“Provide guidance on avoiding the input of sensitive information. Offer training on best practices for interacting with LLMs securely.”
“Maintain clear policies about data retention, usage, and deletion. Allow users to opt out of having their data included in training processes.”
Samsung's three leaks (Slide 12) happened twenty days after the company lifted its ChatGPT ban — with no guidance in place on what was safe to paste in. The cost of that gap: a company-wide ban, reversed in under a month, and proprietary code now permanently outside Samsung's control.
→ Give employees concrete, specific examples of what counts as sensitive before they encounter the temptation to paste it in
→ Publish a plain-language data retention and training-opt-out policy, not just a buried legal Terms of Use clause
→ Make the safe path the easy path — internal AI tooling with proper data controls beats a ban employees route around
Ask five employees what happens to text they type into your company's AI tools. If they don't know, your transparency policy isn't reaching the people it's meant to protect.
Ask whether your users know what happens to the information they type into your AI product. If users think it stays private but it's stored and used for training, that's a disclosure risk your legal team should know about.