Your Staff Are Using AI With Your Data. Do You Have a Policy?

Staff are already using AI tools with company data, often without any policy in place. This is a governance and information security gap, not a technology problem, and one that ISO 27001 auditors will find if it isn't addressed.

AI tools are now part of the working day for most organisations whetherleadership knows it or not. Staff are using ChatGPT to draft emails, summarisedocuments, and speed up repetitive tasks. They are doing it on work devices,with work data, without any formal guidance on what is and is not acceptable.

This is not a technology problem. It is a governance and information securityproblem.

The risk nobody is talking about
When an employee pastes a client name, a contract summary, or a set of personaldetails into an AI tool, that data leaves your environment. Depending on thetool and its data retention settings, that information may be used to trainfuture models, stored on third party servers, or accessible to the vendor.

Most employees do not know this. They are not being careless. They have simplynever been told.

Under GDPR, the organisation is responsible for how personal data is processed,including by third party tools that staff use in the course of their work. Ifthere is no policy, there is no defence.

What ISO 27001 says about this
Information security management under ISO 27001 requires organisations toidentify and manage risks to the confidentiality, integrity, and availabilityof information. AI tool usage by staff is a risk that most organisations havenot formally assessed, documented, or controlled.

If you are working toward ISO 27001 certification or maintaining an existingISMS, the absence of an AI usage policy is a gap that an auditor will find.

What a basic policy looks like
You do not need a fifty page document. A practical AI usage policy for staffcovers the following:

  • What     tools are approved for use and which are not. What categories of data must     never be entered into any AI tool, specifically personal data, client     data, commercially sensitive information, and anything subject to     confidentiality obligations.
  • What     to do if an employee is unsure whether something is safe to share.
  • Who is     responsible for reviewing and updating the policy as tools evolve.

A simplerule to start with: if the data is masked or anonymised in any other context,it should not go into an AI tool in its original form.

The governance angle
Policies without awareness are not policies. Staff need to know the ruleexists, understand why it matters, and know what to do when they are unsure.That means communication, not just documentation.

If you are responsible for governance or compliance in your organisation, AIdata hygiene is worth putting on the risk register now before an incident makesit urgent.

 

Explore other articles

explore