Your AI Isn't Private. But That's Not the Whole Story.
by Claire L. Brady
A recent privacy scare involving Anthropic's Claude made headlines when users discovered that conversations shared through public links could be indexed by search engines. Anthropic quickly addressed the issue, but the incident sparked a much larger conversation about AI privacy—and revealed a common misconception.
Many people assume that a conversation with ChatGPT, Claude, Gemini, or Copilot is either completely private or completely public depending on your license. The reality is far more nuanced.
Not all AI environments are the same
In the past few years, many colleges and universities have invested in enterprise AI platforms. These versions often include stronger contractual protections, enhanced security, single sign-on, administrative oversight, and commitments that institutional data will not be used to train public AI models. Those investments are important, and they significantly reduce many of the risks associated with consumer AI tools.
Enterprise licensing isn't the end of the story
Even in a well-governed AI environment, users still make decisions every day that affect privacy and security. They create public sharing links. They connect third-party services. They enable memory features. They switch between their personal AI account and their institution's enterprise account without realizing the difference. They may even paste confidential information into the wrong tool entirely. In other words, technology can provide guardrails, but it can't replace judgment.
That's why I believe it's time to retire one of the most common pieces of AI advice: "Don't put sensitive information into AI." While well intentioned, that guidance is becoming increasingly incomplete. The better question is: Am I using the right AI environment for this task? That's a much more practical—and ultimately more sustainable—way to think about AI.
Imagine asking a colleague to review a draft document. You would likely make different decisions depending on whether that conversation happened in your office, over a secure institutional platform, or in a crowded airport terminal. The content might be the same, but the environment changes your level of trust.
AI works the same way. The conversation shouldn't begin with Can I use AI?
It should begin with:
Which AI platform am I using?
Is this my institution's approved enterprise environment or my personal account?
What happens to the information I enter?
Who can access this conversation?
Have I enabled features like memory or public sharing?
Those are questions every faculty member, staff member, administrator, and leader should understand.
AI literacy is evolving
A year ago, many institutions focused on teaching people how to write better prompts. Today, prompt engineering is only one piece of responsible AI use. We also need to teach people how to evaluate the environment they're working in, understand privacy settings, recognize the differences between enterprise and consumer tools, and make informed decisions about institutional data.
That shift is subtle, but significant.
The future of AI governance won't be built on blanket rules or fear-based warnings. It will be built on helping people exercise good judgment in different contexts. Just as we teach employees to recognize phishing emails, create strong passwords, and use multi-factor authentication, we now need to help them understand that not every AI environment offers the same protections—or should be used for the same purposes.
The goal isn't to discourage AI use. It's to help people use the right AI, in the right environment, for the right task. That's a much more valuable skill than simply telling people to avoid AI altogether.
5 Questions to Ask Before You Use AI at Work
1. Which AI am I using?
This is the most important question. Are you using your institution's approved enterprise AI platform—or a public consumer version? They may look nearly identical but have very different privacy, security, and data protections.
2. Am I logged into the right account?
Many institutions provide enterprise access to tools like Gemini, Copilot, Claude, or ChatGPT. But it's surprisingly easy to accidentally open your personal account instead. Don't assume you're protected just because your institution has a license.
3. What data am I about to share?
Consider the sensitivity of the information before you hit enter. Student records, personnel information, legal matters, research data, and confidential institutional discussions all deserve additional care—and should align with your institution's policies.
4. What else can this AI access?
Many AI tools can connect to your email, calendar, cloud storage, or other applications. Before enabling those features, understand what information you're giving the AI permission to see.
5. Would I be comfortable explaining my choices?
If someone asked why you chose this AI platform for this task, could you explain your reasoning? Good AI use isn't just about getting the right answer—it's about using the right tool in the right environment for the right purpose.
This image created using ChatGPT