Ask most privacy officers what their AI policy says, and you get a version of the same answer: don't put client names in a prompt, don't paste account numbers, think before you type. Reasonable rules. Sometimes even backed up by a tool that highlights sensitive text before someone sends it.
Ask the same person what the policy says about a full case file getting uploaded to ChatGPT for a summary, and the answer changes. Usually there isn't one.
Policy was written for the prompt
That is not carelessness, it is history. The first wave of AI risk advice came out of chatbot use: someone types a question, the model answers, the risky moment is the sentence in the message box. Policies, training, and tooling all got built around that picture, and it is not wrong. It is just incomplete.
AI tools have moved past the text box. Upload a PDF, attach a spreadsheet, drop in a report, and the model reads the whole thing. None of that goes through the typing-focused advice at all, because nobody typed the risky part. It arrived as a file.
A file carries more than a prompt ever will
A typed prompt is a few sentences someone composed on the spot, which is exactly why prompt-level advice works: there is a moment, a text field, a chance to look before sending. A ten-page case file, contract, or internal report is different. It was written for another purpose, by someone who was not thinking about AI at all, and it typically carries far more personal data than any prompt would: names, dates of birth, national ID numbers, financial details, references to people who are not even the subject of the document.
None of that is unusual. It is what a normal working document looks like. The gap is that policy, training, and most tooling assume the risky content was typed, when a growing share of it never was.
What closes the gap is not another paragraph
Adding a line to the policy ("do not upload documents with personal data") does not solve this any more than "do not paste sensitive data into ChatGPT" solved the typing problem on its own. People need a control at the moment the document is about to go somewhere, the same logic that already applies to typed prompts, applied to files.
BeeSensible's desktop app opens a PDF, marks the sensitive fields on the page, most sensitive ones called out more strongly, and produces a clean copy once someone has reviewed and redacted what needs it.