30 Days Gen AI Risk Trial -Start Now
Skip to main content

AI security decision guides

A clear next step for
sensitive work with AI.

Practical answers, source-backed decisions and useful examples for the people protecting employee AI use.

60 guides available

30 guides

Compliance decisions

Apply the right obligations to a specific employee AI use.

C01

ChatGPT and HIPAA: plans, BAAs and features

Compare the dated OpenAI plan and feature conditions for PHI, then match the applicable BAA, workspace and safeguards. Includes a populated review pack.

C02

De-identifying patient notes before AI

Compare HIPAA Safe Harbor, Expert Determination and ordinary masking with an annotated synthetic patient note and a downloadable review worksheet.

C03

HIPAA minimum necessary for AI prompts

Decide how much patient information an approved AI task needs, with a worked minimum-data worksheet and the treatment exceptions explained.

C04

HIPAA AI audit evidence and retention

Separate AI security events, PHI access records and required HIPAA documentation before setting retention. Includes a record-type review matrix.

C05

PHI sent to AI: assess the HIPAA breach

Use the HIPAA four-factor assessment to investigate a patient-data submission to an AI service, preserve facts and assign notification decisions.

C06

42 CFR Part 2: AI records and consent

Check Part 2 record scope, consent, SUD counselling notes and redisclosure before an AI service receives patient information. Includes a decision worksheet.

C07

ChatGPT DPIA: a worked employee-use example

A worked DPIA for staff rewriting customer-support text with ChatGPT, including data flows, alternatives, residual risks and responsible roles.

C08

ChatGPT DPA: a clause-by-clause review

Review OpenAI DPA v.010126 against a ChatGPT Enterprise use, with clause positions, operational consequences and a populated buyer worksheet.

C09

Special-category data in AI prompts

Review GDPR Articles 6 and 9 before staff upload health, union or other special-category data to AI. Includes a synthetic decision map.

C10

GDPR deletion requests for AI chats and files

Trace an erasure request across AI conversations, uploaded files, saved memories and exported copies. Includes a data-location and evidence checklist.

C11

PCI DSS: card data in AI

Separate cardholder data from sensitive authentication data before staff copy payment details into AI. Includes synthetic classification cases and review steps.

C12

GLBA checks for AI vendors

Assess an AI provider receiving customer information under the FTC Safeguards Rule, with a worked service-provider oversight worksheet.

C13

When an AI leak needs FTC review

Apply the FTC Safeguards Rule’s acquisition test, 500-consumer threshold and notification timing to a fictional employee AI disclosure.

C14

FERPA’s school-official exception for AI

Review institutional purpose, direct control, legitimate educational interest and redisclosure before an AI provider receives student records.

C15

IEPs and student support plans in AI

Decide which student-support details a permitted AI task actually needs, with a synthetic IEP field map and reduced-input examples.

C16

SOX evidence for AI during financial close

Connect an employee’s AI-assisted close task to source records, review evidence and existing controls, with a synthetic financial-close packet.

C17

FINRA: oversee staff use of AI

Map employee AI uses to evaluation, supervisory procedures, communications review and escalation, with a populated operational worksheet.

C18

When are AI prompts FINRA business records?

Classify AI prompts, drafts, communications and review evidence by business purpose before choosing retention and an archive handoff.

C19

AI data leaks under Reg S-P

Add employee AI disclosures to the customer-information incident response plan, with a worked Regulation S-P insert and distinct notice responsibilities.

C20

DORA register: an AI supplier worked example

Map an employee AI supplier to contracts, legal entities, services and functions using a populated DORA register teaching example and linked CSV files.

C21

DORA AI supplier contracts: what to check

Compare AI supplier contract terms with DORA’s general and critical-function requirements, using a populated gap and negotiation matrix.

C22

NIS2 supplier checks for employee AI

Build a jurisdiction and supplier-risk dossier before staff adopt an AI service, with a worked example and explicit national-law questions.

C23

Does an AI vendor’s ISO 27001 scope cover you?

Read a synthetic ISO 27001 certificate and verify the legal entity, service scope, issuer, accreditation and validity before relying on it.

C24

Read an AI vendor’s SOC 2 report

Use an annotated synthetic SOC 2 Type 2 report to examine scope, period, opinion, test exceptions, subservice exclusions and customer responsibilities.

C25

AI data leaks: Australia's NDB rules

Assess likely serious harm, remedial action and notification under Australia’s NDB scheme, using a worked synthetic decision and evidence timeline.

C26

GDPR: can this AI input identify someone?

Use linked-identifier examples to assess whether people remain identifiable after a transformation, with a separate synthetic linkage key and recipient-context review.

C27

ISO 27001 evidence for employee AI DLP

Build a scoped control-test packet with synthetic inputs, expected outcomes, evidence fields and reviewer decisions without inferring ISO certification.

C28

Can CUI go into an AI assistant?

Review the defence contract, information category, cloud service and CMMC boundary before an AI assistant or security intermediary receives CUI.

C29

ITAR technical data in AI: map the recipients

Map technical-data classification, plaintext access, recipients, locations and keys before an AI service receives engineering material.

C30

Employee AI chats under US legal hold

Prepare a preservation handoff for relevant AI chats, files and exports before routine deletion, with synthetic custodians, scope and conflict examples.

20 guides

Developer data protection

Keep code, secrets and debugging context within an intentional boundary.

D01

Protect company data in AI coding

Map developer AI data paths, choose supported controls and plan a scoped pilot using synthetic code, secret, log and context markers.

D02

Choose the code you share with AI

Decide what employer-owned code a developer can share with AI, then prepare a minimal useful snippet using synthetic examples.

D03

Check every Cursor access path

Test Cursor context, file, terminal and MCP access with isolated canaries. Record the client, mode and outcome without using real secrets.

D04

Review Cursor CLI as a new client

Review what changes when an approved Cursor IDE gains a CLI client. Compare account, policy, configuration and execution boundaries.

D05

Keep secrets out of Claude Code context

Review Claude Code file and shell permissions with fake-secret fixtures. Keep documented controls separate from observed test results.

D06

Review secrets in the local Codex CLI

Review local Codex CLI file reads and inherited environment data using synthetic markers and current permission documentation.

D07

Check Copilot exclusions by mode

Check GitHub Copilot content exclusions by editor, mode and repository location, including indirect context and documented limits.

D08

Prepare logs for AI debugging

Prepare a useful AI debugging excerpt from synthetic machine logs while removing unnecessary credentials and customer identifiers.

D09

Review Claude Code support uploads

Review Claude Code feedback, diagnostic uploads and session-sharing choices, with a concrete payload and retention checklist.

D10

Cursor Privacy Mode and company code

Understand Cursor Privacy Mode across code transfer, provider retention, training and Cloud Agents using a dated review matrix.

D11

Choose the right Claude Code account

Compare Claude Code account and sign-in data policies for company code, including training preferences, retention and separate feedback sharing.

D12

Review Codex repository access by location

Review local and hosted Codex repository access with a clear record of identity, source-system grants, data paths and approval scope.

D13

Follow the code beyond your API key

Trace who receives code and credentials when an AI coding tool uses your API key or a gateway, with a concrete recipient worksheet.

D14

Identify the index before retiring access

Identify repository-derived indexes and context before reviewing disconnection, deletion evidence and unresolved retention.

D15

Review Cursor cloud secrets

Choose Cursor Cloud Agent secret types and review what enters saved environments, transcripts and snapshots using only synthetic values.

D16

Separate setup secrets from agent variables

Separate Codex cloud setup secrets from variables available during the agent phase, with a safe fake-value verification procedure.

D17

Protect MCP keys and tokens

Review MCP credential storage, configuration exports, transcripts and retirement using synthetic examples and a lifecycle checklist.

D18

Debug SQL with a synthetic database

Reproduce a SQL aggregation issue with a small synthetic SQLite dataset, working constraints and verified expected query outputs.

D19

Locate Remote SSH and container controls

Map where code, tools and credentials run during Remote SSH or dev-container work before reusing a local AI control result.

D20

Can you send client code to AI?

Review a client’s permission to use source code with AI under the governing contracts, and prepare a clean synthetic alternative.

10 guides

Everyday AI data handling

Review the files, connections and sharing actions employees actually use.

U01

Review screen captures before AI use

Review visible identifiers, fake tokens and small text in synthetic screenshots before sharing an image with an AI assistant.

U02

Check the data behind your slides

Inspect a real synthetic PowerPoint deck for speaker notes, a hidden slide and embedded chart data, then compare its reviewed counterpart.

U03

Review AI browser add-on access

Review an AI browser extension’s declared permissions and site scope using a concrete, inert approved-host example.

U04

Review DeepL before sending a document

Compare DeepL plan and translation-route data terms before sending confidential documents, using a safe synthetic input.

U05

Check who can open the chat link

Review the audience of an AI conversation link and verify access with synthetic content before sharing company information.

U06

Review files that stay in an AI project

Review shared AI project files, collaborators, reuse and ordinary removal separately from a one-off chat attachment.

U07

Set ChatGPT app access before linking data

Configure supported ChatGPT Work app action controls and permission prompts, then plan a synthetic least-privilege verification.

U08

Review AI drafts of security answers

Prepare security-questionnaire answers from approved sources while keeping confidential evidence within its authorised audience.

U09

Keep new ideas private during AI research

Separate public research background from unpublished invention detail before using an AI assistant for patent-related research.

U10

Review an AI screen-sharing session

Review continuous AI screen-sharing scope, notifications and stop controls using a synthetic session-state exercise.

Looking for broader policy templates or a complete industry introduction?

Explore the template library Read industry guides
AI Security Decision Guides: Compliance, Developers and Data | Aona