All learning

Practical advice

SafetyBeginner3 min read

Separate information by sensitivity before using AI

A simple three-level classification that helps staff decide what can go into which AI tool.

The practical answer

Start with this principle

Give staff a small number of clear categories. Public, internal and confidential is often easier to follow than a long policy full of exceptions.

Do this in order

Three steps you can use today

  1. Define the three levels

    Public information is already approved for anyone to see. Internal information stays within the business. Confidential information includes personal, financial, contractual and commercially sensitive material.

  2. Match levels to approved tools

    State which categories each AI service may handle. A free public tool should not become the default destination for internal records.

  3. Give people an uncertain route

    If somebody cannot classify a document, they should pause and ask a named person. The policy must make stopping easier than guessing.

Copy and adapt

Information tiers

TIER 1, open. Fine to paste into any AI tool.
Marketing copy, published prices, general process notes, public FAQs.

TIER 2, internal. Only in tools that meet our data policy.
Draft quotes with no client name, internal procedures, anonymised examples.

TIER 3, never. Does not go into an AI tool at all.
Named client records, staff personal data, bank and card details, signed
contracts, health or access notes, anything covered by a confidentiality
clause.

If you are unsure which tier something is, treat it as tier 3 and ask.