Fundamentals6 min read

Can You Put a Bank Details Slip (RIB) in ChatGPT?

Technically yes, but it's risky. A RIB alone can't empty an account; the IBAN is still personal data. Anonymize it before the AI.

By Pierre de ONYRI

Technically, yes: nothing stops you from pasting a RIB (a French bank details slip: IBAN plus BIC) into ChatGPT. But it isn't a good idea. First, let's correct a stubborn myth. A RIB alone can't « empty your account ». An IBAN (the international identifier of your bank account) isn't enough to debit your money. Still, the IBAN remains personal data. Once exposed, it feeds phishing, identity theft and attempted fraudulent direct debits. Those debits can be challenged. But they create work and risk. The simple rule: never send the real IBAN to an AI. Anonymize it first.

A RIB in ChatGPT: the true and the false

The most common fear is false. « With my RIB, someone can empty my account »: no. The CNIL explains it clearly. An IBAN alone can't directly debit an account. To pull money out, a fraudster must clear one more hurdle. Either they create a fraudulent SEPA direct debit mandate. That requires being registered with a bank as a debit originator. Or they combine your IBAN with identity theft. In other words, your IBAN isn't a key that opens your account. It's sensitive data, but not a password.

The real risk of an exposed IBAN

The real danger isn't an instant theft. It's a set of misuses, slower and more insidious. The CNIL describes them:

  • Illegitimate direct debit orders targeting the harvested IBAN.
  • Targeted phishing, made credible by your genuine bank details.
  • Identity theft attempts, when the IBAN is cross-referenced with other data.

None of these risks « empties » your account in one click. But each creates a very real problem. A fraudulent debit can be challenged. Yet you still have to spot it, build a case and meet the deadlines. That's avoidable time and stress.

What your RIB becomes once inside the AI

Once pasted, your RIB enters the AI provider's processing. It can be stored. Depending on the offering, it may also help improve the model. You lose control over its lifespan and its spread. Yet the IBAN is personal data under the GDPR. The minimization principle is simple: you don't transmit sensitive data when you can avoid it. And here, you can avoid it.

CriterionRIB to your employerRIB in a consumer AI
PurposePrecise (paying your salary)Vague, often just reformatting
ChannelControlled and contractualUncontrolled third-party processing
Possible reuseNo, bounded HR useVaries by offering (training)
Control over the dataFramed by labor lawYou lose control once sent
Handing over your RIB through a controlled channel is nothing like pasting it into a consumer AI. Framing: the IBAN as personal data (GDPR), after the CNIL.

« But I do give my RIB to my employer »

That's true, and it's a fair question. Yes, you entrust your RIB to your employer or a supplier. But through a controlled channel and for a precise purpose: paying you. A consumer AI is neither. The purpose is vague. The channel is third-party processing you don't control. It's not the same context, so it's not the same risk.

The fix: anonymize the IBAN before the prompt

The good news: you can use AI while greatly reducing your IBAN's exposure. Just replace the real value with a token before sending. The AI works on a neutralized RIB. You keep the mapping on your side. And if a fraudulent debit slips through anyway, here are the useful reflexes:

  1. 1Watch your accounts and quickly spot any abnormal debit.
  2. 2Challenge an unauthorized SEPA debit with your bank: the deadline runs up to 13 months after the debit (70 days if the beneficiary's bank is outside the EU/EEA).
  3. 3For a valid challenge, the bank must refund no later than the end of the first business day following your request, barring suspected fraud or gross negligence.
  4. 4For an authorized debit you wish to challenge, the deadline is 8 weeks from the debit, with a refund within 10 business days.

These remedies exist and work. But the best incident is the one that never happens. Never exposing the real IBAN spares you this whole journey.

Diagram: on the left, a bank details slip whose IBAN row is amber (exposed) flows to an AI card; below, the same data passes through an anonymizer that replaces it with cobalt tokens marked by a check, and only the neutralized text reaches the AI.
After the CNIL (IBAN theft, highly personal data) and service-public.gouv.fr (challenging a SEPA direct debit).

That's what ONYRI Sanitize does. The engine detects the IBAN and replaces it with a reversible token before sending. Detection and the token↔value mapping stay in your browser. Only anonymized text reaches the AI. This minimization lowers the risk: it doesn't by itself make a use « 100% compliant » or « without any risk ». But it keeps you in control of the one thing that matters here — your real IBAN.

Frequently asked questions

Can you put a RIB in ChatGPT?
Technically yes, but it's not advisable. A RIB alone can't empty your account: that's a myth. The IBAN, however, is personal data that, once exposed, feeds phishing, identity theft and challengeable fraudulent debits. The safe reflex: anonymize the IBAN before sending it to an AI.
Is an IBAN enough to empty my bank account?
No. The CNIL explains it: an IBAN alone can't directly debit an account. A fraudster must either create a fraudulent SEPA direct debit mandate (while registered as an originator), or combine the IBAN with identity theft. The real risk isn't an instant theft, but misuses to watch for.
How do I challenge a fraudulent debit on my account?
An unauthorized SEPA debit can be challenged with your bank up to 13 months after the debit (70 days if the beneficiary's bank is outside the EU/EEA). The bank must then refund no later than the end of the first business day following the request, barring suspected fraud or gross negligence. An authorized debit, by contrast, is challenged within 8 weeks.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next