Practical advice
Separate information by sensitivity before using AI
A simple three-level classification that helps staff decide what can go into which AI tool.
The practical answer
Start with this principle
Give staff a small number of clear categories. Public, internal and confidential is often easier to follow than a long policy full of exceptions.
Do this in order
Three steps you can use today
Define the three levels
Public information is already approved for anyone to see. Internal information stays within the business. Confidential information includes personal, financial, contractual and commercially sensitive material.
Match levels to approved tools
State which categories each AI service may handle. A free public tool should not become the default destination for internal records.
Give people an uncertain route
If somebody cannot classify a document, they should pause and ask a named person. The policy must make stopping easier than guessing.
Copy and adapt
Information tiers
TIER 1, open. Fine to paste into any AI tool.
Marketing copy, published prices, general process notes, public FAQs.
TIER 2, internal. Only in tools that meet our data policy.
Draft quotes with no client name, internal procedures, anonymised examples.
TIER 3, never. Does not go into an AI tool at all.
Named client records, staff personal data, bank and card details, signed
contracts, health or access notes, anything covered by a confidentiality
clause.
If you are unsure which tier something is, treat it as tier 3 and ask.