Safe use of generative AI at work: what you can put in, approved tools and policy
For anyone who uses, or wants to use, generative AI tools at work, and for team leads who get asked 'can I put this into the chatbot?'. Complete 'Using AI assistants at work responsibly' first. That course gives the basics. This one goes further on the input side: classifying information before you paste it, telling consumer tools from approved ones, reading your organisation's AI policy, stripping a prompt down to the minimum data, and reporting an accidental disclosure. Checking AI output is covered in the AI-checking courses, not here. Examples use UK data protection guidance from the ICO and voluntary guidance from the UK NCSC and US NIST. Your organisation's policy decides what's allowed. This course is not legal advice.
- Level
- Intermediate
- Length
- About 71 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Classify information into your organisation's data categories before it goes into an AI tool
- Choose between a public AI tool, an approved enterprise tool and no AI tool, based on where the data goes
- Identify what your AI acceptable-use policy and approved-tools list tell you, and raise the gaps
- Rewrite a prompt so it carries only the minimum data the task needs
- Report an accidental disclosure to an AI tool promptly through your organisation's incident route
Course outline
- 1.Classifying information before it goes into an AI toolLesson · 13 min
- 2.Choosing between a public AI tool, an approved tool and no toolLesson · 12 min
- 3.Reading your AI acceptable-use policy and approved-tools listLesson · 11 min
- 4.Rewriting a prompt to use the minimum dataLesson · 12 min
- 5.Reporting an accidental disclosure to an AI toolLesson · 8 min
- 6.Safe use of generative AI at work: what you can put in, approved tools and policy: knowledge checkKnowledge check · 14 questions
- 7.Safe use of generative AI at work: what you can put in, approved tools and policy: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- UK NCSC blog: ChatGPT and large language models: what's the risk? (14 March 2023)
- UK NCSC: AI and cyber security: what you need to know (13 February 2024)
- ICO: Guidance on AI and data protection (updated 15 March 2023)
- ICO: What are the accountability and governance implications of AI?
- ICO: How should we assess security and data minimisation in AI?
- ICO: Personal data breaches: a guide (updated 20 August 2025)
- NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (July 2024)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.