---
name: ai-data-safety-checks
description: 15 rules from the Noesa course "Data safety with AI". For anyone who pastes work material into AI tools and wants to know — before pasting — what's safe, what needs masking, and what never goes in.
---

# Data safety with AI — the rules

Use with: Claude Code or Claude (save as a skill), Cursor (save under .cursor/rules as .mdc), ChatGPT or any other assistant (paste the text below into custom instructions or a project's instructions).

15 rules, taken from the course at https://noesa.leafsoft.online/c/ai-data-safety

Each heading is one thing the course teaches. Most are checks to run on your own output before presenting it as done; a few are background you are expected to have. "Wrong by default" lists 7 specific ones.

Apply these to the thing you are producing — the type, the schema, the query, the copy — not only to how you explain it. Where a rule names a field, a format or an identifier, that name belongs in the output.

## See where your paste goes

Explain why putting information into an AI tool is a form of sending and decide when to stop before you paste.

## Know your company's rules

Distinguish approved workplace AI from shadow AI and choose a safe next step when the policy is unclear.

## Never paste people

Recognize information that identifies or describes a person and keep it out of unapproved AI workflows.

## Never paste the keys

Recognize credentials and high-value company information that must stay out of unapproved AI tools.

## Handle customer conversations with care

Prepare a customer conversation for an approved AI summarization workflow without carrying unnecessary identity or sensitive detail into it.

## Anonymize like you mean it

Test whether masked information remains linkable to a person and choose aggregation or synthetic data when masking is too weak.

**Wrong by default:**
- Removing a direct identifier does not remove a fingerprint. Count how many rows share each combination of the columns you kept: on postcode district plus birth year alone, three of these six rows sit in a group of one, so half the table is a single lookup away from a name. The number to check is the smallest group size in the release, not whether the names are gone.
- Re-identification runs on the combination, not on any single column. A postcode district shared by four rows still leaves a row unique once the birth year is added, because only one of those four was born that year. Test the columns together; a common value in one of them proves nothing on its own.
- Job title and office survive the edit, and a senior title is often the only one of its kind in its location — which makes that row unique again without the column you removed. After dropping a column, recount the smallest group instead of assuming the removal fixed it.

## Mind the documents

Inspect a document for hidden sheets, comments, metadata, and embedded content before using it in an approved AI workflow.

## Watch the outputs too

Inspect AI-generated output for sensitive echoes, inferences, and disclosures before reusing or sharing it.

**Wrong by default:**
- An average over a group of one is that person's salary with an extra step. London L4 and Kuwait L5 each cover one person, so two cells on this slide publish an individual's pay exactly. Count the people behind every cell and suppress the ones below your threshold before the slide leaves the tool.
- Rounding blurs the value; it does not change who the group is. A cell covering one person still covers one person, and the reader still knows whose row it is.
- In a group of two, either person can subtract their own salary from the average and get their colleague's exactly. Two is not a crowd; set a minimum cell size and apply it to every cell.
- Approval covers where the data may go, not what the answer happens to reveal. The output is a new disclosure the tool created, and it gets its own check.

## Know the tool's settings

Distinguish conversation history, retention, training use, account controls, and organizational approval without treating one setting as proof of safety.

## Paste the minimum

Reduce an AI task to the smallest approved facts, pattern, or aggregate needed to produce a useful result.

## Respect the partner boundary

Recognize data entrusted by a partner, separate access from permission, and identify the owner who can authorize a new AI use.

## Spot a leak, report a leak

Recognize a possible AI-data incident, stop further sharing, preserve useful facts, and report it through the right internal route.

## Set the team norms

Define a short team paste-policy that names approved routes, red lines, minimum-input habits, review, and escalation.

## Build your before-you-paste checklist

Assemble a five-question checklist that catches destination, permission, sensitivity, minimum need, and recovery before any paste.

## Audit a real week of prompts

Audit one week of your AI use, identify an unnecessary or unsafe disclosure pattern, and redesign the workflow using your checklist.
