Classify the information before the task
Ask who the information is about, who owns it, and what would happen if it appeared in the wrong place. Personal information can include direct identifiers and details that become identifying when combined. Confidential work may include client records, contracts, internal plans, credentials, or unpublished results.
When in doubt, replace real details with fictional examples or use a blank template. The safest useful request often describes the structure of the task without including the underlying record.
Read controls as controls, not guarantees
Consumer AI products offer different history, training, temporary-chat, retention, and deletion controls. These settings change. Check the current official documentation for the account and plan you are using.
Even when model training is off, information may be retained for security, legal, or operational reasons. Managed workplace accounts may follow organization-level policies. Use only the tool and information your organization permits.
Keep a person responsible for higher-risk work
Do not rely on an AI answer alone for medical, legal, financial, employment, cybersecurity, or safety decisions. Use a qualified professional and primary sources. Check factual claims, dates, calculations, and cited material before acting.
A good method names who checks the result, which source controls the decision, and when the tool should not be used.
Practise on real work
Check your information before using AI
Review the information you planned to enter. Do not paste the sensitive version into an AI tool.
Instructions to copy and change
Important details to check
- Can the task work with fictional or blank information?
- Does policy permit the tool and data?
- Is a qualified person required before anyone acts?
Keep these points
- Classify information before prompting.
- Check current controls without treating them as guarantees.
- Name a human reviewer for higher-risk work.
Optional paid help with Ikram Rana
Add a checking step to the task.
Bring a type of AI answer you use regularly, without confidential details. Discuss how to check it against source material and decide which claims need a person’s expertise.
Discuss your task with IkramScope and fees are agreed before work starts. The guides stay free.
Official sources and further reading
- Office of the Privacy Commissioner of Canada principles for generative AI
- NIST Generative AI Profile
- Data controls in ChatGPT
- Gemini Apps Privacy Hub
Product features and policies change. Check the linked source before relying on tool-specific details.