Module
Module 2 of 5Lesson 2 of 2~17 min

What each tool does with your inputs, depending on the plan

Lesson 2 of the module "What happens to your data" in the course "Use AI at work without exposing your data or your company".

Lesson objective

By the end of this lesson, you will be able to say, for your tool and your plan, whether your conversations can be used for training, how long they are kept, whether people can read them, and which settings to turn on, based on the vendor's dated pages.

Where it fits

What happens to your data

What can I put into an AI tool, and what happens to what I put in depending on the tool and the plan?

Lessons in this module

  1. Sorting your information into green, amber and red
  2. What each tool does with your inputs, depending on the plan (this lesson)

What you will learn in the course

This lesson is part of the course Use AI at work without exposing your data or your company

  • Sort the information in your work into green, amber or red based on its nature (public, internal, personal, sensitive, trade secrets, contractual commitments) and the tool considered.
  • Check and configure, for each tool and plan, what happens to your inputs (training, retention, human review, business terms), based on the vendors' dated pages.
  • Apply GDPR basics to the use of an AI tool (personal data, purpose, minimisation, sensitive data, processor, transfers) and prepare data by distinguishing pseudonymisation from anonymisation.
  • Protect the company in everyday AI use (trade secrets, contractual confidentiality, shadow AI, rights over generated content and third-party content).
  • Decide when to disclose the use of AI and who approves an output, placing the AI Act obligations in context (Article 50 transparency, Article 4 AI literacy).
  • Write a team AI policy (green, amber, red data, tools and settings, transparency, human approval, incidents, review) and organise its adoption.