First, Check Your Company’s AI Policy
Before you use any AI tool for work, your first step should be to understand your company's official stance. Many organisations now have clear policies that outline which AI tools are approved for use and which are prohibited. These guidelines are created
to protect both the company and its employees. Using only company-vetted tools is the safest route, as these have typically been reviewed for security and data privacy. If your company has an enterprise-grade AI platform, like Microsoft Copilot for 365 or a business tier of another service, it's because these versions often come with contractual guarantees that your data will not be used to train public models. If you can't find a policy, ask your manager or IT department. Silence from the company isn't a green light; it’s a reason to be extra cautious. Using unapproved 'shadow AI' tools can create significant security blind spots for your organisation.
Know What Data Is Considered Sensitive
Not all data is created equal. The biggest risk comes from inputting information that is confidential, proprietary, or regulated. It's crucial to know how to identify it. Sensitive data typically includes personally identifiable information (PII) like customer names, addresses, or contact details; protected health information (PHI); and financial records like budgets or credit card numbers. It also covers intellectual property, such as trade secrets, product designs, unpublished research, and internal source code. Even seemingly harmless documents like strategic plans, client contracts, and internal meeting notes are considered confidential. A good rule of thumb is to treat AI interactions like a public forum: if you wouldn't share the information in a press release or post it on social media, do not paste it into a public AI tool.
Understand How the AI Tool Uses Your Data
The core issue with many public AI tools is that they often use the data you provide to train their models. When you paste text into a free chatbot, that information might be stored and used to refine future responses, potentially exposing it to other users in paraphrased forms later on. Before using any tool, check its privacy policy and terms of service. Specifically, look for information on data retention and whether your inputs are used for model training. Many platforms now allow you to opt-out of having your data used for training, but you shouldn't rely on this as a foolproof guarantee. Enterprise-level AI solutions are generally safer because they contractually separate your data from the public training pool. Knowing where your data goes is fundamental to using AI responsibly.
Anonymise Your Data Whenever Possible
Even when using an approved tool, it's a best practice to minimise the amount of sensitive data you share. If you need help structuring a report or brainstorming ideas based on a document, try to anonymise the content first. This means replacing real names, company details, and specific figures with generic placeholders. For example, instead of pasting “Notes from the Q3 strategy meeting for Project X with Client Y,” you could generalise the prompt to “Summarise the key action items from a client strategy meeting.” You can ask the AI to help you draft the structure of a document or improve the tone of a paragraph without feeding it the full, confidential context. This practice allows you to leverage the power of AI for formatting and language assistance without risking sensitive information.
Always Verify AI-Generated Output
AI is a powerful assistant, but it is not infallible and should not be blindly trusted. AI models can 'hallucinate'—that is, produce incorrect, biased, or completely fabricated information with a high degree of confidence. Before using any AI-generated content in a report, presentation, or email, you are responsible for fact-checking it. This includes verifying data points, confirming sources, and ensuring the output is accurate and appropriate. Human oversight is a critical part of the process. The final work product is your responsibility, not the AI's. Always review and revise outputs to ensure they are factually correct and do not contain any biased, offensive, or inappropriate content before sharing them.














