Four Data Boundaries to Set Before Using AI on Company Material
Not legal theory but working agreements: what must never enter external tools, who can authorise exceptions, how long data is retained, and what guidance staff actually need.
Key takeaway
Not legal theory but working agreements: what must never enter external tools, who can authorise exceptions, how long data is retained, and what guidance staff actually need.

When someone pastes customer records into an external AI tool it is rarely deliberate misconduct — the company never said what was allowed. Rather than assigning blame afterwards, set four clear boundaries in advance. None of them requires a legal background to decide.
One: name the material that must not leave
Draw the line by consequence of exposure rather than by file type. At minimum, put these off limits for external tools:
- Personally identifiable information: identity documents, phone numbers, home addresses, health details.
- Material the customer asked to keep confidential, and project files under a confidentiality agreement.
- Unpublished financial data, pricing strategy and cost structure.
- Credentials, keys and internal system addresses.
Two: say who can authorise exceptions
Exceptions will be needed; what matters is that the path is clear:
- Name a specific approver rather than "ask management".
- Record each authorisation: what material, for what purpose, valid for how long.
- Default to no: without explicit authorisation, treat it as prohibited rather than leaving it to individual judgment.
Three: agree retention and cleanup
The lifecycle after material enters a tool needs defining too:
- How long conversations and uploads are kept, and who clears them.
- Whether material must be removed when a project ends.
- How work held under a personal account is transferred or deleted when someone leaves.
Four: give staff usable guidance
A policy must be readable in thirty seconds or it will not be followed. Make it one page containing:
- A may-paste / must-not-paste table using concrete examples rather than abstract categories.
- Whom to ask when unsure, naming a person and how to reach them.
- A minimum redaction rule, such as "replace customer names with industry and size band".
A note on tool selection
Confirm the data-use terms during selection: whether inputs may be used for training, whether that can be disabled, and where data is stored. These are usually stated plainly in the terms — someone just has to read them.
Summary
The point of these boundaries is not to restrict use but to let people use tools with confidence. When rules are vague, the cautious avoid the tools and the bold misuse them, and neither outcome is good.