Start with Your Company’s AI Policy
Before you even type your first prompt, your first stop should be your company's official policy on using generative AI. Many organisations are creating specific guidelines that outline which AI tools are approved, for what purposes they can be used,
and what types of information are strictly off-limits. These policies are designed to protect both the company and its employees from security breaches, legal issues, and accidental data leaks. Your employer may require mandatory training on how to use these tools responsibly. Familiarising yourself with these rules is the best way to ensure you are using workplace AI safely and in compliance with company expectations.
Assume Your Conversations Are Not Private
A good rule of thumb when using any workplace communication tool is to assume a lack of absolute privacy, and AI chatbots are no exception. Depending on the platform (like Microsoft Copilot or Slack AI) and your company's specific configuration, your interactions may be logged and accessible to your employer. While enterprise versions of these tools often have stronger privacy controls, and platforms like Microsoft state they don't use your business data to train their public models, your organisation can still retain this data for years. This means managers or HR could potentially review conversations for compliance or internal investigations. Treat every chat as part of your professional record—if you wouldn't want it read by your boss, don't type it.
Never Share Confidential or Personal Information
This is the most critical rule. Never input sensitive information into a workplace chatbot. This includes proprietary company data like trade secrets, financial records, strategic plans, or client information. It also applies to Personally Identifiable Information (PII) about yourself or others, such as passport details, home addresses, or financial data. Even an innocent query can lead to an accidental leak if sensitive data is included in the prompt. For example, Samsung employees reportedly leaked confidential code by entering it into a public AI tool. Always use designated secure systems for handling sensitive information, not the general-purpose AI assistant.
Understand How Your Data Might Be Used
It's important to distinguish between consumer-grade AI tools (like the free version of ChatGPT) and enterprise-level solutions integrated into your workplace (like Microsoft Copilot for 365). Consumer tools often use your conversations to train their future models unless you specifically opt out. Enterprise solutions typically offer more robust privacy, stating that your company's data will not be used to train their public AI. However, the chatbot still processes your data to generate a response, and that data lives on your company's systems. Be aware of the difference and always err on the side of caution by avoiding sensitive inputs, regardless of the platform.
Fact-Check the AI’s Output
Generative AI tools are designed to predict the next logical word, not to be factually accurate. This can lead to a phenomenon known as “hallucination,” where the AI confidently presents incorrect or completely fabricated information. Always treat AI-generated content as a first draft, not a final product. Before using any data, code, or text from a chatbot in your work, you must independently verify its accuracy with trusted sources. The responsibility for the final output remains with you, the human user. Think of the AI as a helpful but sometimes unreliable assistant; it supports your work but doesn't replace your professional judgment.
Maintain a Professional Tone
Just as with email or team chats, all communication via a workplace chatbot should remain professional. AI tools are increasingly used to analyse communication for sentiment or summarise interactions. While it may feel like you're talking to a machine, the record of that conversation could be reviewed by people. Using respectful and appropriate language is not just good practice; it reflects on your professionalism. Some employees use AI to help soften their tone or check for clarity, which can be a great use case, but the ultimate responsibility for the message you send lies with you.














