Safe Use of Generative AI at Work
Generative AI tools such as ChatGPT, Microsoft Copilot, Google Gemini and Claude can save real time on drafting, summarising and research. They also create new risks: confidential data pasted into the wrong tool, unchecked answers reaching customers, and staff quietly using unapproved tools. This guide sets out simple, plain-English rules any business can adopt so staff get the benefit of AI without exposing business or customer data.
These rules are vendor-neutral: they apply equally to ChatGPT, Microsoft Copilot, Google Gemini, Claude, AI features inside everyday software, and any new tool a member of staff discovers next week. The goal is not to ban AI — it is to make the safe route the easy route.
Rule 1: Use approved tools only
Most AI problems at work start with 'shadow AI' — staff using whatever tool they found first, on a personal account, with no oversight. Agree a short list of approved tools and make it easy to find.
- Name the tools staff may use, and for what kind of work.
- Use business accounts, not free personal accounts, wherever possible.
- Check whether the tool trains on your data and whether that can be switched off.
- Confirm where the data is stored and whether that suits UK GDPR obligations.
- Tell staff how to request a new tool rather than adopting it quietly.
Rule 2: Protect confidential data
Anything typed or pasted into an AI tool leaves your control. Unless you are on a business plan with contractual data protections, treat a prompt like an email to an outside company.
- Never enter customer personal data — names, contact details, financial or health information.
- Never enter employee data, payroll or HR matters.
- Never enter passwords, keys, security configurations or incident details.
- Never enter commercially sensitive material — contracts, pricing, plans, unreleased work.
- Anonymise first: replace real names and figures with placeholders where the task allows.
- When in doubt, leave it out and ask whoever owns the data.
Rule 3: Know what AI is for — and what it is not
| Good uses | Use with care | Not acceptable |
|---|---|---|
| Drafting and rewording | Customer-facing text | Legal or contractual advice |
| Summarising public material | Technical instructions | Decisions about individual employees |
| Brainstorming ideas | Research with sources | Uploading confidential documents to unapproved tools |
| Explaining concepts | Translations of important content | Presenting AI output as verified fact without checking |
| Formatting and templates | Code for internal use | Anything you would not want the data owner to see |
Rule 4: Check before you use or send
Generative AI produces confident, fluent text whether or not it is correct. The person using the tool remains responsible for the output.
- Treat every AI answer as a draft, not a finished product.
- Verify facts, figures, quotations and links before relying on them.
- Get specialist review for legal, financial, HR or safety-related content.
- Watch for out-of-date information — many tools have a knowledge cut-off.
- Make sure the final wording sounds like your business, not a template.
Pair this rule with the verification checklist
For anything that could influence a business decision or be published, work through our step-by-step verification checklist:
Rule 5: Be honest about AI use
- Disclose AI assistance where the audience would reasonably expect to know.
- Do not present AI-generated research or analysis as independent expert work.
- Check client contracts — some prohibit or restrict AI use on their material.
- Keep a record of significant AI-assisted work where the risk warrants it.
Rule 6: Report mistakes early
Mistakes will happen — confidential data pasted in error, a wrong answer sent to a customer. Staff need to know that reporting quickly is safe and expected. A business that punishes honest reports ends up with hidden problems instead of fixed ones.
- Name a person or inbox for AI questions and incident reports.
- If confidential data was entered in error, report it the same day.
- Delete the conversation where the tool allows it, and record what happened.
- Treat repeated near-misses as a sign the rules or training need improving.
Keep it current
AI tools change monthly. Review the approved list, the data rules and any staff guidance every few months, and whenever a new tool or AI feature arrives in software you already use.
Plain-English Takeaway
Generative AI is safe at work when staff use approved tools on business accounts, keep confidential and personal data out of prompts, check every answer before it is used, and report mistakes early. Write the rules down, keep them short, and review them regularly.
Downloadable guide
Download the Safe Use of Generative AI Checklist
A printable one-page checklist of the rules: approved tools, confidential data, acceptable use, checking outputs and reporting mistakes.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
AI Answer Verification Checklist
Check factual claims, sources, assumptions and approval before using or publishing an AI-generated answer.
View guideAI Policy Starter Guide
The starting points for a sensible, plain-English AI policy for a small business.
View guideAI Readiness Checklist
Check whether your business is ready to adopt AI tools safely and usefully.
View guideQuestions to Ask Before Buying an AI Tool
The practical questions that separate useful AI tools from expensive experiments.
View guide