โ†
AI for Operations Certification
Aware ยท M13 ยท lesson 13 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Security and Confidentiality in AI-Assisted Operations
๐Ÿ“–
now learning

Security and Confidentiality in AI-Assisted Operations

15 min

Overview

You're in a confidential strategy meeting discussing a potential acquisition. The deal is not yet public. The CEO outlines the target company, the financial terms, the timeline. Two weeks later, you read a news article that mentions specific details of the acquisition that match the meeting discussion. How did the press get this information?

Later, you discover that someone from the meeting used an AI system to help analyze the acquisition. They pasted parts of the deal summary into ChatGPT to get analysis. They asked questions about the financial model. They ran scenarios. They didn't think twice about it. Confidential information went into a third-party AI system and was stored on OpenAI's servers.

Or you work in procurement. You use an AI system to analyze your supply chain and find cost optimization opportunities. The system learns your suppliers, your pricing, your volumes, your cost structures. Competitors would pay good money to know this information. But you've been sending it to a cloud AI system without a confidentiality agreement with the vendor.

Or you're in operations trying to use AI to optimize your internal processes. You describe your process workflows to an AI system to get improvement suggestions. Now the AI system has detailed knowledge of your operational procedures, your cost structure, your bottlenecks, your staffing model. This is proprietary information about how you run your business.

The confidentiality risk of AI is different from data privacy risk (which we covered earlier). Privacy is about protecting personal information and complying with regulations. Confidentiality is about protecting your company's secrets: competitive information, financial details, strategic plans, proprietary processes, vendor relationships.

This lesson covers the confidentiality risks in using AI systems for operations, how to identify what information is actually sensitive, how to use AI without exposing confidential information, and how to manage shadow AI (the tools people use secretly) which is often the highest confidentiality risk.

What Counts as Confidential Operational Information

Operations professionals deal with information that's often confidential: vendor contracts, pricing, supplier relationships, cost structures, internal processes, financial performance, strategic plans, upcoming changes, employee compensation data. This information has value. Competitors would benefit from knowing it. Vendors would benefit from knowing you're evaluating alternatives. Employees would benefit from knowing salary ranges. The public would benefit from knowing about upcoming layoffs or facility closures before they happen.

Confidentiality obligations come from multiple sources:

1. Contractual Confidentiality

You have contracts with vendors, customers, and partners that include confidentiality clauses. These clauses say you can't disclose their information to third parties without consent. When you send vendor contract data to an AI system, you're potentially violating these clauses. The vendor didn't consent to OpenAI knowing their pricing or terms.

2. Business Confidentiality

Information about how your business operates is confidential. Your supply chain structure, your cost model, your processes, your staffing, your financial performance. This information is valuable and should be kept within your organization.

3. Legal Confidentiality

Information subject to attorney-client privilege (advice from lawyers), work product (analysis created for litigation), trade secrets (formulae, algorithms, processes that give you competitive advantage). This information often has specific legal protection.

4. Public Company Confidentiality

If your company is public, certain information (earnings before announcement, M&A plans, material events) is subject to securities law restrictions. You can't publicly discuss non-public material information. Sending that information to an AI system that stores it on cloud servers is risky.

The common thread: if the information is valuable to competitors or if you have a contractual obligation to keep it confidential, don't send it to an uncontrolled third-party AI system.

The "Would a Competitor Pay for This?" Test

Simple heuristic: if a competitor would pay money to know this information, it's confidential. Apply this to operational data. Would a competitor pay to know your suppliers and pricing? Yes. Would they pay to know your cost structure? Yes. Your process bottlenecks? Yes. Your upcoming expansions or consolidations? Absolutely. If yes, it's confidential and you shouldn't send it to uncontrolled AI systems.

How Confidential Information Leaks Through AI Systems

The mechanics of confidentiality breach through AI systems are worth understanding because they're different from traditional data security breaches.

Storage Risk

When you input data into an AI system, the system stores it. Free ChatGPT stores your conversations on OpenAI's servers. OpenAI's policy says they store it temporarily and don't train their model on it (for paid accounts), but it's still stored on their infrastructure. If OpenAI is breached, your data could be exposed. If OpenAI's terms change, your historical data could be retrained into models. You have no control.

Training Risk

Some AI systems explicitly train on user data. If you use a free or personal account, there's a higher risk that your data goes into model training. That means your operational information becomes part of the model's training data. It could potentially be extracted or influence the model's outputs.

Retention Risk

Even if the AI vendor doesn't train on your data, they store it. When do they delete it? How long does it sit on their servers? Many vendors have vague retention policies. Some keep data indefinitely. You have no easy way to verify data deletion.

Access Risk

Who at the AI vendor can access your data? Customer support staff? Engineers? Law enforcement with a subpoena? Most AI vendors have some level of access controls, but employee access is broader than you'd want for confidential information. And law enforcement can compel access.

Inference Risk

Even if your data isn't explicitly exposed, information you send to an AI system can be inferred by others using the system. You ask the AI for analysis of "our acquisition targets." Someone else using the same AI system sees in the public documentation that you're analyzing acquisitions. Competitors might infer what you're analyzing.

This is less of a direct breach and more of an information leakage, but it's real.

Accidental Disclosure Risk

Humans make mistakes. An employee sends confidential data to the wrong AI tool. An employee accidentally shares a conversation that includes confidential information. A consultant or contractor sends data to an AI system they use personally without realizing the data is confidential. These accidents happen frequently.

Shadow AI: The Unmanaged Confidentiality Risk

Shadow AI is the biggest confidentiality risk in most organizations. It's the AI tools that employees use without organizational awareness or oversight.

Typical scenario: an operations analyst discovers ChatGPT. It makes their job easier. They start using it daily for various tasks. They're not sending highly classified information, but they're sending operational data: process descriptions, performance metrics, vendor information, strategic thoughts. They don't go through IT to approve the tool. They don't notify their manager. They just use it because it works.

The organization has no visibility. No one knows what data is going where. There's no data processing agreement with the vendor. There's no oversight. If there's a breach or if confidential information leaks, the organization is exposed but didn't even know the tool was in use.

Shadow AI grows because: (1) the tools are free or cheap and employees can use them personally, (2) they're easy (no IT approval process), (3) they're genuinely useful, and (4) most employees don't think deeply about confidentiality risks.

Managing shadow AI doesn't require banning tools. It requires visibility. Most organizations solve this with an application approval process: teams request approval to use new tools, compliance/security quickly vets them, and the tool gets added to the approved list with clear guidelines on what data can and can't be used with it. Fast approval (1-2 days for most tools) combined with visibility is more effective than bans that employees circumvent.

Shadow AI Governance Process

1. Request Form

Team wants to use a new AI tool. They fill out a form: tool name, vendor, business justification, what data will be processed. This takes 5 minutes. The form creates a record and forces someone to think about what data they're exposing.

2. Quick Review

Compliance/security reviews the form. For non-sensitive tools with no data concerns, approval is automatic (same day). For tools that will touch confidential or personal data, security asks questions: "Does the vendor have a data processing agreement?" "What's their retention policy?" "Are there confidentiality concerns?" Most tools get approved within 1-2 days.

3. Approval with Guardrails

Tool gets approved with specific guidelines. Example: "ChatGPT approved for general operational analysis and writing tasks. Cannot be used for: vendor contracts, pricing data, customer information, strategic plans." This is clear and helps the team self-police.

4. Documentation

Add the approved tool to your list. Communicate to the organization: "ChatGPT is approved for these purposes. If you want to use it for other purposes, request approval." Over time, you build a library of known tools with known restrictions.

5. Periodic Audit

Quarterly, ask the team: "Are you using any AI tools we haven't approved?" or "Are there new tools people want?" This catches new tools early and prevents shadow AI from getting too large.

This process takes minimal overhead and provides visibility. You're not banning anything. You're creating transparency and nudging teams to think about confidentiality before they expose data.

Secure AI Usage Policies

Once you have visibility into AI tools in use, establish clear policies about what data can and can't be sent to them.

1. Classify Your Operational Data

Use a simple classification scheme:

Public: Information that's already public or wouldn't matter if competitors knew. (Process improvements that are widely known, generic operational advice, historical information already disclosed).

Internal: Information that's not public but isn't highly sensitive. (General process descriptions without financial details, organizational structure, non-confidential performance metrics).

Confidential: Information that would be valuable to competitors or has contractual confidentiality restrictions. (Vendor contracts, pricing, cost structures, supplier relationships, upcoming plans, strategic initiatives).

Restricted: Information with special legal protections. (Trade secrets, attorney-client privileged information, non-public financial data, material non-public information for public companies).

2. Create a Data Handling Policy

Example policy:

"Public and Internal data can be sent to any approved AI tool.

Confidential data can be sent only to AI tools with: SOC 2 Type II certification, a signed Data Processing Agreement, and documented confidentiality protections (encryption at rest, no model training on customer data).

Restricted data should not be sent to any external AI tool. If analysis is needed, use internal tools or consult with legal/security about specific approved approaches.

Before sending data to an AI tool, employees should ask: 'How is this data classified? Does this tool handle that classification?'"

3. Train Your Team

A 15-minute training covering: "Here's how we classify data. Here's which tools can handle which classifications. Here's what to do if you want to use a tool with a higher-classification dataset. Here's what not to send to any external AI tool (our vendor contracts, our pricing, our strategic plans)."

Most breaches happen because people don't understand what's sensitive. A simple training prevents 80% of problems.

4. Establish Escalation Paths

"If you want to use an AI tool for data that's confidential or restricted, ask your manager or reach out to security. We can help you figure out if it's okay or find an alternative."

This prevents the situation where someone thinks they can't use a tool and so they just use it secretly.

Secure Prompting Practices

Even when using approved tools, there are practices that reduce confidentiality risk.

1. Anonymize Before Sending

If you need to analyze operational data, remove identifying information before sending to an AI system. Example: instead of "We pay Supplier X $500K per year for widgets," say "A key supplier costs $500K annually for commodities." Instead of "Our COO Sally hired her cousin," say "A manager hired a family member." This reduces the specificity and replaces identifiable details.

2. Use Aggregated Data

Instead of sending detailed transaction data, send summarized metrics. "Our top 20 suppliers represent 60% of our spend, with average contract value of $250K" is less sensitive than individual supplier contracts and pricing.

3. Ask for Analysis, Not Details

Instead of asking "Here's our supply chain data, what would competitors pay for this?" ask "How can a company typically optimize supplier diversity?" You get useful analysis without exposing your specific data.

4. Use Hypotheticals

"If a company had X cost structure and Y margin requirement, how would they typically approach pricing?" You get reasoning without exposing your actual numbers.

5. Avoid Sending Confidential Headers or Context

If you copy text from a confidential email or document, be careful about headers or context that identifies the source. A prompt that says "Here's from our acquisition discussion with Company X" is worse than "Here's a financial analysis I need help understanding" (even if the content is similar).

6. Don't Ask the AI to Keep Secrets

Asking "This is confidential, please don't use this in training or share it" doesn't give you confidentiality protection. The AI tool's actual practices (whether they train on data, how long they keep it) don't change based on your request. Either the tool has real confidentiality protections (contracts, certifications) or it doesn't. Your request doesn't change that.

7. Review AI Outputs for Unintended Information Leakage

Sometimes AI systems output information that wasn't in your input. They generate plausible examples or details that might actually be confidential or inaccurate. Review outputs before using them, especially if you'll share them with others. If the AI invented a detail about your business, double-check it and correct it before using.

The "Would This Be on the Front Page of the Wall Street Journal?" Test

Before sending data to an AI system, ask: if this information ended up on the front page of a major newspaper, would that be a problem? For vendor contracts: yes, probably (competitors would learn your terms). For pricing structures: yes (competitors would learn your margins). For strategic plans: absolutely. For a process description without financial details: maybe not. For general operational tips: no. If the answer is "yes," don't send it to an uncontrolled AI system. If the answer is "no," you're probably okay, assuming no confidentiality clauses with third parties.

Vendor Confidentiality Considerations

For operations professionals who send vendor or supplier information to AI systems, there are specific confidentiality risks.

Many vendor contracts include confidentiality clauses: "Vendor information disclosed by Vendor to Buyer will be kept confidential and not disclosed to third parties without Vendor's consent." When you send that vendor's data to an AI system, you might be violating the clause. The vendor didn't consent to third-party processing.

How to handle:

1. Review Vendor Contracts

Do you have blanket confidentiality obligations that apply to all vendors? If yes, sending vendor data to external AI systems probably violates the clause. You need vendor consent.

2. Ask Vendors

"We want to use an AI analysis tool to help with supplier optimization. Your data would be sent to [vendor name]. Is that okay?" Many vendors will say yes if asked. Some will say no. Getting permission eliminates the legal risk.

3. Use Anonymized Vendor Data

Analyze vendor metrics without identifying which vendor is which. "Vendor A costs $500K, Vendor B costs $450K" becomes "pricing range $450K to $500K."

4. Use Dedicated Vendor Analysis Tools

Some vendors (procurement platforms, BI tools) have vendor relationship agreements with confidentiality built in. Use these instead of general-purpose AI.

5. Negotiate Vendor Agreements Upfront

When you contract with new vendors, include language allowing you to use their data with approved third-party analysis tools. Example: "Vendor agrees that Buyer may process Vendor information using third-party vendors approved by Buyer for procurement optimization and supply chain analysis, provided such third-party vendors are subject to confidentiality obligations consistent with this Agreement."

What to Do Monday Morning

  • Identify your sensitive operational information: Make a list of information in your operations that's confidential. Vendor contracts? Pricing? Cost structure? Supplier relationships? Strategic plans? Upcoming changes? For each category, ask: "Would competitors pay for this?" If yes, it's confidential and you should have a policy about where it can go.
    - Inventory shadow AI tools your team is using: Ask your team informally: "What AI tools are people using for operational work?" You'll probably discover 5-10 tools. List them. For each one, document: what data is it touching? What's the confidence level that confidential information is being sent? Create a simple spreadsheet with tool name, purpose, and risk assessment.
    - Set up an AI tool approval process: Create a one-page form for teams to request approval to use new AI tools. Include: tool name, business justification, what data will be processed. Give yourself a process for approving tools quickly (same day for obvious choices, 1-2 days for reviews). Use this to bring shadow AI into the light.

Key Takeaways

  • Confidentiality in operations includes vendor data, financial information, cost structures, strategic plans, and proprietary processes: If competitors would pay for the information, it's confidential and shouldn't be sent to uncontrolled AI systems.
    - Shadow AI (tools people use without organizational approval) is the biggest confidentiality risk: Most data breaches through AI happen via tools organizations don't even know are in use. Manage shadow AI through visible approval processes and clear data handling policies, not blanket bans.
    - Storage, training, retention, and access risks mean that uncontrolled AI systems are not secure homes for confidential information: For confidential data, use tools with SOC 2 Type II certification, signed data processing agreements, and documented no-training-on-customer-data policies.
    - Anonymize and aggregate before sending operational data to AI systems: Remove identifying details, use aggregated metrics instead of individual data points, and ask for analysis rather than sending raw data.
    - Review vendor contracts for confidentiality obligations: Sending vendor data to external AI systems without vendor consent potentially violates confidentiality clauses. Ask vendors for permission or anonymize data before sending.
    - Training and clear policies prevent most confidentiality breaches: A 15-minute training on data classification and simple policies on what data can go where prevents 80% of unintended leakage.

Frequently Asked Questions

Is information I send to ChatGPT really confidential, even though I'm using it in a business context?

It depends on your ChatGPT plan. With a free or personal ChatGPT account, OpenAI may use conversations for model training and improvement. With a ChatGPT Plus account or ChatGPT for Business, OpenAI commits not to use your conversations for training, though they still store conversations on their servers. Neither option includes a confidentiality agreement. If you need real confidentiality protection for operational data, use Microsoft 365 Copilot (which has a Data Processing Agreement with encryption and no training on customer data), or use an on-premises AI tool where data stays on your servers.

If I'm careful about what I send to ChatGPT, is it safe to use for operational analysis?

It depends on how careful. If you're anonymizing data (removing specific vendor names, customer names, financial details), using aggregated metrics rather than individual records, and asking for analysis rather than sending raw data, you can reduce risk to acceptable levels for non-critical work. But if you're sending any data that would be valuable to competitors, that's a risk. For truly confidential analysis, use approved tools with confidentiality agreements or on-premises tools.

What if someone in my organization accidentally sends confidential data to an AI system?

First, don't panic. One accidental upload isn't a massive breach (though it's worth addressing). Second, act quickly: notify the AI vendor and request data deletion. Most vendors can delete specific conversations if you request immediately. Third, understand what was sent and assess the damage (is this data that would materially harm the company if leaked?). Fourth, use the incident as a teaching moment. Was your data classification policy clear? Was the employee trained on what not to send? What process could prevent this next time? Most organizations discover they need better training or more user-friendly approved tools after an accidental send.

Can I ask an AI system to promise not to use my data in training?

Your request doesn't change the vendor's actual practices. Either the vendor has a contractual commitment not to train on customer data (and a data processing agreement that backs it up), or they don't. Your prompt asking them not to train doesn't create that commitment. The vendor's actual behavior is determined by their terms of service and data practices, not by what you ask in a conversation. If you need protection against training, you need a vendor with that commitment in their contract, not a request in your prompt.

How do I handle confidentiality concerns with consultant or contractor use of AI systems?

Add language to consultant/contractor agreements: "Consultant may not send Confidential Information to external AI systems without prior written approval from Client. Consultant understands that personal or unapproved AI tools may not provide adequate confidentiality protections. Approved AI tools for this engagement are [list]. If Consultant needs to analyze Confidential Information with an AI system, request approval from [contact]." This creates explicit requirements and a channel for getting approval rather than having consultants guess about what's okay.