Initial IAAsk a question ↗
← All resources

Governance · 11 min

What data can you give
to AI at work?

A visual classification and twelve questions to decide before copying a document into a tool.

IN 60 SECONDS

Key takeaways.

  1. 01

    The permitted tool depends on the data, purpose and safeguards actually configured.

  2. 02

    Minimisation remains a valuable habit: share only what is necessary for the expected result.

  3. 03

    A short rule, business examples and an exception process are more useful than an unenforceable ban.

01 · Classify

A three-zone rule to get started.

This classification is a practical awareness tool, not a legal determination. Adapt it to your security policy, contracts and data categories.

The key point: internal data does not become harmless when copied into a familiar interface. You need to know its destination, retention and the provider's secondary uses.

02 · Govern

The tool, data and purpose belong together.

For personal data, identify the purpose, applicable lawful basis, people concerned, retention period and rights to support. Apply data protection from the design of the use case.

Also check actual settings: history, training, sharing, connectors, administrator accounts and deletion. A policy only works if the configuration matches it.

  • Public or synthetic: usable in approved tools after checking reuse rights.
  • Internal: approved environment, explicit purpose, controlled access and retention.
  • Sensitive or secret: processing prohibited by default outside a specifically designed and authorised arrangement.
03 · Authorise

Twelve questions before enabling a tool.

The approval sheet should be understandable to business, security, legal and operations teams.

  1. 01

    What specific problem does the tool solve?

    ✓
  2. 02

    Which data categories will be sent to it?

    ✓
  3. 03

    Can unnecessary data be removed or masked?

    ✓
  4. 04

    Is personal or sensitive data involved?

    ✓
  5. 05

    Is content used to train or improve the service?

    ✓
  6. 06

    Where are data and backups processed?

    ✓
  7. 07

    How long are inputs and outputs retained?

    ✓
  8. 08

    Who can access the account, histories and logs?

    ✓
  9. 09

    Which connectors provide access to other data?

    ✓
  10. 10

    How can content be deleted, exported or recovered?

    ✓
  11. 11

    How does a user report an error or incident?

    ✓
  12. 12

    Who reviews authorisation when the tool or use case changes?

    ✓
04 · Keep it active

Train people in decisions as well as prompts.

The AI literacy expected by the European framework extends beyond writing an instruction. People need to understand capabilities, limitations, risks in the usage context and internal rules.

Work with real examples: a CV, contract, CRM export, meeting notes or document collection. Teams learn to recognise the data, choose the tool and check the result.

DECISION POINT

This guide is informational and is not legal advice. Have your security, data and legal officers validate the rules for your context.

SOURCES & METHOD

Check and explore further.

We prioritise official texts and reference frameworks. This guide's recommendations are our practical interpretation of those sources, to adapt to your context.

  1. 01
    CNIL — AI system compliance ↗

    Guidance on incorporating data protection requirements.

  2. 02
    CNIL — Data protection from collection ↗

    Minimisation, transparency, retention and security.

  3. 03
    European Commission — AI literacy ↗

    Official questions and answers on Article 4 of the AI Act.

  4. 04
    ANSSI — Security of generative AI systems ↗

    Recommendations for cautious integration with information systems.

AI governance

Need a rule all your teams can understand?

We connect usage policy, tool configuration, training and operational responsibilities.

View the related service ↗