AI-generated illustration: decide what information belongs in an AI task before sharing it.
Before sharing business data with AI, decide what the task actually needs, classify the information that remains, and check whether the exact tool and account are approved to receive it. If any of those answers is unclear, change the input or stop. A familiar brand, a paid subscription or a removed customer name is not enough to make an upload appropriate.
The useful question is not simply, “Is this document confidential?” It is, “May this version of these fields go to this destination for this purpose?” That smaller decision is something a team can explain, review and repeat.
This guide offers a practical screening method, not a legal opinion or a guarantee of compliance. It extends the boundaries in our guide to using AI in a small business without losing control. Start with one real workflow, but practise the method on invented data before handling customer or employee information.
Start with the task, not the whole file
Write one sentence describing the output you need. “Draft a polite appointment reminder” is a task. “Upload the customer folder and see what AI can do” is not a sufficiently bounded one.
Then list the facts needed for that output. A generic reminder template might need the tone, the type of appointment and the instructions a customer should follow. It probably does not need their name, address, payment history or the entire email conversation. Those details can often be inserted later in the approved customer system.
This distinction also helps when scoring AI use cases by value, risk and reversibility. If the proposed benefit depends on exposing a large amount of sensitive information, reducing the input may change whether the pilot is worth doing.
Use four working labels for the remaining information
A small team needs labels that lead to actions. The following four labels are a suggested operating convention, not statutory categories or a substitute for your organisation’s existing classification scheme. If you already have a policy, use its definitions and approval process.
Public: approved for this kind of reuse
An already published product description or opening-hours page may be a suitable input for a rewriting task. Still check that it is current, that you have the right to reuse it, and that combining it with other information does not reveal something new. Information being visible on the internet does not make every use of it unrestricted.
Internal: useful inside the business, not cleared for general release
Examples include an unpublished process note or an internal meeting agenda without sensitive details. Use only a destination approved for that class and purpose. “Internal” should not become a catch-all label that quietly includes customer records, staff matters and commercial secrets.
Confidential: limited access and explicit handling conditions
Client briefs, unpublished pricing, supplier negotiations and identifiable customer correspondence can belong here. Identify the owner and the relevant contractual or organisational restrictions. Do not assume that an employee’s ability to open a file includes permission to transfer it to another service.
Restricted: stop and use the specialist route
For this screening method, put passwords, access tokens, highly sensitive personal details and material whose disclosure could cause serious harm in a stop category. Do not paste it into a general AI chat. If there is a genuine business need, the responsible security, privacy or legal owner should decide on an appropriately controlled process.
Mixed files need particular care. A mostly public presentation can still contain one confidential speaker note. Either separate and review the permitted material or handle the file at the level required by its most sensitive remaining content. Renaming the file does not change what it contains.
Look beyond names and visible paragraphs
Review the actual material you intend to send. A spreadsheet may include hidden sheets, comments, formulas or exported identifiers. A document can contain tracked changes, earlier drafts and author details. Screenshots may expose browser tabs, account names or notifications. Audio can include names, voices and background conversations.
Context can identify people even when obvious identifiers have gone. “The only evening-shift engineer at our Bristol branch” may be enough for a colleague to recognise someone. Exact dates, unusual incidents and small-group totals can create similar problems.
The ICO’s guidance on pseudonymisation distinguishes replacing identifiers from making information anonymous. In particular, data that can be linked back to a person using separately held information remains personal data in the hands of the party holding that information. Treat labels such as “Customer A” as a risk-reduction measure to assess, not an automatic permission to upload.
Check the destination as carefully as the data
The same input can have a different risk profile in two accounts of the same product. Confirm the approved workspace and account, rather than relying on a colleague saying that “we use that AI”. Check the applicable terms and settings at the time of the task.
The NCSC’s 7 September 2026 guidance on shadow AI explains how unapproved services can reduce an organisation’s visibility and control over its information. Its practical implication for a small team is straightforward: provide a clear approved route, and make it easy to ask when a task does not fit.
Before approving the destination, establish:
Whether the specific data class and business purpose are permitted, including any client restrictions.
How inputs and outputs are retained, whether they may be used to improve models, and which controls actually apply to this account.
Who can access the conversation, files and generated result, including workspace members and linked services.
Whether connectors or agents can retrieve more information or take actions beyond the proposed task.
Who owns the decision, where the approved result belongs, and what the deletion or incident process is.
A “not used for training” statement answers one question, not all five. It does not by itself establish that there is no storage, no access by authorised operators, no onward transfer or permission from your client. If the answer is uncertain, record the gap instead of filling it with an assumption.
Minimise first, then review the transformed input
There are several ways to reduce what leaves the business. Remove fields the task does not require. Replace real details with genuinely invented examples when you are testing a format. Summarise a business problem without including the underlying case history. Use aggregated figures when the task only needs a broad trend.
Each method has limits. An aggregate based on one person reveals that person’s result. A fictional name attached to a distinctive real story may still identify someone. A summary can retain the commercially sensitive fact you were trying to protect. Review the new version as a separate input rather than assuming that a transformation made it safe.
The ICO’s introduction to anonymisation is useful when identification risk matters. The guidance carries an under-review notice following the Data (Use and Access) Act; check the current text and obtain appropriate advice for your circumstances. This article does not certify an anonymisation technique.
AI-generated diagram: review the reduced input and its destination before a person approves sharing.
A fictional example: an appointment reminder
Imagine a repair business wants AI to improve the wording of a reminder. Its proposed input is a real email thread containing a customer’s name, home address, phone number, appointment time, payment dispute and a note about a health condition affecting access to the property. This example is invented; it is not a report of a test or customer outcome.
The intended output is only a reusable reminder template. That means the customer’s identity, payment dispute and health detail are unnecessary. The team does not need to argue about whether all those fields can be made acceptable: it can remove them from this task altogether.
The revised input says: “Write a friendly reminder for a home-repair appointment. Leave placeholders for the customer name and appointment date. Ask the customer to confirm access arrangements through our usual contact channel. Do not invent a cancellation fee, promise an arrival time or include personal information.”
A reviewer checks that this generic input is permitted in the approved workspace, then checks the output against the business’s real service terms. Staff insert the actual booking details later in the authorised booking system. They do not add the removed email thread as an attachment “for context”.
If the task changes to deciding how to handle the individual customer’s access needs, the old approval no longer fits. That is a different purpose involving different information and requires a fresh decision. A useful approval belongs to a defined task, not to every future use of the same tool.
Keep a short decision record
A record should explain the decision without creating another unnecessary copy of sensitive data. Reference the approved source location and record the categories reviewed, not the customer’s private details. Keep the record in the system your organisation uses for this purpose.
Task and intended output:
Source location and owner:
Necessary fields:
Working classification:
Fields removed or replaced:
Identification or confidentiality concerns remaining:
Approved destination and account:
Retention, access and connected-tool checks:
Decision: share / change input / stop
Approver and date:
Review trigger or expiry:
For recurring work, save the reviewed procedure as well as the decision. Revisit it when the input changes, a connector is enabled, the tool’s terms change or a new person gains access. A reusable template is useful; an approval that silently expands over time is not.
When the output is client-facing, include this boundary in the client brief for AI-assisted content. The brief should identify approved source material and what must stay outside the AI workflow.
Use AI to challenge the process, not grant permission
You can ask an assistant to review a generic description of your screening process. Do not upload the disputed material to ask whether uploading it is safe: that would perform the very transfer you have not approved.
Review this fictional data-sharing scenario.
Task: [generic task]
Information categories: [categories only; no real records]
Proposed destination controls: [non-sensitive summary]
Identify missing approval questions and unnecessary fields.
Separate known facts from assumptions.
Do not declare the transfer compliant or authorised.
The answer may help a reviewer spot omissions, but it is not evidence that a vendor’s settings or your organisation’s permissions are correct. Check those against the actual approved records.
If information was already shared, stop further spread
Pause the workflow and contact the person responsible for security or privacy through the established channel. Record what was shared, when, with which account and which service, without copying the material into more places. Follow the organisation’s incident process for containment, access review and any required notifications.
Deleting a chat may be one available step, but do not describe it as proof that every copy or log has disappeared. If credentials were exposed, the responsible owner should handle revocation or replacement promptly. Do not keep experimenting with the same material while waiting for advice.
For UK organisations, the ICO’s AI and data-protection guidance is a starting point for the broader assessment. The operational checklist here supports that work; it does not replace it.
Reader Q&A
Does removing a customer’s name make an AI upload anonymous?
No. Other details may still identify the person, and a replacement label may be linkable to a separate record. Review the remaining information and context rather than treating name removal as automatic permission.
Is a paid AI account safe for confidential business data?
Payment alone does not answer that. Check the exact account, applicable terms, retention, access, connected tools and your organisation’s approval for the data and purpose.
What should we do with a file containing several data classes?
Separate and review the material the task actually needs, or handle the file at the level required by its most sensitive remaining content. Check comments, hidden sheets, attachments and other non-obvious information too.
Can we ask AI to decide whether a document is safe to upload?
Do not upload an unapproved document to make that decision. Ask about a generic or fictional scenario without real records, then have the responsible person verify the actual permissions and controls.
Can an approved connector access every company folder?
It should only receive the access required for the approved task. Review its actual scope and inherited permissions; approval of the tool does not automatically approve every folder or future action.
How often should a data-sharing decision be reviewed?
Review it when the purpose, input, account, terms, access or connected tools change, and at the review date your organisation sets. A new task or more sensitive input needs a fresh decision.
Make the next upload a deliberate decision
Choose one routine task and write down its minimum input. Classify that input, remove unnecessary details, check the exact destination and name the person who can approve it. If the remaining uncertainty matters, stop or choose a different method. The aim is a useful result with an explainable data-sharing decision, not the largest possible upload.
Originally published on Prodify Digital.
Republished and formatted with AI assistance. This article contains affiliate links; purchases through them may earn a commission.


Top comments (0)