Skip to main content

Four Data Boundaries to Set Before Using AI on Company Material

Not legal theory but working agreements: what must never enter external tools, who can authorise exceptions, how long data is retained, and what guidance staff actually need.

Key takeaway

Not legal theory but working agreements: what must never enter external tools, who can authorise exceptions, how long data is retained, and what guidance staff actually need.

Four Data Boundaries to Set Before Using AI on Company Material

When someone pastes customer records into an external AI tool it is rarely deliberate misconduct — the company never said what was allowed. Rather than assigning blame afterwards, set four clear boundaries in advance. None of them requires a legal background to decide.

One: name the material that must not leave

Draw the line by consequence of exposure rather than by file type. At minimum, put these off limits for external tools:

  • Personally identifiable information: identity documents, phone numbers, home addresses, health details.
  • Material the customer asked to keep confidential, and project files under a confidentiality agreement.
  • Unpublished financial data, pricing strategy and cost structure.
  • Credentials, keys and internal system addresses.

Two: say who can authorise exceptions

Exceptions will be needed; what matters is that the path is clear:

  • Name a specific approver rather than "ask management".
  • Record each authorisation: what material, for what purpose, valid for how long.
  • Default to no: without explicit authorisation, treat it as prohibited rather than leaving it to individual judgment.

Three: agree retention and cleanup

The lifecycle after material enters a tool needs defining too:

  • How long conversations and uploads are kept, and who clears them.
  • Whether material must be removed when a project ends.
  • How work held under a personal account is transferred or deleted when someone leaves.

Four: give staff usable guidance

A policy must be readable in thirty seconds or it will not be followed. Make it one page containing:

  • A may-paste / must-not-paste table using concrete examples rather than abstract categories.
  • Whom to ask when unsure, naming a person and how to reach them.
  • A minimum redaction rule, such as "replace customer names with industry and size band".

A note on tool selection

Confirm the data-use terms during selection: whether inputs may be used for training, whether that can be disabled, and where data is stored. These are usually stated plainly in the terms — someone just has to read them.

Summary

The point of these boundaries is not to restrict use but to let people use tools with confidence. When rules are vague, the cautious avoid the tools and the bold misuse them, and neither outcome is good.