NNAWALABS

Data hygiene · Human review · Field protocol

Before you paste: a three-light gate for AI inputs

A practical way to separate what can go into a tool, what needs minimization and approval, and what should stay out.

Person writing with a pen in an open notebook beside a laptop and small plant
A person writes in an open notebook at a desk beside a laptop and small plant. Contextual workspace photograph; no endorsement or product use is implied. Photo by Shixart1985 on Wikimedia Commons · CC BY 2.0.

An AI chat is not a blank page. It is a data transfer into a system with settings, retention, integrations, and history. This gate does not declare a tool “safe” or “unsafe.” It interrupts reflexive pasting and makes the team understand what it is sending, why, and into which environment.

1. Treat every prompt as a data transfer

Data does not end at the text box. It can travel through attachments, connectors that read mail or storage, chat history, and outputs that people copy elsewhere. The decision therefore starts before prompt writing: what is the data, who owns it, which environment is approved, and what exact purpose requires it?

NIST’s Generative AI Profile lists leakage and unauthorized use or disclosure among potential data-privacy impacts. OWASP’s 2025 GenAI guidance likewise identifies sensitive-information disclosure as a risk for LLM applications. That does not make every use dangerous. It makes copy-and-paste a data decision, not merely a writing shortcut.

NAWA / CONTROL NOTE

This is an editorial awareness and workflow framework—not a legal or security determination and not a substitute for your organization’s policies.

2. Map five flows before choosing a color

Record the main input, every attachment, any connector or plugin, the expected output, and where history remains. The prompt itself might be public while an attached spreadsheet contains names or identifiers. A prompt might be minimized while a connector can see a much wider folder than the task requires.

Also ask whether the account is personal or organizational, whether that environment is approved for the work category, who can access history, and what retention or deletion is documented. NCSC’s secure-AI guidance emphasizes understanding and monitoring inputs and operating systems without exposing sensitive data to unauthorized parties.

  • Typed prompt
  • Files and images
  • Connectors and plugins
  • Output and onward sharing
  • History, retention, and deletion

3. Green: public, synthetic, and reversible

Use green for material already public, a synthetic example that cannot be traced to a real person, customer, or transaction, or text you could publish unchanged without expected harm. Think: reorganizing a published press release, testing an email template with fictional names, or summarizing a public document while retaining its link.

Green still requires output review. A model can add unsupported facts or mix versions. The color describes input sensitivity only; it does not prove the result is accurate or the tool appropriate.

  • Public source with a link
  • Clearly synthetic data
  • No secrets or identifiers
  • A reversible task
  • Human review before publication

4. Amber: minimize, de-identify, and approve

Amber is lower-sensitivity internal work that may be useful after data minimization and in an approved environment. Replace a name with a role, an exact date with a range where possible, remove employee and customer numbers, and share sample rows rather than an entire file. Do not call data anonymous when remaining details can easily identify someone.

Before proceeding, check organizational policy, account settings, and applicable agreements—not only a marketing sentence. Record who approved, which fields were removed, and why each remaining field is necessary. If you cannot explain a field’s need, remove it or use a synthetic substitute.

NAWA / CONTROL NOTE

Redaction reduces exposure; it does not guarantee that people cannot be re-identified or automatically make data non-personal.

5. Red: stop and change the route

Treat passwords and secret keys, government identifiers, individual health or employment records, customer data, privileged legal material, unpublished financial results, proprietary source code, and deal plans as red unless a formally approved environment and controls specifically cover the use.

Red does not mean “never use AI.” It means the employee does not decide alone from a chat box. Route the request to the data owner, privacy, security, or legal function according to policy, or rebuild the task with synthetic data. SDAIA describes personal-data protection in Saudi Arabia through the Personal Data Protection Law and national governance frameworks.

  • Credential, password, or API key
  • Identity, health, or employee record
  • Customer data or confidential contract
  • Unpublished financial figure
  • Trade secret or proprietary code

6. Run the 90-second scrub

Copy the task into a temporary working note before the tool. Underline every name, identifier, exact date, exact amount, and private link. Replace details while preserving the problem’s structure: “sales manager,” “Q3,” “Company A,” or a rough range. Separate instructions from data and test with the smallest sample that can answer the question.

Check file properties, hidden comments, unintended tabs, and text embedded in images. If the task depends on person-level precision—such as an employee or customer decision—a quick scrub may be inappropriate. Stop and use the formal route.

  • Replace people with roles
  • Turn exact values into ranges
  • Remove IDs and private links
  • Test a small sample
  • Inspect attachments and connectors

7. Separate vendor claims from verified controls

Create a control card for each tool. Does the vendor say inputs are excluded from training—and for which plan? What retention period applies? Can an administrator control history and connectors? Where is deletion documented? Record the source link, plan, region, and verification date. Never carry a promise from a general page into every product edition and account.

Keep three layers distinct: a vendor claim in current documentation, behavior your team tested in the actual account, and a contractual or internal assurance reviewed by its owner. A conversation disappearing from the interface does not prove erasure from every log, and clicking a control is not a contractual commitment.

  • Plan and account tested
  • Training, retention, deletion
  • Documented location or region
  • Admin rights and connectors
  • Source link and verification date

8. Review output as if risk can return

An output can repeat names from context, infer sensitive facts, or follow hostile instructions embedded in an attached document. Check facts and sources, confidentiality, whether the text makes a decision about a person, and whether it will leave the organization. For high-impact work, human review must be a real decision point—not ceremonial sign-off.

Test the gate on one task this week. Classify the input, note what you removed, and save a one-line decision: use, constrain, or stop—and why. A good gate does not turn everything green. It makes stopping normal before the data is inside the system.

NAWA / CONTROL NOTE

Nawa Labs reviewed the linked sources on 29 July 2026. Products, settings, and policies change; verify the current version and your organization’s environment.

Sources and limits

These are primary or official guidance sources. The article does not determine compliance or assess a particular tool.

Not legal, security, privacy, or procurement advice.

Back to the labNawa method