Type: Checklist | Path: Apply AI | Level: Beginner
An AI tool can help rewrite a customer message without needing the customer's name, contact details, account history, or an entire inbox export. Before you paste, decide what information the task genuinely needs and whether your organization permits that information in that tool.
Outcome: Use a repeatable check to choose between proceeding, reducing the input, or asking for approval. Prerequisites: No coding. For practice, use the invented example below; you do not need to upload any work files or buy a subscription.
Start with the tool and the task
Write one sentence describing the job: “Create a polite reply explaining the published delivery process.” That sentence gives you a way to challenge every extra detail. If the task is about tone, confidential order history probably adds little value.
Check the approved product, account, workspace, and feature. A familiar brand or a work email address alone does not establish permission. The NCSC's guidance on shadow AI explains why unapproved services can reduce an organization's visibility and control over its data. Ask the relevant internal owner when the approved route is unclear.
Use this checklist before submitting
-
Confirm permission. Is this exact use allowed for this category of information? Being allowed to view a file does not automatically mean you may upload it elsewhere.
-
Reduce the input. Use the fewest sentences and fields that still let you complete the task. Prefer genuinely invented examples when learning a workflow.
-
Remove secrets. Never place passwords, access tokens, private keys, or payment credentials into an ordinary chat prompt. They are unnecessary for writing or analysis practice.
-
Check identifying details. Names and emails are obvious; a rare job title, exact incident date, customer ID, or a combination of facts may also identify someone. Replacing a name with “Customer A” does not prove that the text is anonymous.
-
Inspect the whole attachment. Hidden sheets, comments, document properties, screenshots, and copied email threads can contain information beyond the visible paragraph. A small plain-text excerpt is easier to inspect.
-
Understand the destination. Review the organization's guidance on storage, retention, access, model training, and any connected third-party service. These are separate questions.
-
Limit permissions and output sharing. A rewrite does not need inbox-wide access or permission to send messages. Check the generated text and its intended audience before sharing it.
Product settings matter, but they do not replace the first check. For example, OpenAI's enterprise privacy page says covered business data is not used for model training by default. That statement does not mean every account has the same controls, that content is never retained, or that your employer has approved your particular use. Verify the current plan and configuration rather than relying on a remembered screenshot.
Work through an invented example
Suppose a fictional service team wants help writing a calm response to a delayed delivery. Its original note includes a customer's name, street address, phone number, order number, and an internal explanation of a staffing problem.
For a tone exercise, start instead with this entirely invented input:
“Write a brief, polite reply to a fictional customer whose delivery is late. Acknowledge the delay. Say that the team will check the order status. Do not invent an arrival date, refund entitlement, or promise. Leave a placeholder for the next update time.”
The useful result is a reusable draft with placeholders. An authorized person can add verified order details later in the approved customer-support system. No real customer record is necessary for this practice task. If accurate case-specific analysis genuinely requires restricted information, pause and obtain the appropriate route rather than disguising it superficially.
Watch for instructions inside documents
A file being summarized might contain text telling the assistant to reveal other information or contact an external address. This is an example of the indirect prompt-injection risk described by OWASP. Treat supplied documents as material to inspect, not permission to perform new actions. Keeping unnecessary connections disabled and reviewing outputs reduces the possible impact; a prompt saying “ignore malicious instructions” is not a complete security control.
Try the check
You want to turn a real employee performance review into a generic feedback-writing template. Should you upload it after replacing the employee's name?
A safer answer is to write a fully fictional scenario or use an approved blank template first. The original may still identify the person and contain restricted employment information. If you need the real record, ask the appropriate internal owner about the permitted process.
When an upload goes wrong, stop further sharing and follow your organization's incident-reporting process. Deleting a chat should not be assumed to recall every copy. This checklist is practical risk reduction, not a legal compliance determination.
Sources reviewed on 5 October 2026: NCSC, The hidden risks of shadow AI; OpenAI, Enterprise privacy; OWASP, LLM01 Prompt Injection. Links appear beside the relevant claims. Example review: synthetic scenario checked manually; no external AI service was tested.