T12-L01 · Security, privacy & governance · Level 1 User · 18 minutes
At Level 1, you control one person's input and output. Your first safety control is simple: decide what may enter the AI service before you paste, upload, photograph, or connect anything.
2. The summary is due at 18:40
You need a summary before you leave. In the Company version, the source is a customer contract containing names, prices, and negotiated terms. In the Lab version, it is a collaborator's unpublished manuscript with participant details in one table. Nobody has given you a clear AI rule, but a chatbot is open in your personal account and the task looks harmless. You only want a summary.
The disclosure happens when you submit the material, not when you publish the answer. A whole PDF can expose much more than the paragraph you wanted summarised. Paying for an account, using a familiar brand, or deleting the chat later does not establish that this particular tool and data are approved.
You need a decision that works before the deadline pressure wins: classify the material as green, yellow, or red; confirm the tool boundary; then either proceed, reduce the input, use a cleared route, or stop.
3. After this you can
- Classify a proposed paste as green, yellow, or red in seconds.
- Distinguish data that looks harmless from a tool that is actually approved for it.
- Rewrite a red request so it uses public, synthetic, or non-identifying material.
- Explain the stop-and-ask rule to a colleague without making legal claims.
4. Prerequisites
T01-L01· What AI can and can't do for your work.- Paper, a spreadsheet, or a text editor for a five-row classification sheet.
- Your organisation's current list of approved AI services and permitted uses, if one exists.
- No AI account is required. You can complete every exercise offline.
Use only public, synthetic, course-provided, or explicitly approved material while learning. If you cannot find a rule or responsible contact, uncertainty means stop and ask, not “use a personal account.”
5. The idea in one page
Pasting text, uploading a file, attaching an image, speaking into a transcription feature, or connecting a drive all send information into a service. What happens next depends on the provider, product, account type, settings, integrations, contract, and local policy. Inputs may be retained in logs, available to authorised reviewers, or used for service improvement under some configurations. Do not guess from the logo or interface. If you cannot verify the controls for your account, plan as though the input could be retained and seen outside your organisation.
Classify the actual content, not the size of the request.
| Class | Practical meaning | What you do |
|---|---|---|
| Green: public or synthetic | The material is already intentionally public, or it was invented for the task. It contains no hidden identifier, credential, private comment, restricted attachment, or unpublished result. | You may use it in an allowed task. Still check copyright, licences, source terms, and output accuracy where relevant; green is not permission to ignore them. |
| Yellow: internal, not sensitive | Routine internal material with no personal data, secret, unpublished finding, confidential term, or restricted detail. Examples might include a generic agenda or an approved style guide. | Use only a service your organisation has explicitly approved for this purpose and data class. If the approval is unclear, stop and ask. |
| Red: restricted or sensitive | Personal or health data, participant or customer records, credentials, security details, trade secrets, negotiated terms, unpublished work, salary or applicant information, production data, or material covered by a confidentiality commitment. | Do not submit it to an AI service unless an accountable owner has cleared the specific tool, purpose, and data in writing. Active passwords, API keys, tokens, and private keys should never be pasted into a prompt. |
“Approved” does not mean popular, paid, enterprise-looking, hosted in a region named on a marketing page, or already used by a colleague. It means the responsible people have named the service and allowed this kind of task with this kind of information, normally through an organisation-managed arrangement. A tool can be approved for public drafting but not participant records. Approval belongs to the combination of tool + account + purpose + data, not to the brand alone.
Use this fast screen:
Would I be comfortable seeing this exact input made public beside my organisation's name?
A yes is only a quick green check, not final permission. A no or not sure means yellow or red until you confirm otherwise.
There are three useful ways to continue without casually exposing red material:
- Minimise or anonymise first. Remove information the task does not need and replace details with neutral placeholders. Removing a name alone is not enough when dates, rare conditions, job titles, locations, or free text can identify someone. At Level 1, prefer fully synthetic examples whenever possible.
- Ask about shape, not content. Request a blank structure, checklist, formula pattern, or set of questions without supplying the live record. “Give me a six-heading contract-summary template” needs no customer contract.
- Use the cleared route. If the real data is essential, use only the specific approved system and process. Let the accountable data, security, privacy, research, or contract owner decide whether the route is suitable.
Sometimes none of these preserves the task. That is a valid stop. A useful AI answer is not worth bypassing a boundary you cannot verify. If people are using personal accounts because no legitimate route exists, report the unmet need honestly: a usable approved path usually produces safer behaviour than a ban people quietly work around.
6. The worked example: classify before you paste
Mira in the Lab and Jonas in the Company use the same five-step method:
- Name exactly what would leave the organisation.
- Look for identifiers, secrets, confidential terms, or unpublished material.
- Assign green, yellow, or red before choosing a tool.
- For yellow, verify the exact approved route. For red, stop or transform the request.
- Recheck the rewritten input as though it were a new item.
Lab framing: manuscript and participant work
Mira records five things she recently considered pasting. She classifies the input, not the hoped-for summary.
| Proposed input | Class and decision | Safe rewrite |
|---|---|---|
| A paragraph from an openly published article, with its citation | Green. It is public, and the task is allowed. | Paste only the relevant paragraph and citation, then verify the output against the article. |
| A generic internal meeting agenda with no project names or results | Yellow. It is internal even though it looks ordinary. | Use the approved workspace after confirming routine agendas are permitted, or replace the agenda topics with generic labels. |
| A collaborator's unpublished manuscript | Red. Publication status and the collaborator's trust matter; Mira cannot grant permission alone. | Ask for a blank review checklist with headings such as claim, evidence, limitation, and question. Apply it locally without supplying manuscript text. |
| A participant table with names removed but rare conditions, dates, and free-text notes intact | Red. Removing one direct identifier has not removed re-identification risk or sensitive content. | Create five fictional rows with invented dates and ordinary categories to test the desired table operation. Keep the real table out of the exercise. |
| An error message containing a live API token | Red. The credential can grant access. | Revoke or rotate the exposed token through the proper route, then ask about the error using [TOKEN_REMOVED] and a minimal synthetic example. |
For the manuscript, Mira's original request was unsafe:
Summarise this unpublished manuscript and identify its weakest claim.
[full manuscript]
She changes the task so no manuscript content leaves her workspace:
Create a blank manuscript-review checklist with these columns:
section, main claim, evidence supplied, limitation, and question for the author.
Do not assess any real manuscript. Return only the empty checklist and brief instructions.
The rewritten request is green because it asks for a generic structure. Mira does the substantive review herself. If she later needs AI to process the manuscript text, she asks the project owner which system and permission cover that collaborator's work.
Company framing: contracts and people data
Jonas applies the identical method to office work.
| Proposed input | Class and decision | Safe rewrite |
|---|---|---|
| Text from the company's public product page | Green. It is intentionally public. | Paste only the relevant published text and link, then check that the draft adds no unsupported promise. |
| An internal weekly update with project codes but no customer, financial, or personnel details | Yellow. “Not very secret” is still internal. | Use only the approved workspace if this purpose and content are permitted, or replace project codes with Project A and Project B. |
| A customer contract with names, prices, and negotiated clauses | Red. The whole document contains more than the summary requires. | Ask for a generic contract-summary template covering parties, term, deliverables, exceptions, dates, and open questions. Fill it locally or use a specifically cleared contract process. |
| CVs for applicants | Red. They contain personal information and concern a consequential employment process. | Ask for a blank, human-owned interview-note template based only on approved public role criteria. Do not ask the AI to rank people. |
| An invoice showing supplier bank details and an employee approver | Red. Financial and personal details are unnecessary for a formatting example. | Use a fictional invoice containing Supplier A, INV-001, 100 units, and invented amounts, with no real bank, tax, address, or contact data. |
Jonas also turns his unsafe request into a green one:
Create a one-page blank template for summarising a customer contract.
Include: parties, effective date, term, deliverables, payment structure,
exceptions, termination conditions, unresolved questions, and source clause.
Do not provide legal interpretation or example clauses.
The parallel is deliberate. Mira does not need to reveal a manuscript to obtain a review structure; Jonas does not need to reveal a contract to obtain a summary structure. Both keep the real judgement with the responsible person. Neither rewrite declares the real work approved, anonymous, compliant, or legally sufficient.
7. What goes wrong
A paid plan is treated as approval
Symptom: you assume payment or an “enterprise” label permits every internal file.
Fix: find the named organisational service, managed account, permitted purpose, and allowed data class. Missing any one means stop and ask.
A region name settles the question
Symptom: a vendor's location or an “EU” label is treated as proof of where every input, backup, log, support process, and connected feature operates.
Fix: do not infer controls from branding. Ask the responsible owner to confirm the approved configuration and use.
The whole PDF goes in for a short summary
Symptom: appendices, comments, signatures, hidden text, and unrelated records leave with the wanted page.
Fix: minimise before upload. If the relevant excerpt is still red, use a synthetic example, ask only for the output shape, or use the cleared route.
“Just this once” uses a personal account
Symptom: urgency turns the absence of an approved tool into permission to use another one.
Fix: do the task manually, request the approved path, or submit a green structural prompt. A deadline does not change the input class.
Someone else's data feels safer than yours
Symptom: a colleague's manuscript, applicant's CV, participant row, or customer's email is pasted because you are not the subject.
Fix: treat information entrusted to you at least as carefully as your own. You cannot create approval merely by being able to open the file.
Deleting the chat is treated as undo
Symptom: after a mistaken paste, you delete the visible conversation and assume the disclosure no longer matters.
Fix: follow your organisation's incident or security reporting route promptly. State what was sent, to which service and account, and when. Do not hide the event or invent your own legal conclusion.
8. Do it yourself: a 15-minute paste audit
Do not copy sensitive content into the audit. Describe each item generically, such as customer contract or participant table, and keep the sheet only where your organisation permits.
Minutes 0–3: list your last five actual or intended AI pastes, uploads, images, recordings, or connected files. Record the service and whether the account was personal or organisation-managed.
Minutes 3–7: assign green, yellow, or red. Write the signal that decided it: public source, synthetic fixture, internal status, personal data, credential, confidential term, unpublished work, or uncertainty.
Minutes 7–11: verify every yellow item against the named approved tool, purpose, and data class. If you cannot verify all three, change its decision to stop and ask.
Minutes 11–14: rewrite every red request to green. Remove the live content and ask for a blank structure, use invented data, or describe the technical shape. If the original task cannot work without red data, write a green routing question such as Which approved process handles this data class? Never copy an active credential into the sheet.
Minute 14–15: reclassify each rewrite from scratch. A rewrite passes only if someone could read the exact proposed input without learning the protected facts.
Use this single five-row sheet:
| No. | Generic description of input | Tool/account | Green / Yellow / Red and reason | Decision or green rewrite | Rewrite rechecked? |
|---|---|---|---|---|---|
| 1 | Yes / No | ||||
| 2 | Yes / No | ||||
| 3 | Yes / No | ||||
| 4 | Yes / No | ||||
| 5 | Yes / No |
9. Exit check
Deliver exactly one artifact: the completed five-row paste-classification sheet, with a reason for every class and every red item rewritten to green.
It passes when the sheet contains no sensitive content or active credential, every yellow decision names how approval will be checked, and another person can understand why each proposed input proceeds, changes, or stops.
10. Rule to remember
Green is public. Yellow is approved tools. Red is nobody's business but ours.
11. Further reading & tools
- Taught:
T01-L01· What AI can and can't do for your work — introduces why an input may leave the company or lab and why approval comes before use. - Taught:
T12-L02· Privacy and labelling in everyday work — continues with practical anonymisation, verification, labels, and manipulation attempts. - Catalogued: Privacy & safe AI use — practises data minimisation, source boundaries, verification, and human escalation with fictional information.
- Catalogued: NIST Privacy Framework (opens in a new tab) — voluntary guidance for identifying and managing privacy risk; it does not approve a particular paste or tool.
- Catalogued: NIST Generative AI Profile (opens in a new tab) — risk-management guidance for generative AI, including data privacy and information-security concerns.
- Catalogued: Tools index — product references only; confirm the current account, configuration, data handling, and organisational approval before use.