Information that should not go into public AI tools
Unit ID: AIT-M11-U00 Estimated active time: 15-20 minutes
The main idea
Some information should not be pasted into general tools.
Once text is in a prompt it has left your control. You may not know where it is stored, who can see it, or whether it is retained.
Why this matters
This decision is much easier made in advance than in the moment. Under deadline, the reasoning becomes "it is probably fine", which is not a decision.
Safe example
A real customer complaint may contain personal and confidential details.
Name, account, address, and often health or financial detail, all in a message that feels like ordinary text.
Better working habit
Remove, replace, or avoid sensitive details unless the tool is approved.
Three options in order of preference. "Avoid" is a legitimate answer and the one people forget is available.
What to watch for
Do not assume a popular tool is approved for every data type.
Approval is per category, not per tool. A tool approved for internal drafting may not be approved for customer data.
Mini practice
Classify sample information into safe, anonymise, or do not share.
Then check your list against your organisation's actual policy.
Check yourself
Before moving on, answer:
- What category of information is this?
- Is this specific tool approved for that category?
- Could I do this task without the tool at all?
