Lesson 5 · AI Foundations
Privacy, confidential data, and safe tools
- Length
- 26 minutes across 7 sections
- You will be able to apply
- The Three-Way Match
- You will produce
- Commit Statement
- You will work
- 2 gated questions
Approved for what data, on which account, for which purpose?
Core question
The fastest route from a productivity tool to a reportable incident is a paste. Confidential, personal, regulated, customer, employee and proprietary information leaves your control the moment it enters a service, and unlike a bad draft, it cannot be recalled. There is no undo.
The question people ask is whether a tool is approved. That question has no useful answer. A tool that is entirely appropriate for public marketing copy may be prohibited for a customer record, and the same tool on a personal account may retain and train on inputs that an enterprise agreement forbids. Approval is not a property of software.
The pathology: Intent Laundering
Nobody pastes a customer file into an unapproved service in order to do something wrong. They do it to solve a problem quickly, for a legitimate business reason, usually under time pressure, usually to help someone. The legitimacy of the purpose is real, and it is doing something quietly destructive: it is being used as evidence that the transfer is acceptable.
Because purpose feels like permission, permission has to be checked as three separate things that must all hold at once.
The Three-Way Match
Definition
The Three-Way Match requires that the data class, the tool-and-account, and the purpose are each approved, and approved together, before anything is entered. Three legs. All three must hold. Any unmatched leg stops the task, and no leg may be inferred from another: an approved tool does not approve a data class, and an approved purpose does not approve an account.
The match is checked before the tool is opened, because the moment the material is on screen the pressure to proceed is already applied.
When to Use It
Use it every time material you did not personally author is going to enter an AI system. That covers customer text, employee text, supplier documents, screenshots, spreadsheets, logs, and anything you copied from another system. Material you wrote yourself about a real person is still about a real person.
Re-run it when any leg changes: a new account, a new plugin or integration, a new region, a new data source feeding the same workflow. Integrations are the leg that changes without anyone announcing it.
How to Apply It
- Classify the material before opening any tool, and classify the most sensitive element in it rather than the general character of it.
- Identify the exact tool, the exact account, and the region and retention terms that account operates under.
- State the purpose in one sentence, and check that the approval you are relying on actually covers that purpose.
- When any leg fails, substitute a fictional or redacted example and ask, rather than proceeding and disclosing later.
The approval on record covers this specific use, not merely a similar one.
- Purpose
- The approval on record covers this specific use, not merely a similar one.
- Tool and account
- This account, region and retention terms are the ones that were approved.
- Data class
- The most sensitive element in the material is approved for external processing.
| Leg | What people check | What actually has to be true |
|---|---|---|
| Data class | That it feels internal | The most sensitive element in the material is approved for external processing |
| Tool and account | That the tool is on the approved list | This account, in this region, under these retention and training terms, is the approved one |
| Purpose | That the reason is legitimate | The approval on record covers this use, not merely a similar one |
Worked example 1 of 3
A support lead at OmniCorp Retail needs help restructuring a difficult escalation response. The ticket contains a customer name, an order history and a complaint about a delivery driver. The tool is approved. The purpose is unimpeachable. The lead runs the match anyway.
- Support lead
- Data class first. Most sensitive element is a named customer complaining about a named employee.
- Trevor Okafor
- That is two people, one of whom works here. Which account are you on?
- Support lead
- My own login on the approved assistant. Approved for drafting customer communications.
- Trevor Okafor
- Approved for drafting them. Not for processing a complaint about an employee, which is an HR matter with its own path. That leg fails.
- Support lead
- Then I strip both names and the driver reference, keep the structure of the complaint, and ask for help with the shape of the response.
- Trevor Okafor
- That works. And send the actual escalation to HR through the normal route today, not after you have drafted something.
Nothing was blocked. The lead got the help she needed within four minutes. The only thing that changed was that a complaint about a named employee did not enter a system approved for customer correspondence.
Why This Works
Separating the three legs removes the possibility of laundering one through another. When purpose, tool and data are considered as a single impression, a strong leg carries the weak ones, and purpose is almost always the strong leg. When they are checked separately, a failing leg stays visible.
Classifying the most sensitive element rather than the general character does the rest. Material is not sensitive on average. One line in a ten-page document determines its handling, and that line is usually the reason someone needed help with the document in the first place.
Worked example 2 of 3Optional depth
Jo Halvorsen at OmniCorp Studio wanted a résumé reformatted for a subcontractor she was proposing to a client. Data class: a named individual's contact details and employment history. Tool and account: the practice account, approved. Purpose: preparing a client proposal, approved. Two legs held; the data leg did not, because personal data of a third party was never in scope for that approval. She asked the subcontractor to send a version with contact details removed, reformatted that, and reattached the details herself. Ninety seconds of friction, no personal data transferred.
Worked example 3 of 3Optional depth
Marisa Delgado at OmniCorp Financial discovered that an approved assistant had been connected to a shared drive by a well-meaning administrator so it could answer questions about internal procedure. The tool leg had been approved months earlier without any integration. The new connection meant the tool now had reach into folders containing customer correspondence, and no approval covered that. Nobody had done anything prohibited. The integration had silently changed one leg of every match anybody had run since.
Edge Cases and NuancesOptional depth
Redaction is weaker than it feels: a record stripped of names can still identify a person through dates, amounts and sequence, particularly in a small population. Fabricating a structurally similar example is safer than redacting a real one. Screenshots carry more than the visible content, including window titles, adjacent records and the identity of the person logged in. And material that is already public may still be restricted by contract rather than by sensitivity, which is a leg that classification alone will never catch.
A legitimate purpose is treated as evidence that the data movement is acceptable.
- Intent Laundering
- A legitimate purpose is treated as evidence that the data movement is acceptable.
- Three-Way Match
- Each leg is checked independently; a failing leg stops the task regardless of purpose.
Knowledge check
A support agent wants to paste a customer ticket into an approved AI tool to draft a response. The ticket contains a complaint naming a specific employee. The tool is approved for drafting customer communications. Does the match hold?
Common Failure Modes
The match end to end
Dr. Naomi Ellery at OmniCorp Health was asked whether clinicians could use an approved assistant to help draft referral letters. The purpose was strong: referral letters were consuming four hours of clinician time a week and were frequently late, which delayed patients.
Data class: clinical history of an identified patient, the most sensitive class the organisation holds. Tool and account: the enterprise assistant on the clinical tenancy, in region, with training on inputs contractually disabled. Purpose: producing a clinical document that becomes part of the patient record. Two legs held. The purpose leg failed, because the existing approval covered administrative correspondence, not the production of clinical record content.
Naomi did not overrule it and did not abandon it. She scoped a narrower use that matched on all three legs, drafting the non-clinical sections of the letter from data already in the record, and opened a formal approval request for the clinical sections with the evidence the pilot would need. The narrow use went live in nine days. The broad one went through review and took eleven weeks. Both outcomes were correct.
Decision point
Alan Brixmoor at OmniCorp Public receives an urgent request: a citizen's benefits case is being escalated to a minister's office, and a colleague wants to paste the full case file into the approved assistant to produce a chronology by end of day. The tool is approved. The purpose is genuine and urgent. What do you do?
Self-check
Mark the level that describes you today. Nothing is submitted.
| Behaviour | Ready | Developing | Not yet |
|---|---|---|---|
| Checking the legs separately | |||
| Classifying material | |||
| Responding to a failed leg |
Commit
Commit Statement
Complete every line in your own words, then sign and date it. The test of this one is what you do the next time someone is stuck and in a hurry.
| Window | Field application |
|---|---|
| Days 1 to 7 | Run the three-way match before every AI task for a week. Note every occasion a leg failed and what you did instead. |
| Days 8 to 21 | Establish the region, retention and training terms of the account you actually use. Write them down where your team can see them. |
| Days 22 to 30 | Audit the integrations connected to your approved tools and re-run the match against what they can now reach. |
The three-way match protects the decisions you personally make. It does not build the data classification scheme, the tool approval register, the contractual review or the integration inventory that let an organisation answer these questions without relying on individual discipline. Constructing that apparatus is the capability the paid programs develop next.