FourWindsDigital

Acceptable AI use

What may and may not go into an AI tool, and who is responsible for what comes out.

Version 2026-09-10.1Updated 10 September 2026

This applies to any AI tooling we set up, manage or recommend. It exists because the most expensive AI incidents are not technical failures; they are somebody pasting the wrong thing into a chat box.

Do not put these into an AI tool

  • Passwords, API keys, tokens or any other credential.
  • Payment card numbers or full bank details.
  • Special-category personal data (health, biometrics, ethnicity, religion, sexual orientation, trade union membership) unless a documented assessment says otherwise.
  • Material covered by a confidentiality agreement that does not permit it.
  • Anything you would not be able to explain putting there.

Business plans, not personal ones

Your people should be on business or enterprise tiers, because those carry contractual terms about training and personal subscriptions do not. You buy those from the vendor on your own account; we do not sell, resell or administer anybody's seats. Someone using a personal subscription for work is outside those terms, and that is a data protection issue rather than a preference.

Output is a draft

Every model produces confident wrong answers. Anything acted on, published or sent to a customer must be reviewed by a person who is competent to judge it. Where output is used in a decision affecting an individual, a person must make that decision.

Where the EU AI Act applies

Some uses carry obligations beyond data protection, particularly anything touching recruitment, credit, or access to services. Tell us before you deploy into those areas so the classification is done first.

Telling us when it goes wrong

If something confidential has gone into a tool, tell us the same day. Containment gets harder by the hour and nobody is in trouble for reporting quickly.