Organisations should treat any prompt containing internal documents, customer records, or contract details as a data handling event, not a convenience step. The safest approach is to define clear approval, redaction, and acceptable-use rules, then give employees sanctioned alternatives for summarisation and drafting. Without governance, users will keep pasting sensitive material into tools that may retain it longer than intended.
Why Employee Prompting Needs Data Governance, Not Just AI Policy
When employees paste internal context into ChatGPT, the governance problem starts before the model response is returned. The organisation is deciding whether sensitive information may leave its controlled environment, who can approve that disclosure, and what redaction is required first. That is why effective policy treats prompts as a governed data flow, not as an informal productivity shortcut.
The practical boundary is the same one used for other sensitive disclosures: if the material would not be safe to place in an email to an external party, it should not be pasted into an unsanctioned public prompt. Where the business does want AI assistance, the safer pattern is to provide approved tools, pre-processing steps, and scoped use cases that preserve utility without requiring raw sensitive input.
Organisations often underestimate how quickly “just summarise this” becomes a disclosure channel for customer records, contracts, pricing, incident notes, or source code. A usable policy therefore needs clear approval criteria, not just a list of prohibited content. It should tell employees what can be shared, what must be redacted, and what to do when the task is important but the content is too sensitive for direct submission.
Controls That Make the Policy Work in Practice
A workable control set usually combines acceptable-use rules with data classification, redaction requirements, and sanctioned alternatives for drafting or summarisation. The key design choice is to move the decision away from every individual worker and into defined workflows, so users are not forced to improvise when they need speed. That also makes exceptions auditable instead of invisible.
Where organisations already use retention, access review, or secret-management controls, the same discipline should extend to AI input handling. Sensitive text pasted into a prompt can expose obligations tied to confidentiality, customer commitments, legal privilege, or regulated data handling. If the business cannot state who approved the prompt, what was removed, and which approved tool was used, the control is too weak to rely on.
Useful policy elements include:
- approved and prohibited categories of content
- mandatory redaction steps for named entities, account data, and contract terms
- approved enterprise AI tools with documented data-handling settings
- escalation paths for legal, security, and privacy exceptions
- logging or attestations for high-risk use cases
For related identity and access governance depth, see Ultimate Guide to NHIs and its section on Regulatory and Audit Perspectives, which are useful when a policy must be defensible under broader access and governance controls.
Risk and Threat Considerations
Prompting becomes a risk issue when sensitive context can be retained, logged, reused, exposed through misconfiguration, or handled outside approved jurisdictions or contractual terms. The concern is not only model output quality, but also disclosure of confidential data, accidental creation of a record in a third-party system, and loss of control over information that was intended for internal use only.
Failure mechanism: Users paste material that is too detailed for the tool or use case, the organisation has no enforceable guardrail, and the prompt content becomes part of an external processing flow that was never designed for that sensitivity level. The failure is usually procedural first, then technical if the enterprise has no sanctioned alternative with tighter data controls.
Impact: Sensitive corporate context can be exposed beyond the intended audience, retained longer than expected, or combined with other content in ways that create confidentiality, legal, or contractual risk. At scale, the organisation also normalises unsafe disclosure habits, which makes future exceptions harder to detect and stop.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI 600-1, NIST AI RMF and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Organizational Context | AI prompt governance must reflect business context and data sensitivity. |
| PR.DS-01 — Data-at-Rest Data Managed | Sensitive prompt input is a data handling event requiring protection decisions. | |
| GV.RM-01 — Risk Management Strategy | Employee use of ChatGPT should be governed through explicit risk acceptance and approval paths. | |
| Recommendation — Define prompt-handling rules by data class and business context. Protect sensitive prompt content with approved handling and redaction rules. Set approval thresholds for high-risk AI prompt use cases. | ||
| NIST AI 600-1 | MAP 1.3 — Contextualize AI Use Cases | GenAI use must be bounded by the sensitivity and purpose of the task. |
| Recommendation — Contextualize each AI use case before allowing sensitive inputs. | ||
| NIST AI RMF | GOVERN 1.3 — AI Risk Management Policy | The question is about establishing organisational AI use policy and accountability. |
| Recommendation — Publish policy that defines acceptable prompt data and approval paths. | ||
| CIS Controls v8 | 6.3 — Data Protection | Prompt redaction and sanctioned alternatives are data protection controls. |
| 3.4 — Access Control Management | Approved AI tools and exceptions need controlled access and governance. | |
| Recommendation — Implement data protection controls for sensitive AI inputs. Restrict sensitive AI use to approved accounts and tools. | ||
Practitioner Guidance
What to prioritise: Start by classifying the prompt content, not the tool. If the employee needs to paste customer data, contracts, credentials, source code, or incident material, route that use case through a sanctioned workflow or reject it unless redaction and approval rules are already defined.
What to verify: The policy should make three things explicit: which content is banned, which content requires redaction, and which approved AI service may be used for sensitive drafting. If employees cannot tell the difference without asking security every time, the rule is too vague to scale.
Practitioner takeaway: Governance succeeds when employees have a safe, faster path than the unsanctioned one; if the approved option is slower or less useful, sensitive prompting will keep happening informally.
Related resources from NHI Mgmt Group
- How should healthcare organisations govern employee use of GenAI when sensitive patient data may be pasted into public tools?
- What do organisations get wrong about allowing employee ChatGPT use?
- How should security teams govern employee use of ChatGPT and similar AI tools?
- How should organisations govern employee use of consumer AI chatbots?