Module
Module 2 of 5Lesson 1 of 2~15 min

Sorting your information into green, amber and red

Lesson 1 of the module "What happens to your data" in the course "Use AI at work without exposing your data or your company".

Lesson objective

By the end of this lesson, you will be able to sort a piece of information from your work into green, amber or red based on its nature and the tool considered, and to justify borderline cases.

Where it fits

What happens to your data

What can I put into an AI tool, and what happens to what I put in depending on the tool and the plan?

Lessons in this module

  1. Sorting your information into green, amber and red (this lesson)
  2. What each tool does with your inputs, depending on the plan

What you will learn in the course

This lesson is part of the course Use AI at work without exposing your data or your company

  • Sort the information in your work into green, amber or red based on its nature (public, internal, personal, sensitive, trade secrets, contractual commitments) and the tool considered.
  • Check and configure, for each tool and plan, what happens to your inputs (training, retention, human review, business terms), based on the vendors' dated pages.
  • Apply GDPR basics to the use of an AI tool (personal data, purpose, minimisation, sensitive data, processor, transfers) and prepare data by distinguishing pseudonymisation from anonymisation.
  • Protect the company in everyday AI use (trade secrets, contractual confidentiality, shadow AI, rights over generated content and third-party content).
  • Decide when to disclose the use of AI and who approves an output, placing the AI Act obligations in context (Article 50 transparency, Article 4 AI literacy).
  • Write a team AI policy (green, amber, red data, tools and settings, transparency, human approval, incidents, review) and organise its adoption.