AI security decision guides
A clear next step for
sensitive work with AI.
Practical answers, source-backed decisions and useful examples for the people protecting employee AI use.
60 guides available
30 guides
Compliance decisions
Apply the right obligations to a specific employee AI use.
ChatGPT and HIPAA: plans, BAAs and features
Compare the dated OpenAI plan and feature conditions for PHI, then match the applicable BAA, workspace and safeguards. Includes a populated review pack.
De-identifying patient notes before AI
Compare HIPAA Safe Harbor, Expert Determination and ordinary masking with an annotated synthetic patient note and a downloadable review worksheet.
HIPAA minimum necessary for AI prompts
Decide how much patient information an approved AI task needs, with a worked minimum-data worksheet and the treatment exceptions explained.
HIPAA AI audit evidence and retention
Separate AI security events, PHI access records and required HIPAA documentation before setting retention. Includes a record-type review matrix.
PHI sent to AI: assess the HIPAA breach
Use the HIPAA four-factor assessment to investigate a patient-data submission to an AI service, preserve facts and assign notification decisions.
42 CFR Part 2: AI records and consent
Check Part 2 record scope, consent, SUD counselling notes and redisclosure before an AI service receives patient information. Includes a decision worksheet.
ChatGPT DPIA: a worked employee-use example
A worked DPIA for staff rewriting customer-support text with ChatGPT, including data flows, alternatives, residual risks and responsible roles.
ChatGPT DPA: a clause-by-clause review
Review OpenAI DPA v.010126 against a ChatGPT Enterprise use, with clause positions, operational consequences and a populated buyer worksheet.
Special-category data in AI prompts
Review GDPR Articles 6 and 9 before staff upload health, union or other special-category data to AI. Includes a synthetic decision map.
GDPR deletion requests for AI chats and files
Trace an erasure request across AI conversations, uploaded files, saved memories and exported copies. Includes a data-location and evidence checklist.
PCI DSS: card data in AI
Separate cardholder data from sensitive authentication data before staff copy payment details into AI. Includes synthetic classification cases and review steps.
GLBA checks for AI vendors
Assess an AI provider receiving customer information under the FTC Safeguards Rule, with a worked service-provider oversight worksheet.
When an AI leak needs FTC review
Apply the FTC Safeguards Rule’s acquisition test, 500-consumer threshold and notification timing to a fictional employee AI disclosure.
FERPA’s school-official exception for AI
Review institutional purpose, direct control, legitimate educational interest and redisclosure before an AI provider receives student records.
IEPs and student support plans in AI
Decide which student-support details a permitted AI task actually needs, with a synthetic IEP field map and reduced-input examples.
SOX evidence for AI during financial close
Connect an employee’s AI-assisted close task to source records, review evidence and existing controls, with a synthetic financial-close packet.
FINRA: oversee staff use of AI
Map employee AI uses to evaluation, supervisory procedures, communications review and escalation, with a populated operational worksheet.
When are AI prompts FINRA business records?
Classify AI prompts, drafts, communications and review evidence by business purpose before choosing retention and an archive handoff.
AI data leaks under Reg S-P
Add employee AI disclosures to the customer-information incident response plan, with a worked Regulation S-P insert and distinct notice responsibilities.
DORA register: an AI supplier worked example
Map an employee AI supplier to contracts, legal entities, services and functions using a populated DORA register teaching example and linked CSV files.
DORA AI supplier contracts: what to check
Compare AI supplier contract terms with DORA’s general and critical-function requirements, using a populated gap and negotiation matrix.
NIS2 supplier checks for employee AI
Build a jurisdiction and supplier-risk dossier before staff adopt an AI service, with a worked example and explicit national-law questions.
Does an AI vendor’s ISO 27001 scope cover you?
Read a synthetic ISO 27001 certificate and verify the legal entity, service scope, issuer, accreditation and validity before relying on it.
Read an AI vendor’s SOC 2 report
Use an annotated synthetic SOC 2 Type 2 report to examine scope, period, opinion, test exceptions, subservice exclusions and customer responsibilities.
AI data leaks: Australia's NDB rules
Assess likely serious harm, remedial action and notification under Australia’s NDB scheme, using a worked synthetic decision and evidence timeline.
GDPR: can this AI input identify someone?
Use linked-identifier examples to assess whether people remain identifiable after a transformation, with a separate synthetic linkage key and recipient-context review.
ISO 27001 evidence for employee AI DLP
Build a scoped control-test packet with synthetic inputs, expected outcomes, evidence fields and reviewer decisions without inferring ISO certification.
Can CUI go into an AI assistant?
Review the defence contract, information category, cloud service and CMMC boundary before an AI assistant or security intermediary receives CUI.
ITAR technical data in AI: map the recipients
Map technical-data classification, plaintext access, recipients, locations and keys before an AI service receives engineering material.
Employee AI chats under US legal hold
Prepare a preservation handoff for relevant AI chats, files and exports before routine deletion, with synthetic custodians, scope and conflict examples.
20 guides
Developer data protection
Keep code, secrets and debugging context within an intentional boundary.
Protect company data in AI coding
Map developer AI data paths, choose supported controls and plan a scoped pilot using synthetic code, secret, log and context markers.
Choose the code you share with AI
Decide what employer-owned code a developer can share with AI, then prepare a minimal useful snippet using synthetic examples.
Check every Cursor access path
Test Cursor context, file, terminal and MCP access with isolated canaries. Record the client, mode and outcome without using real secrets.
Review Cursor CLI as a new client
Review what changes when an approved Cursor IDE gains a CLI client. Compare account, policy, configuration and execution boundaries.
Keep secrets out of Claude Code context
Review Claude Code file and shell permissions with fake-secret fixtures. Keep documented controls separate from observed test results.
Review secrets in the local Codex CLI
Review local Codex CLI file reads and inherited environment data using synthetic markers and current permission documentation.
Check Copilot exclusions by mode
Check GitHub Copilot content exclusions by editor, mode and repository location, including indirect context and documented limits.
Prepare logs for AI debugging
Prepare a useful AI debugging excerpt from synthetic machine logs while removing unnecessary credentials and customer identifiers.
Review Claude Code support uploads
Review Claude Code feedback, diagnostic uploads and session-sharing choices, with a concrete payload and retention checklist.
Cursor Privacy Mode and company code
Understand Cursor Privacy Mode across code transfer, provider retention, training and Cloud Agents using a dated review matrix.
Choose the right Claude Code account
Compare Claude Code account and sign-in data policies for company code, including training preferences, retention and separate feedback sharing.
Review Codex repository access by location
Review local and hosted Codex repository access with a clear record of identity, source-system grants, data paths and approval scope.
Follow the code beyond your API key
Trace who receives code and credentials when an AI coding tool uses your API key or a gateway, with a concrete recipient worksheet.
Identify the index before retiring access
Identify repository-derived indexes and context before reviewing disconnection, deletion evidence and unresolved retention.
Review Cursor cloud secrets
Choose Cursor Cloud Agent secret types and review what enters saved environments, transcripts and snapshots using only synthetic values.
Separate setup secrets from agent variables
Separate Codex cloud setup secrets from variables available during the agent phase, with a safe fake-value verification procedure.
Protect MCP keys and tokens
Review MCP credential storage, configuration exports, transcripts and retirement using synthetic examples and a lifecycle checklist.
Debug SQL with a synthetic database
Reproduce a SQL aggregation issue with a small synthetic SQLite dataset, working constraints and verified expected query outputs.
Locate Remote SSH and container controls
Map where code, tools and credentials run during Remote SSH or dev-container work before reusing a local AI control result.
Can you send client code to AI?
Review a client’s permission to use source code with AI under the governing contracts, and prepare a clean synthetic alternative.
10 guides
Everyday AI data handling
Review the files, connections and sharing actions employees actually use.
Review screen captures before AI use
Review visible identifiers, fake tokens and small text in synthetic screenshots before sharing an image with an AI assistant.
Check the data behind your slides
Inspect a real synthetic PowerPoint deck for speaker notes, a hidden slide and embedded chart data, then compare its reviewed counterpart.
Review AI browser add-on access
Review an AI browser extension’s declared permissions and site scope using a concrete, inert approved-host example.
Review DeepL before sending a document
Compare DeepL plan and translation-route data terms before sending confidential documents, using a safe synthetic input.
Check who can open the chat link
Review the audience of an AI conversation link and verify access with synthetic content before sharing company information.
Review files that stay in an AI project
Review shared AI project files, collaborators, reuse and ordinary removal separately from a one-off chat attachment.
Set ChatGPT app access before linking data
Configure supported ChatGPT Work app action controls and permission prompts, then plan a synthetic least-privilege verification.
Review AI drafts of security answers
Prepare security-questionnaire answers from approved sources while keeping confidential evidence within its authorised audience.
Keep new ideas private during AI research
Separate public research background from unpublished invention detail before using an AI assistant for patent-related research.
Review an AI screen-sharing session
Review continuous AI screen-sharing scope, notifications and stop controls using a synthetic session-state exercise.
Looking for broader policy templates or a complete industry introduction?
Explore the template library Read industry guides