Governance Quick Reference

Reference intermediate

This is your one-page guide to using AI safely at work. You do not need to be a lawyer or a privacy expert. Good decisions come down to a few habits: know how sensitive your information is, hold back what should never leave your organisation, be honest about where AI helped, and check the output before it goes anywhere public.

Your employer's own policy always wins. If anything here conflicts with your company's rules, follow your company, and when in doubt, ask your manager, IT, or compliance contact first.

Data Classification Levels

"Data classification" just means sorting information by how sensitive it is, so you know how carefully to handle it. Map your content to a level before you decide whether AI can see it.

Level What it means Office examples Safe to put in AI?
Public Already published or meant for anyone Press releases, public website copy, published annual reports Yes — no restrictions
Internal For staff, not secret but not public Draft status reports, internal newsletters, generic meeting notes Usually yes, in an approved tool
Confidential Limited audience, harm if leaked Unreleased financials, pricing models, deal terms, strategy decks Only with explicit approval and a sanctioned, contractually-covered tool
Restricted Legally protected or highly sensitive Personal data (names, salaries, health), customer lists, contracts under NDA No — do not paste; strip or anonymise first

If you are unsure which level something is, treat it as the more sensitive one. Caution costs a few minutes; a leak costs far more.

What You Should Never Upload

Some categories carry real legal or commercial risk and should not be pasted into a general AI tool unless your company has formally approved that specific tool for that purpose.

Never upload Why it matters What to do instead
Personal data (names + salaries, health, home addresses) Privacy law (GDPR and similar) restricts it Replace with placeholders like "[Employee A]"
Customer or client records Breaches trust and often a contract Aggregate or anonymise before asking
Passwords, API keys, access tokens Hands attackers the keys Never paste; rotate any you accidentally share
Unreleased financials or M&A details Market-sensitive; can be unlawful to disclose Wait until public, or use an approved tool
Anything under an NDA You promised in writing to keep it private Keep it out of AI entirely
Full contracts or legal documents May contain protected and privileged terms Summarise the question without the full text
Anonymise-before-you-ask template:
"Help me analyse this variance report. I have replaced all
names and account numbers with placeholders ([Region A],
[Client 2], [GL-XXX]). Here is the structure and the figures..."

Rule of thumb: if you would not email it to a stranger outside your company, do not paste it into a public AI tool.

How to Cite AI Assistance

Being transparent about AI use builds trust and protects you. You do not need a footnote on every email, but disclose when the AI did meaningful work or when your audience would want to know. Match the disclosure to the stakes.

Situation Disclosure needed? Suggested wording
Rough draft you then rewrote yourself Usually no None required
Final report or analysis shared externally Yes "Drafted with AI assistance and reviewed by [your name]."
Research findings or data summaries Yes "Initial synthesis generated by AI; figures verified against source."
Client-facing deliverable Check policy Follow your firm's disclosure standard
Anything submitted as your own expert judgement Yes State that AI assisted and you take responsibility
Footer you can reuse:
"Portions of this document were prepared with the help of an
AI assistant. All facts, figures, and recommendations have
been reviewed and approved by the author."

The goal is honesty, not apology. AI is a tool — citing it shows you used it responsibly.

Checklist: Before Sharing AI Output Externally

Run through this before any AI-assisted work leaves your hands — a stakeholder email, a proposal, a status report. It takes two minutes and saves you from common mistakes.

Check Ask yourself If it fails
Accuracy Are all facts, names, dates, and numbers verified against a source? Fix or remove unverified claims
Hallucination Did the AI invent a statistic, quote, or citation? Confirm every source actually exists
Confidentiality Does the output reveal anything above Internal level? Redact or get approval
Tone & audience Does it sound like you and suit the reader? Edit in your own voice
Bias & fairness Are conclusions balanced, not skewed or stereotyped? Re-prompt for a balanced view
Numbers Do totals, percentages, and variances actually add up? Recalculate by hand or in a sheet
Ownership Can you stand behind every sentence? Rewrite anything you cannot defend
Final gut-check before you hit send:
1. Would I be comfortable if this appeared in the press?
2. Have I personally confirmed the figures?
3. Did I remove every piece of confidential data?
If any answer is "no," pause and fix it first.

When to Pause and Ask

Some moments call for a quick check with a human first. There is no shame in asking — it marks you as careful.

Trigger Who to ask
New AI tool not on your approved list IT or security team
Confidential or restricted data involved Manager or compliance
Output going to a regulator, client, or the public Legal or your team lead
Unsure how to classify something Whoever owns the data

Related References

Governance sounds heavy, but it is just everyday good judgement applied consistently. Classify, withhold, disclose, check — do those four and you can use AI with confidence.