Decide whether a tool is authorised for the information before entering business data. A useful AI response does not establish permission to share the underlying records.
Classify the task and the information separately
A public service description and a customer dispute can both be summarised, but they do not have the same handling requirements. Describe the task first, then identify whether it needs public, internal, personal, confidential or access-related information.
Ask whether a lower-data version would answer the question. A synthetic invoice can help discuss a field layout without exposing a real supplier record. Removing a name may not be enough if the remaining details still identify a person or reveal sensitive business information.
Use a provider and use-case review
| Question | Decision it supports |
|---|---|
| Is this tool approved for the task? | Avoid informal adoption of an unreviewed service. |
| Which data is needed? | Reduce unnecessary disclosure. |
| Who can access inputs and outputs? | Understand organisational and provider access. |
| What handling terms apply? | Review retention, training use, location and contractual conditions for the actual service. |
| Can the tool take actions? | Separate drafting from sending, editing or executing. |
| Who reviews the result? | Assign responsibility for accuracy and permitted use. |
Terms can differ between products, account types and configurations. Verify the actual service in use rather than relying on a broad brand-level statement.
Keep untrusted content within its boundary
A document or web page may contain instructions that are unrelated to the business task. OWASP identifies prompt injection as a risk when such content influences an AI system’s behaviour. Treat retrieved material as information to assess, not as permission to change access or perform a new action.
Limit connected tools and data to the required task. A summarisation assistant does not need unrestricted access to every customer record or the ability to send arbitrary messages. Review output before consequential use and test how the system handles misleading instructions in sample content.
Write an understandable staff rule
A useful internal rule says which tools and data classes are approved, what must not be entered and where staff can ask about uncertain cases. Include a reporting route for an accidental disclosure. A vague instruction to “use AI responsibly” leaves people to guess.
For organisations handling personal information in Kenya, the Data Protection Act is relevant to the organisation’s decisions. The checklist here is an operational discussion aid, not a legal determination or a claim that a chosen provider makes every use compliant. Obtain appropriate advice for the specific processing.
Approve a bounded use, then revisit it
- Document the task, information categories and approved service configuration.
- Set the reviewer and permitted output uses.
- Test representative wrong or misleading inputs.
- Record material provider or integration changes.
- Review access when people or responsibilities change.
A narrow, well-understood use is easier to review than a blanket permission to paste any business record into any assistant.
Sources and further reading
Put the decision into practice
Describe the information categories and intended AI action without sending confidential records.
Explore AI Business Automation Discuss the requirement by email