9pm. Payroll is due. One paste.
It's 9pm. Payroll closes tomorrow morning, and one formula in the spreadsheet is broken. Someone on your team does what millions of people do every day: they copy the sheet into ChatGPT and ask, "Why isn't this working?"
The AI fixes the formula in ten seconds. Problem solved.
Except that spreadsheet held fifty employees' names, salaries and bank account numbers. And it just went to an outside company.
Nobody hacked anything. Nobody did anything malicious. A good employee was trying to do their job well and fast. That's what makes this risk so easy to miss, and why I believe it belongs on every leader's radar, not just IT's.
This isn't an IT problem
I'm the Senior Director of HR and Operations at SUPERWISE. When people talk about AI risk, the conversation usually gets handed to IT or security. I think that's a mistake.
Look at where the sensitive data actually lives:
- HR has salaries, performance reviews, medical leave and home addresses.
- Finance has bank details, contracts and forecasts.
- Sales and customer success have client names, emails and deal terms.
- Legal has agreements and disputes.
Those are the teams pasting information into AI tools every day. IT can't see what goes into a chat window, and they shouldn't have to guess. The people who own the data need to own the conversation.
For me, it's personal. Employees trust HR with the most private parts of their lives. "I was just trying to fix a formula" is never a good enough reason to break that trust.
Every company is making one of three choices
Your team is already using AI. Whether you've decided anything or not, you're making one of these choices:
- Ban it. It sounds safe, but people find workarounds on their phones and personal accounts. You lose the productivity and you still have the risk.
- Ignore it. Everyone moves fast, and private data quietly leaves the building. Nobody knows until a customer or auditor asks.
- Make it safe. Let people keep using the tools they love, with a safety net underneath.
Most companies think they've picked option three because they have an AI policy. I own our policies, so I'll say it plainly: a policy is a piece of paper. Employees sign it on day one. It doesn't help at 9pm when payroll is due and someone is tired.
Good intentions aren't a control. A safety net has to work even when people forget.
What I chose
I chose option three, and the safety net I use is SUPERWISE Sentinel.
Think of it as a filter between your team and the AI. Before anything leaves the computer, Sentinel checks it and hides the private details, like names, emails, phone numbers, account numbers and passwords. Those details are swapped for a simple marker, such as [REDACTED], before anything is sent. The AI can still help with the question. It just never sees the private information.
Back to that 9pm payroll moment. With Sentinel, the formula still gets fixed. The salaries and bank details never leave the building.
What I value most as a leader:
- Nothing changes for my team. They keep using ChatGPT and Claude the same way. No new tool, no extra steps.
- It works every time, not just when someone remembers the rules.
- I have proof. It keeps a record of what it caught, so if a customer, auditor or our board asks how we handle AI, I can show them instead of saying "trust us."
Five questions to ask your team this week
You don't need to be technical to lead on this. Start with a conversation. Ask your team:
- Which AI tools are you using for work?
- What kind of information do you paste into them?
- If a customer asked us to prove their data stayed private, could we?
- Does our AI policy actually protect us when someone's rushed?
- Who here owns this?
If the answers make you uneasy, you're not alone. Most leaders I talk to are in the same spot.
AI is one of the best things to happen to how we work. I don't want my team to use it less. I want them to use it without putting the people who trust us at risk. That's a leadership decision, and it's one every business leader should be making now.
Curious what this looks like in practice? Watch the Sentinel live demo or learn more on the Sentinel page.
Next step
See how Sentinel hides names, account numbers, and other private details before a prompt reaches the AI, and keeps a record of what it caught. See SUPERWISE Sentinel.