Free AI safety guidance. No email required.Open the safety page

Online AI

Cloud tools are convenient. The boundary still needs a name.

Online AI can be the fastest way to begin. Before uploading files or connecting accounts, check the exact product, plan, settings, integrations, and people who can see the result.

A

Account

Personal, team, enterprise, education, API, and embedded product access can have different controls and terms.

D

Data

Know what you are sending, what the provider retains, and whether the organization has approved that use.

C

Connections

Drive, email, browser, CRM, calendar, and third-party actions widen the boundary beyond the chat box.

R

Review

Name who verifies facts, approves decisions, corrects errors, and records important use.

Before upload

Ask seven questions.

A clear “no” is better than a vague “probably.”

  1. Is this tool approved? A familiar brand does not automatically make a personal account appropriate for work files.
  2. What information is in the input? Public, internal, confidential, regulated, copyrighted, or someone else’s personal information?
  3. What does this exact plan retain? Check current controls for history, training, abuse monitoring, support access, deletion, and region.
  4. What can connected tools reach? A connector may expose more than the one file visible on screen.
  5. Who can share the output? Generated content can travel into email, documents, customer records, or public posts in seconds.
  6. What review is required? Higher consequence means stronger evidence, approval, and audit notes.
  7. What is the fallback? If the service is unavailable, changes behavior, or produces a bad result, can the work continue?

Three common lanes

“Online AI” is not one thing.

The interface may look similar while the operating boundary is very different.

LaneBest forMain cautionMinimum control
Public consumer appLearning, public information, personal brainstorming, and low-risk drafts.Account settings and service terms may not match organizational requirements.Do not upload restricted information. Verify current data controls.
Managed workplace accountApproved team workflows with admin controls and shared policy.Connectors, sharing, role permissions, and user behavior still matter.Admin ownership, approved uses, training, review, and incident path.
API or embedded systemRepeatable software workflows, controlled interfaces, logging, and integration.Developers now own authentication, data flow, prompts, retries, errors, and downstream actions.Architecture review, least privilege, testing, logging, and approval gates.

The connector rule

Permission is part of the prompt.

When an AI tool can search email, open Drive files, change records, or trigger another system, the risk is no longer limited to generated text.

Read is not write.

Give the smallest permission needed. A tool that summarizes a document does not need the ability to delete it.

Preview is not approval.

Show proposed changes before committing them when the action affects customers, money, records, schedules, access, or public communication.

Convenient is not invisible.

Document which accounts, folders, and systems the tool can reach. Review them after staff changes and product updates.

Governance note

NIST’s AI Risk Management Framework is designed to help organizations manage AI risks and promote trustworthy and responsible use. It is a flexible framework, not a product approval list.

Next useful step

Before the next upload, set the boundary.

The free safety page gives your team a plain-language verification routine, data traffic light, and response path for suspicious AI-assisted scams.

Resource access

Get the resource

Enter an email address to receive access.

We use this information to deliver the resource and understand which materials are useful. We do not sell it. See the privacy page.

Your link is ready.

It expires after 24 hours. The link may also be emailed when delivery is configured.

Download the resource