AI Security Updated June 24, 2026

The 7 Rules of Safe Workplace AI Use (+ a 5-Second Checklist)

The seven golden rules for using AI safely at work, the data that must never enter an unapproved tool, and a five-second checklist to run before every prompt. A practical acceptable-use playbook for any employee.

AI at work is a force multiplier — and a liability — depending on a few habits. These are the rules we teach in our AI Security & Awareness Training course, distilled into something any employee can apply today.

The seven golden rules

  1. Use approved tools only. Everything else is shadow AI — and it strips away the protections your organization negotiated.
  2. Protect data in prompts. Restricted data needs an explicitly approved tool. (See the never-enter list below.)
  3. Treat every prompt as a public statement. Wouldn’t want it leaked? Don’t type it.
  4. Verify before you rely. Consequential output gets human verification, every time.
  5. You remain accountable. AI assists; you decide. Your name is on the result.
  6. No autonomous actions. AI agents don’t send, change, or execute anything without human approval.
  7. Be transparent. Follow disclosure rules; never pass AI output off as independent expertise.

What never enters an unapproved AI tool

Some data simply doesn’t belong in a tool that isn’t cleared for it. Never paste:

  • Personal information — customer, employee, or anyone’s: IDs, contact, health, or financial details.
  • Customer & client data — contracts, documents, tickets, anything under a confidentiality agreement.
  • Credentials & secrets — passwords, API keys, tokens, security configurations, network details.
  • Confidential business information — strategy, financials, M&A, legal matters, unreleased products, pricing.
  • Proprietary code & IP — source code, algorithms, trade secrets, internal designs.
  • Regulated data — anything covered by privacy or sector rules that apply to your business.

The litmus test:

“Would I email this exact content to a stranger?” If no — it doesn’t go in.

Verify before you rely

Verification scales with consequence: a brainstorm needs none, a client deliverable needs a lot. Because AI is a pattern predictor, not a fact engine, check:

  • Facts, figures, names, citations — against an authoritative source before they leave your hands. (AI invents confident, well-formatted citations that don’t exist.)
  • Specialist content — legal, financial, medical, compliance: a qualified person signs off before use. Always.
  • Code — review and test it like code from an unknown contributor, because that’s what it is.
  • What’s missing — AI answers are often plausible but incomplete. The absence of a caveat is not evidence there isn’t one.

Where your prompt actually goes

On many free and consumer tools, your prompt doesn’t just vanish after you read the reply. It may be retained (for days, months, or indefinitely), reviewed by provider staff, used to train the next model, and exposed if the provider is breached. Approved enterprise tools change all four — that’s the entire point of using them. The chat box looks the same; the protections behind it are not.

The five-second before-you-prompt checklist

Run this before you hit enter. It takes about five seconds and prevents most AI incidents.

  • TOOL — Am I in an approved tool, on my work account?
  • DATA — Is everything in this prompt (attachments included) free of restricted data, or is this tool cleared for it?
  • STAKES — How will this output be used, and what verification does that require?
  • NAME — Am I prepared to put my name on the result?

Five things to remember

  1. Pattern predictors, not fact engines. Confidence is not accuracy.
  2. Prompts are disclosures. Restricted data never enters unapproved tools.
  3. Verify before you rely. You are accountable for everything you use.
  4. Voices and faces can be faked. Verify sensitive requests out-of-band, every time.
  5. When in doubt, report. Fast reporting is protection, not punishment.

These habits — a careful prompt, a verified output, a fast report — are what the human firewall looks like in the age of AI. To turn them into reflexes across your whole team, see the AI Security & Awareness Training course or browse SecureLabs Academy.

Save this to your AI assistant

Published June 24, 2026.

Frequently asked questions

What are the rules for using AI safely at work?

Seven golden rules: use approved tools only; protect data in prompts; treat every prompt as a public statement; verify before you rely; remember you stay accountable; allow no autonomous actions without human approval; and be transparent about AI use. Together they keep sensitive data out of the wrong tools and keep a human responsible for every result.

What data should never be put into an AI tool?

Never put personal information, customer or client data, credentials and secrets, confidential business information, proprietary code or IP, or regulated data into an unapproved AI tool. The litmus test: would you email this exact content to a stranger? If not, it doesn't go in.

What is the before-you-prompt checklist?

A five-second check with four questions — TOOL: am I in an approved tool on my work account? DATA: is everything in this prompt free of restricted data, or is this tool cleared for it? STAKES: how will this output be used, and what verification does that require? NAME: am I prepared to put my name on the result? Five seconds of thought prevents most AI incidents.

Who is accountable when AI does the work?

You are. AI assists; you decide. If you use AI output, you own it as if you wrote it yourself. Accountability never transfers to the tool, which is why consequential output always gets human verification before it's relied on.

Make these habits automatic

Turn every employee into a careful, confident AI user — and your first line of defense against AI-powered attacks.

Explore AI Security & Awareness Training