When a reviewer pastes an agency's annual report draft into a personal ChatGPT, Gemini or Copilot account, the unpublished numbers can be stored for months or years, read by human reviewers and used to train future models. Why that's a UPSI problem, how Copilot differs between work and personal accounts, and why human feedback still beats AI feedback.
In this article
Key takeaways
- Consumer AI chatbots aren't a safe place for an unpublished annual report draft: ChatGPT Free, Plus and Pro, consumer Gemini and personal-account Microsoft Copilot can all use conversations to train models unless the user opts out.
- Microsoft stores consumer Copilot conversations for 18 months by default, and Google keeps Gemini chats that human reviewers have read for up to three years, even after the user deletes them.
- Copilot is safe or unsafe depending on the account: signed in with a work (Entra ID) account it carries enterprise data protection and isn't used to train foundation models; signed in with a personal Microsoft account it's a consumer product.
- A pre-results annual report draft often contains unpublished price sensitive information, and SEBI's PIT Regulations only allow UPSI to be communicated for legitimate purposes, to recipients bound to confidentiality.
- Data that goes into training can resurface: researchers extracted more than 10,000 verbatim training examples from ChatGPT for about US$200 of queries, and nearly 4,500 shared ChatGPT chats turned up in Google Search in 2025.
- AI feedback on an annual report tends to be generic; the reviewer's value is knowing the strategy, the board's sensitivities and what was promised to investors, which no chatbot has.
The agency's draft lands on a Thursday evening: 300 pages, comments due Monday, and a board review the week after. A chatbot sits one browser tab away. Paste the chairman's message in, ask what's weak, and you'd have a page of comments in a minute.
We understand the urge. But before that draft goes anywhere near ChatGPT, Gemini or Copilot, it's worth knowing what happens to it once you press enter, and what your agency loses when its feedback comes from a model instead of from you.
What happens when you paste the draft into a chatbot
On a personal account, the providers' own terms describe what follows.
First, it's stored. The conversation, including any file you upload, is kept on the provider's servers. Microsoft stores consumer Copilot conversations for 18 months by default. Deleting the chat from your history doesn't always delete every copy.
People can also read it. Consumer chatbots use human reviewers for quality and safety. Microsoft says some Copilot conversations are subject to "both automated and human review". Google's Gemini privacy hub asks users not to enter "confidential information that you wouldn't want a reviewer to see", and keeps chats that reviewers have read for up to three years, even after you delete your activity.
And it can train the next model. On ChatGPT Free, Plus and Pro, conversations can be used to train OpenAI's models unless you opt out. Google uses Gemini chats to train its models when Keep Activity is on. Microsoft uses consumer Copilot conversations and uploaded files for training unless you opt out. Since 2025, consumer Claude users choose whether their chats are used, with five-year retention if they agree.
Key number: 18 months — how long Microsoft keeps consumer Copilot conversations by default
Most reviewers never change these settings. Even those who opt out of training haven't opted out of storage or human review.
Can your draft show up in someone else's chat?
There's no public case of a company's unpublished annual report surfacing in a stranger's chatbot conversation. But the routes by which it could happen are real, and each one has already happened to someone.
Models can memorise what they're trained on. In 2023, a team of researchers from Google DeepMind and several universities extracted more than 10,000 verbatim training examples from ChatGPT for about US$200 of queries, some over 4,000 characters long. A chairman's message isn't likely to be reproduced word for word, but a distinctive figure, a project name or a planned announcement doesn't need to be.
Sharing features leak too. In mid-2025, nearly 4,500 ChatGPT conversations that users had shared by link turned up in Google Search, and OpenAI withdrew the feature, calling it a "short-lived experiment". A reviewer who shares a chat with a colleague to show the "AI's comments" can create exactly that kind of link.
And people make mistakes inside large companies. In 2023, Samsung engineers pasted source code and meeting notes into ChatGPT within weeks of being allowed to use it, and the company banned generative AI tools for staff soon after.
Once the draft leaves your systems on consumer terms, you no longer decide who sees it or for how long.
Does this apply to Microsoft Copilot?
Yes, and Copilot causes the most confusion, because the same name covers two very different products.
Signed in with a work or school account (Microsoft Entra ID), Microsoft Copilot Chat runs with enterprise data protection. Prompts and responses stay inside the Microsoft 365 service boundary, they're covered by your company's data protection agreement with Microsoft, and they aren't used to train the underlying foundation models. A green shield next to the New Chat button tells you the protection is on.
Signed in with a personal Microsoft account, Copilot is a consumer product. Microsoft uses those conversations, including uploaded files, for model training unless you opt out. India isn't among the countries Microsoft excludes from training (its list is Brazil, mainland China, Israel, Nigeria, South Korea and Vietnam). Conversations are kept for 18 months and some are reviewed by people.
| Tool and account | Used to train models? | Human review | Fit for an unpublished draft? |
|---|---|---|---|
| ChatGPT Free, Plus or Pro | Yes, unless you opt out | Possible | No |
| ChatGPT Business or Enterprise | Not by default | Under the business terms | Only if your company approves it |
| Gemini on a personal Google account | Yes, when Keep Activity is on | Yes; reviewed chats kept up to three years | No |
| Copilot on a personal Microsoft account | Yes, unless you opt out | Yes | No |
| Copilot Chat on a work (Entra ID) account | No | Under the enterprise terms | Only within your company's AI policy |
The practical test is simple: if you're on your phone, your home laptop or a browser where you're logged in with Gmail or Outlook.com, assume you're on consumer terms.
The UPSI problem
For a listed company, this isn't only a privacy issue. A draft annual report prepared before results are public often contains unpublished price sensitive information (UPSI): the financial results, guidance, capital plans, an acquisition the board hasn't announced.
Under SEBI's Prohibition of Insider Trading (PIT) Regulations, 2015, an insider may only communicate UPSI for legitimate purposes, the performance of duties or the discharge of legal obligations. The company's agency qualifies: it's an advisor under a confidentiality agreement, and the company records it in its structured digital database. A consumer chatbot provider qualifies on none of those counts. It isn't bound to the company, it isn't on the database, and its terms allow it to keep and use what it receives.
Whether a particular paste breaches the regulations depends on the facts. But the reviewers who handle annual report drafts (the CFO's office, the company secretary, investor relations, business heads) are usually designated persons under the company's own insider trading code. That's the wrong group to be testing the edges.
In practice: treat the agency's draft the way you treat board papers. If you wouldn't email it to your personal Gmail, don't paste it into a personal chatbot.
There's a contractual angle too. Most agency agreements carry confidentiality clauses that run both ways, and the draft is the agency's work in progress. Uploading it to a third-party service can breach the agreement your own company signed.
Why human feedback is worth more than AI feedback

Read the infographic as text
- The approved number. Know which figure the board signed off.
- The leader’s voice. Know what sounds right for this year’s message.
- The exact status. Commissioned and operational are not the same.
- The competitive context. Show how your strategy differs from a peer’s.
- The promise to investors. Explain whether last year’s commitments were delivered.
AI can suggest edits. People supply context and accountability.
Set the risk aside for a moment and ask what the agency needs from a review.
Ask a chatbot to review a chairman's message and you'll get comments that would fit any company: tighten the opening, add more data, make the ESG section more specific, consider a stronger call to action. Some of it will be fair. Almost none of it will be what the agency can't already see for itself.
The comments that change a report are the ones only the reviewer can make. That the capex number on page 34 is the board-approved figure, not the one in the investor presentation. That the MD doesn't want "transformation" anywhere near this year's message after last year's results. That the new plant should be described as commissioned, not operational, because of a pending approval. That a peer has just announced the same strategy and the wording needs to show how this one is different. That the theme promised investors something last year and this report has to show whether it was delivered.
A model has none of that context. It also has no accountability. When it confidently "corrects" a number that was right, or suggests softening a statement legal has already approved, someone still has to catch it. Generic AI comments add a round of changes; they rarely remove one.
There's a relationship cost as well. Agencies can tell when feedback has come from a chatbot: it's long, evenly weighted and oddly impersonal. It signals that the reviewer didn't engage, and the agency responds in kind, defending every point instead of solving the real ones.
What this means for CFOs, company secretaries and IR teams

Read the infographic as text
- Set the policy. Name approved tools. Keep drafts out of personal accounts.
- Check the account. Use the approved work account and verify its protection.
- Use AI for checks. People own the substantive comments.
- Send one set. Reconcile finance, legal, secretarial and IR feedback.
- Make it specific. Page. Problem. Replacement. Must-fix or preference.
- Put it in the AI policy. Say explicitly that annual report drafts, board papers and anything containing UPSI may not go into personal AI accounts, and name the approved enterprise tool if there is one.
- Check the shield. If your company uses Microsoft 365, tell reviewers to use Copilot only when signed in with their work account and to look for the green shield.
- Keep AI to mechanical checks, if at all. Spelling, consistent terminology and number cross-checks can be done in an approved enterprise tool. The substantive comments should come from people.
- Consolidate the feedback. One set of comments per round, reconciled across finance, secretarial, legal and IR, saves the agency more time than any tool. Our guide to starting the annual report early covers how to set up owners and sign-offs.
- Be specific. Page number, the problem, and what you want instead. Separate must-fix items (facts, numbers, legal) from preferences.
None of this means companies should avoid AI altogether. Agencies can use it well, inside a private, contract-covered setup, as we argued in our piece on how annual report agencies should use AI. The difference is where the draft goes and who does the judging.
The review is the one stage of the annual report where the company's own knowledge is irreplaceable. Spend the hour, mark up the pages, and send the agency comments only you could have written.
Frequently asked questions
Is it safe to upload a confidential annual report draft to ChatGPT?
Not to a personal ChatGPT account. On ChatGPT Free, Plus and Pro, conversations can be used to train OpenAI's models unless you turn that off, and a pre-results draft often contains unpublished price sensitive information. ChatGPT Business and Enterprise don't train on your data by default, so if your company has one of those, use it, and only within your company's AI policy.
Does Microsoft Copilot use my data for training?
It depends on how you're signed in. Microsoft uses consumer Copilot conversations, including uploaded files, for model training unless you opt out, and stores them for 18 months by default; India isn't on its list of excluded countries. Signed in with a work or school Entra ID account, Copilot Chat has enterprise data protection, shown by a green shield, and prompts aren't used to train foundation models.
Can something I paste into a chatbot appear in someone else's chat?
It's unlikely in any single case, but it isn't impossible. Content used for training can be memorised: researchers extracted thousands of verbatim training examples from ChatGPT. Human reviewers can read some consumer chats, and nearly 4,500 shared ChatGPT conversations turned up in Google Search in 2025.
Is an unpublished annual report draft UPSI?
Often, yes. SEBI's Prohibition of Insider Trading Regulations treat information that isn't generally available and is likely to affect the share price, such as financial results, as unpublished price sensitive information. A draft annual report prepared before results are public can contain it. UPSI may only be communicated for legitimate purposes, to recipients who are bound to keep it confidential.
Should companies use AI to review their agency's annual report draft?
Not for the feedback itself. AI comments on a draft tend to be generic, because the model doesn't know the company's strategy, the board's sensitivities or last year's commitments to investors. If a company wants mechanical checks such as spelling or number consistency, it should run them in an approved enterprise tool, and the substantive comments should still come from the people who know the business.
Sources
- Privacy FAQ for Microsoft Copilot — Microsoft
- Microsoft Copilot Chat Privacy and Protections — Microsoft Learn
- What if I want to keep my history on but disable model training? — OpenAI Help Center
- Gemini Apps Privacy Hub — Google
- Updates to Consumer Terms and Privacy Policy — Anthropic
- Scalable Extraction of Training Data from (Production) Language Models — arXiv (Nasr, Carlini et al.)
- OpenAI is removing ChatGPT conversations from Google — Engadget
- Samsung Bans Generative AI Use by Staff After ChatGPT Data Leak — Bloomberg
- Information Sharing Under SEBI's Insider Trading Rules — Mondaq (S&R Associates)



