Rule 1: Know What You’re Protecting
You cannot protect data you haven't classified. Before your team can safely use AI, they must understand what qualifies as confidential information. The first step is to create a clear data classification policy. Generally, this includes client information,
employee personal data, financial records, unpublished strategy documents, and intellectual property like source code or product roadmaps. A recent report found that a significant percentage of employee prompts to public AI tools contain sensitive data, with customer information and employee PII being the most common leaks. By clearly defining what’s sensitive, you give your team a framework for making smart decisions. This isn’t just an IT task; it’s a foundational business practice in the age of AI.
Rule 2: Treat AI as a Third Party
The most critical mindset shift is to treat every public AI tool like an external contractor. You wouldn’t email your company's secret strategy to a random consultant, and the same logic applies here. When an employee pastes text into a free, public AI chatbot, that data often leaves your company's control and can be used to train the model. This act can inadvertently destroy the protected status of that information. A US court has already ruled that conversations with a public AI platform are not protected by attorney-client privilege because they are not confidential. This principle extends to all proprietary information. The simplest rule for employees is: if you wouldn't say it in a public cafe, don't type it into a public AI.
Rule 3: Establish a Clear AI Usage Policy
Hope is not a strategy. To use AI safely, you need clear, written guidelines. An effective AI policy doesn't need to be complicated, but it must be specific. It should outline which AI tools are approved for use and which are banned. For approved tools, it should specify what types of data can and cannot be entered. For instance, the policy might state that public AI tools are only for non-sensitive tasks like brainstorming general ideas, while a vetted, enterprise-grade AI platform can be used for summarising internal reports that contain no personal data. In India, while specific AI laws are still developing, the Digital Personal Data Protection (DPDP) Act, 2023, sets clear obligations for handling personal data that apply to AI use.
Rule 4: Train Your Team Continuously
A policy is only effective if people follow it. Regular, practical training is essential for building a culture of AI security. This training should move beyond simple dos and don'ts. Help employees understand the 'why' behind the rules—explain the risks of data leaks, regulatory penalties under frameworks like the DPDP Act, and the potential damage to company reputation. Use real-world examples. For instance, show how an employee trying to save time by asking an AI to summarize HR data could lead to a serious data breach. Short, frequent training sessions are often more effective than a single annual presentation. The goal is to make secure AI usage an instinctual part of daily workflow.
Rule 5: Vet Your Tools and Use Enterprise Solutions
Not all AI tools are created equal. Free, consumer-grade AI platforms often have terms of service that allow them to use your inputs to train their models, which is a major risk. For business use, companies should invest in enterprise-grade AI solutions. These platforms typically offer crucial security features like data encryption, access controls, and a contractual guarantee that your company's data will not be used for model training. Before adopting any new AI tool, your IT and legal teams should conduct a thorough security and privacy review. This includes scrutinizing the vendor's data processing agreements to ensure they meet your company's standards and comply with regulations like the DPDP Act.
Rule 6: Anonymise Data and Verify Outputs
When using AI for tasks that involve sensitive information is unavoidable, the next best step is to anonymise the data. This means removing all personally identifiable information (PII) and company-specific identifiers before inputting the text into an AI tool. For example, instead of pasting a customer complaint that includes a name and account number, an employee could rewrite the query to focus on the generic problem. Furthermore, it's crucial to remember that AI models can 'hallucinate'—inventing facts or information that sound plausible but are incorrect. All AI-generated output, especially content intended for external use, must be carefully reviewed and verified by a human to ensure accuracy and to prevent the accidental inclusion of confidential details learned from other inputs.














