Skip to main content
AI Security Hub
01AI Security Pillar

User Input Security

Control the prompts, files, requests, and conversation history entering an AI system.

Business focus

Control what enters AI

Why it matters

Security starts with a defined business boundary

User input security defines what employees and connected applications may submit to AI. It helps a business keep sensitive information out of unapproved tools and makes approved use easier to understand.

Business risk

A useful AI assistant can also become a new path for client records, credentials, contracts, or internal decisions to leave approved systems. The first control is knowing what enters the workflow and who is allowed to submit it.

What this pillar covers
  • Prompts and sensitive questions
  • Uploaded files and client documents
  • API requests and connected applications
  • Session context and conversation history
Launch reading list

Start with these practical guides

Each pillar begins with one anchor guide and two supporting articles. Published guides become active automatically as they enter the blog.

Publishing soon

AI Data Loss Prevention for Businesses Using Generative AI

Map where sensitive data can enter, move through, and leave an AI workflow.

Part of the launch series
Publishing soon

ChatGPT Security for Business: A Practical Control Checklist

Set account, data, upload, output, and monitoring rules for business use.

Part of the launch series
Publishing soon

AI Subprocessor Risk: What to Review Before Sharing Business Data

Understand which vendors may process business information behind an AI service.

Part of the launch series

Questions for leadership

  • Which AI tools are approved for business information?
  • What information must never be entered into a public AI service?
  • Who owns employee guidance and exception decisions?
  • Can the business identify which data entered each AI workflow?
Practical control checklist

Put the pillar into practice

  1. 1Maintain an inventory of approved AI tools and owners.
  2. 2Classify the information employees may and may not submit.
  3. 3Document rules for uploads, connectors, and conversation retention.
  4. 4Give employees a clear reporting path for accidental disclosure.
  5. 5Review the policy when tools, vendors, or business processes change.
Review a real workflow

Turn this pillar into operating controls

Map the data, access, approvals, monitoring, and evidence around one important AI use case before expanding it.

Explore the diagnostic