Understand the Core Risk
The biggest danger with public AI tools is that your inputs become their property. Many free, consumer-grade platforms like ChatGPT or Claude state in their terms of service that they use your prompts to train their models. When an employee pastes text
into a public AI tool, that data doesn't just vanish; it can be stored, reviewed by the vendor, and absorbed into the model's training dataset. This means your internal data could theoretically appear in a response to another user outside your organisation. Research shows that a significant percentage of employee prompts contain sensitive information, including customer data, employee PII, and financial details. This isn't usually malicious—it’s often an attempt to save time—but it exposes the business to huge risks, from compliance violations to reputational damage.
Establish a Clear AI Usage Policy
Your first line of defence is a formal, plain-language policy that governs how employees can use AI. This document should explicitly define what constitutes sensitive or confidential information—think intellectual property, financial records, client lists, and employee data—and prohibit it from being entered into public AI tools. The policy should also specify authorised tools and uses, while clearly banning unvetted applications. It’s not enough to simply write a policy; it must be communicated clearly during onboarding and reinforced with regular training to ensure everyone understands the rules. The goal is to create guardrails that mitigate legal and business risks without completely stifling productivity.
Upgrade to Business-Grade Tools
If your team needs AI to stay competitive, don't let them rely on personal accounts. The most critical step is to invest in enterprise-grade AI subscriptions, such as Microsoft 365 Copilot or the business tiers of Google's Gemini. These paid accounts are fundamentally different from their free counterparts. They come with enterprise-level privacy guarantees, ensuring that your company’s data remains within your own digital workspace and is never used to train the provider's public models. While these tools require an investment, the cost is minimal compared to the potential financial and reputational damage of a single data leak. By providing a secure, sanctioned alternative, you remove the main incentive for employees to use risky public tools.
Train Employees on Data Anonymisation
Even with the best policies, employees need practical skills to handle data safely. Teach your team the habit of anonymising information before it ever touches an AI prompt. This involves removing or altering personal identifiers so that individuals cannot be recognised. Simple techniques include using placeholders like "Client X" instead of real names, generalising specific dates to ranges like "last quarter," and stripping out exact financial figures. For more sensitive applications, data masking techniques can replace real data with random characters, or data can be aggregated to show team totals instead of individual performance metrics. This practice allows employees to get the structural or stylistic help they need from an AI without ever exposing the underlying confidential data.
Implement Technical Safeguards
Policy and training are crucial, but they should be backed by technology. Data Loss Prevention (DLP) solutions can be configured to monitor and block attempts to upload sensitive information to unauthorised external platforms. These systems can scan text in real-time and automatically stop a prompt containing flagged keywords or data patterns from ever leaving the employee's browser. Furthermore, organisations should enforce strong access controls, ensuring that employees can only access the data absolutely necessary for their jobs. Continuous monitoring of data activity can also help detect risky behaviour or anomalous data movements in real-time, allowing security teams to intervene before a leak escalates.
Maintain Human Oversight
Finally, cultivate a culture where AI is treated as an assistant, not an authority. Any output generated by an AI—whether it's code, a report, or a client email—must be reviewed by a human expert before it's used. AI models are known to "hallucinate," or invent plausible-sounding but incorrect information. Relying on unchecked AI output can lead to costly mistakes and damage your company's credibility. An effective AI policy should mandate that no final decision, especially one affecting business or employment, is made without independent human judgment and verification.














