AI-Use Rules That Protect Confidential Information
The biggest risk of using AI in an organization is leakage of confidential information. Prevent it with "rules and operations" more than technology.
Items the Rules Must Include
- Information classification: e.g., 4 tiers of public/internal/confidential/personal
- Permission by tier: confidential = external AI prohibited, internally approved tools only, etc.
- Approved-tool designation: a whitelist of AI services that may be used
- Masking principle: abstract proper nouns/figures before input
- Training-use off: settings/contracts that prevent input being used for training
- Logs: a mechanism to trace who input what
Operating Tips
- Not just prohibition but present safe alternatives (prevent shadow AI use)
- Show concrete examples (OK/NG). Abstract rules aren't followed
- Periodic education and updates (linked with the "organizational change" chapter)
Key Point
"Prohibition" alone makes the field use it hidden. Presenting classification, approved tools, and alternatives as a set is effective confidentiality protection.