What you can and can't paste in: handout
One slide per page with speaker notes. Choose "Save as PDF" in the print dialog.
Notes · slide 1
Before this session, do your homework, because people will ask specific questions. Find out: whether your company has an AI or acceptable use policy and where it lives; which tools and accounts are approved; what the approved your AI assistant setup does with the data you give it, in the words of your IT or legal team, not a guess; and who people should contact if they make a mistake. If there's no policy, say so honestly and use this session to show what sensible defaults look like while one is written. Open by saying: "This isn't a session to scare you off. Most people don't use AI as much as they could because they're not sure what's allowed. The aim is to make you confident, not nervous."
Notes · slide 2
30 seconds. Mention that you'll finish with where to find your company's actual rules, so people know this is about their workplace, not general advice from the internet.
Notes · slide 3
When people are asked what they're allowed to put into AI tools, a lot of them aren't sure. Some respond by not using it at all; others paste in everything. Both are problems. If you've interviewed people at your company about AI use, quote what you heard, anonymised. If not, ask the room: "Hands up if you've ever hesitated before pasting something in because you weren't sure it was allowed." Then: "Hands up if you've ever pasted something in and wondered afterwards." Keep it light; nobody's in trouble here. One minute.
Notes · slide 4
Keep this factual and specific to your company. Explain in your IT or legal team's words what the approved setup means: for example, whether conversations are retained, who in the company can access them, and whether the provider may use them. Do not state product facts you haven't confirmed; tools and contracts differ and change. The key behavioural message is simple: use the work account for work, never a personal account or a random free website, even if it seems quicker. Likely question: "Is it safe to paste anything into the approved one?" Good answer: "It's safer, not unlimited. Some data shouldn't go into any tool without a specific reason and approval; that's the red category we're about to cover." Two minutes.
Notes · slide 5
These three questions cover most situations without anyone needing to memorise a policy. The first is about the tool. The second is about what's actually in the text, including bits you might not notice, like an email signature or a customer number buried in a spreadsheet. The third is a gut check: if this ended up somewhere it shouldn't, would it embarrass someone, harm a customer, or break a promise your company made? If yes, stop and strip it down, or don't use it. Two minutes.
Notes · slide 6
Transition. Say: "Here's a simple way to sort things. Your policy has the final word; this is the everyday version."
Notes · slide 7
Three minutes. Green is the large majority of everyday use: rewording your own email, summarising a published report, asking how to structure a presentation. Amber is where people need judgement: an internal strategy document might be fine in the approved tool but not in a free one; a customer complaint is fine once names and order numbers are taken out. Red should not go in without explicit approval: anything identifying a person's health, performance, pay or grievance; passwords, API keys and access codes; financial results before they're published; anything under legal privilege or a non-disclosure agreement. Important: adjust these to match your company's policy. If your policy is stricter or looser, use its categories, and say so. Likely question: "What about my own performance review?" Good answer: "Your own information is yours to decide about, but anything about other people, like feedback on a colleague, is red."
Notes · slide 8
Pick the examples relevant to your audience. The pattern in each pair: the same task can be safe or unsafe depending on what's in the input. Sales people can still get help writing a follow-up; they just describe the prospect as "a mid-sized logistics firm, finance director, worried about cost" rather than pasting the CRM record. Finance can still get help structuring a variance commentary using made-up or rounded numbers, then put the real figures in by hand. Two minutes.
Notes · slide 9
This is the practical skill that unlocks most amber cases. It usually takes a minute. Demonstrate it live if you can: take an anonymised or invented support email with a name, order number and address, and edit it down in front of the room. Point out that the AI's answer is just as useful without the personal details, because it doesn't need them to write a good reply; you add them back at the end. Warn people about the bits they won't think to check: email signatures, quoted earlier messages at the bottom of a thread, and hidden columns in spreadsheets. Two minutes.
Notes · slide 10
Illustrative, not a real quotation. This is the most common way sensitive data ends up in AI tools: not someone deliberately sharing secrets, but someone in a hurry pasting the file in front of them. Spreadsheets and long email threads are the usual culprits because they contain far more than the part you're thinking about. Ask the room: "What's the file you most often have open that would be a problem?" You'll get answers like the CRM export, the payroll file, the ticket queue. That's the list to be careful with. One minute.
Notes · slide 11
People think about the text they type and forget everything else. A screenshot of a dashboard might include customer names in the corner. A meeting transcript includes what everyone said, including the off-hand remark about a colleague. Uploading a document counts the same as pasting it. If your AI assistant at your company is connected to email, documents or chat, explain what it can see and what that means; check this with IT first. One to two minutes.
Notes · slide 12
Data safety isn't only about inputs. If AI writes something wrong and you send it to a customer, that's your company's mistake, not the tool's. Find out whether your company has a position on disclosing AI use, for example in customer communications or published content, and tell people what it is. If there isn't one, say so and tell people to use judgement and ask their manager. Legal and contractual wording always gets a qualified human review. One minute.
Notes · slide 13
Timing: 10 minutes. Four minutes alone: people list three real tasks and write down what they'd need to paste in for each, then mark the colour. Three minutes: they take one amber item and write the stripped-down version, describing the situation, removing names and identifiers. Three minutes: share with a neighbour or in breakout rooms and check each other's work, asking "is there anything left that could identify someone?" Walk around. Expect questions about edge cases; if you don't know the answer, write it down and promise to check with whoever owns the policy. Those questions are valuable: they show where the policy is unclear. If online, ask people to post one before-and-after in the chat, without any real data.
Notes · slide 14
3 minutes. The second question is the important one: usually the answer is no, the task still works fine without personal details. Where it genuinely doesn't, for example someone needs to analyse real customer feedback at scale, that's a conversation for their manager and whoever owns data at your company, not something to work around. Collect the open questions and commit to answering them in your follow-up email.
Notes · slide 15
Fill in the real contact before the session, usually the data protection lead, IT security or a specific mailbox. Edit the slide text to include it. Stress the culture point: people who report a mistake quickly should be thanked, not punished, because it's the only way the organisation can respond properly. If people fear blame, they hide mistakes, and that's far worse. If you're not sure how your company handles this, ask before running the session. One minute.
Notes · slide 16
The one-page version of this session. Suggest people keep it pinned near their desk or in their chat sidebar for a few weeks. If your company has its own checklist, use that instead and tell people where it is. Thirty seconds.
Notes · slide 17
Replace the placeholders on this slide with real links before you present. If there's no policy yet, say so plainly: "We don't have a written policy yet. Until we do, follow the traffic lights and the checklist, and ask me if you're unsure." Then follow up with whoever should own one; the questions from today's exercise are good evidence for what it needs to cover.
Notes · slide 18
One minute, then questions. Common question: "Can I use it on my phone?" Good answer: depends on your company's setup; tell them what's approved. Another: "What about tools built into other software we use?" Good answer: those count too, and the same three questions apply; check with IT if unsure.
Notes · slide 19
Small and concrete. Send the link and a one-page version of the checklist in your follow-up email so there's no excuse. Ask people to reply with any question the policy didn't answer. Thank them, and remind them that the aim is confident use, not less use.