It takes about two seconds, and it genuinely works. You copy a block of text, paste it into a chatbot, and get back in a moment what would have taken an hour. That trade is why your team keeps making it, and most of the time it's a good trade. The part nobody priced is what the paste costs when the text is the wrong text: in those two seconds it leaves your company, and on most consumer tools it leaves for good.
Where "the cloud" actually goes
When you type into a chatbot, the words don't stay on your screen. They travel to the provider's servers to be processed. That part is true of almost any web service, and on its own it isn't alarming. The part that matters for work is what happens next.
On free and personal tiers, the text you submit can be retained and used to help train future versions of the model. Your input becomes part of the system. There's no recall button, no way to reach in and pull a specific paragraph back out. Paid enterprise plans usually change this with a contract that turns training off, but that protection only exists if your organization is on such a plan and has set it up. By default, the door swings one way.
Samsung learned this in public
This isn't a worst-case thought experiment. Within about three weeks of allowing ChatGPT internally, Samsung engineers had pasted proprietary source code and an internal meeting transcript into it on three separate occasions. The company banned generative AI tools on company devices soon after.
Look at the order of events. The ban came after the data was already gone. That's the hard thing about this kind of exposure: every control you can think of acts on the next paste, never the one that already happened. Once the data leaves, the decision has already been made for you.
It happens far more than anyone tracks
The Samsung engineers weren't unusual, only unlucky enough to be noticed. Cyberhaven, analyzing real usage across 1.6 million workers, found that 11% of everything employees paste into ChatGPT is sensitive, with internal-only documents, source code, and client data at the top of the list. Roughly one in nine pastes carries something the company would not want sitting in a third party's training data.
None of this comes from bad intent. It comes from a tool that is genuinely useful and a moment of friction someone wanted gone. The contract is dense, the chatbot summarizes it in seconds, and the trade looks free because the cost is invisible and deferred.
The decision the paste skips past
Every one of those pastes is a tiny, unconsidered decision about what your company is willing to send out into the world. Right now, your people are making that decision hundreds of times a week, alone, on instinct, with no line to tell them when to stop.
The fix isn't to scare people off a useful tool. It's to draw the line once, clearly (a simple traffic-light call on data: green goes in, yellow with care, red never), so the two-second paste doesn't have to carry a judgment call it was never meant to hold. Drawing that line is the foundation of the governance systems we build, and it's the part your team keeps applying to every new tool without us. Seeing what's already flowing out comes first: the AI Readiness Assessment maps where AI is in use across your organization and what kind of data is going into it, in about two minutes.
The moment the data leaves is the moment the choice is gone. The only place left to make it is before.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- What's Safe to Paste Into ChatGPT?. The line that decides what's fine to send out.
- The 4 Stages of AI Governance Maturity. What structure underneath the paste looks like.