6 min read
Prompting safely
The two questions to ask every time
Public or unapproved AI tools are genuinely useful, and using them well is not complicated. By unapproved we mean any tool your organisation has not vetted, which may not meet its security and privacy requirements. It comes down to two questions you should ask before and after every prompt: what am I putting in, and how much do I trust what comes out. Get those two right and you get the benefit without the risk.
What goes in: never paste secrets
A prompt you type into a public or unapproved AI tool leaves your device. It travels to a company's servers, and depending on the service and its settings, it may be stored, reviewed by staff, or used to train future versions of the model. Treat anything you type there as if you were saying it out loud in a public place, because in effect you are handing it to someone else.
So keep certain things out of the box entirely:
- Passwords, codes and keys of any kind.
- Personal data about yourself or other people: full names tied to sensitive details, ID numbers, addresses, health or financial information.
- Confidential work material: customer records, contracts, unreleased plans, internal documents, anything covered by a duty of confidentiality.
If you would not post it publicly, do not paste it into a public or unapproved AI tool. When you need help with something sensitive, remove or replace the identifying details first. Instead of a real client's information, describe the situation in general terms, or swap in placeholder names and numbers.
What comes out: treat it as a draft
The previous lesson showed why an AI answer can be confidently wrong. That leads straight to the second habit: whatever the tool produces, treat it as a first draft, not a finished, trusted result. It is a strong starting point that you then check, correct and take responsibility for.
That means reading the output critically rather than pasting it straight into an email, a report or a piece of code. Verify any facts, figures and quotes against a reliable source. Read generated text for errors and for claims that are simply invented. If it wrote code or instructions, understand what they do before you run them. The tool drafts; you edit and you own the result.
A simple everyday example
Suppose you want help replying to a difficult customer complaint. The unsafe version is to paste the customer's full email, name and account number in and copy the reply straight back to them. The safe version is to describe the situation without the personal details, ask for a draft reply, then read it, adjust the tone, correct anything wrong, and add the real details yourself at the end, on your own systems.
Same tool, same benefit, none of the exposure. Guard what goes in, verify what comes out, and public or unapproved AI tools become a safe part of your everyday work.
Check yourself
Where this lesson comes from
Built from
- Workshop 4: Introduction to AI and Machine Learning (V3.0): safe use of AI tools, data privacy
alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement