Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Do not put into AI what you would not send to an unknown recipient

Use approved tools, minimise the input and verify every output before it affects a customer, transaction or decision.

Employees and users of generative AI servicesAbout 6 minutes of reading + 3 questions
Start with the example Already entered confidential information?

What you will learn

  • Identify information that does not belong in a public AI service.
  • Restrict permissions granted to plugins and connected accounts.
  • Verify outputs before business or financial use.

Practice example

Summarising a customer report

Public AI serviceSummarising a customer report

Upload the complete document with the customer's name, account number and contact details to get a short summary.

The document contains unnecessary dataThe tool is not approved for business dataThe output sounds confident
Fictional example for practice.
Show the example explanation
The document contains unnecessary data
A summary may not require the customer's name, account number or other identifiers.
The tool is not approved for business data
A personal account and public service may have different rules for storage and use of prompts.
The output sounds confident
Fluent text can still include a wrong fact, missed condition or invented statement.

Classify the information before entering it

Do not enter customer personal data, account or card numbers, credentials, business secrets, internal incidents, contracts or unpublished code into a public AI service without organisational approval and verified processing terms.

Even with an approved tool, provide only what the task needs. Remove names, identifiers and details that do not change the task. Replacing a name is not full anonymisation if a person can still be identified from the remaining details.

Use an approved account and service

  • Perform work through an account and service approved by your organisation.
  • Check whether input is used for model training, how long it is retained and who can access it.
  • Do not assume a paid version automatically satisfies organisational policy.
  • Do not enter information when its destination and accountable owner are unclear.

Restrict plugins and integrations

An AI plugin may request email, calendar, contact, cloud-drive or business-application access. Check the publisher, purpose and each permission. If the task needs a calendar, access to all mail and files is a reason to stop.

Review connected applications periodically and remove those no longer used. A password change alone may not revoke access previously granted to an integration.

Verify the output before using it

Treat an AI output as a draft. Check:

  1. facts, figures, dates and cited sources;
  2. whether an important condition or exception is missing;
  3. whether the output reveals data that should not be included;
  4. whether the decision belongs to a person or a defined process;
  5. whether the document should be marked as a working draft.

Do not allow AI to approve a payment, change recipient details or send a sensitive message without the appropriate control.

If confidential information was already entered

  1. Stop adding information and record the service, account, time and affected content.
  2. Use available controls to delete the conversation, file and related data, but do not assume this completely reverses the event.
  3. Notify the data owner and relevant security, privacy or legal team under organisational procedures.
  4. Revoke unnecessary integrations and active tokens.
  5. If a password, key or other secret was entered, replace it through the official process and review its use.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

You want a public AI service to summarise a document containing customer data. What is the safe next step?

Why does this matter? Input to an external service is processing and disclosure of data, even when the goal is only a summary.

  1. Upload it because only my account can see the conversation.

    Conversation visibility does not explain every rule for service storage, processing and access.

  2. Check organisational policy and use an approved tool with only necessary, de-identified content.Correct answer

    An approved tool and minimised input reduce unnecessary exposure.

  3. Rename the file but leave its contents unchanged.

    Renaming the file does not remove personal or confidential information from it.

An AI plugin requests access to all email and cloud files but only needs to schedule meetings. What do you do?

Why does this matter? Broad permission increases the information available to the plugin and the impact of compromise.

  1. Approve everything because the plugin uses AI.

    An AI label does not establish that each permission is necessary or safe.

  2. Verify the publisher and choose the smallest permission set, or do not connect it.Correct answer

    Permissions should match a specific function and a verifiable publisher.

  3. Approve access and change the password later.

    Changing a password may not revoke an integration that was already authorised.

AI produced a confident explanation of payment terms. How do you use it?

Why does this matter? Generated text can sound certain even when a fact is wrong or invented.

  1. Send it without review because the grammar is correct.

    Style is not evidence of factual accuracy.

  2. Check every important claim against the current document or responsible person.Correct answer

    Verification against an authoritative source preserves accuracy and accountability.

  3. Ask the same AI to certify that its answer is completely accurate.

    The model is not an independent source for validating its own answer.

No registration. Your answers are not sent; the result is just for you.

Minimise data, restrict access, verify the output

AI does not replace data-protection rules, access control or accountable human decisions.

Recognise impersonation and deepfake content

References

Sources and further reading

The advice not to enter confidential information into public generative-AI services and to verify outputs is based on the UK NCSC explanation of large-language-model risks and its guidance on AI and cyber security. Account-protection habits are supplemented by the US CISA Secure Our World resources. Each organisation must confirm its own data-processing rules and approved tools.

Content last reviewed