The risk starts before the prompt is sent
Teams often encounter AI through an individual task: summarising a document, preparing a draft, or researching a question. In a regulated or commercially sensitive environment, the more important question comes first: what information is appropriate to use in that workflow, under what controls, and with whose approval?
Copying proprietary material into a general-purpose service can create avoidable uncertainty about retention, access, jurisdiction, contractual terms, and future use of the information. The right approach depends on the organisation's data classification, chosen providers, configuration, and applicable obligations.
Design the data path deliberately
A sound design starts with the information itself. Teams can classify the material, define approved sources, limit access to the people and systems that need it, and decide how inputs and outputs will be retained and reviewed. Where a task involves sensitive evidence, the workflow should make the data boundary and accountable owner clear.
The technical controls matter, but so do the operational ones. A policy that nobody can follow in daily work is not a useful safeguard.
Questions to resolve before deployment
- What types of information may enter this workflow?
- Which provider, environment, and contractual terms apply?
- Who can access the inputs, outputs, and activity records?
- Which uses need legal, security, privacy, quality, or scientific review?
- How will the team respond when an input or output falls outside the approved boundary?
Interactive Prototype
Interactive VantagePoint prototype
Explore a legacy sandbox that illustrates a controlled data-routing pattern using representative example inputs.
This legacy sandbox illustrates a controlled routing concept using representative example inputs. It is an interface prototype, not a representation of a configured client environment.
The Lonrú view
Good AI governance does not begin with a generic prohibition. It begins with a practical design that helps people use the right information in the right environment for a clearly defined purpose.
If you need to design a safer AI workflow for proprietary information, start a conversation.
Continue the conversation
Bring the signal into a working session.
Explore how the same thinking can map to a specific scientific, commercial, or operating decision.
Start a conversation