Map the data before the tool
For any AI tool, ask: what data goes in, where is it processed, does it train anyone else’s models, and who could see it? If a vendor can’t answer clearly, that’s the answer. Public chatbots pasted with customer data remain one of the most common accidental disclosures we see.
- Classify data allowed into each tool — and block the rest technically, not just by policy.
- Prefer enterprise agreements with training opt-outs and data-residency terms.
- Log what’s shared with AI services so reviews are possible later.
Treat model output as untrusted input
AI-generated content can be wrong, and AI systems can be manipulated through the text they read — a technique called prompt injection when it hides in documents, emails, or web pages. Anything an AI system reads should be treated like an attachment from a stranger: parsed with care, never acted on without checks. Keep a human in the loop for anything that moves money, deletes data, or sends external communications.
Bound the permissions
Agentic tools that click, write, and send need the same least-privilege discipline as any admin account. Give each agent its own scoped credentials, separate from personal user accounts, with allow-lists for what it may touch. Review those permissions like you review admin access.
Monitor and rehearse for AI-specific failures
Add AI tools to your logging and incident plans. What does an incident look like when an agent misfires at scale, or a model leaks data it shouldn’t have had? Rehearse it like ransomware: define the kill switch, who pulls it, and how you recover.
Keep an AI inventory
Shadow AI is today’s shadow IT. Maintain a simple register of approved tools, owners, data classifications, and review dates — and make it easy for staff to request new tools through the front door, so the back door stops getting used.
Key takeaways
- Classify and technically restrict what data reaches each AI tool.
- Treat model output — and the content models read — as untrusted.
- Scope agentic tools with least-privilege, dedicated credentials.
- Rehearse AI-specific incidents, not just ransomware.
- Keep an approved-AI inventory with a fast front-door request path.
