When connecting your business systems to AI, you want to make sure that you’re fully aware of which tools provide the security level you need. This is especially important when dealing with personal, confidential, or proprietary information. Let’s go through the risks you need to be aware of when using LLMs and how to avoid a potential data leak.
To see a video explaining this, view the recording here:
AI Security Do’s and Don’ts
When you start connecting AI to your business systems, you are going to start getting a lot more questions about AI security. By keeping these AI security do’s and don’ts in mind, you’ll know exactly what data your AI can access and how it’s using that information.
Tool Usage
Do – Use AI tools approved by your IT or security team: You want your organization to approach AI adoption correctly and put the right security measures in place. The first thing you should do is check with your IT or security team; they will have the right license types for you.
Sometimes different models work better for different roles within the organization. For example, developers may need one account type, and those on the sales or marketing teams may need another type. Your IT or security team should know what account type is right for your role.
Don’t – Use personal AI accounts for company data: When implementing AI into business functions first became common, many people started using personal AI accounts for work. Thankfully, there are now many more corporate account options that give you better control over your company’s data. You want to make sure your IT or security team knows who and what has access to that data, when they use it, and what they’re using it for.
Data Agreements
Do – Use business-grade AI with data agreements in place: You want to make sure your AI client isn’t using your company data to train the AI model. Look for the data agreement and read through it thoroughly, searching for phrases like “we won’t use your data to train our model.” Make sure you double-check. While most enterprise plans include this, many free plans don’t, so you’ll want to read carefully.
Don’t -Use free AI tools for business-sensitive decisions: ChatGPT’s basic tier doesn’t have a data agreement promising not to use your data, so it may use your inputs to train future models. This increases the possibility that a competitor could come across your business information.
If you are entering business-sensitive documents into your AI, make sure you have a business plan that explicitly prohibits the AI from using that information without your permission.
Sensitive Data
Do – Keep sensitive customer data out of AI prompts: If you are regularly handling sensitive information, keep it out of the AI model. You can either mask the data or simply don’t include it within your prompt. You can’t risk your AI leaking sensitive information about your customers or your business.
Don’t – Paste confidential financial data into ChatGPT: When handling confidential financial data, you need to make sure your AI doesn’t have access to it. One common example is when you include credit card numbers in an Excel spreadsheet and send the whole thing to your AI without double-checking the data included. This goes for any type of sensitive information, not just financial data. Make sure that your AI can’t access any private information about your customers or business.
Private Connections
Do – Use AI with your own private data environment (RAG/MCP): By connecting your own MCP or other private data environment to your AI, you’re giving your AI proper context into your business. This makes your AI smarter and creates an even more powerful tool for your team.
Don’t – Share passwords or API keys with AI tools: This seems like an obvious one, but you don’t want to give AI access to things it should not have access to. Once you share passwords or API keys with your AI, you don’t know what it could do with them.
Output Review
Do -Review AI outputs before acting on them: Your AI will always want to generate an answer for you, but it may not always be accurate. Some engines are better at answering certain queries than others, so make sure you’re using the right LLM for your needs.
For example, while Claude is great for deep reasoning and writing code, it can’t generate images. ChatGPT, however, was created for general-purpose tasks, including image generation. Different AIs will give you different results, so you need to make sure you review any outputs for accuracy before you act on them.
Don’t – Assume AI outputs are always accurate or current: The power of AI lies in the ability for it to understand a simple, natural language query. You don’t have to be a programmer or developer to get what you want. If you write a very simple sentence, it can comprehend what you’re asking for and do those things for you.
The trouble is, AI can make assumptions and go on its own tangents, so you can’t just trust the first iteration of the results. If you’re routinely asking for something specific, make sure you have a repeatable process documented so that will give you the same results each time. You can also make sure there is something within your prompt that instructs your AI to check its answers before it sends you the response.
PopdockAI’s Security Model
PopdockAI is leading the industry in AI security thanks to our 7-layer security model. This amount of protection ensures you can control which data is shared with each person at your organization, all the way down to the field level.
Mask sensitive information like credit card numbers, social security numbers, and other private data from both employees and AI clients that don’t need access to it. With PopdockAI, you get peace of mind knowing that your data stays secure and protected.
Contact the eOne team to learn more about PopdockAI’s seven layers of security and how you can utilize PopdockAI within your organization.