cyber&
Back to Resources

What information should not go into an AI tool

Decide what an approved AI tool may receive, minimize inputs, and keep sensitive data and secrets out.

Start with the situation

AI services differ in contracts, retention, training use, connectors, and administrative controls. A paid or enterprise label alone does not decide what is safe to share.

The decision to make

Use only an approved tool for an approved purpose, and provide the least information needed for the task.

A practical sequence

  1. Identify personal data, client information, confidential plans, regulated records, credentials, or source code.
  2. Confirm the exact service, account, feature, and connector are permitted by your organization.
  3. Remove names, identifiers, unpublished figures, and unnecessary context. Use invented examples when they can achieve the same result.
  4. Treat generated content as unverified; check facts, sources, permissions, and impact before using it.

Real-world examples

  • Replace a real customer record with a fictional sample before asking for formatting help.
  • Describe a coding pattern without pasting production secrets or proprietary modules.
  • Review permissions before connecting an AI assistant to mail, files, or source repositories.

Common mistakes

  • Assuming an opt-out setting makes every input appropriate.
  • Pasting passwords, API keys, access tokens, private keys, or recovery codes.
  • Uploading a whole document when a short, de-identified excerpt would be enough.

What to do next

If sensitive information was submitted, stop sharing more, preserve the relevant details, and report it through the appropriate internal route.

Approval and data minimization matter more than the convenience of a prompt.

Trusted official references

  • NIST

    AI Risk Management Framework

    A voluntary framework for identifying and managing risks throughout AI use and governance.

    View official source
  • NIST

    Generative Artificial Intelligence Profile

    Companion guidance on risks specific to generative AI, including data privacy and information integrity.

    View official source