I put sensitive data into an AI chat. What do I do now?
First, breathe. A one-second mistake is not a catastrophe — but it does need a few steps taken now, in the right order. The key idea: deleting is not the first step — changing what can be used against you (passwords, card) is. You delete and turn off training right after. Take the steps one at a time.
First steps, right now
- Take stock first: what exactly did you put in there — a password? card details? your CNP (personal identification number) or a photo of an ID document? client data? Write it down exactly, because the next steps depend on it.
- Treat the data as exposed and act on each item: the password — change it now and turn on two-step verification; the card — call your bank on the number on the back of the card and ask for it to be blocked or reissued; the ID document/CNP — over the coming period, watch out for accounts or loans opened in your name.
- Only then delete the conversation from the app's history and turn off, in the settings, the use of your conversations for training (most AI apps have the option). Deleting limits the damage, but doesn't undo it — that is why the step with the passwords and the card comes first.
- If it was work data (clients, contracts, financial data): tell your IT team or your data protection officer immediately. Don't wait — the company has legal reporting deadlines and can limit the damage only if it finds out quickly.
- If it was someone else's data (a client, a friend, family): tell that person, so they too can change their password or keep an eye on their account if needed.
What NOT to do
- Don't reassure yourself with "it's just a chat" — what you wrote has already left for a company's servers; work on the assumption that it isn't coming back.
- Don't continue the conversation with even more details to "fix it" — you are adding exposure, not reducing it.
- Don't hide the incident from your company if it was work data — it's the delay that makes things worse, not the mistake itself.
- Don't pay for "services" that promise to delete your data from the AI — they can't; deletion is done only from the app's official settings.
How to spot it next time
- It almost always happens in a hurry: you paste a whole email, a contract or a spreadsheet "to have it summarised", with all the real data still in it.
- You send a photo of an entire ID document to get help with a form, instead of covering the details that aren't needed.
- It's not just what you paste: if the assistant is connected to your email or files, it reaches sensitive data on its own — see the playbook about connecting the assistant to other apps.
- The rule for next time: if you wouldn't write it on a public noticeboard, don't paste it into an AI chat — see the guide "What NOT to put into AI tools".
This guide is meant to help you act fast. It does not replace official instructions from your bank, the police or the authorities. When in doubt, call the numbers above.