Skip to main content
AI Security Hub
01AI Security Pillar

User Input Security

Control the prompts, files, requests, and conversation history entering an AI system.

Business focus

Control what enters AI

Why it matters

Security starts with a defined business boundary

User input security defines what employees and connected applications may submit to AI. It helps a business keep sensitive information out of unapproved tools and makes approved use easier to understand.

Business risk

A useful AI assistant can also become a new path for client records, credentials, contracts, or internal decisions to leave approved systems. The first control is knowing what enters the workflow and who is allowed to submit it.

What this pillar covers
  • Prompts and sensitive questions
  • Uploaded files and client documents
  • API requests and connected applications
  • Session context and conversation history
Operating model

Turn control what enters ai into repeatable controls

A policy is only the starting point. For each AI use case, name the business owner, define the allowed boundary, configure the relevant technical controls, and decide what evidence proves those controls are working. Repeat the review when the model, data, connected tools, or business purpose changes.

Start with a single high-value workflow instead of trying to govern every experimental use at once. That makes it possible to test the controls with real users, find exceptions, and create a pattern the rest of the business can reuse.

StepDecisionEvidence to retain
1Scope the workflowOwner, purpose, approved data, users, and connected systems.
2Apply the controlsConfiguration, access rules, approval points, and test cases.
3Operate and reviewLogs, review results, exceptions, incidents, and change records.

Questions for leadership

  • Which AI tools are approved for business information?
  • What information must never be entered into a public AI service?
  • Who owns employee guidance and exception decisions?
  • Can the business identify which data entered each AI workflow?
Practical control checklist

Put the pillar into practice

  1. 1Maintain an inventory of approved AI tools and owners.
  2. 2Classify the information employees may and may not submit.
  3. 3Document rules for uploads, connectors, and conversation retention.
  4. 4Give employees a clear reporting path for accidental disclosure.
  5. 5Review the policy when tools, vendors, or business processes change.
Authoritative guidance

Use recognised guidance to validate the control design

These resources help teams translate AI-specific risks into documented, testable business and technical controls. Apply them to the actual data, permissions, and actions in the workflow rather than treating them as a one-time compliance exercise.

Review a real workflow

Turn this pillar into operating controls

Map the data, access, approvals, monitoring, and evidence around one important AI use case before expanding it.

Explore AI services