30 Days Gen AI Risk Trial -Start Now
Skip to main content

Everyday AI data handling

Review screen captures before AI use

Treat a screenshot as a disclosure of everything visible in its pixels, including small text, URLs, identifiers and console details. Prepare the minimum image needed for the question, remove unnecessary sensitive content using an approved workflow, then reopen the actual exported file. A picture format does not make readable company information harmless to share.

For IT security and customer-facing teams

Aona field notesU01
Static image review
The edges count too

Check the URL, side panels and small text as well as the main message.

Code-native fictional interface. All identifiers and token-like strings are fake; no OCR or endpoint-enforcement result is asserted.

01

Define what the assistant needs to see

Start with the question the image should answer. If the task concerns an error message, the entire desktop or customer record may be unnecessary. Choose a view that preserves the useful error and surrounding context without unrelated information.

The download uses a fictional helpdesk screen. Its reporter address, request identifier and bearer-style marker are all synthetic. The example shows why a useful troubleshooting screenshot can contain several different disclosure decisions even when the main error text seems innocuous.

02

Inspect the whole image at useful resolution

Review browser or application chrome, address bars, account labels, tabs, side panels, tooltips and console output. Small text may be readable to people or image-capable tools. Do not rely on a reduced thumbnail to decide that a value cannot be recovered from the full image.

In the source example, the top URL contains a case marker, the main panel includes a reporter and request marker, and the console includes a fake token. The prepared version removes those known values while retaining the error, stack frames and a consistent request placeholder.

Inspect the whole image at useful resolution
Image areaSynthetic source detailPrepared example
Top toolbarCase marker in the URLGeneric prepared-excerpt label
Main recordExample email and request identifierNeutral placeholders
ConsoleFake bearer-style tokenUnnecessary line removed
Error and stackMissing quantity and two framesRetained for the question

03

Prepare and inspect the exported copy

Use the organisation’s approved image-handling method to remove unnecessary pixels or capture a narrower clean view. Keep enough context for the task to remain understandable. A decorative overlay or light blur should not be treated as a guarantee that text is no longer readable.

Reopen the exact raster file you plan to attach and inspect it at full resolution. Check that you have selected the prepared copy rather than the original. If you keep an editable source document or presentation, review that file separately because its underlying layers and embedded material are a different task.

04

Resolve the remaining disclosure decision

A clean-looking image may still reveal customer circumstances, internal routes or business information that the task does not require. Record who permits the remaining material to be sent to the selected service and account. Removing an identifier is not the same as obtaining permission for the content.

OAIC guidance recommends reviewing privacy risks and suitability before entering personal information into AI products. Apply the organisation’s own obligations to the actual data and service. The synthetic example illustrates preparation and review; it does not certify an arbitrary screenshot as anonymous or legally shareable.

Source context: OAIC: Use of commercially available AI products

05

Keep image preparation separate from control coverage

Confirm the exact upload or paste path if an endpoint policy is part of the workflow. A text-prompt test does not establish image analysis or OCR coverage, and a supported document format does not establish screenshot-redaction support.

Use the downloadable image pair and review key for training with fake content only. The images were created from a synthetic interface and visually checked; no AI service or Aona protection test is claimed. Live screen sharing introduces changing content and session controls, which belong in the separate guide.

Put it into practice

Synthetic screenshot review pair

Compare the original pixels with a prepared copy and identify what was removed or retained.

Code-native fictional interface. All identifiers and token-like strings are fake; no OCR or endpoint-enforcement result is asserted.

Synthetic helpdesk screenshot with a case URL, example email, request marker and fake token
Original synthetic image: review the URL, identifiers and console text. Every value is fictional.View full-size example
Prepared synthetic helpdesk screenshot with known identifiers and fake token removed
Prepared counterpart: known exercise values removed, error and stack context retained. This is not a general redaction test.View full-size example
Known changes in the example
01

Removed

Case URL marker, reporter address and fake token

See the review key

02

Preserved

Error, two stack frames and request relationship

Enough context for the question

03

Still to decide

Permission and supported upload path

No real-service test performed

Synthetic screenshot review pair
CheckLook forDecision
Peripheral contentURLs, account labels and side panelsNeeded for the question?
Small textConsole values and identifiersRemove unnecessary disclosure
Prepared copyThe exact exported imageInspect again at full resolution

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

README.mdInspect
# Static screenshot exercise

Both images show a fictional interface and contain no real company data. The raw image includes deliberate fake identifiers and a non-working token-like marker. No live screen, account or AI service was accessed.

Compare screenshot-before.png with screenshot-reviewed.png at full resolution. Use review-key.csv to find the known changes, then complete screenshot-review.md. The prepared image was rendered from the intended clean content, not produced by a general redaction engine. Do not treat this pair as proof that arbitrary blurring or an endpoint product removes image data.

## Guide and sources

Canonical guide: https://aona.ai/resources/guides/company-screenshots-ai-data-leaks/
Source review: 2026-09-21
- OAIC: Use of commercially available AI products: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
Download README.md
screenshot-before.pngInspect
screenshot-reviewed.pngInspect
review-key.csvInspect
area,source_example,prepared_example,purpose
Toolbar,SYNTHETIC_U01_CASE_014,Prepared excerpt,Remove case-specific URL
Reporter,alex@example.invalid,[IDENTIFIER REMOVED],Remove unnecessary identifier
Request,SYNTHETIC_U01_REQUEST_021,[REQUEST 1],Preserve correlation without original marker
Console,NOT_A_TOKEN_U01_7K9,Line removed,Remove fake credential-like detail
Error,ValueError and two stack frames,Retained,Preserve debugging context
Download review-key.csv
screenshot-review.mdInspect
# Image disclosure review

Question the image must answer: ____________________
Minimum useful view: ____________________
Peripheral and small-text findings: ____________________
Pixels removed or clean view recaptured: ____________________
Exact exported filename reopened: ____________________
Remaining content owner/account approval: ____________________
Intended input-path coverage: UNVERIFIED
Decision: NOT YET REVIEWED
Download screenshot-review.md

Before you proceed

Keep these distinctions clear

Reviewing only a thumbnail
The original image can retain readable detail that is invisible at a reduced preview size.
Attaching the original by mistake
Reopen and identify the actual prepared file before sharing it.

Apply it to employee AI use

Bring your actual data path.

Aona can help evaluate policy outcomes on supported employee prompt and file paths.

This topic does not establish automatic screenshot OCR, image redaction or coverage of every image input. Confirm the exact supported route.

Use the synthetic image pair to discuss the required control and whether the selected endpoint path can meet it.

Review your use case

FAQ

Questions for this decision

Is a screenshot safer simply because the information is not plain text?
No. Visible pixels can contain readable text and identifying context. Review the whole image and the selected recipient rather than relying on the file type.
Does the prepared example prove blur is safe?
No. The prepared image was rendered with known example fields removed. It is a training counterpart, not a test of blurring, an OCR engine or a general sanitizer.
Can Aona redact every screenshot sent to AI?
Do not infer that from this guide. Confirm the exact client, image input route and supported policy action. Text or document coverage does not automatically establish image coverage.
Does this checklist cover continuous screen sharing?
No. It covers a static image file. A live session can expose new windows and notifications after it starts and needs its own sharing and stop-control review.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. OAIC: Use of commercially available AI products

    Explains suitability and privacy review for personal information supplied to AI.

    regulator · checked 2026-09-21
Company screenshots and AI data exposure