"Don’t put sensitive data into an AI prompt."

I hear this advice a lot, and while it makes sense, I think it oversimplifies the problem.

As more applications start using GenAI to summarize documents, answer questions, support employees, or process customer information, sensitive data is going to show up in some of these interactions.

So instead of only asking whether sensitive data should enter a prompt, I think there is another useful question to ask: What actually happens to that data once it does? Let’s take a simple example.

A Simple Customer Support Request