Most teams now use AI tools every day, for drafting emails, summarising documents and answering client questions faster. That’s a good thing. The risk is that almost nobody checks what is being typed or uploaded into those tools. We put together a short checklist for business owners and managers to fix that, and you can download it for free below.
Why this matters
This is rarely deliberate misuse. It’s a lack of awareness of what happens to information once it leaves your own systems.
A well-known example: in 2023, engineers at Samsung’s semiconductor division pasted confidential chip design code into ChatGPT to help debug it. The code left the company’s systems the moment it was pasted in, with no way to get it back. Samsung restricted employee use of generative AI shortly after.³
None of this means you should avoid AI. It means your team needs a few clear rules that everyone understands, not a policy document nobody reads.
One rule of thumb to start with
The checklist builds on this with a simple way to sort information into three groups:
When in doubt, treat it as Restricted. Asking a manager takes five minutes. Getting data back once it has left the building isn’t possible.
What’s in the checklist
Seven pages, written for business owners and managers, not IT specialists:
- What data is safe to share with AI tools, and what never is
- What to check before you use AI output with a client
- How to handle sensitive company information, and why every AI tool needs a named owner
- Three things to check in any AI vendor contract
- A simple routine for when someone shares something they shouldn’t have
- A “do this, not that” overview you can share with your team
- A five-minute weekly check for managers

Get the AI security checklist
Leave your name and email and we’ll send the PDF straight to your inbox.
Who it’s for
The checklist is for anyone responsible for a team that uses AI, whether that’s ChatGPT, Claude, Copilot or a tool someone installed on their own. It works as a starting point for a conversation with your team this week. It isn’t a full AI policy, and it doesn’t replace legal advice.
1. LayerX, Enterprise AI and SaaS Data Security Report 2025
2. KPMG and the University of Melbourne, Trust, attitudes and use of artificial intelligence: A global study 2025
3. Forbes, Samsung Bans ChatGPT Among Employees After Sensitive Code Leak, 2 May 2023


