How to Decline an Unapproved AI Tool Request in Writing
A colleague messages you: “can you just run this through ChatGPT to summarize it, it’ll take two minutes.” The document has a client name in it, or a salary figure, or a contract clause nobody outside the company should see. You need to say no, in writing, without sounding like the person who ruins everyone’s shortcuts.
The instinct is to either comply because refusing feels awkward, or to fire back a flat “we can’t do that” that answers the request but ignores the actual need. Both responses cost you something. There is a better shape for this message, and it takes about the same thirty seconds as either bad option.
Acknowledge The Goal Before You Touch The Method
Whatever the request was for, speed, a second opinion, a cleaner summary, that goal is legitimate. Say so first. “Good idea to get this summarized” costs you nothing and tells the other person you are on their side, not their obstacle. Skipping this step is what turns a policy reminder into a scolding.
Name The Specific Risk, Briefly
You do not need to explain data governance from first principles. One sentence naming the actual risk does the job: this document has a client name in it, this tool retains what you paste, this one hasn’t been reviewed for that kind of data. Specificity also makes the refusal harder to argue with, because it is not a rule for its own sake, it is a reason tied to this document.
Always Hand Back A Path, Not Just A No
A refusal with nothing attached reads as obstruction, even when it is correct. Pair it with what is actually approved: the sanctioned tool, a version of the document with identifying details removed, or a quick turnaround from you instead. The goal is for the other person to end the exchange with a way forward, not just a closed door.
Before:
We can’t use ChatGPT for anything with client data in it, that’s against policy, you’ll need to find another way to do this.
After:
Good instinct to get this summarized quickly. This version has the client name and contract terms in it though, and public AI tools retain what gets pasted in, so let’s not use ChatGPT for this one. I can run it through the approved local tool and have a summary back to you in five minutes, or you can strip the identifying details first if you want to do it yourself.
The second version says no exactly once and spends the rest of the message being useful, which is why it gets followed instead of worked around.
This Is Not A Hypothetical Risk
The habit this message is trying to stop is already widespread and growing. A 2026 report from data security firm Cyberhaven found that the share of corporate data employees paste into AI tools that is sensitive has risen sharply over two years, and a large share of that traffic runs through personal, unmanaged accounts rather than anything IT can see or control. That is the practical reason a “just this once” request matters: the tool doesn’t know it’s a one-off, and neither does whatever system it feeds into. Read the full report if you want numbers to cite in your own policy conversations.
If this keeps coming up on your team, it is worth writing the rule down once rather than re-explaining it message by message. See how to ask your company to approve an AI tool if the sanctioned option does not exist yet, and how to write an AI use policy for a small team for the standing version of this conversation.
A Wrivio Context For The Redirect
Save the shape of this message once, since the specifics change every time but the structure does not.
Rewrite this as a short, friendly written response that declines an unapproved AI tool request. Acknowledge the goal in the first sentence, name the specific data risk in one sentence, and offer a concrete approved alternative. No lecturing, no policy citations unless I include one. Keep every name, date, figure, and commitment exactly as written.
Press Ctrl+Shift+Space, paste your quick draft, and check the diff, since this is a message people forward, and it should read as helpful on the second read too.
Common Questions
How do I say no without sounding like the compliance police?
Open by agreeing with the goal, name the specific risk in one sentence, and immediately offer an approved alternative, which keeps the message about the document rather than about the rule.
What if there is no approved AI tool yet?
Say that plainly and offer to do the task yourself or flag the gap to whoever owns tool approvals, rather than letting the missing option become the reason someone uses an unapproved one anyway.
Is pasting a client name into a public AI tool actually risky?
Yes, most consumer AI tools can retain and, depending on settings, use submitted text, and a growing share of what employees paste into them is confidential business or personal data.
Should I escalate instead of handling it myself?
Handle a one-off request yourself with a quick redirect; escalate if the same request keeps happening, since a repeated pattern usually means the approved option is missing or too slow.
Does this apply to public tools only, or also to other employees’ AI subscriptions?
It applies to any tool your company has not reviewed and approved, personal subscription or not, since the review is about data handling, not about who is paying for the account.
Keep sensitive text off public AI tools with a rewriter that can run locally on your own machine: Download Wrivio for Windows.
Read Next
How to Write a Message Supporting a Decision You Argued Against
The gap between disagree and commit and quiet sabotage is what you write next. A structure for backing a decision in writing without erasing your objection.
How to Write a Message Correcting Your Own Mistake
You sent the wrong number, missed a deadline, or broke something. How to own it in writing in a way that rebuilds trust instead of drawing it out.
How to Ask a Coworker to Redo Work Without Friction
The work came back wrong and you need it done again. How to ask for a redo that fixes the work without bruising the person or slowing them down next time.
How to Prepare for an AI Audit as a Small Team
California is building an AI auditor registry and the EU AI Act is now enforceable. Here is a practical checklist to get audit-ready without over-engineering.
This article is filed underWorkplace Writing, which has 132 articles.