Ask any engineering manager whether their team pastes code into ChatGPT and you'll get

a nervous laugh. The honest answer is constantly — a stack trace here, a config file

there, "just cleaning up this SQL." Most of it is harmless. Some of it carries an AWS

key, a database password, or a customer's PII straight to a third-party model.

I've spent the last while looking at how teams try to control this, and most of the