Decide What Data Your AI Is Allowed to See
An approved model does not automatically make every document appropriate input. Govern the complete information path.

The question “Which AI tool may we use?” needs a companion: “Which information may this workflow send to it?”
A supplier approval is useful, but it cannot answer every question about purpose, user access or sensitivity. The same service may be appropriate for public product information and inappropriate for a confidential personnel case under the chosen configuration.
Turn classification into a usable decision
Define practical categories with examples from the organisation: public, internal, confidential and restricted. For each category, specify approved workflows and environments, required handling, and the person who can authorise an exception.
These are organisational design choices, not universal legal classifications. Involve the relevant data, privacy and security owners so the rules match actual obligations and contracts.
Reduce the material sent to what the task needs. A support draft may need a problem description and product details; it may not need an entire customer history. Redaction can help, but context and combinations of details may still identify someone or reveal confidential information.
Follow the full information path
Map the prompt, uploaded files, retrieval store, inference service, tool responses, logs, backups and generated output. Ask where each is processed and retained, who can access it and how it is deleted.
An EU storage location answers only part of this map. Inference location, support access, subprocessors and connected tools deserve separate examination. Obtain service-specific evidence rather than assuming that a regional label covers every component.
OWASP identifies sensitive-information disclosure as an application risk involving both the model and its context. Read OWASP’s sensitive-information guidance.
Make the rule available at the point of use
Put concise handling guidance beside upload and connector controls. Enforce access restrictions and destination rules where possible. Provide a route for legitimate exceptions, with an owner, documented scope and review date.
Review the outputs too. A summary can expose confidential information even when every input came from an approved repository. Retrieval permission and permission to disclose are separate decisions.
My starting deliverable would be a one-page data-flow map for a single use case. Trace a real example from entry to deletion. Any unanswered question becomes a specific architecture or supplier-review task.







