Lesson 004Field guide · AI Safety & Privacy
Using AI for Sensitive Work
Guardrails for client data, health info, and confidential work.
You'll learn
- The minimum-necessary rule for sensitive tasks
- Anonymizing that actually holds — beyond swapping names
- What to find out about your tool's plan and policies
- The four signs a task shouldn't go to AI at all
- How to keep AI genuinely useful for exactly this kind of work
01Section
The gray zone after the never-paste list
What Not to Share with AI drew the hard lines: credentials, IDs, other people's private data, confidential material, and anything you've promised to protect. But most sensitive work lives in a gray zone — tasks you legitimately need help with, built on information you can't expose. A difficult employee conversation. A client proposal. A question about your own health paperwork.
The answer isn't "no AI for anything sensitive." It's a set of guardrails that get you the help while the sensitive details stay home. This lesson gives you four.
Before we start
Rules for health, legal, and employee data vary by country, industry, and contract — and they change. This lesson is education, not professional advice. Where a law or policy applies to you, it wins.
Checkpoint
02Section
Guardrail 1: minimum necessary
Plain-language definition
Minimum-necessary sharing — giving the AI only the details the task actually requires — and defaulting to fewer. Most tasks need the situation and the goal, not the identities and the exact figures.
Before any sensitive prompt, ask: what does the AI need to do this job well? The answer is usually "less than I have." Drafting needs tone and context. Planning needs the shape of the problem. Almost nothing needs real names, real account numbers, or a full document paste.
Too much
Here's the full HR file on Marcus Webb, including his last two performance reviews and salary. Help me write his improvement plan.
Minimum necessary
An employee in a client-facing role has missed several deadlines over two months, after previously strong performance. Help me draft a supportive, clear improvement plan with regular check-ins.
The second prompt produces an equally useful draft — and far less that could identify anyone. In a small team, still check what the details add up to; that's the next guardrail.
Checkpoint
03Section
Guardrail 2: anonymize so it holds
Swapping "Sarah" for "Customer A" is the start, not the finish. Details combine: "our only warehouse in a small coastal town" plus "the manager who joined in January" can identify a person as surely as a name. Anonymizing that holds means checking what the pieces add up to.
Strip the direct identifiers: Names, emails, account numbers, addresses, and any job title only one person holds.
Generalize the specifics: Exact amounts become ranges ("around $50k"), exact dates become rough timing ("earlier this year"), small places become descriptions ("a regional office").
Check the combination: Reread as a stranger who knows your industry: could they narrow it to one person or company? If yes, generalize further.
Keep a swap key on your side: Note which placeholder maps to which real detail — in your own file, never in the chat — and restore them after you copy the draft out.
Privacy note: Work accounts and personal accounts are different worlds. Sensitive work tasks belong in whatever tool your workplace has approved — pasting work matters into a personal free-plan account is a common way policy trouble starts.
Checkpoint
04Section
Guardrail 3: know your tool's rules
AI tools don't all handle your data the same way — and neither do plans within the same product. Free, paid, and business tiers can differ on how long conversations are kept, whether they can be used to improve models, and who can see what. You don't need to become a policy expert. You need answers to a few questions, once per tool.
- Training use: Can my inputs be used to train or improve models — and is there a setting to turn that off?
- Retention: How long are conversations kept, and what does deleting actually delete?
- Workplace rules: Does my employer have an approved AI tool or a written policy? If yes, that's the answer for gray-zone tasks — though an approved tool never overrides the never-paste categories or a specific contract or NDA (guardrail 4).
- Plan differences: Is there a business plan with stronger data terms for work use?
Checkpoint
05Section
Guardrail 4: know when the answer is no
Sometimes the right call is not using AI for the task. Four signs:
- A law, contract, or policy says no. Health records, privileged legal matters, regulated client data — where a rule covers it, the rule wins over convenience.
- Anonymizing would break the task. If the job only works with the real details — reviewing a specific contract's exact clauses, say — and those details can't leave, it goes to a person or an approved tool instead.
- You couldn't verify the answer. High-stakes questions where you can't tell right output from wrong — legal interpretations, medical decisions — need a qualified human, not a fluent guess.
- It's someone else's call. Another person's health, legal, or financial situation isn't yours to feed into a tool — even anonymized — without asking them.
Key takeaway
When the task needs the real details and the real details can't leave, the answer isn't a cleverer prompt — it's a qualified person.
Pause and think: Think of the most sensitive task on your plate this month. Which guardrail applies — and would any of the four "no" signs stop it?
Checkpoint
Prompt exercise
Run a sensitive task with the guardrails on
Pick a real sensitive-ish task — a difficult conversation, a delicate email, a plan involving people. Copy this prompt into ChatGPT, Claude, Gemini, Copilot, or whichever AI tool you have access to — the website doesn't run AI itself. The prompt asks the AI to flag anything identifying as a second check — but your own placeholders and generalizing are the real protection.
Help me with a sensitive work task. Ask me one question at a time to understand the situation. Ground rules: I'll answer with placeholder names and generalized details only — never ask me for real names, companies, or exact figures, and if anything I share could identify a real person or organization, stop and tell me before continuing. Once you understand the situation, help me with: [describe the task — e.g., planning a difficult conversation, drafting a delicate email]
Reflection: Notice what the placeholders cost you: usually nothing. Good advice fits the situation, not the names — that's why these guardrails are affordable.
Quick check
4 quick questions — no pressure
There's no pass or fail here. Answer them all, and we'll show you the answers either way.