AI assistants can help with routine work, but each organisation needs to decide what information its employees may share.
Choose approved business accounts
Use tools and account types approved by your organisation. Review the provider’s applicable privacy, retention and administrative settings rather than assuming all products or subscriptions handle data identically.
Keep confidential information out of unapproved prompts
Avoid pasting customer records, credentials, contracts, internal financial information or personal data unless there is an approved lawful workflow and the tool is configured appropriately.
Check permissions before using Microsoft Copilot
Copilot can surface information that a user is already authorised to access. Review file permissions and oversharing in Microsoft 365 before enabling broad use.
Verify AI-generated output
AI responses can contain invented facts, incorrect calculations or misleading references. Check source documents and require human approval before sending consequential advice or making business decisions.
Create a simple AI usage policy
Document approved tools, permitted data, prohibited tasks, review responsibilities and how staff should report an accidental disclosure.
Book cybersecurity and AI training
Learn these skills with Matthew Southgate in our combined full-day course. View and book upcoming training events, or register interest in the online training course.