Business ·
Data cannot be protected after it has already reached the model
Data protection in AI work begins before a prompt is sent. A company needs to know what reaches the model, on what basis, where it is retained, who sees the result and what follows a failure. “Do not upload secrets” creates no practical boundary without tools and rules.
Classify data first
Public material, internal instructions, commercial terms, personal information and secrets require different handling. A simple scale tells employees what can enter a public service, what belongs only in a managed environment and what must not reach a model.
Use examples from actual work: contracts, correspondence, CVs, source code and financial reports. An abstract policy is difficult to apply to a daily request.
Know the route of a request
Record the provider, processing region, retention, training use, subprocessors and deletion options. Verify these conditions in contracts and settings rather than assuming them from marketing language.
Browser extensions, integrations and agents deserve separate review because they may receive more context than the user sees in the message field.
Minimisation reduces consequences
A model often needs a document structure, selected fields or an anonymised passage. Remove or replace names, contacts, contract numbers and commercial figures when they are irrelevant to the task.
The strongest rule is implemented technically: a filter warns about sensitive information, a company interface restricts available models, and a request template inserts only necessary fields.
Knowledge access is checked during retrieval
Connecting AI to company knowledge does not grant universal access. Retrieval must enforce the current user’s permissions and retain every passage’s origin.
Otherwise an employee may receive through an answer a document they cannot open directly. This is more dangerous than an ordinary generation error because the convenient interface conceals the breach.
Agent actions require separate controls
If a system sends messages, changes CRM or creates documents, give it a dedicated account and minimal permissions. Irreversible and financial operations need confirmation.
Logs retain the input, retrieved sources, tool call, result and approving person while masking secrets from open records.
Test controls with scenarios
Attempt to request another user’s data, override instructions through a document, expose system context and force a prohibited operation. An incident needs to be detectable, stoppable and reviewable.
Within the Method, I connect protection to workflow architecture. A usable AI service knows its allowed sources, data volume and action boundaries in advance, so security does not depend only on human caution.
AI for a specific process
If you are considering AI implementation, we can start with the process, available data, automation boundaries and a way to assess the result.