
Start here
Before an employee or a student pastes a paragraph into a public AI chatbot, there is a useful question hiding behind the habit: is any of this information something a person is actually allowed to share with a company they do not control? France's data protection authority, the CNIL, put that question at the centre of guidance aimed at people who use generative AI systems, not only the companies that build them.
What the documents say
The CNIL's Q&A on the Use of Generative AI Systems, published 18 July 2024, states that 'end-users should only submit information that they are allowed to share in the prompt or input data,' adding that people 'should never share confidential information such as personal data, company or administrative data... when using a consumer service.' The same answer places legal responsibility on the organisation deploying a tool, not only the individual typing into it, stating that 'the organisation deploying the system will bear the legal liability in case of misuse of AI by its staff,' which is why the guidance recommends training end-users on a system's limits, and treating outputs with scrutiny for accuracy, plagiarism and bias rather than accepting them at face value. The document sits inside wider CNIL AI compliance guidance, which separately covers system design for organisations that build rather than use these tools.
Check this
The mechanism worth testing on yourself: before pasting a document, a client name, a medical detail, or an internal figure into a consumer AI assistant, ask whether you would forward that same paragraph to an outside company by email without your employer's knowledge. If the answer is no, the CNIL's guidance says the prompt should not include it either, because a consumer account offers no contractual promise about who else might see or process that content. This is a check anyone can run in seconds, before typing rather than after.
What holds and what fails
The distinction the CNIL draws holds well as a first filter: separating what a person is personally comfortable sharing from what an organisation has authorised them to share catches a meaningful share of accidental disclosures. It does not hold as a complete safeguard, because the guidance depends on organisations actually training staff and providing input templates for approved tasks, steps it recommends but cannot enforce. Where an employer has done none of that preparation, an individual applies the CNIL's general test without a specific list of what counts as authorised at work. This is an editorial reading; the guidance is addressed to organisations as much as to individual users.
- Before your next prompt, ask whether you would send the same text to an outside company by email.
- Ask whether your employer has told you which categories of data are off-limits in AI tools.
- Treat an AI system's output as a draft to verify, not a finished, sourced answer.
A regulator cannot watch every prompt typed into a chatbot, so guidance like this works by giving a person a portable question to ask themselves first, one more durable than any single company's terms of service.
Sources & reading trail
States that end-users should only submit information they are authorised to share and should never enter confidential or personal data into a consumer generative AI service.
Source published: 18 July 2024 · Retrieved: 16 September 2026
The CNIL's hub page linking its main guiding principles and recommendations for organisations using or developing AI systems, confirming the Q&A sits within a wider guidance programme.
Source published: Not established · Retrieved: 16 September 2026
Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.