AI Prompt Engineering
Guidelines
Security-focused prompt engineering guidelines for enterprise teams. Covers safe prompting practices, data leakage prevention, prompt injection awareness, output validation, and approved prompt templates for common business tasks.
Why Enterprise Prompt Engineering Guidelines Matter
Employees use AI tools every day to process business information. Without guidance on safe prompting, the default behaviour is to paste whatever data is relevant into the prompt, including PII, confidential client data, and credentials.
The Guidelines
Click each section to expand the guideline content. Share this with your teams and embed it in your AI acceptable use policy.
Safe prompting means providing AI tools with the context they need to do the task, and nothing more. The context window is not a secure container; its contents may be logged, retained, and exposed in future outputs.
Must NEVER be included in any AI prompt:
- Personal Identifiable Information (PII), names, addresses, National Insurance/SSN, dates of birth, financial account numbers
- Credentials, API keys, passwords, authentication tokens, secrets of any kind
- Confidential business information, unpublished financials, M&A activity, pricing strategy, competitive intelligence
- Client or customer data subject to confidentiality agreements or data processing agreements
- Source code for production systems unless the tool is explicitly approved for code use and contains no secrets
- Data classified as Restricted under your data classification policy
Context Window & Memory Considerations
- Assume everything in the context window may be logged by the AI provider, even in enterprise tiers
- Multi-turn conversations accumulate context: earlier messages containing sensitive data remain in context throughout the session
- AI tools with memory or persistent context carry information between sessions, never rely on data being forgotten
- When using RAG (retrieval-augmented generation), data retrieved from external sources is inserted into the context window and subject to the same rules as directly entered data
How to Implement These Guidelines
Follow these five steps to go from guidelines template to organisation-wide enforcement within 30 days.
FAQ
Frequently Asked Questions
What is prompt injection and why does it matter for enterprises?
What data should never be included in an AI prompt?
When does AI output require human review before use?
How do I test a prompt for security vulnerabilities?
Enforce Prompt Guidelines in Real Time
Aona enforces prompt engineering policies in real time, detecting sensitive data in AI prompts before it reaches the model, blocking prompt injection patterns, and logging all AI interactions for compliance evidence.