- A Calm Sequence for a Bad Morning
Someone Put Company Data Into an AI Tool. Now What?
Six steps in order. The first one is not disciplining anybody. You need their cooperation, and you need it before memory fades.
FIRST, SLOW DOWN
Most of These Are Not Breaches. Some Are.
The instinct on discovering this is either to panic or to wave it away, and both close off the response you need. What determines which situation you are in is narrow and answerable: what data, into which tool, under what terms, and whether it is recoverable.
Work the steps in order. Do not start with a conversation about consequences, the person who did it holds the account, the timeline, and the recollection of exactly what was pasted, and a defensive employee is an employee whose memory gets worse.
If regulated data may be involved, involve counsel or your compliance officer at step three rather than at the end. We are a technology firm and we work alongside them; we do not substitute for them.
When an AI-related incident hits a Dallas business, the first hour decides how expensive the rest of it becomes. We are close enough to be on site the same day from Plano, which is the practical difference between containing a problem and documenting one.
THE SEQUENCE
Six Steps, In This Order
1
Establish exactly what was submitted
Which document, which fields, how many records, which tool, which account, when. Ask the person directly and without blame. Write it down while it is fresh; this record is what every later decision rests on.
2
Classify the data
Was it identifiable? Regulated? Contractually confidential? A draft marketing plan and a list of patients with diagnoses sit on completely different tracks, and everything downstream depends on which one this is.
3
Read the terms that actually applied
Not the terms of the tier you thought was in use. The terms of the account that was actually signed into. Retention, training rights, and deletion options differ sharply between them. If regulated data is involved, bring in counsel or compliance at this point.
4
Delete what can be deleted, and record it
Remove the conversation, disable history, and request deletion through the vendor’s formal channel where one exists. Keep the confirmation. Do not overstate what deletion achieved, retention in backups is common.
5
Decide on notification with advice
Whether this triggers a notification obligation to patients, clients, funders, or an insurer is a legal determination, not a technical one. Your job at this step is to have steps one through four documented well enough that the determination can be made properly.
6
Fix the reason it happened
There was a job to be done and no approved way to do it. Sanction a tool, write the policy, and close the technical gap. Skipping this step guarantees a second incident, and a second incident is much harder to characterize as an accident.
What not to do
Do not delete the evidence trail before recording it. Do not tell staff the matter is closed before you know whether it is. And do not respond with a blanket ban on AI. It reads as a punishment, it drives the same behavior onto personal phones, and it leaves you blinder than you were this morning.
Is this automatically a reportable breach?
Not automatically, and that determination is not ours to make. It depends on the data, the terms that applied, and your obligations. What we can do is establish the technical facts quickly and clearly so your counsel or compliance officer is deciding on evidence rather than on a vague account.
Can we get the data back or truly deleted?
You can usually delete the conversation and often request account-level deletion. What you generally cannot obtain is a guarantee about every copy in every backup. Document what you requested and what was confirmed, and describe it accurately, overstating deletion creates a second problem later.
Should the employee be disciplined?
That is your call, not ours. What we would observe is that if no written policy existed, the organization has a weak position and a strong incentive to fix the cause rather than the person. Where a clear policy was in place and knowingly ignored, that is a different conversation.
How do we know this has not happened before?
You do not, until you look. This is the most common reason businesses commission an AI security audit. One visible incident almost always means several invisible ones, and finding them is a matter of querying logs you already hold.
BK
Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022. He has walked practices and firms through this sequence, usually on the phone, usually the same morning.
Last reviewed August 2026 · Questions we have not answered here? Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.