Put AI to work responsibly · Part 2 of 4 · 2 min read
Before your team pastes data into AI.
Check the exact product, training terms, retention, permissions, and meeting consent before approving a tool.
Approve a product and a use case, not a brand.
The same vendor may offer consumer accounts, business workspaces, developer APIs, and connected agents under different terms. A “no training” commitment does not by itself answer retention, access, logging, or where data is processed.
Before approving a tool, record these six answers from its current documentation and your agreement:
- Product and account: which tier, workspace, and identity will employees actually use?
- Input: which data categories may be submitted, by whom, and for which tasks?
- Processing: what are the training-use rules, retention periods, deletion options, and relevant exceptions?
- Access: who can see prompts, files, outputs, shared links, and administrator logs?
- Connections: which applications can the tool read or change, and how is that access revoked?
- Evidence: who reviewed the terms, on what date, and when will the decision be revisited?
Keep a link or copy of the applicable terms with the decision. Do not use a screenshot of a training toggle as the entire vendor review.
For a small trial, use non-sensitive material first. Test whether the output is useful before requesting access to a larger or more sensitive dataset.
Check the permissions people can actually grant.
Review application consent and integrations in your workspace. An approved chatbot and an assistant with permission to read mail, join meetings, or edit records create different risks.
- Meeting tools: establish who may invite them, how participants are informed, what consent is required, and who receives the recording or transcript. Confirm legal requirements for the actual meeting.
- Connectors: grant the smallest useful scope. Test whether inherited document permissions survive retrieval and sharing.
- Actions: require explicit authorization and appropriate review before sending, publishing, deleting, or making financial changes.
- Offboarding: remove tokens and delegated access, not just the employee's visible account.
Use the Microsoft 365 or Google Workspace checklist with an administrator. Record what you observed in your tenant rather than relying on a claim about a universal default.
Edited September 29, 2026. Research and source dates are retained; this edit is not a fresh review of every statistic or legal development.
