Skip to content
AI & HRMay 16, 2026 7 min read

Your managers are training your competitors' AI with your performance reviews. Stop them this week.

If your managers are pasting performance reviews, promotion packets, or comp discussions into consumer ChatGPT, your most sensitive HR data is now training data. Here's the 5-step lockdown that takes a week.

Your managers are training your competitors' AI with your performance reviews. Stop them this week. — article cover
PJ
Pawan Joshi
Global HR & Operations
Share

I've sat in three CHRO offices in the last six months where the same scene played out: the legal team realizing that managers across the org had been pasting unredacted performance reviews — names, comp, ratings, the works — into the free tier of ChatGPT to 'help write better feedback.' That data is, depending on the tier, in the training corpus or in retained chat logs that the vendor can subpoena, get breached, or change policy on tomorrow.

How widespread this actually is
62%
of managers admit to pasting some form of HR document into consumer AI tools
Cyberhaven, 2025
11%
of all data pasted into ChatGPT in enterprise environments is sensitive
Cyberhaven, 2025
$4.9M
average cost of a data breach involving HR records
IBM Cost of a Data Breach Report, 2025
0
consumer AI tools that contractually qualify as a sub-processor under GDPR Art. 28

The 5-step lockdown (one week, no budget required)

  • Day 1: send a one-paragraph policy email naming the specific tools that are and are not approved for HR content. Be concrete, not aspirational.
  • Day 2–3: deploy DLP rules in your email and browser that flag pasting of names + ratings + comp into non-approved domains. Most enterprise security suites already have a template.
  • Day 3: stand up an approved alternative — either an enterprise tenant of Copilot/ChatGPT with zero-retention and no-training, or a self-hosted model. The reason people use the consumer tool is that it's the only one available.
  • Day 4: rewrite your manager enablement: 'AI can draft, but only inside the approved tool, and only with PII removed.' Show, don't tell — give them three before/after examples.
  • Day 5: add a one-line attestation in your performance review tool: 'I have not pasted any portion of this review into a non-approved AI tool.' This isn't legal protection; it's a behavior nudge that works.
What's safe vs. what isn't
Approved (with zero-retention contract)
  • Enterprise ChatGPT, Copilot, Gemini, Claude with signed DPA.
  • Self-hosted open-weight models.
  • Your HRIS vendor's native AI features if covered under the existing DPA.
Not approved
  • Free or Plus tier of any consumer AI assistant.
  • Any AI 'browser extension' a manager installed themselves.
  • Any AI tool that hasn't signed a DPA with you, regardless of marketing claims.
Found this useful? Share it.
Written by
Pawan Joshi

HR & Operations leader scaling global remote teams across Nepal, the Philippines, Australia, and the US. Tech-leaning writing lives on Medium.

Work with me