Frontier IntegrationAI adoption & integration
← All guides

Security & adoption

Before you put business information into an AI tool

Work through the data, access, and review questions before connecting an AI tool to your business.

Before uploading a file, decide what information the task actually needs and whether the chosen tool is approved to handle it. The answer depends on the data, the service, and your organization’s requirements.

Start with the information

Look beyond the filename. A spreadsheet might contain customer contact details, internal pricing, or comments that were never intended to leave the business. Consider whether you can complete the exercise with fictional records or a smaller, redacted extract.

Check the actual account and service

Read the current terms and settings for the account you would use. Establish what is retained, whether inputs may be used for training, who can access them, and what deletion controls exist. Record the answers and the date you checked them; avoid assuming that different plans or tools handle data in the same way.

Bring unresolved requirements to the people responsible for your information and systems before proceeding.

Consider what a connection can do

Uploading a sample file and connecting a shared drive create different exposures. Identify which records an integration can read and whether it can send messages, edit files, or take other actions. Limit access to what the task needs and require approval for consequential actions.

AI systems can be manipulated by instructions embedded in material they process, a problem known as prompt injection. The NCSC’s guidance for business leaders explains this risk and why security needs attention throughout a system’s use.

Make review part of the workflow

Agree on who checks the output, what they check, and what happens when something goes wrong. NIST’s AI Risk Management Framework provides a broader structure for managing AI risks; this short guide is a starting conversation, not a security assessment.

A practical next step is to write down one proposed task, the information it requires, the people who can approve its use, and the actions the tool would be allowed to take. That gives your team a concrete proposal to review.