Lesson 04 · 8 minutes
Know what not to share
Classify information before using an AI product and minimise what leaves your approved systems.
Why this matters
Useful AI features can make it easy to disclose information without noticing the boundary crossed.
Product, plan and organisational controls differ, so a familiar brand is not enough assurance.
The practical bit
Before pasting or uploading, ask who the information identifies, who owns it, what agreement or policy covers it and what harm disclosure could create. Use the minimum information required for the task.
Remove names and unnecessary details, use approved organisational products, or create a synthetic example. When privacy, retention or training terms are unclear, stop and confirm them rather than assuming.
What it looks like
Test a staff-letter workflow with invented names and situations before considering real employee information, then follow the organisation’s approved tools and policy.
Ask for help understanding the structure of a medical form without uploading identifiable records or treating the generated explanation as medical advice.
Removing a person’s name but leaving enough role, date, location or case detail for them to remain identifiable.
Use your judgement
Try it now
- Choose a document or task you might give an AI product.
- Mark personal, confidential, commercially sensitive and unnecessary details.
- Create a reduced or synthetic version that can still test the workflow.
Use this in a real situation
Practise with a permitted fileWork through a file example without handing over sensitive material.Open the practical →Keep this
Use the least sensitive context that can produce a meaningful test.