80 Comments
User's avatar
Ruben Hassid's avatar

UPDATE: I had to update this guide with the new Claude-5-Fable.

Please read this new part, because it impacts your data heavily.

Zane's avatar

you are too fast ahaha thank you!!!

Silvia Pellegrini's avatar

Great newsletter, very useful. It aswered a question I had for a long a time about AI privacy. I took several classes on general AI and never found a content like this one. Thank you Ruben!

Ruben Hassid's avatar

this is really nice to read, Silvia. thank you :)

may i ask what that question was?

Anisha Jain's avatar

Incognito mode in Claude exists and I didn't know about it until last week.

Work task? Open incognito. Close the tab when you're done. Nothing saves to history, nothing trains the model. Should've been my default for the past year.

Ruben Hassid's avatar

and we never stop at incognito - stack three things working together: training off + temporary chat + anonymized inputs

Alexander Korenberg's avatar

Dangerous suggestion to rely on the incognito tab. 30 day data retention (Anthropic commercial terms) still applies and there is still no confidentiality agreement so you are still at risk of waiving legal privilege, foregoing possible patent rights and breaching client confidentiality. See my comment in this thread for details. If you want to know what of your data Anthropic has stored, you can ask for it in the app settings and get it send to you. Basically anything you entered in the last 30 days. Please be careful! Unless you terms of use have an explicit confidentiality agreement and ideally give you full control over data retention, these risks probably apply. Caveat - not legal advice, information only - you need to make up your own mind :)

Ruben Hassid's avatar

its written in the newsletter, its not 100% fullproof!

Alexander Korenberg's avatar

Appreciate that and no criticism implied. The comment I replied to here may have missed that and I thought it would be worthwhile pointing out these two specific risks which have come up in real court cases. More information is always better than less in this area.

Your article is great for pointing out the risks of using personal AI at work, which is really important. But if you are in a regulated industry the correct advice is to only use AI that offers control over the data and a confidentiality agreement and in all other cases to make sure clients are informed about what is happening to their data and provide consent. And that of course transmits from any employer to any employee. I would be delighted to chat about all this off-line if you are interested!

Zane's avatar

Finally. FINALLY. This is the guide i have been waiting for!! I knew about the training toggle but never had a full picture of everything else like the anonymizing, connectors, temporary chats. Turned off everything already.

This is the guide that should come in the onboarding email of every AI tool.

Ruben Hassid's avatar

connectors section is the one i want people to re-read twice. one toggle and the AI can read emails or files you forgot existed. there’s too much exposure and risk.

Sophia KSP's avatar

Really probably dumb question: If I pay for Claude but use my work gmail to sign in, did I give access to my emails and drive without realizing?

IDAN SIVAN's avatar

On point! I have written an article about these scenarios that are evolving into shadow AI.

Dr Jodi Nelson-Tabor's avatar

This is really solid information that everyone should be trained on and have knowledge from day one. Companies also have a responsibility in educating staff and having clear policies from day one.

Ruben Hassid's avatar

take ownership first. company's training will arrive late, if at all. it will probably say just use Copilot

Russell Pallesen's avatar

Wild, I was thinking about this exact topic today. It’s like you read my mind.

Ruben Hassid's avatar

i think i did!! :)

Abhishek's avatar

That’s a great read, Ruben!

One approach I use is to anonymize sensitive information with a local LLM first, then pass the sanitized output to whichever AI tool I want to use. It helps balance privacy concerns with the benefits of cloud-based AI models.

It might be worth including this as a practical workaround for teams that want to use AI without exposing sensitive data.

Ruben Hassid's avatar

your approach is really solid. what local LLM do you use?

TheMoneySavvyAngel's avatar

Excellent read. My company blocked all AI because we have Copilot. So no others work on or network.

Ruben Hassid's avatar

you can use your personal account but be very very smart and cautious about it.

Thea Caliva's avatar

When are you publishing articles for the newest Claude models?

Ruben Hassid's avatar

i'm supposed to publish it last Sunday but Fable 5 got blocked.

Bhrigoo Mint's avatar

Very useful and lot of people r not even aware of these. Thank you.

Ruben Hassid's avatar

let's not only find out it was a problem once something goes wrong

Reports & Reads's avatar

This is so insightful, thanks so much, Ruben!!

Ruben Hassid's avatar

you're most welcome! how is it going so far? :)

Pete Scott's avatar

We do pay for AI, probably because of Copilot. 😔

Especially for our designers, but for everyone who is curious enough to pursue, our relatively small nonprofit team can have $1,000 per month to test and learn platforms and have an unlimited number of tokens to figure it out.

Don’t get left behind. Leverage your skills and creativity to amplify your abilities through AI. Don’t lose your job over stupid reasons. We’re willing to invest in our people to make sure they future proof their professional lives.

Ruben Hassid's avatar

unfortunately, majority of the companies idea of investing in their people starts and ends in Copilot.

Pete Scott's avatar

While this could seem problematic, what an incredible opportunity for everyone else!

Greg Clough's avatar

Reuben, thank you. You must be burning the midnight oil in NY.

Just a quick follow-up if I may. I presume the paper trail might lead back to the offender if he or she is one of only a few people who saw the material? But in saying it may appear somewhere it shouldn't, do you mean it may turn up in a response to an AI prompt made by a fellow company employee, or in such places as a news story, a non-company website, or other location?

Ruben Hassid's avatar

i’m in Tel Aviv :) bottom line is once you take confidential information out of its controlled environment and run it through a third-party tool, you've lost control of where the output goes

Greg Clough's avatar

Thank you Reuben. Very useful. How can a company know if you have used their information on your own subscribed AI platform using only your own personal computer?

Ruben Hassid's avatar

most of the time, they can't. but the risk of getting fired or sued by the company is a possibility.

if you paste company data into a personal AI, and that data later surfaces somewhere it shouldn't, the paper trail leads back to you

Dorian Cottle's avatar

What's wrong with Copilot? Isn't it the same models but you can pick and choose across several brands?

Ruben Hassid's avatar

only in Copilot Studio. even then you're not getting raw GPT-4o (or raw Claude), only Microsoft's version of it