Governance Quick Reference
This is your one-page guide to using AI safely at work. You do not need to be a lawyer or a privacy expert. Good decisions come down to a few habits: know how sensitive your information is, hold back what should never leave your organisation, be honest about where AI helped, and check the output before it goes anywhere public.
Your employer's own policy always wins. If anything here conflicts with your company's rules, follow your company, and when in doubt, ask your manager, IT, or compliance contact first.
Data Classification Levels
"Data classification" just means sorting information by how sensitive it is, so you know how carefully to handle it. Map your content to a level before you decide whether AI can see it.
| Level | What it means | Office examples | Safe to put in AI? |
|---|---|---|---|
| Public | Already published or meant for anyone | Press releases, public website copy, published annual reports | Yes — no restrictions |
| Internal | For staff, not secret but not public | Draft status reports, internal newsletters, generic meeting notes | Usually yes, in an approved tool |
| Confidential | Limited audience, harm if leaked | Unreleased financials, pricing models, deal terms, strategy decks | Only with explicit approval and a sanctioned, contractually-covered tool |
| Restricted | Legally protected or highly sensitive | Personal data (names, salaries, health), customer lists, contracts under NDA | No — do not paste; strip or anonymise first |
If you are unsure which level something is, treat it as the more sensitive one. Caution costs a few minutes; a leak costs far more.
What You Should Never Upload
Some categories carry real legal or commercial risk and should not be pasted into a general AI tool unless your company has formally approved that specific tool for that purpose.
| Never upload | Why it matters | What to do instead |
|---|---|---|
| Personal data (names + salaries, health, home addresses) | Privacy law (GDPR and similar) restricts it | Replace with placeholders like "[Employee A]" |
| Customer or client records | Breaches trust and often a contract | Aggregate or anonymise before asking |
| Passwords, API keys, access tokens | Hands attackers the keys | Never paste; rotate any you accidentally share |
| Unreleased financials or M&A details | Market-sensitive; can be unlawful to disclose | Wait until public, or use an approved tool |
| Anything under an NDA | You promised in writing to keep it private | Keep it out of AI entirely |
| Full contracts or legal documents | May contain protected and privileged terms | Summarise the question without the full text |
Anonymise-before-you-ask template:
"Help me analyse this variance report. I have replaced all
names and account numbers with placeholders ([Region A],
[Client 2], [GL-XXX]). Here is the structure and the figures..."
Rule of thumb: if you would not email it to a stranger outside your company, do not paste it into a public AI tool.
How to Cite AI Assistance
Being transparent about AI use builds trust and protects you. You do not need a footnote on every email, but disclose when the AI did meaningful work or when your audience would want to know. Match the disclosure to the stakes.
| Situation | Disclosure needed? | Suggested wording |
|---|---|---|
| Rough draft you then rewrote yourself | Usually no | None required |
| Final report or analysis shared externally | Yes | "Drafted with AI assistance and reviewed by [your name]." |
| Research findings or data summaries | Yes | "Initial synthesis generated by AI; figures verified against source." |
| Client-facing deliverable | Check policy | Follow your firm's disclosure standard |
| Anything submitted as your own expert judgement | Yes | State that AI assisted and you take responsibility |
Footer you can reuse:
"Portions of this document were prepared with the help of an
AI assistant. All facts, figures, and recommendations have
been reviewed and approved by the author."
The goal is honesty, not apology. AI is a tool — citing it shows you used it responsibly.
Checklist: Before Sharing AI Output Externally
Run through this before any AI-assisted work leaves your hands — a stakeholder email, a proposal, a status report. It takes two minutes and saves you from common mistakes.
| Check | Ask yourself | If it fails |
|---|---|---|
| Accuracy | Are all facts, names, dates, and numbers verified against a source? | Fix or remove unverified claims |
| Hallucination | Did the AI invent a statistic, quote, or citation? | Confirm every source actually exists |
| Confidentiality | Does the output reveal anything above Internal level? | Redact or get approval |
| Tone & audience | Does it sound like you and suit the reader? | Edit in your own voice |
| Bias & fairness | Are conclusions balanced, not skewed or stereotyped? | Re-prompt for a balanced view |
| Numbers | Do totals, percentages, and variances actually add up? | Recalculate by hand or in a sheet |
| Ownership | Can you stand behind every sentence? | Rewrite anything you cannot defend |
Final gut-check before you hit send:
1. Would I be comfortable if this appeared in the press?
2. Have I personally confirmed the figures?
3. Did I remove every piece of confidential data?
If any answer is "no," pause and fix it first.
When to Pause and Ask
Some moments call for a quick check with a human first. There is no shame in asking — it marks you as careful.
| Trigger | Who to ask |
|---|---|
| New AI tool not on your approved list | IT or security team |
| Confidential or restricted data involved | Manager or compliance |
| Output going to a regulator, client, or the public | Legal or your team lead |
| Unsure how to classify something | Whoever owns the data |
Related References
- AI Prompting Rules & Best Practices — write clearer, safer prompts.
- Practical AI Cheat Sheet — ready-made templates for everyday tasks.
- AI Tool Comparison Matrix — compare tools on privacy and data handling.
- Troubleshooting Guide — fix wrong, generic, or risky output.
Governance sounds heavy, but it is just everyday good judgement applied consistently. Classify, withhold, disclose, check — do those four and you can use AI with confidence.