NITDA warns against entering sensitive data into public AI tools
NITDA warned organisations and employees not to enter sensitive information into public AI tools, including ChatGPT, Gemini, Claude and Copilot. The agency issued the advisory through its Computer Emergency Readiness and Response Team, CERRT.NG, in a post on X on Saturday.

Key takeaways · 4
- 01
Keep personal, classified, official-use and confidential information out of public AI platforms.
- 02
NITDA named ChatGPT, Gemini, Claude and Copilot as examples of public AI tools.
- 03
NITDA said providers may retain or log submitted information and may use it to train AI models.
- 04
For official work, NITDA recommends using only approved AI tools.
Submitted data may leave organisational control
NITDA warned that information entered into public AI platforms may no longer remain under the control of the organisation that supplied it.[1] The agency said service providers could retain or log submitted data, and could use it to train AI models.[1] NITDA also said personally identifiable information could be exposed inadvertently.[1] These are risks the advisory identifies; it does not say that every provider handles data in the same way or that every submission will be retained or used for training.[1]
NITDA links exposure to legal and security risks
NITDA said exposure of personal data could constitute a personal data breach and could violate applicable data-protection laws.[1] It also warned that such exposure could have legal consequences.[1] Separately, the agency said disclosing classified, official-use or confidential information to external AI providers could compromise national security.[1] NITDA warned that these disclosures could expose organisations and employees to disciplinary or legal consequences.[1] The advisory therefore treats sensitive-data exposure as both an organisational security concern and a potential compliance issue.[1]
Use approved tools for official work
NITDA advised organisations and employees not to enter confidential, classified, official-use or personal data into public AI platforms.[1] For official work, it recommended using only approved AI tools.[1] The warning was issued through CERRT.NG in an advisory posted on X on Saturday.[1] The Sun published its report on the warning on October 4, 2026, at 8:14 p.m. WAT.[1] NITDA had also warned organisations and individuals in May about DeepLoad, an AI-powered malware capable of stealing browser-stored passwords and other sensitive information.[2]
The warning gives organisations a clear basis for reviewing which AI tools employees can use for official tasks and what information they may submit. A practical response is to make approved-tool guidance easy to find and to remind staff that drafting and research prompts can contain sensitive data.
Why it matters
Test yourself on this story — 2 questions.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
5 October 2026
NITDA warns against entering sensitive data into public AI tools