversations, security credentials, recovery codes, encryption keys or other secrets.

CISA offers a useful rule of thumb: avoid sharing information with AI that you want to keep private.

Does This Mean AI Chatbots Are Unsafe?

No.

The point is not that every AI chatbot is automatically unsafe.

The better lesson is that different AI services have different privacy policies, settings, business models and data-retention practices.

Users should understand those differences.

For example, ChatGPT provides controls over whether conversations can be used to improve models. OpenAI says users can disable “Improve the model for everyone” in Data Controls. New conversations will then remain in chat history but will not be used to train ChatGPT.

ChatGPT also offers Temporary Chat.

According to OpenAI, Temporary Chats do not appear in regular chat history, do not create new memories and are not used to improve its models. OpenAI says temporary conversations may still be retained for up to 30 days for safety purposes.

Other AI services have their own policies and settings, so users should check the service they are actually using rather than assuming all chatbots handle information identically.

What Should You Do Before Uploading a Document to AI?

Documents deserve special attention because people often forget how much hidden personal information they contain.

Before uploading a PDF, bank statement, CV, contract, medical report or official document, look through it carefully.

Remove information that the AI does not need.

That can include your account number, home address, phone number, personal email, signature, national ID number, passport number and customer reference numbers.

You can also replace names with labels.

For example:

Employee A

Customer B

Company X

This technique is often called anonymisation or redaction.

It allows you to keep much of AI’s usefulness while reducing unnecessary exposure.

Be Extra Careful With AI Tools Connected to Other Apps

Modern AI assistants can sometimes connect with external services and applications.

That can make them much more useful, but it also means users should understand what information an app can access.

OpenAI, for example, says users receive information about data access when connecting apps and can disconnect an app to remove its access.

Whenever you connect any AI service to email, cloud storage, workplace systems or another account, review the requested permissions.

Do not approve access automatically.

Ask whether the tool genuinely needs each permission to perform the task.

A Simple Rule Everyone Can Remember

You do not need to become a cybersecurity expert to use AI more safely.

Remember this rule:

Give AI the information it needs—not everything you have.

Want help writing an email?

AI needs the message, not your banking password.

Want help understanding a laboratory result?

It may need the relevant values, not your passport number.

Want help with a contract?

It may need the clauses in question, not confidential information about every customer.

Want advice about an account problem?

Describe the problem without revealing your password or OTP.

AI becomes much safer to use when you develop this habit.

What If You Already Shared Sensitive Information With an AI Chatbot?

Do not panic, but take appropriate action based on what you exposed.

If you shared a real password, change it immediately and avoid reusing the old password elsewhere.

If you exposed banking credentials or card information, contact your bank through its official channels and follow its security instructions.

If you exposed an OTP, recovery code or API key, replace or revoke it where possible.

You should also review the AI service’s options for deleting conversations and managing your data.

For ChatGPT specifically, OpenAI provides controls for deleting chats, managing model-improvement settings and using Temporary Chat for conversations where additional privacy is desired.

opinion