AI Guides › Trend Watch

What A Data Breach At An AI Company Should Change About Your Habits

By Nigel Guy · 3 min read

When an AI company reports a security incident, most people do one of two things: panic and delete everything, or shrug because "everything leaks eventually." Neither changes much. The panic fades within a week and old habits return; the shrug means the same sensitive material keeps going into the same chat box. A breach is actually a useful prompt — not to react to that one incident, but to fix the habits that decide how much any incident could cost you.

The rule: assume anything you type into an AI tool could one day be exposed, and shape your habits so that if it were, the damage would be small — then a breach becomes an inconvenience rather than a crisis.

If you're directly affected

Work through these promptly, in this order:

  1. Read the company's official notice, not commentary about it. Note what data was involved and what they recommend.
  2. Change your password for that service, and anywhere else you reused it.
  3. Turn on two-factor authentication if it wasn't already on.
  4. Rotate any API keys or access tokens connected to the service.
  5. Review connected apps and integrations and remove anything you don't actively use.
  6. Watch for targeted phishing. Breaches are often followed by convincing emails referencing the incident. Go to the service directly rather than clicking links.

The Exposure Audit (for everyone)

Whether or not you were affected, use the moment to check what you're putting at risk:

Habit Question Better default
What you paste Do you paste client data, credentials, or personal details? Remove or replace identifying details before pasting.
Chat history How long do your conversations stay stored? Use retention or deletion settings if available; clear old chats you don't need.
Training settings Are your conversations used to train models? Check and set this deliberately.
Connected accounts What email, drives, or tools have you linked? Keep only what you use.
Account security Unique password? Two-factor on? Both, always.
Work material Does your employer allow this tool for this data? Check the policy before, not after.

The Paste Test

Before sending anything sensitive, ask: "If this conversation appeared in public tomorrow, would it cause real harm to me, a client, or someone else?" If yes, rewrite the input without the sensitive parts, use a tool approved for that data, or don't use AI for that task.

What to skip

Guardrails

All 751 AI guides · JulieMango plans from £17/mo