The Four-Question Test
Before you paste anything sensitive into an AI tool, run it through these four quick questions. A practical filter for using AI responsibly.
AI tools are genuinely useful at work—but what you type into them can sometimes be stored, reviewed, or used to improve the service, depending on the tool and your settings. That doesn't mean avoid them. It means be thoughtful about what goes in. Here's a fast filter.
The four questions
Trade secrets, unreleased plans, legal or financial records, anything under an NDA or a rule like HIPAA. If yes, check your tool's data policy first.
Names, emails, health details, customer records. Personal data deserves extra care—strip it or anonymize it when you can.
A gut check. If seeing this text on a public page would be a problem, treat it as sensitive.
Many workplaces have an AI policy or an approved private tool. When one exists, follow it—it usually answers the first three for you.
How to use it
This takes about five seconds in your head before you paste. Most everyday work—drafting, summarizing public information, brainstorming, fixing your own writing—sails through all four with no issue. The test is there to catch the small number of cases that deserve a pause.
When in doubt
Two easy moves keep you safe. First, remove or fake the sensitive details—AI can still help with 'a customer' and '[Company]' standing in for the real ones. Second, ask whether your workplace offers a private or enterprise version of the tool, where your data isn't used for training. When unsure, ask before you paste.
Confidential? Identifies someone? Would a leak hurt? Is there a rule? Four quick questions catch nearly every risky paste.