Before you paste it into AI: a data-safety checklist for UK small businesses

Laptop showing code beside a plant and coffee mug

Written by

in

Generative AI makes an unusual promise: give the system more context and the answer often improves. That same behaviour creates its most immediate business risk. The easiest way to obtain a tailored summary, email or analysis is to paste in material that may contain personal data, client confidences, commercially sensitive details or intellectual property.

The first control is therefore not a clever prompt. It is deciding what the service should receive at all.

This is general information, not legal or cyber-security advice. The appropriate controls depend on the data, the service, the contract and the purpose.

Treat the prompt as a disclosure

Close view of software code displayed on a computer screen
Photo by Bernd Dittrich on Unsplash

Typing information into an external AI service transfers it to a supplier’s system. The friendly chat interface can disguise that basic fact. Before using real material, identify the data controller and processor roles, where data is processed, how long it is retained, whether it may be used for training and who can access logs.

A free consumer account and a contracted business service may have different terms and controls even when the model name looks identical. Do not infer business confidentiality from familiarity with the brand.

Begin with a defined purpose

Laptop workspace with code, phone and reading glasses
Photo by Daniil Komov on Unsplash

State the business problem before selecting the tool. “We want AI” is not a purpose. “We want to produce a first summary of public consultation responses, with a person verifying every theme” is specific enough to assess.

A good governance step is to document the business requirement, the risks and the mitigations before adopting a tool. The NCSC likewise encourages leaders to consider the operational and reputational consequences if an AI system fails or its confidentiality is compromised.

Ask whether the same outcome can be achieved with public, synthetic or properly anonymised material. If the personal data is not necessary, do not provide it.

Personal data still carries obligations

UK data-protection principles continue to apply when AI is involved. A business needs a lawful basis, transparency, purpose limitation, data minimisation, accuracy, security and appropriate retention. Special-category data and criminal-offence data require additional care.

Removing a name may not anonymise a record. A job title, location, unusual event and date can identify somebody when combined. Pseudonymised data remains personal data when the organisation can reconnect the code to a person.

Use the ICO’s AI guidance and risk toolkit where processing may affect individuals. A data-protection impact assessment may be required when processing is likely to result in high risk.

Confidential and regulated information

Create a short classification rule employees can apply. For example:

  • Public: already approved for publication; suitable for approved tools.
  • Internal: ordinary business information; use only in contracted, approved services with appropriate settings.
  • Confidential: client, employee, pricing, legal, security or unpublished strategy information; do not enter without an assessed use case and explicit controls.
  • Highly restricted: passwords, authentication secrets, payment data, medical information or similarly sensitive material; prohibit from general-purpose AI prompts.

The exact labels matter less than giving people a usable decision. “Be careful with AI” is not an operational policy.

Check the service, not just the model

Review:

  1. contractual confidentiality and data-processing terms;
  2. whether prompts or outputs are used to train models;
  3. retention periods and deletion controls;
  4. processing locations and international transfers;
  5. administrator access, audit logs and user management;
  6. encryption and account security;
  7. subprocessors and connected plugins;
  8. export and termination arrangements; and
  9. the supplier’s incident process.

Disable unnecessary integrations. Connecting email, storage and customer systems can broaden a limited writing assistant into a route across the organisation’s information.

Minimise before prompting

Use a template, abstract facts or synthetic example where possible. Replace real names and identifiers, remove irrelevant columns and shorten documents to the passages needed for the purpose. Do not upload an entire mailbox to summarise one thread.

Remember that prompts, uploaded files, conversation history and generated output may all be retained differently. A safe prompt can still produce an unsafe output if the system has access to connected data.

Human review is a control, not a slogan

Generative systems can produce plausible errors, invented citations and uneven results. Assign a person with enough subject knowledge and authority to check the output. The reviewer should compare important claims with original sources, not merely read the generated prose for confidence.

For decisions affecting people, clarify what the AI contributes and what the human decides. A person who automatically accepts the recommendation is not meaningful oversight.

Keep proportionate records of the use case, tool version or service, sources, checks and final decision. That gives the business a clearer basis for oversight, repeatability and incident response if something later needs to be checked.

A ten-question pause before “send”

  1. What outcome am I trying to achieve?
  2. Is this an approved business service and account?
  3. Does the input contain personal, client or confidential information?
  4. Can I remove or replace that information?
  5. Do we understand the provider’s training and retention terms?
  6. Is there a lawful and transparent basis for this processing?
  7. Could a connected tool expose more data than intended?
  8. Who will verify factual claims and citations?
  9. Could an incorrect or leaked output harm someone?
  10. What record of the process should be retained?

If those questions feel excessive for a routine task, that is useful information. The right answer may be to use public or synthetic data, choose a contracted service with stronger controls, or complete the task without AI.

The value of generative AI does not depend on treating every document as prompt material. Good adoption is selective: clear purpose, minimum necessary data, appropriate service, accountable review.

Further reading on The Perry

Browse this section

Move naturally through the Journal articles or jump back to the section overview.

Back to Journal

Previous in Journal

Read previous

How to choose a password manager: a practical UK guide without a league table

Next in Journal

You are at the end of this section.

Sources and further reading

Source check: 23 August 2026. Recheck provider terms and current ICO guidance for each use case.

Featured image credit: Photo by Daniil Komov on Unsplash.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *