Setting Safe Data Boundaries

The 4:00 PM Dilemma

Meet Sarah, a project manager facing a tight deadline. She has a transcript filled with client names, budget figures, and unreleased product ideas.

Sarah is tempted to paste this into a public AI tool to get a summary by 5:00 PM. This is the starting point of Shadow AI—using unapproved tools for sensitive company data.

It's 4:00 PM, and you have a deadline looming—is the AI co-pilot you're about to use a helpful assistant or a dangerous leak? Meet Sarah. She has a messy transcript from a major client meeting. It contains names, budgets, and secret product plans. If Sarah pastes this into a public AI tool, she's engaging in Shadow AI. Once uploaded, those secrets are no longer private and could even show up in someone else's AI results later.

The Traffic Light Framework

To protect your company, you must categorize data before you click 'send'. Use the Traffic Light Framework to decide what is safe to share.

To keep data safe, think like a traffic light before you prompt. Red means Stop. Never share Personal Identifiable Information, unreleased financials, or trade secrets. Yellow means Caution. Internal notes or draft strategies must be 'scrubbed' or sanitized before use. Green means Go. Publicly available research and standard grammar checks are safe to share. Red data includes Social Security numbers, customer names, and proprietary code. This information must never leave your company's secure environment. Green data is already public. You can freely use AI to summarize industry reports or help with standard email formatting. Yellow data, like internal project names or meeting notes, is useful for AI tasks but requires sanitization to remove specific identifiers first.

The 3-Step Sanitization Framework

When you have Yellow Light data, you must 'scrub' it using three simple steps to remove the risk.

If you're working with Yellow Light data, don't just paste it. Apply the 3-Step Sanitization framework. First, Remove. Delete all specific names, dates, and locations. Second, Replace. Use generic placeholders like 'a senior stakeholder' instead of a specific name. Third, Generalize. Instead of a 15% budget cut, call it a 'significant budget adjustment'. This keeps the context while hiding the secrets.

Practice: Scrub the Prompt

Apply the 3-Step Sanitization to Sarah's prompt. Rewrite it to make it safe for a public AI tool.

Original: "Summarize notes from our meeting with Global Logistics Ltd. They want to reduce their $2M contract by 10% because of the Alpha-7 engine delay."

Now it's your turn. Look at Sarah's prompt about Global Logistics and the Alpha-7 engine. Rewrite it in the box below to make it 'Green Light' safe, then click submit.

Common Pitfalls

Don't fall for these common misconceptions about AI data safety. Even incognito settings aren't a silver bullet.

Many people fall into two dangerous traps. First, the Private Chat Myth. Turning off history doesn't make your data invisible; the AI provider can often still see and process it. Second, the Shadow AI Trap. Using a personal account for work might feel faster, but it bypasses the security guardrails your company has built. Always remember: you are the Pilot. No sensitive data should ever leave your company's secure perimeter.

Spot the Risk

A colleague wants to send this prompt to an AI. Click on all the elements that make this a RED LIGHT risk.

Let's test your eyes. Look at this prompt. There are three specific pieces of information that violate our safety rules. Click on them to flag the risk. Excellent. You identified the client name, the specific financial figure, and the proprietary project code. This prompt is definitely a Red Light.