User Input Security
Control the prompts, files, requests, and conversation history entering an AI system.
Control what enters AI
Security starts with a defined business boundary
User input security defines what employees and connected applications may submit to AI. It helps a business keep sensitive information out of unapproved tools and makes approved use easier to understand.
A useful AI assistant can also become a new path for client records, credentials, contracts, or internal decisions to leave approved systems. The first control is knowing what enters the workflow and who is allowed to submit it.
- Prompts and sensitive questions
- Uploaded files and client documents
- API requests and connected applications
- Session context and conversation history
Turn control what enters ai into repeatable controls
A policy is only the starting point. For each AI use case, name the business owner, define the allowed boundary, configure the relevant technical controls, and decide what evidence proves those controls are working. Repeat the review when the model, data, connected tools, or business purpose changes.
Start with a single high-value workflow instead of trying to govern every experimental use at once. That makes it possible to test the controls with real users, find exceptions, and create a pattern the rest of the business can reuse.
Start with these practical guides
Each pillar begins with one anchor guide and two supporting articles. Published guides become active automatically as they enter the blog.
AI Data Loss Prevention for Businesses Using Generative AI
Map where sensitive data can enter, move through, and leave an AI workflow.
Read the guideChatGPT Security for Business: A Practical Control Checklist
Set account, data, upload, output, and monitoring rules for business use.
Read the guideAI Subprocessor Risk: What to Review Before Sharing Business Data
Understand which vendors may process business information behind an AI service.
Read the guideQuestions for leadership
- Which AI tools are approved for business information?
- What information must never be entered into a public AI service?
- Who owns employee guidance and exception decisions?
- Can the business identify which data entered each AI workflow?
Put the pillar into practice
- 1Maintain an inventory of approved AI tools and owners.
- 2Classify the information employees may and may not submit.
- 3Document rules for uploads, connectors, and conversation retention.
- 4Give employees a clear reporting path for accidental disclosure.
- 5Review the policy when tools, vendors, or business processes change.
Use recognised guidance to validate the control design
These resources help teams translate AI-specific risks into documented, testable business and technical controls. Apply them to the actual data, permissions, and actions in the workflow rather than treating them as a one-time compliance exercise.
- NIST AI Risk Management Framework
A lifecycle-oriented framework for governing AI risk.
- OWASP Securing Agentic Applications
Practical secure-design guidance for AI systems that use tools.
- CIS AI and LLM Companion Guide
AI-aware interpretations of established security controls.
Turn this pillar into operating controls
Map the data, access, approvals, monitoring, and evidence around one important AI use case before expanding it.