Sort information before you paste it
A quick information check prevents many avoidable mistakes. You can use four practical labels inside your team, even if they are informal. Match the labels to your own policies and obligations; they are a working aid, not a legal classification system.
- Public: already intended for anyone to see, such as a published product description.
- Internal: routine working material that should stay within the organisation.
- Confidential: customer, employee, financial, contract, or unreleased business information.
- Restricted: passwords, access tokens, payment credentials, government identifiers, or highly sensitive records.
Minimise and replace details
Ask whether the tool needs the original data at all. A customer message can often be rewritten with a fictional name and no account number. A spreadsheet question may need totals and column meanings, not every person’s record. A contract question may need a short excerpt, not the entire agreement.
Use placeholders such as [CUSTOMER], [DATE], or [AMOUNT] and keep the mapping outside the AI tool. Do not assume that removing a name is enough: combinations of location, job title, dates, and events can still identify someone.
Review the service and account settings
Services differ in how they handle prompts, uploaded files, logs, and feedback. Read the current privacy and data-use documentation for the specific service and account type you will use. Confirm retention, model-improvement use, deletion options, access permissions, and the locations or subprocessors described by the provider.
Use the organisation’s approved account where one exists. Turn on available security controls, limit access to people who need it, and avoid sharing a personal account with colleagues. For regulated or contract-bound information, ask the appropriate privacy or security contact before starting a workflow.
Check what comes back
Generated text can be wrong, incomplete, outdated, or overly confident. Verify names, dates, figures, quotations, links, code, and recommendations against source material before you rely on them. Do not let an AI draft make a payment, approve a customer, hire someone, or decide a person’s rights without the appropriate human process.
When the output includes a claim, ask for the source or point it back to the supplied document. Then open the source yourself. A citation-looking link is not proof that the claim is correct.
Have a simple stop-and-report rule
If someone pastes restricted information by mistake, stop using that conversation for further work. Follow your organisation’s incident process, record what was shared and where, and use the provider’s available deletion or support process. Do not promise that deleting a chat erases every system copy unless the service confirms how deletion works.
A short team rule is easier to follow than a long warning: use approved services, share only the minimum, never paste credentials, and ask before using confidential or regulated data.
