Understand the Core Risk
Public generative AI tools, like many free versions of popular chatbots, often use the data you provide to train their models. This means that when an employee inputs text, that information might be stored and could even resurface in responses to other
users. Several high-profile incidents have occurred where employees accidentally leaked confidential data, such as proprietary source code or internal meeting notes, by pasting them into a public AI tool. This doesn't mean AI should be avoided, but it does require a clear understanding that anything typed into a public-facing AI could potentially become public knowledge. The fundamental rule is to treat the input field of a public AI tool as if you were posting on a public forum.
Identify Your Sensitive Data
Before you can protect sensitive information, you must know what it is. This type of data is any information that, if disclosed, could cause significant harm to an individual or an organisation. While this varies by industry, sensitive data generally falls into a few key categories. Personally Identifiable Information (PII) includes names, addresses, social security numbers, and phone numbers. Financial information like bank account details, credit card numbers, and corporate financial records is also highly sensitive. Other examples include employee data, customer lists, intellectual property like trade secrets, and confidential business plans or contracts. Establishing clear company guidelines on what constitutes sensitive information is the first step toward protecting it.
Anonymise Data Before You Prompt
One of the most effective techniques for safely using AI is data anonymisation. This involves removing or altering specific details so that the data cannot be traced back to an individual or your company. For example, instead of asking the AI to “Review this email from John Smith at Acme Corp regarding the Q3 sales decline,” you can generalise it. A safer prompt would be: “Review this draft email to a client about a quarterly performance dip. Replace specific names and figures with placeholders like [Client Name], [Company Name], and [Metric].” By using pseudonyms, generalising details, and removing identifying numbers, you can get help with the structure, tone, and clarity of your work without exposing the raw, confidential information.
Focus on Low-Risk Tasks
A great way to integrate AI safely is to start with tasks that don't involve sensitive data. Use AI to brainstorm ideas for a marketing campaign, summarise public articles, draft generic social media posts, or learn about a new topic. You can ask it to help you structure a report, generate creative headings, or explain a complex concept in simpler terms. These activities allow you to and your team to build confidence and develop good habits with AI tools without putting any confidential information at risk. Once your team is comfortable with safe prompting and understands the boundaries, you can gradually explore more complex use cases.
Use Business-Grade AI Tools
Many companies are now adopting enterprise-level AI solutions for their employees. Platforms like ChatGPT Team, Microsoft Copilot for Microsoft 365, or Google Workspace AI often come with crucial security and privacy features that are absent in the free, public versions. These business-tier accounts typically include contractual guarantees that your company's data will not be used to train the public models and will not be retained beyond what is necessary to provide the service. While they come at a cost, it is often minimal compared to the potential financial and reputational damage of a data leak. Always use company-approved tools for any work-related tasks and reserve personal accounts for non-work purposes.
Always Verify the Output
Beyond data privacy, it's critical to remember that AI models can make mistakes, a phenomenon sometimes called “hallucination.” They can generate plausible-sounding information that is factually incorrect, biased, or outdated. Never blindly trust AI-generated content, especially for important decisions. Always have a human in the loop to fact-check the output, review the logic, and ensure the information is accurate and appropriate before sharing it or acting on it. This final check is a non-negotiable step for responsible AI use.














