Before putting confidential information into an AI tool, identify the task, the information involved and the permission to use that service. Review client commitments, internal policy, personal data responsibilities and the provider's actual terms. A useful output does not resolve whether the input was appropriate to share.
Check training or product-improvement use, retention, access, subprocessors and account settings. Reduce or remove sensitive information where the task allows. Assess output accuracy and confidentiality separately: a tool can produce an incorrect answer even when its data handling is suitable.
Define an approved task and minimum input
Describe the work the AI tool will perform, such as summarising a contract section or drafting questions for an internal meeting. Identify what information is genuinely needed. A redacted extract or synthetic example may achieve the objective without exposing a complete client file. Removing a name may not be enough where dates, commercial facts and unusual circumstances still identify the client or reveal the confidential transaction.
Check authority to disclose the material before uploading it. Client terms, non-disclosure agreements, intellectual property rights and professional obligations may restrict use even where the text contains no personal information. An employee's access to a document for ordinary work does not automatically authorise supplying it to an external tool. Give staff an approved route for uncertain cases rather than relying on a broad instruction to use common sense.
Assess the actual account and provider arrangement
Identify the contracting entity, purchased plan and relevant terms. Check retention, human support access, subprocessors and optional product improvement or training uses. Consumer and business versions of a product may have different controls. Record which settings are centrally enforced and which an individual user can change. Do not rely on an old screenshot of a setting if the service or subscription has since changed.
Where personal information is involved, use the ICO's AI guidance alongside the organisation's normal data protection assessment. [1] Review lawful basis, transparency, minimisation, security and any relevant transfer arrangement for the actual use. A provider saying that it does not train on an input does not answer every question about storage, access or confidentiality. Keep these issues separate so one reassuring feature does not obscure an unresolved risk elsewhere.
Protect connected information and instructions
Some tools can search drives, read email or use connected applications. Review the permissions and datasets available to those features before enabling them. A narrow prompt may still expose a broad connected archive if access is excessive. Use a controlled test with harmless material and confirm which sources the tool can reach. Apply the access principles in Access controls for client records to integrations as well as direct uploads.
Treat content returned from external documents or websites as information to evaluate, not authority to change business instructions or disclose secrets. A document can contain misleading requests or malicious instructions. Staff should verify unexpected actions and recipients independently. For confidential tasks, limit the tool's available actions and do not allow an output to trigger external communication or a financial commitment without the appropriate human decision.
Review the output against the source and purpose
Check factual claims, quotations, calculations and omitted qualifications. A fluent summary may invert an exception or invent a contractual obligation. Keep the original accessible to the reviewer and identify which parts of the answer were checked. Do not present unverified output as completed professional advice or attach a person's name as reviewer unless they have actually performed and accepted that review.
Consider whether the output itself contains confidential information that needs restricted storage. Deleting the original upload does not remove a copied summary in an unrestricted chat export or shared document. Apply a retention decision to prompts, outputs and supporting files. Record useful process evidence without preserving more client content than necessary for the approved task.
For Data processing agreement review, provide the intended use, sample redacted input, provider terms and relevant client restrictions. Use Data protection when using cloud software for the surrounding cloud review and identify any proposed automated actions explicitly. Agree a policy based on permitted tasks, data categories and review responsibilities. Keep it current when tools gain new connectors or features, because a previously narrow drafting workflow can become a substantially different information-sharing arrangement.
Test an accidental disclosure response
Suppose a member of staff pastes a client document into an unapproved AI account. Establish a route for prompt internal reporting that gathers the provider, account, content and timing without circulating the document more widely. Identify who can investigate available deletion controls and assess any contractual or personal data implications.
Use the incident to examine how the mistake became possible. Staff may need a clearer approved workflow, a narrower data preparation step or access to an appropriate business account. Avoid treating a reminder email as the only corrective action if the ordinary task still encourages copying confidential material into an unsuitable tool. Record the factual outcome and update the practical instructions for that task.
Illustrative scenario
A consultant wants an AI summary of a client agreement. The firm first considers whether a redacted extract would achieve the purpose and whether the service is authorised for that material. A responsible person checks the output against the original document before it influences advice or a commercial decision.
Preparation checklist
- Define the task and the minimum information required.
- Check client permissions, provider terms and account settings.
- Assess personal data and international transfer issues.
- Require a suitable human check before relying on the output.
Frequently asked questions
Is removing the client's name enough?
Not always. Context, dates and unusual facts can still identify a person or expose confidential commercial information. Assess the whole input and use a narrower extract where possible.
Does no training mean no retention?
Not necessarily. Review the provider's actual storage, access and deletion terms separately from training settings, and confirm which provisions apply to the purchased account.
Can an AI summary replace checking the original contract?
No. Verify material conclusions against the source, including exceptions and definitions. A fluent summary may omit qualifications or introduce obligations that the agreement does not contain.
Do integrations need separate approval?
Assess their permissions and reachable information before enabling them. A connector can expose much more material than a single upload and may introduce actions beyond the original approved task.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction