Know Your Company’s AI Policy First
Before you paste anything into an AI chatbot, the first and most crucial step is to understand your employer's rules. A growing number of companies have formal policies outlining which AI tools are approved for use and, more importantly, what kind of data
is permissible to use with them. These guidelines are designed to protect both you and the company from legal, reputational, and security risks. Many organisations now provide employees with enterprise-grade AI tools that have enhanced security features and contractual guarantees that your data won't be used for model training. Using a personal or public AI account for work tasks could violate company policy and expose sensitive information. If your company doesn't have a clear policy, ask your IT or security department for guidance. This simple check is your first line of defense.
Treat All Public AI as Public Megaphones
The single most important habit is to treat any information you enter into a public generative AI tool as if you are shouting it in a public square. Unless you are using a secure, private enterprise version where your company has a specific contract, your inputs could be logged, stored, or even used to train the model further. This means sensitive data like customer lists, internal financial figures, proprietary source code, or strategic plans should never be entered into a public AI tool. A 2023 study highlighted that a significant percentage of employees had unknowingly pasted confidential data into ChatGPT. The core risk is that this data can be unintentionally exposed later through model behavior or a security breach, with no way to retrieve it.
Master the Art of Anonymisation
You can still leverage AI's power without feeding it sensitive information by mastering data anonymisation. This goes beyond replacing a name with "Person X." The goal is to strip out all personally identifiable information (PII) and confidential specifics while preserving the context of your query. For instance, instead of pasting an email containing a client's name, company, and project details, you would replace them with generic but contextually relevant placeholders like "[Client Name]," "[Technology Company]," and "[Project Alpha]." This technique allows the AI to understand the structure and intent of your request—like asking it to draft a reply or summarise a document—without ever seeing the actual confidential data. Think of it as creating a template of your problem for the AI to solve.
Use AI for Structure, Not for Substance
One of the safest ways to boost productivity with AI is to use it for generating structure, not for processing sensitive substance. For example, instead of asking an AI to "summarise this confidential report," ask it to "create a template for a quarterly business review report including sections for key metrics, achievements, challenges, and next steps." You can also ask it to generate boilerplate code, create project plan outlines, brainstorm generic marketing slogans, or draft a standard communication template. In these scenarios, you are not providing any sensitive inputs. You are simply using the AI as a sophisticated starting point, after which you can manually populate the resulting structure with your confidential information within your own secure environment.
Always Verify, Never Trust Blindly
Productivity gains from AI are worthless if the output is incorrect or biased. Generative AI models can famously "hallucinate"—that is, invent facts, sources, or data with complete confidence. A critical habit is to always verify any information the AI provides before using it in your work. If it gives you a statistic, find the original source. If it generates code, have it reviewed for errors and security vulnerabilities. This human-in-the-loop oversight is a non-negotiable part of using AI responsibly. Think of the AI as an incredibly fast but occasionally unreliable intern. You are still the one ultimately responsible for the accuracy and quality of your work.














