Slide 22 of 27
Part 4 · PreventionSlide 22
Slide 22 · Mitigation Category 4 of 6
The cheapest control is also the one teams skip first.
📄 OWASP LLM Top 10:2025 · LLM02 Prevention — User Education and Transparency
OWASP — User Education
Educate Users on Safe LLM Usage + Ensure Transparency in Data Usage

“Provide guidance on avoiding the input of sensitive information. Offer training on best practices for interacting with LLMs securely.”

“Maintain clear policies about data retention, usage, and deletion. Allow users to opt out of having their data included in training processes.”

Samsung's three leaks (Slide 12) happened twenty days after the company lifted its ChatGPT ban — with no guidance in place on what was safe to paste in. The cost of that gap: a company-wide ban, reversed in under a month, and proprietary code now permanently outside Samsung's control.

→ Give employees concrete, specific examples of what counts as sensitive before they encounter the temptation to paste it in
→ Publish a plain-language data retention and training-opt-out policy, not just a buried legal Terms of Use clause
→ Make the safe path the easy path — internal AI tooling with proper data controls beats a ban employees route around

Ask five employees what happens to text they type into your company's AI tools. If they don't know, your transparency policy isn't reaching the people it's meant to protect.

💼 Business takeaway

Ask whether your users know what happens to the information they type into your AI product. If users think it stays private but it's stored and used for training, that's a disclosure risk your legal team should know about.

← BackNext → Secure Configuration