THE SHORT ANSWER

Before using data with AI, define the purpose, confirm authority, minimize the information, classify sensitivity, restrict access, understand vendor use and retention, protect outputs and establish deletion and incident processes. Do not enter confidential data into unapproved tools.

Map data into, through and out of the system

  • Input and retrieved context
  • Prompt and conversation history
  • Model or vendor processing
  • Logs, telemetry and human review
  • Generated output and downstream storage
  • Training, retention and deletion conditions

Use the least information that can achieve the purpose

Replace real records with synthetic or de-identified examples where feasible, remove unnecessary fields, restrict retrieval scope and avoid copying complete documents when a bounded extract will do.

De-identification can fail when information is combined, so treat it as a risk reduction rather than an automatic guarantee.

Protect business information as well as personal information

Source code, contracts, strategy, credentials, financial data and unreleased product information may be confidential even when they do not identify a person. Apply classification, approved tools and access controls.

Verify the service conditions

  • Does the provider use inputs or outputs to improve models?
  • Where and how long is information retained?
  • Which administrators and subprocessors can access it?
  • Can settings, contracts or architecture limit use?
  • How are deletion, export and incidents handled?

Requirements vary by data, contract and jurisdiction; involve privacy, security and legal specialists where appropriate.

Sources & further reading

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0)

    National Institute of Standards and Technology. Voluntary, rights-preserving guidance organized around GOVERN, MAP, MEASURE and MANAGE. NIST was revising AI RMF 1.0 when checked on 28 September 2026, so organizations should verify the current version before formal adoption.

  2. OECD AI Principles

    OECD.AI. Intergovernmental principles updated in May 2024 covering inclusive benefit, human rights and fairness, transparency, robustness and accountability. They are high-level guidance rather than a complete operational control set.

  3. The NIST Cybersecurity Framework 2.0

    National Institute of Standards and Technology. Current outcome-based guidance for governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risk. It does not prescribe one implementation.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗