AI tools can help draft an email, summarise public information or turn notes into a first draft. They can also receive far more information than a staff member intended to share.
A prompt might include a customer's name, a contract, internal financial figures or part of a confidential document. Once that information leaves the business, your control depends on the provider's current terms, settings and security.
Different AI services handle prompts in different ways. Some may use content to improve their services, while some business plans offer stronger controls. Do not assume a paid account is private. Check the terms for the exact product and settings your team uses.
1. Set a clear AI use policy
Tell staff which tools are approved and what must never be entered. Cover personal information, client files, passwords, private financial data, contracts, internal plans and source code.
Keep the rule practical: if the information would not be sent to an unknown outside provider, it should not be pasted into an unapproved AI service.
Include the policy in onboarding and review it when tools or provider terms change.
2. Use approved business accounts
Where the business chooses to use AI, manage access through approved work accounts rather than personal accounts.
Before approval, check whether the service uses prompts or files to improve its systems, how long it keeps the content, who can access account history and how the business can delete its information. Also review the available administrator controls and where information is processed when that matters to your obligations.
Record the decision. Marketing labels such as "business" or "enterprise" are not a substitute for reading the current terms.
3. Add controls for sensitive information
Some security products can warn users or block sensitive information before it is submitted to an AI website. The available controls depend on the devices, browser, licences and service in use.
Start by identifying the information that needs protection. Then ask your IT provider which controls can cover the approved tools and how exceptions will be handled. Test the setup rather than assuming every prompt and file upload is protected.
4. Train staff with real work examples
A policy in a shared folder is easy to forget. Show staff how the rules apply to their normal tasks.
For example, practise summarising a customer issue after removing names, account numbers and identifying details. Explain why replacing a name is not enough if the rest of the prompt still identifies the person or business.
Staff should also know who to contact before using a new tool or uploading an unfamiliar file.
5. Review how approved tools are used
Use the administration and reporting features available in your approved service. Review account access, new integrations and unusual use at an interval that suits the risk.
The aim is to find unsafe habits and gaps in the setup, not to surprise staff with hidden monitoring. Tell employees what the business records and why.
6. Make it easy to report a mistake
Someone who pastes the wrong information into a tool should report it immediately. A quick report gives the business a chance to check account history, contact the provider and get privacy or legal advice if needed.
Leaders should follow the same rules as everyone else. Staff are more likely to speak up when the process focuses on limiting harm rather than assigning blame.
Use AI with a clear boundary
The safest starting point is simple: approved tools, work accounts, known data rules and a quick way to ask for help. If the business cannot explain what happens to a prompt, private information should stay out of it.
Ask JCPIT about setting an AI use policy to give staff a short set of rules for approved tools and private information. We will confirm the tools, accounts and access in scope before reviewing technical controls.