Knowledge Centre
AI GuidesGuide and Checklist

Safe Use of Generative AI at Work

6 minutes to completeEvergreen guide — kept up to date

Generative AI tools such as ChatGPT, Microsoft Copilot, Google Gemini and Claude can save real time on drafting, summarising and research. They also create new risks: confidential data pasted into the wrong tool, unchecked answers reaching customers, and staff quietly using unapproved tools. This guide sets out simple, plain-English rules any business can adopt so staff get the benefit of AI without exposing business or customer data.

These rules are vendor-neutral: they apply equally to ChatGPT, Microsoft Copilot, Google Gemini, Claude, AI features inside everyday software, and any new tool a member of staff discovers next week. The goal is not to ban AI — it is to make the safe route the easy route.

Rule 1: Use approved tools only

Most AI problems at work start with 'shadow AI' — staff using whatever tool they found first, on a personal account, with no oversight. Agree a short list of approved tools and make it easy to find.

  • Name the tools staff may use, and for what kind of work.
  • Use business accounts, not free personal accounts, wherever possible.
  • Check whether the tool trains on your data and whether that can be switched off.
  • Confirm where the data is stored and whether that suits UK GDPR obligations.
  • Tell staff how to request a new tool rather than adopting it quietly.

Rule 2: Protect confidential data

Anything typed or pasted into an AI tool leaves your control. Unless you are on a business plan with contractual data protections, treat a prompt like an email to an outside company.

  • Never enter customer personal data — names, contact details, financial or health information.
  • Never enter employee data, payroll or HR matters.
  • Never enter passwords, keys, security configurations or incident details.
  • Never enter commercially sensitive material — contracts, pricing, plans, unreleased work.
  • Anonymise first: replace real names and figures with placeholders where the task allows.
  • When in doubt, leave it out and ask whoever owns the data.

Rule 3: Know what AI is for — and what it is not

Good usesUse with careNot acceptable
Drafting and rewordingCustomer-facing textLegal or contractual advice
Summarising public materialTechnical instructionsDecisions about individual employees
Brainstorming ideasResearch with sourcesUploading confidential documents to unapproved tools
Explaining conceptsTranslations of important contentPresenting AI output as verified fact without checking
Formatting and templatesCode for internal useAnything you would not want the data owner to see

Rule 4: Check before you use or send

Generative AI produces confident, fluent text whether or not it is correct. The person using the tool remains responsible for the output.

  • Treat every AI answer as a draft, not a finished product.
  • Verify facts, figures, quotations and links before relying on them.
  • Get specialist review for legal, financial, HR or safety-related content.
  • Watch for out-of-date information — many tools have a knowledge cut-off.
  • Make sure the final wording sounds like your business, not a template.

Pair this rule with the verification checklist

For anything that could influence a business decision or be published, work through our step-by-step verification checklist:

AI Answer Verification Checklist

Rule 5: Be honest about AI use

  • Disclose AI assistance where the audience would reasonably expect to know.
  • Do not present AI-generated research or analysis as independent expert work.
  • Check client contracts — some prohibit or restrict AI use on their material.
  • Keep a record of significant AI-assisted work where the risk warrants it.

Rule 6: Report mistakes early

Mistakes will happen — confidential data pasted in error, a wrong answer sent to a customer. Staff need to know that reporting quickly is safe and expected. A business that punishes honest reports ends up with hidden problems instead of fixed ones.

  • Name a person or inbox for AI questions and incident reports.
  • If confidential data was entered in error, report it the same day.
  • Delete the conversation where the tool allows it, and record what happened.
  • Treat repeated near-misses as a sign the rules or training need improving.

Keep it current

AI tools change monthly. Review the approved list, the data rules and any staff guidance every few months, and whenever a new tool or AI feature arrives in software you already use.

Plain-English Takeaway

Generative AI is safe at work when staff use approved tools on business accounts, keep confidential and personal data out of prompts, check every answer before it is used, and report mistakes early. Write the rules down, keep them short, and review them regularly.

Downloadable guide

Download the Safe Use of Generative AI Checklist

A printable one-page checklist of the rules: approved tools, confidential data, acceptable use, checking outputs and reporting mistakes.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.