Blocking the sites does not work — people use their phones — and a policy document does not survive a deadline. What works is making the safe path the easy one: a browser extension that masks personal data in the chat box before the message is sent, and puts the real values back in the reply so the work still reads normally. Staff carry on using the tool they already use, in the same way; names, emails, phone numbers and ID numbers become tokens like [PERSON_1] on the way out and are restored on the way back, so nobody has a reason to route around it. That covers claude.ai, ChatGPT, Gemini, Grok, DeepSeek, Kimi, Mistral, Perplexity and Copilot, and it covers files before they are uploaded, which is where most of the volume actually is.
Why the usual controls do not hold
Three things get tried, in roughly this order, and all three fail for the same reason: they make the correct behaviour more expensive than the incorrect one.
- Block the domains. People use a personal laptop or a phone. You have not removed the behaviour, you have removed your visibility of it.
- Write a policy. Everybody signs it. Nobody rereads it at 17:40 with a customer waiting.
- Buy the enterprise plan. Worth doing, and it settles the training question — but it does not stop the data going into a chat log, and the chat log is the thing that leaks.
Mask at the box, restore in the reply
Redaction in the browser works because it is invisible in the direction that matters. The person types the email as they always would; what leaves the machine is a token. The model answers about a token; what appears on screen is the real value again. There is nothing to remember and nothing to opt into.
Draft a reply to Marcus Delacroix
([email protected]) about his
invoice, ref 8001015009087.Draft a reply to [PERSON_1]
([EMAIL_1]) about his
invoice, ref [NATIONAL_ID_1].The reply comes back written to [PERSON_1] and is put back on screen written to Marcus. Nothing about the task changed.
The part people forget: attachments
Most of the personal data that reaches a model does not get typed. It gets attached — a spreadsheet of customers, a CV, a scanned ID, an exported report. Any control that only watches the text box misses the majority of the volume by a wide margin. Documents need redacting before upload, in place, with their formatting intact, or people will simply not do it.
And the part that is already done
Everything above is preventative, and prevention says nothing about the eighteen months before you installed anything. That history sits in the chat logs of whichever account was used. A retrospective audit — walking existing conversations and reporting, per person, what has already been shared — is usually the uncomfortable half of this work and usually the half that gets the budget approved.
One specific thing to check while you are there: shared chats and published artifacts are public web pages. In July 2026 Google indexed thousands of them from claude.ai, at which point "anyone with the link" had quietly come to mean "anyone who searches".
What good looks like
- It is on by default and needs no decision per message. Any control with a checkbox is a control most people leave unticked.
- It is reversible. If the reply comes back full of tokens, staff will turn it off within the week.
- It covers files. See above; this is where the volume is.
- It fails closed. If it cannot reach its service or the plan is exhausted, it should stop, not quietly let the message through unmasked.
- It does not create a second copy of the problem. A tool that logs everything it masked so you can review it later has just built the database you were trying not to have. Counts, not contents.
Common questions
Can we just block ChatGPT and Claude at work?
You can, and people will use their phones instead. Blocking removes your visibility of the behaviour rather than the behaviour, and it also removes the productivity you were paying for. Masking personal data before it is sent keeps the tool usable while keeping the data out, which is the only version staff do not route around.
Does an enterprise AI plan solve the data problem?
Partly. It settles the question of whether your prompts train a public model, which is worth having. It does not stop personal data from entering the chat log itself, and the chat log is what leaks — through a shared link, an export, a compromised account, or a subject access request you now have to answer.
What about files people upload to AI tools?
That is where most of the personal data actually goes, and any control that only watches the text box misses it. Documents need to be redacted before upload, with formatting preserved, including scanned PDFs and images which need OCR before anything can be masked at all.
Try it on your own data
A free workspace takes one step — 250 requests a month, three connected systems, no card.
Create a workspace