The message you actually have to send

Kindly.

Someone has just pasted a contract into a chatbot in a shared channel. The instinct is to write something stern.

Don't. The goal is that they tell you next time, and shame is the most reliable way to guarantee they won't.

In the channel, right after

Public correction in a shared channel is doing two jobs at once: fixing this instance, and teaching everyone silently reading. Both go better without an edge on it.

The gentle correction
Hey — heads up, that one had customer details in it. Public AI tools
keep what you send them, so best not to run that through it. No drama,
easily done.

If it's useful, there's a checker that tells you what's in a block of
text before you send it, and it runs entirely in your browser:
dontpastethat.com/check-a-paste

"No drama, easily done" is the load-bearing phrase. It tells everyone else in the channel that reporting this class of mistake is survivable, which is the only reason anyone will report the next one.

When it was a key or a token

Different message, because this one has a clock on it and a specific action attached.

Rotate it now
That block had a live key in it — can you rotate it now rather than
later? Treat it as disclosed, because it has been.

Rotating takes ten minutes. Working out whether it was actually
exploited takes weeks and never reaches a confident answer, which is
why rotating first is the cheaper move every time.

Once it's rotated, let [TEAM] know so it's logged. Nothing else needed
from you.

"Nothing else needed from you" matters. The reason people delay reporting a leaked credential is rarely the rotation — it's the expectation of an investigation. Close that off in the same message and you get told faster.

The reasoning, if someone wants to argue about whether it really counts as disclosed: the credentials page.

Before they start

The cheapest intervention available. Nobody has formed a habit yet, and nobody is defensive about one.

New starter email
Subject: One thing about AI tools before you start

Welcome aboard.

One request that isn't in any of the paperwork: be careful what you
paste into public AI tools. Anything you send leaves [ORGANISATION],
and it can't be recalled.

The short version of what not to send, and what to do instead, is
here — it takes about two minutes to read:
dontpastethat.com

There's also a five-minute test if you'd like to check your own
instincts. Most people score lower than they expect, including the
people who wrote the policy:
dontpastethat.com/paste-test

Anything you're unsure about, ask [TEAM] first. Asking is always fine.

When you're announcing the policy

The message that goes out when the paragraph lands in the handbook. Most versions of this get skimmed because they lead with the document rather than the reason.

Policy announcement
We've added a short section to the [POLICY NAME] about AI tools. The
whole thing is four sentences, so here it is rather than a link:

Don't paste customer or employee data, credentials, source code,
contracts, or health and legal records into ChatGPT, Claude, Gemini,
Copilot or anything similar. A prompt is a disclosure — once it's
sent it can't be recalled.

Two practical things:

- To check whether a block of text has anything sensitive in it,
  dontpastethat.com/check-a-paste reads it in your browser and sends
  nothing anywhere.
- If you've already pasted something you shouldn't have, tell [TEAM]
  today. That's the right call and it isn't a disciplinary matter.
  Telling us late is the only version that causes a problem.

We're not banning AI. [APPROVED TOOL / We're working on a sanctioned
option and will share it when it's ready.]

The last line does more than it looks like it does. A policy that reads as a ban gets routed around — usually onto a personal phone, where nobody can see it. Saying you are not banning AI, and meaning it, is what keeps the behaviour somewhere visible.

A note on where these go

These are written for chat — Slack, Teams, Google Chat, whatever your organisation actually uses. The wording is deliberately platform-neutral, because the message that works is the same in all of them and the one thing that would date these fast is naming a product.

If you paste them into email instead, cut the first line of each. Chat openers read as abrupt in an inbox.

The licensing bit

Everything in this kit is released under CC0 — public domain. No attribution, commercial use fine, and rewriting it in your own voice is encouraged rather than merely tolerated. Deliberately not CC BY: an attribution requirement nobody can satisfy inside an internal policy document would make ordinary use technically infringing, and this exists to be used.

One ask, not a rule: leave a link to dontpastethat.com somewhere in it. It is the only thing that turns a paragraph someone skimmed into a page they can actually read when they need it.