The Golden Rule: Never Share Sensitive Data
The most significant risk when using public AI models is unintentional data leakage. Think of these tools as a public forum; what you enter can be stored, processed, or even used to train the model further. The cardinal rule for any professional is to never
input sensitive or confidential information into a non-approved AI tool. This includes personally identifiable information (PII) like names and addresses, protected health information (PHI), financial records, client contracts, trade secrets, or internal company strategy documents. A simple act of pasting a client list to be sorted or a confidential report to be summarised could lead to a serious data breach with legal and reputational consequences.
Beware of 'Shadow AI'
In the quest for efficiency, employees often use AI tools and applications without approval from their IT or security departments. This phenomenon is known as 'Shadow AI'. While it might seem harmless to use a new grammar checker or a trendy chatbot, these unsanctioned tools operate outside of your company’s security framework. They create blind spots where sensitive data could be leaked or misused, expanding the company's vulnerability to cyberattacks. A large percentage of employees are already using AI for work, often without formal training on data security, making this a widespread issue. The risks are not just about data leaks but also non-compliance with data protection regulations.
Stick to Company-Approved Tools
The safest way to leverage AI's power is by using tools that your company has vetted and approved. Organisations are increasingly providing enterprise-grade AI solutions, like Microsoft Copilot or other internal platforms, which come with robust security measures and contractual agreements that protect company data. These approved platforms are often configured to prevent data from being used for public model training and ensure compliance with privacy laws. Before you start experimenting with a new, publicly available AI tool, always check your company’s policy. If a sanctioned alternative exists, use it. If not, go through the proper channels to have a new tool evaluated.
Anonymise and Generalise Your Prompts
Sometimes you need AI's help with a problem but cannot share the specific details. In these cases, the skill of anonymising and generalising your prompts becomes invaluable. Instead of asking, “Draft a response to our client, Acme Corporation, regarding the delayed shipment of order #54321,” you could generalise the prompt. Try something like, “Write a professional email to a client apologising for a shipment delay and offering a proposed solution.” This approach allows you to get a useful template or structure from the AI without ever exposing any confidential client or company information. By removing specific names, figures, and details, you get the assistance you need while keeping sensitive data secure.
Always Verify AI-Generated Content
Data risk isn't just about what you input; it's also about what you get out. Generative AI models are known to 'hallucinate'—that is, to produce information that is inaccurate, misleading, or entirely fabricated, but presented convincingly. Relying on unverified AI output for reports, presentations, or client communication can lead to significant operational and reputational damage. Before using any AI-generated content, fact-check it against trusted sources. Remember that as the professional, you remain responsible for the accuracy and integrity of your work, regardless of whether an AI helped create it. Treat AI as a helpful assistant, not an infallible authority.














