AI tools are useful for drafting, summarising, brainstorming, and turning rough notes into clearer language. The risk is not "AI is bad"; the risk is pasting information into a tool before the business has decided what is safe to share. For a small team, the practical rule is simple: if the information would create harm if it appeared in the wrong inbox, do not paste it into a public or unmanaged AI tool.
This checklist is written for ordinary New Zealand SME work: emails, quotes, customer records, website copy, contracts, accounts, and internal notes. It is not legal advice. It is a safer operating habit you can use before staff, contractors, or owners ask an AI tool to help with business admin.
Never paste
Information that should stay out of AI prompts
Some information is too sensitive to paste into a general-purpose AI tool. Keep it in your own systems, or remove identifying details before asking for help with wording or structure.
Customer and patient details
Names, addresses, phone numbers, email addresses, case notes, appointment notes, health details, complaints, or anything that identifies a person.
Credentials and access details
Passwords, MFA codes, recovery codes, API keys, private links, admin URLs, cPanel details, DNS logins, or mailbox forwarding rules.
Commercially sensitive work
Unpublished pricing, margin calculations, quotes, tenders, supplier terms, payroll details, board papers, or private strategy notes.
Legal, HR, and conflict material
Employment disputes, disciplinary notes, settlement wording, legal letters, incident reports, or anything that should remain privileged or tightly controlled.
Safer prompts
How to ask for help without exposing private data
You can still use AI productively. The trick is to separate the task from the sensitive facts. Ask for a structure, checklist, tone rewrite, or generic draft, then add the real details inside your own system.
- Replace names with roles: "customer", "supplier", "staff member", "tenant", or "client".
- Remove exact addresses, phone numbers, email addresses, dates of birth, account numbers, and file references.
- Use invented examples when asking for policy wording, email templates, or process checklists.
- Keep final customer-specific wording in your email, CRM, ticketing, or document system, not in the AI prompt.
- Do not upload screenshots that include private tabs, inboxes, URLs, tickets, invoices, or hidden account details.
Good use cases
Business tasks where AI is usually lower risk
AI is safer when the input is generic and the output is reviewed by someone who understands the business. Treat it like a draft assistant, not a private record-keeping system.
First-draft templates
Ask for a generic appointment reminder, quote follow-up, complaint acknowledgement, or handover checklist without customer-specific details.
Plain-English rewrites
Paste a non-sensitive paragraph and ask for simpler wording, shorter sentences, or a more helpful structure.
Internal checklist ideas
Ask for a starting checklist for onboarding, website launch, password handover, device setup, or email migration, then adapt it privately.
Public website drafts
Use AI to outline service-page sections or FAQs, then rewrite them so they match the real business and do not invent claims.
Team rule
A simple AI safety policy for an SME
A policy does not need to be long. It needs to be easy to remember while someone is busy. Start with this: AI tools may be used for structure, summaries, and draft wording, but staff must not paste personal data, credentials, customer records, private commercial information, legal/HR material, or confidential screenshots into unmanaged AI tools.
Add one owner for the policy, one place where approved tools are listed, and one process for asking before a new tool is used. If the business handles sensitive customer information, make the default answer "do not paste" unless someone has checked the tool, account settings, and data-handling terms.
NZ privacy context
Personal information still counts when it is inside a prompt
For a New Zealand business, the privacy question is not whether the tool is clever or convenient. The practical question is whether the prompt includes information about an identifiable person, whether the business has a lawful reason to use it that way, and whether the tool provider may retain, disclose, train on, or process that information outside the business's control.
Identify the information
If the prompt includes names, contact details, photos, emails, IP addresses, account notes, or enough context to identify someone, treat it as personal information.
Check the purpose
Ask whether using the information in an AI tool fits the reason it was collected. If the answer is unclear, use a fictional example instead.
Keep it secure
Prompts, uploaded files, screenshots, and generated outputs should be treated like business records when they contain sensitive details.
Review before acting
AI output can be wrong, biased, or too confident. A person should review anything that affects a customer, staff member, invoice, account, or legal position.
Tool approval
Questions to ask before approving an AI tool
an SME does not need an enterprise governance programme to make better choices. It does need a short approval checklist so staff know which tools are allowed, what they can be used for, and what must never be pasted into them.
- Who owns the account and who can see prompt history, uploaded files, and generated outputs?
- Can the business turn off training, retention, or sharing of prompts where the tool offers those controls?
- Where may personal information be processed or stored, and does that create an overseas-disclosure question?
- What is the approved use: drafting public copy, summarising generic notes, writing code examples, or something more sensitive?
- Who reviews the output before it is sent to a customer, published, used for a decision, or copied into a business system?
- How does the business delete prompt history or revoke access when a staff member, contractor, or tool is no longer approved?
Prompt decision tree
A 30-second check before pasting anything
Use this as the everyday rule at the keyboard. If any answer is uncomfortable, stop and rewrite the prompt with placeholders or ask for a generic template instead.
Could this identify someone?
If yes, remove identifiers or avoid the tool unless the business has approved that exact use and checked the provider terms.
Would this harm the business if leaked?
If yes, keep it out of the prompt. That includes pricing strategy, disputes, payroll, supplier terms, credentials, and unpublished plans.
Can a placeholder do the job?
Most drafting tasks work with invented names, fake dates, approximate categories, and generic scenarios.
Will a human check the answer?
Do not rely on AI output for customer commitments, account recovery, legal wording, technical changes, or payment instructions without review.
Overseas and provider risk
Cloud tools can create disclosure and retention questions
Many AI tools are operated by providers outside New Zealand or process data across multiple systems. That does not automatically make them unusable, but it does mean the business should understand whether personal information is being disclosed, retained, used for the provider's own purposes, or protected by comparable safeguards.
Low-risk pattern
Use prompts that contain no personal, confidential, credential, customer, pricing, legal, HR, or commercially sensitive details.
Higher-risk pattern
Uploading emails, documents, screenshots, contracts, CVs, complaints, call notes, or support tickets with real identifiers.
Business control
Prefer managed accounts, approved tools, clear retention settings, access controls, and a process for removing staff or contractors.
Evidence trail
Keep short notes on why a tool is approved, what settings were checked, and which prompt categories are allowed or banned.
Recovery
What to do if sensitive information was pasted
Do not panic, but do treat it like an incident. Record what was pasted, which tool was used, who used it, and whether credentials or personal information were involved. If passwords, API keys, tokens, or recovery codes were pasted, rotate them immediately and check account activity.
- Save a short internal note with the date, tool, prompt type, and information category.
- Rotate any exposed credentials, keys, tokens, or recovery codes.
- Check mailbox forwarding rules, admin accounts, and recent sign-in logs if account data was involved.
- Tell the relevant owner or manager so the same mistake is not repeated quietly.
- Update the business AI rule with a clearer example if the mistake came from ambiguity.
Related reading
Email security, recovery, and safe handover
AI safety often overlaps with account security: mailbox access, MFA, password recovery, and admin ownership. These pages connect the AI checklist to the wider support cluster.
Official references
NZ privacy guidance to cross-check
These official Privacy Commissioner resources are useful when a business is deciding whether a tool is safe enough for personal information, confidential business information, or customer-facing decisions.