Prohibited
Unapproved handling of highly sensitive information
Do not place highly sensitive client or business information into an AI service that has not been approved for that use.
Illustrative example — not client work
See how ActiveHub can assess proposed AI uses individually, identify the controls each use requires and distinguish acceptable uses from situations where the business should not proceed.
The answer is different for each use.
Some uses involve limited information, straightforward human review and low consequences if an output is imperfect.
Others involve confidential information, important decisions or consequences that require significantly stronger controls.
Two proposed uses should not proceed in their current form.
The assessment therefore does not recommend either:
It recommends different decisions according to the use.
The ratings below are qualitative decision aids. They are not claims of mathematical precision.
Control intensity
| Proposed use | Information sensitivity | Consequence of error | Human review | Supplier/data concern | Overall recommendation |
|---|---|---|---|---|---|
| Use 1Routine internal drafting | Low | Low | Straightforward | Low if approved tool used | Proceed with standard controls |
| Use 2Client meeting summaries | Medium | Medium | Required | Medium | Proceed with additional controls |
| Use 3Internal knowledge search | Medium | Medium | Required for important use | Medium | Proceed with controls |
| Use 4Highly sensitive files in unapproved public AI | High | High | Does not resolve data-handling concern | High | Do not proceed |
| Use 5Automated professional recommendations | Medium–High | High | Absent in proposed use | Medium | Do not proceed |
Risk does not increase simply because more AI is involved.
It increases when factors such as these combine:
A comparatively sophisticated AI use may be acceptable in one controlled context.
A simple use may be unacceptable if it involves information or decisions that should not be handled that way.
Use 1
Employees use an approved AI tool to prepare first drafts of routine internal material using non-sensitive information.
Examples could include:
The use may:
The proposed use does not require:
The tool may produce statements that were not present in the source information.
Employees may accept generated wording without checking it.
A low-risk use can gradually expand into employees entering more sensitive information unless boundaries are clear.
This is a proportionate use where:
The control burden should remain proportionate.
Do not create an approval process so heavy that the administrative control costs more than the risk it addresses.
Use 4
The business has not established whether:
Uploading the material may conflict with obligations the business owes to the client.
Once highly sensitive information is submitted to an unsuitable service, the business may have limited ability to reverse the disclosure.
An individual employee would effectively be choosing a new information-processing service without the business evaluating the implications.
Even perfect human review of the generated output would not resolve the risk created by sending highly sensitive information to an unapproved service.
The use should not be permitted in the proposed form.
The issue is not that highly sensitive information can never be processed using AI.
The issue is that the proposed service and data-handling arrangement have not been established as appropriate for the information.
If there is a strong business case, the business may separately assess whether an approved service can support the use under appropriate contractual, security, privacy, confidentiality, access and retention controls.
That would be a different proposal requiring its own assessment.
The risk assessment should focus on the use rather than assigning one universal risk level to a technology.
Imagine the same approved AI service being used for two tasks.
| Use ALower-risk use | Use BHigher-risk use | |
|---|---|---|
| Use and purpose | Draft an internal meeting agenda using:
| Analyse highly confidential client records and produce a recommendation that could materially affect the client. |
| Information sensitivity | Low. | High. |
| Potential consequence of error | Limited. | High. |
| Human review | Easy. | Essential. |
| Supplier/data requirements | Significant. | |
| Likely decision | Proceed with standard controls | Requires substantially stronger controls and may not be acceptable depending on the service and proposed process |
The decision also depends on:
Therefore:
“Approved AI tool” does not mean “approved for every use”.
The business does not need a large governance bureaucracy to establish useful controls. It needs a small number of clear rules employees can actually follow.
Control 1
Define which services and account types employees may use for business information.
Employees should not treat public availability as business approval.
Control 2
Define categories such as:
The categories should use language employees understand.
Control 3
Define when generated content must be reviewed before:
Control 4
Require important facts, calculations, quotations, sources, actions and recommendations to be checked where errors could matter.
Control 5
AI-enabled systems should not expand access beyond what employees reasonably need.
Control 6
Perform proportionate review before allowing a service to process information where confidentiality, privacy or security materially matters.
Control 7
Define a short list of uses the business does not permit.
Examples from this assessment include:
Control 8
Employees should understand that:
Using AI does not transfer responsibility for the business decision to the tool.
Control 9
Provide a simple route for employees to ask:
“Can I use this tool for this information and this purpose?”
when the situation does not fit the standard rules.
The business should avoid a long list of theoretical prohibitions employees cannot remember.
A short list of clear boundaries is more useful.
Based on this assessment:
Prohibited
Do not place highly sensitive client or business information into an AI service that has not been approved for that use.
Prohibited
Do not automatically issue professional recommendations to clients without responsible human review.
Prohibited
Do not use AI search or summarisation to obtain information the employee is not authorised to access.
Prohibited
Do not represent generated facts, quotations, summaries or recommendations as checked when they have not been checked.
Prohibited
Do not use real confidential client information merely to test an unfamiliar AI service.
Use non-sensitive test material until the service and use have been appropriately assessed.
This example shows one way an AI risk review can be presented. The scope, controls and depth of a real assessment depend on the proposed use, the information involved and the consequences if something goes wrong.