Judgment in the Age of AI · Article 13
“Improving efficiency” is not sufficient authority to upload internal documents. Minutes, customer lists, contracts, source code, unpublished financial data and employee records may be governed by company policy, confidentiality duties, privacy law and contractual restrictions. A tool’s ability to accept a file does not mean the organisation permits it.
Pass the document through four gates
- Ownership: Is the information yours, the organisation’s, a client’s or a third party’s?
- Necessity: Does the task require the full document or only a de-identified excerpt?
- Tool: Is the service approved, where is data stored, how long is it retained and how is it used?
- Authority: Do you have explicit permission, and does the recipient meet contractual and privacy requirements?
A safer alternative workflow
Test the prompt with fictional material. Once the structure works, extract only the minimum necessary passage and remove customer, employee, project and system identifiers. Prefer an approved enterprise tool, and continue treating the output as internal information.
Three categories that should stop the upload
- Passwords, API keys and access tokens
- Unauthorised personal or health information
- Material protected by legal privilege, confidentiality agreements or security classification
Real efficiency completes the task without unnecessarily expanding the surface on which data can be exposed.
References
- OAIC: Privacy and Commercially Available AI Products
- Cyber.gov.au: Guidelines for Secure AI System Development
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.