Control over AI
Blog
GDPR and workplace AI 6 min read

Your AI policy covers what people type. What about the file they attach?

Most AI policies are written for the prompt: don't type client names, don't paste account numbers. Almost none of them say anything about the report, case file, or spreadsheet someone uploads whole. That gap is not small.

Privacy officer reviewing an AI policy document
Quick answer

Most AI policies tell staff what not to type into a prompt. Very few say anything about attaching or uploading a full document. That is a real gap: a single PDF upload can carry more personal data than months of typed prompts, and no typing-focused rule catches it. Closing the gap means adding a document step, not just a prompt step, to how you think about AI risk.

01

AI policies are almost always written around the moment of typing

02

Full-document uploads bypass every rule that assumes someone typed the risky part

03

A ten-page case file carries far more personal data than a typed prompt ever will

04

Closing the gap needs a document-level control, not another paragraph of policy

Ask most privacy officers what their AI policy says, and you get a version of the same answer: don't put client names in a prompt, don't paste account numbers, think before you type. Reasonable rules. Sometimes even backed up by a tool that highlights sensitive text before someone sends it.

Ask the same person what the policy says about a full case file getting uploaded to ChatGPT for a summary, and the answer changes. Usually there isn't one.

Policy was written for the prompt

That is not carelessness, it is history. The first wave of AI risk advice came out of chatbot use: someone types a question, the model answers, the risky moment is the sentence in the message box. Policies, training, and tooling all got built around that picture, and it is not wrong. It is just incomplete.

AI tools have moved past the text box. Upload a PDF, attach a spreadsheet, drop in a report, and the model reads the whole thing. None of that goes through the typing-focused advice at all, because nobody typed the risky part. It arrived as a file.

A file carries more than a prompt ever will

A typed prompt is a few sentences someone composed on the spot, which is exactly why prompt-level advice works: there is a moment, a text field, a chance to look before sending. A ten-page case file, contract, or internal report is different. It was written for another purpose, by someone who was not thinking about AI at all, and it typically carries far more personal data than any prompt would: names, dates of birth, national ID numbers, financial details, references to people who are not even the subject of the document.

None of that is unusual. It is what a normal working document looks like. The gap is that policy, training, and most tooling assume the risky content was typed, when a growing share of it never was.

What closes the gap is not another paragraph

Adding a line to the policy ("do not upload documents with personal data") does not solve this any more than "do not paste sensitive data into ChatGPT" solved the typing problem on its own. People need a control at the moment the document is about to go somewhere, the same logic that already applies to typed prompts, applied to files.

BeeSensible's desktop app opens a PDF, marks the sensitive fields on the page, most sensitive ones called out more strongly, and produces a clean copy once someone has reviewed and redacted what needs it.

PreviewAnonymise (4)
The desktop app marks sensitive fields in a document for you to redact before you share it or paste it into AI.

This is scoped honestly: PDF only today, no Word, no Excel, no scanned documents. It is a deliberate step someone takes before a file is shared or uploaded, not a background scanner. But it covers exactly the moment the typing-focused policy does not: the file, not the sentence.

The policy question worth asking

Not "do we have an AI policy," most organisations do. The sharper question is whether that policy, and the controls behind it, cover documents as a distinct risk, or whether every rule quietly assumes the risky content was typed.

If it is the latter, the gap is not in how carefully the policy was written. It is in what it was written to cover.

FAQ

Common questions

Why don't most AI policies mention documents?

Because the early wave of AI risk advice came from chatbot use, where the obvious risk is what someone types into a message box. File upload came later, and policy writing has not caught up. Most policies still read as if the only input to an AI tool is a typed sentence.

Is a document upload actually riskier than a typed prompt?

Often, yes, simply by volume. A typed prompt is a few sentences. A ten-page case file, contract, or report can carry dozens of names, dates of birth, financial details, and references to people who are not even the subject of the document. None of that gets a second look before it goes in as one upload.

What closes this gap in practice?

A control that works on the document itself: something that opens a file, marks the sensitive fields on the page, and lets someone redact before the file is shared or uploaded. BeeSensible's Document Redaction module does this for PDFs today, alongside the existing browser-level control for typed prompts.

See how BeeSensible works

Detect sensitive data before it leaves your team, in any app, in real time.