The AI-Safe Desk · Module 2: The four bands
Red and black: never, and never without a policy
Red is information where redaction is not enough, because the content itself is the risk. Special category data: health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone, and sex life or sexual orientation. Criminal records are a separate category with similar protection, so treat them as red too. Safeguarding information about children or vulnerable adults. Legally privileged material. Anything covered by a specific confidentiality agreement. Anything you have been told is restricted.
Red does not go into a consumer tool at all. It may go into an internal deployment, if and only if your organisation has a written policy saying so, and you have read it. If there is no policy, red stays out until there is one, whatever the time saving.
Black is the small category of things that should never go into any AI tool, however it is deployed: passwords and credentials, encryption keys, security configurations, and anything that would let someone else get into a system. There is no redacted version of a password.
| Band | Rule |
|---|---|
| Green | Any tool. Check the output, as always. |
| Amber | Redact first, then any tool. Less redaction on a business or internal tool. |
| Red | No consumer tool, ever. Internal tool only with a written policy you have read. |
| Black | No AI tool, ever. Credentials, keys, security settings, anything that opens a door. |
In practice. A school administrator was asked to draft a letter to parents about a pupil with a medical condition. Red twice over: a child, and health data. Her instinct was to redact the name and paste the rest. But the letter's whole content was the condition, and the school had no AI policy.
She wrote it herself and raised the absence of a policy with the head. Six weeks later the school had one, and it said exactly what she had done.
At your desk. Write down, for your role, the three kinds of red information you handle most. Then find out: does your organisation have a written AI policy that covers them? If yes, read it. If no, write down who you would ask.
Write it down.
- My three red categories:
- Does a written policy exist:
- Who I would ask: