Unlock Futures

AI • Privacy • Workplace Skills

Before You Put Information Into AI

5 privacy questions to ask — a practical 10-minute guide for safer everyday AI use.

⏱ About 10 minutes 🎓 Beginner friendly 💛 Free lesson

Prefer to read? The full lesson notes are written out below.

Why this matters

AI tools can save you real time — drafting emails, summarising information, organising ideas, preparing presentations. But a useful prompt can also contain information that should not be shared.

Privacy is becoming a much bigger part of AI literacy. Microsoft, for example, has introduced stronger privacy and safety commitments for AI used in education, including limits on how student information can be used and an emphasis on human oversight for consequential decisions. The bigger lesson applies well beyond schools: whether you work in a business, a community organisation, education, finance or administration, the question is not simply can AI help me with this task? We also need to ask what information am I giving the AI in order to get that help?

Practical AI literacy has two parts.

Capability — knowing what AI can do. Judgement — knowing when and how to use it appropriately.

This is not about being afraid of AI. It is about using AI confidently, with judgement.

The 5-question privacy check

Before you paste, upload or connect anything to an AI tool:

  1. 1 What information am I sharing?
  2. 2 Do I have permission to share it?
  3. 3 Does this AI tool protect my data?
  4. 4 Can I remove or anonymise details?
  5. 5 Would I be comfortable if this left my control?

You do not need to turn this into a complicated process. The goal is simply to create a short pause before you click send.

QUESTION 1

What information am I sharing?

Not all information carries the same risk. Start by identifying the type of information.

Lower risk

  • Public information
  • Generic ideas
  • Made-up examples

Pause first

  • Internal plans
  • Unpublished work
  • Client context

Higher risk

  • Personal details
  • Passwords & credentials
  • Sensitive records

Teaching habit: classify the information before you think about the prompt. Ask yourself — is this public, internal, personal or sensitive information? That one question can change how you approach the task.

QUESTION 2

Do I have permission to share it?

Your information?

You may be able to choose what you share.

Someone else's information?

Pause. Consent, policy and confidentiality may matter.

If a document contains customer information, employee details, student information or confidential business material, you may not have the authority to put that information into an external AI system.

A simple workplace test

Would I put this information into an external website without checking first?

If the answer is no — or even unsure — check first.

Using AI does not remove our normal responsibilities around confidentiality.

QUESTION 3

Does this AI tool protect my data?

The logo on the screen is not the privacy policy. It is easy to assume that because a tool is well known, every account has the same protections. A personal account, a school account and an organisation-managed work account can have different settings and protections.

Check the account and settings

  • Is this a personal, school or work account?
  • Are prompts used to improve or train models?
  • Who can access chat history or uploaded files?
  • What does your organisation's policy allow?

As an example, Microsoft states that prompts and responses in its work and school Copilot Chat with enterprise data protection are not used to train foundation models.

The important lesson is not to memorise one company's policy. Policies and products change. The habit is: know which account and tool you are using, and check the current privacy terms when the information matters.

QUESTION 4

Can I remove or anonymise details?

Often, AI does not need the real identity to help with the task. Ask: does it actually need the real name, phone number, customer number, address or organisation name to do this job? Very often, it does not.

Before

"Please rewrite this email to Sarah Chen at ABC Health about her account number 483921…"

After

"Please rewrite this email to a client about an account issue. Keep the tone professional…"

The AI can still help with the writing. You are not making the prompt weaker — you are making the information you share more deliberate. Remove what the AI doesn't need.

QUESTION 5

Would I be comfortable if this left my control?

The front-page test

If this prompt appeared on a screen in a meeting — would I be comfortable?

This is not a legal test, and it does not replace your organisation's privacy policy. It is a practical pause that helps us notice risk before we click Send.

Sometimes we become so focused on getting a good AI response that we stop noticing how much information we have placed into the prompt. If seeing that prompt outside the chat would make you uncomfortable, that is a strong signal to stop and reconsider what you are sharing.

Try it: the 30-second privacy challenge

You want AI to improve a customer-service email. What does it actually need?

Original material

  • Customer name
  • Phone number
  • Order number
  • Complaint details
  • Your draft reply

What does AI need?

  • Complaint context
  • Your draft reply
  • Desired tone

Remove the identifiers first, then ask AI to improve the message. A better prompt does not mean giving AI more personal information — it means giving AI the right information for the task.

Before you press Send

5 questions. 10 seconds. Better judgement.

  1. 01What information am I sharing?
  2. 02Do I have permission to share it?
  3. 03Does this AI tool protect my data?
  4. 04Can I remove or anonymise details?
  5. 05Would I be comfortable if this left my control?

Use AI confidently — but don't outsource your judgement.

What to do next

If you would like to use AI tools more confidently at work or at home — at your own pace, without jargon — your first discovery call is always free.