Practical workplace rules for personal data, confidential information, customer data and material employees should not put into unapproved public AI tools.

01

The safest rule is specific, not vague

Telling employees not to enter 'sensitive data' into AI leaves too much interpretation. Organisations should name the categories that matter and distinguish between approved enterprise tools with agreed controls and unapproved public services.

02

Information to restrict in unapproved public AI tools

  • Customer or employee personal data, especially special-category or highly sensitive information.
  • Passwords, authentication material, security configurations or incident details.
  • Confidential contracts, legal advice or non-public commercial negotiations.
  • Trade secrets, proprietary source code, unpublished product information or strategic plans.
  • Client material supplied under confidentiality obligations.
  • Information that the employee does not have authority to disclose to an external service provider.
03

Approved tools still need rules

An enterprise licence or contractual control can change the risk, but it does not make every input automatically appropriate. Employees still need to follow data protection, confidentiality, retention, purpose limitation and access rules that apply to the underlying information.

04

Pair data rules with verification rules

Input controls prevent one class of problem. Output controls address another. Staff should know when they must verify factual claims, calculations, citations, legal propositions or consequential recommendations before relying on or sharing them.

05

Blanche perspective

Create a one-page employee rule set with real examples from your business. Then connect it to a short escalation route so a useful but unusual AI use can be reviewed rather than quietly attempted outside the rules.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Irish DPC: AI, large language models and data protection