From understanding the dangers of Shadow AI to using Gemini securely, we’re sharing a non-negotiable list of best practices to protect your company’s data.
TL;DR
- Around 70% of UK companies use or explore AI, but 68% of staff use unapproved AI tools.
- Free AI tools often use input for training, potentially exposing sensitive company data to the public.
- Always use company-approved AI tools like Gemini within Google Workspace and avoid entering sensitive personal or customer data, even with approved AI services.
Implement a policy outlining approved AI tools and banning high-risk activities. - Provide AI training to employees to address blind spots and prevent accidental security mistakes.
- Craft precise prompts to ensure accurate results, data protection, and compliance, avoiding accidental exposure.
According to a recent survey by Moneypenny, around 70% of UK companies are now either using or exploring AI for tasks such as content creation, customer service, and analytics.
With this massive convenience comes a massive security headache. While employees dip their toes into using integrated AI tools like Gemini, a significant number of UK staff (68%) are using unapproved AI tools, according to this SAP report.
The lack of comprehensive AI training and unsupervised adoption creates serious risks and has already caused security vulnerabilities, including data exposure. While most organisations are starting to train their people, the progress is too slow to match the pace of adoption.
5 Tips To Protect Your Business Data When Using AI
1. Never use Free AI tools for work (Seriously)
The practice of using unapproved or external AI services by employees is so common that there’s now a term for it: Shadow AI.
Most free AI tools, including the free versions of Gemini and ChatGPT, use your input to train their models. This means anything you type in could become part of the public AI’s knowledge base, permanently exposing your sensitive company information to the public domain and potentially our competitors. Once it’s in, it’s out.
Always use AI tools approved by your company (such as Gemini within the Google Workspace environment). If you need a specific AI tool for a task and are unsure if it’s approved, check with your IT admin.
2. Don’t Feed AI Sensitive Data or Company Secrets
Although Google explicitly states it will not use your Google Workspace data (Gmail, Drive, Docs, and Gemini prompts/responses) to train its AI without permission, you should still exercise caution.
Avoid entering sensitive or personal information belonging to yourself, colleagues, or customers to maintain the highest level of privacy and data security.
3. Introduce an Internal AI Rulebook
An AI policy can guide everyone towards using AI in the smartest and most secure way possible.
A short PDF shared among employees to highlight the AI tools they can use and clearly ban the high-risk activities (like putting sensitive client data into free chatbots) can save you from a data leak.
To make it even more comprehensive, you can also include a few notes on AI ethics and prompt engineering, which we’ll discuss next.
4. Master Prompt Engineering
Well crafted prompts are essential to using AI efficiently and securely. The way you ask questions or give instructions affects the reliability of AI responses, the protection of sensitive data, and compliance with company and legal standards.
Poorly crafted prompts can lead to errors, biased results, or accidental exposure of confidential information. Our latest AI training session includes practical skills to write precise prompts, helping you harness AI confidently while keeping data and operations safe.
Here’s an example of safe vs. risky prompting:
Risky Prompt:
“Summarise this confidential client report and include all details.”
This could expose sensitive client information to the AI inappropriately.
Safe Prompt:
“Summarise the key findings of this report in a way that does not include client names or sensitive personal data.”
Protects confidential information while still producing a useful summary.
5. Training is a Top Security Move
The rush to adopt Gemini and other AI tools is so fast that it naturally leaves a few blind spots, and the most critical one is training.
This lack of guidance means employees can be left to figure out new features and their security and compliance implications on their own, leading to accidental mistakes.
Attending Gemini or other AI training sessions and having at least one person within the company to monitor updates and share knowledge with everyone is a great start.
Bonus tip: How to add an extra layer of protection to your Gemini activity
To add an extra layer of protection to your Gemini activity, open gemini.google.com and navigate to the Activity tab from the left panel. There, you can choose to automatically delete your chats and other activities if your Google Workspace admin allows it.
You can also click on Manage my Activity verification and enable an extra layer of verification for your activity history; this is useful if you’re using a shared device.

Can my Admin See My Gemini History or Activity?
While using the standalone Gemini chat app, the admin can view the full chat transcript using specialised retention and data loss prevention tools such as Google Vault or other security investigation services.
While using integrated features within Gmail, Sheets, Docs, etc, the prompt and response content are not saved and therefore can’t be viewed later by the admin.
Takeway
Gemini and other AI tools offer immense potential for boosting efficiency and productivity. However, AI adoption requires monitoring, training and human oversight.
Always try to use the best practices to protect your company’s data to minimise risks.
Curious to learn more about Gemini? Join our latest Gemini training course to learn how to incorporate it into your workday and how to craft efficient (and safe) AI prompts.


