Free tool · no signup
Safe to Paste? The 30-Second Workplace AI Check
Answer five questions and get a clear green, yellow, or red verdict — plus what to do instead — before you paste work information into ChatGPT or another AI tool.
The five questions
Pick the answer that best fits the specific tool, task, and information you're about to use. "Not sure" is a real answer — it usually means "ask first."
How to read the result
The same green / yellow / red language used in the RoleReady data guide.
Green — safe to paste (with care)
Approved tool, public or clearly approved content, nothing sensitive or identifiable. Paste the minimum and still review the output.
Yellow — pause, use placeholders or ask first
Something is unclear or could be abstracted. Replace real details with placeholders or a fictional example, or get a specific "yes."
Red — don't paste this
The content or the approval state doesn't support it. Use an approved internal system, a blank template, or a fictional example instead.
Why this matters (primary sources)
The check is built around guidance from the organizations that study this, not hunches.
- Use only company-authorized AI services. Microsoft advises employees to follow their organization's policies, use only company-authorized AI services, and avoid disclosing "sensitive or confidential company details, including personal information about employees or vendors." Microsoft Support
- AI can make mistakes. Microsoft's same guidance says to "always double-check AI-generated results before using them in your work," because AI can make mistakes. Microsoft Support
- Untrusted content can carry prompt injections. OWASP documents how instructions hidden in documents, web pages, or emails can manipulate a model's behavior, including unauthorized actions and data exfiltration. OWASP Cheat Sheet Series
- Removing names is not automatic anonymisation. The UK Information Commissioner's Office explains that data can still be re-identified from indirect details, and that pseudonymised data is still personal data. ICO
- Generative AI needs risk management. NIST's Generative Artificial Intelligence Profile (NIST AI 600-1) catalogs generative-AI risks and recommends risk-management practices. NIST
- Data controls differ by product and plan. OpenAI publishes a Data Controls FAQ; data-use settings and terms vary by product, so verify the specific tool your employer approves. OpenAI Help Center
The method behind the check
Don't give the AI the sensitive document. Ask for the structure, method, questions, or template instead.
- Name the task. Decide whether you need a checklist, structure, formula, set of questions, or a first-draft framework.
- Replace the real context. Use placeholders, fabricated examples, and only the minimum needed to explain the pattern.
- Reapply and review privately. Add real facts later in an approved environment, then verify every output before anyone relies on it.
Turn the habit into a system
This check is a fast screen. If you want the reusable daily system — the green/yellow/red data guide, the five-question check on paper, 30 copy-ready prompts, and review worksheets — it's a one-time download.
Prefer a book? Read Safe AI at Work on Amazon — $2.99 USD (sold separately; does not include the kit's downloadable files).
Limitations
Read these — they're the honest part.
- This is practical productivity education, not legal advice, a compliance audit, a cybersecurity test, an employer policy, or authorization to use any AI tool.
- A green result is not a compliance guarantee. Your employer's policy, approved-tool list, contracts, and professional obligations always come first.
- This check does not evaluate a specific tool's terms, data controls, or security. Those differ by product and plan — verify them separately.
- It cannot tell you whether a lightly edited document is truly anonymous. True anonymisation can require specialist analysis.