AI tools can help us complete so many tasks more quickly such as summarise documents, draft communications and analyse information. However, using an AI tool also means giving that tool information. This information might include a colleague's name, a customer record, an identity number or health information, a client contract, and whether this information is about you or others, it is important that we protect it, and understand the risks with sharing it.
Before sharing information with AI, the first step is awareness.
Ask yourself:
What information am I about to share, who does it relate to, and does the AI actually need it?
Information about people can cause harm if it is exposed, misused or shared unnecessarily. Depending on the information involved, this could lead to loss of privacy, identity fraud, financial harm, embarrassment, discrimination or other consequences.
Being aware of what you are sharing helps you make a deliberate decision before information reaches an AI service.
What do we mean by personal information and PII?
You may hear terms such as personal information, personal data and personally identifiable information (PII).
The exact definitions can vary between countries and organisations, but the basic idea is straightforward:
It is information that identifies a person, or could help someone identify them.
Some information can identify a person directly:
- Full name
- Email address
- Telephone number
- Home address
- A recognisable photograph
Other information may identify someone when combined with additional details:
- Job title
- Employer or team
- Age
- Location
- Employee or customer number
- Date of birth
- Online identifiers
For example, "a finance manager" could describe thousands of people.
"The only finance manager in the Madrid office working on Project Orion" may describe just one.
This means removing someone's name does not always make the information unidentifiable. Context matters too.
Other identifiers
Some information can be especially useful for verifying, linking or impersonating someone's identity.
Examples include:
- Passport numbers
- National identity numbers
- Social security or national insurance numbers
- Driving licence numbers
- Tax identification numbers
- Health or insurance identification numbers
- Employee or customer identifiers
- Account or membership numbers
- Biometric identifiers
- Bank account details
- Payment card information
- Passwords and PINs
These details deserve particular care because their misuse can have serious consequences.
For example, a person's name may already be publicly available. Their passport number, national identity number or insurance identifier usually is not.
A useful rule is:
The more useful a piece of information could be for proving or assuming someone's identity, the more carefully it should be handled.
It is not only your decision: organisational obligations
If you are using AI at work, much of the information you handle is not yours to share, even if it seems harmless and even if you are using a tool on your work computer.
Organisations take on obligations about how information is handled. These often include:
- Contracts with clients, funders and partners, which may contain confidentiality clauses, data processing agreements or restrictions on where information can be stored or transferred
- Legal and regulatory duties, such as data protection law, which govern how personal information is used and shared
- Internal policies, which set out what can be shared with external services, and which tools are approved for which kinds of information
This means some information may be off limits for AI tools regardless of whether it contains personal details. A contract, a funding agreement, a set of user research notes or a client's internal report might all be covered by commitments your organisation has made.
A useful way to think about it:
A tool being available on your work computer is not the same as it being approved for the information you are about to share.
If you are unsure, check your organisation's guidance or ask the person responsible for data protection before sharing.
An easy check before sharing
Before sending a prompt or uploading a file, ask:
- What information am I sharing?
- Look for personal information, identity details, sensitive information, financial details, credentials and confidential information.
- Who does this information relate to?
- It might be about you, a colleague, customer, applicant, supplier or someone else.
- Does the AI genuinely need this information?
- If removing a detail would not affect the result, consider leaving it out.
- Can I remove, redact or replace it while keeping the useful context?
- A person's name might become "[Customer]" or "[Employee]", while an unnecessary identity number might be removed entirely.
- Could the person still be identified from what remains?
- Consider the combination of details, not only obvious identifiers such as names.
- Am I comfortable and permitted to share the remaining information with this AI tool?
- Follow your organisation's guidance and use approved tools and processes.
How Guardrails helps
Guardrails helps you build this awareness into the way you use AI.
Before your prompt reaches the AI tool, Guardrails checks for supported types of personal information and shows you what it has detected.
You can then review the information and decide whether it should be replaced or whether it genuinely needs to remain.
Guardrails provides a safeguard, but you remain in control of what you share.
Guardrails is due to launch by Sep 1st 2026. Sign up to our newsletter to be the first to get access to Guardrials.
