© All rights reserved to Barnea Jaffa Lande Law offices

AI in Organizations: No Longer Enough to Say “Do Not Input Confidential Information”

Summary

  • Risk begins with the prompt: AI tools create real value for organizations, but privacy, information security, and compliance risks arise as soon as information is entered.

  • The key issue is the full data path: Risk depends not only on whether information is stored or used for training, but also on what was entered, where it went, who had access to it, and how the output was used.

  • Organizational use creates legal and operational exposure: Employees may enter personal, sensitive, or confidential business information, and both prompts and outputs can have legal, regulatory, and internal governance implications.

  • The response should be practical governance: Organizations should map actual uses, establish clear rules, vet and configure approved tools, review vendors, and train employees to use AI in a controlled and responsible manner.

The routine use of AI tools creates real value for organizations, but it also gives rise to privacy, information security, and compliance risks from the moment a prompt is entered. To mitigate these risks, the key questions extend beyond whether information is stored or used for training: what information was entered, where it went, who had access to it, and how the output was used. This article outlines the main risk areas and suggests practical steps to help organizations use AI effectively, safely, and in a controlled manner.

 

AI Prompts Can Become Part of an Investigative Record

Two cases recently reported in the Israeli media illustrate how what appears to be a private conversation with a chatbot may become part of an investigative file.

 

In the case involving the disappearance of Mali and Liel Yahalomi, who were ultimately found in Argentina and were not suspected of any crime, it was reported that the two women used AI-based search engines, including Gemini, to ask about purchasing a phone without presenting identification, countries with no extradition treaty with Israel, and applications that might allow them to be located. It was also reported that those exchanges had been deleted and later restored, although it was not disclosed how investigators obtained the information or restored the exchanges.

 

In another case, in which two young men were indicted for the arson of a Japanika restaurant branch in Givatayim, the State noted in its detention application that a forensic extraction of one defendant’s phone revealed questions posed to ChatGPT before the incident, including about the seriousness of the offense and the applicable penalty. The chats were presented as part of a broader body of evidence, and the proceedings are ongoing.

 

This does not mean that every exchange with an AI tool is exposed, and a prompt alone does not prove intent or conduct. Its evidentiary weight depends on the user’s identity, timing, context, and the manner in which the information was generated and stored. Still, these cases illustrate that an AI prompt may become a digital record of significance in an investigation, legal proceeding, regulatory review, or internal organizational inquiry.

 

How AI Use Creates Privacy and Compliance Risk Inside Organizations

Employees use AI tools to summarize documents, draft letters, analyze data, and review code. In doing so, they may enter CVs, performance evaluations, customer complaints containing medical or financial information, source code, access credentials, draft contracts, and other sensitive business information. As a result, prompts may contain personal information about customers and employees, trade secrets, and material that may be protected by legal privilege.

 

Why Storage and Training Are Only Part of the Picture

From a legal and information-security perspective, risk arises as soon as information is entered into an AI tool, even absent an overt leak or investigation. Entering information may constitute disclosure to an external vendor, use of information for an additional purpose, or the granting of access that was not approved in advance. In appropriate cases, it may be inconsistent with the purpose for which the information was collected, the consent given or duty to inform, confidentiality undertakings, information-security requirements, or the terms of engagement with a customer.

 

Uploading information to an unapproved or unsupervised AI tool may also be treated as a security incident requiring clarification, documentation, and mitigation, and, in some cases, an assessment of whether reporting to the Privacy Protection Authority is required.

 

There is also no binary answer to whether an AI tool “stores” a conversation or “trains” on it. Information may be stored in an account, on a device, with the vendor or in audit logs; transferred to sub-vendors and storage platforms, including outside Israel; and subject to retention periods and permissions broader than those applied within the organization. Deleting a conversation from the chat window does not guarantee its immediate deletion from all systems and backups.

 

When an AI tool is connected to email accounts, documents, HR systems, or CRM systems, the potential exposure also extends to information the tool can access through the user’s permissions.

 

AI-tool outputs also require attention. An AI system may classify a candidate, draw conclusions about an employee’s performance, or generate new information about a customer. If the result is saved in a file, transferred to another system, or influences a decision, the organization remains responsible for its use. Organizations should therefore assess whether the use is consistent with the original purpose and notice provided to data subjects, whether the information is accurate, who may access it, and whether human oversight is required.

 

AI Vendors, Employee Monitoring, and Organizational Accountability

For risk-management purposes, organizations should examine three areas: their obligations toward data subjects, their relationship with the AI provider, and the privacy of employees who use AI tools. The Protection of Privacy Law and the Protection of Privacy Regulations (Data Security) may apply when personal information is entered into an AI tool, stored through it, or used to generate information about an identified or identifiable individual.

 

A generic data processing agreement with the vendor is not enough. Organizations should determine whether the vendor acts only as a “holder” (processor) that processes information solely on the organization’s behalf, or whether it may also use the information for its own purposes, such as service improvement or model training.

 

Organizations should also examine their outsourcing obligations under Regulation 15 of the Privacy Protection Regulations; the basis for transferring information outside Israel; the use of sub-vendors; retention and deletion periods; the handling of security incidents; and their control capabilities. Vendors’ promises not to use information for AI training do not eliminate the organizations’ risk-management responsibilities, as they do not address issues such as information access, retention, transfer, and deletion.

 

At the same time, an organization’s technological ability to view employees’ logs or AI chats does not justify blanket monitoring. Controls should be transparent, tied to a defined legitimate purpose, limited to what is necessary, and used accordingly. Organizations should explain to employees what information is collected about their use of AI tools, who is authorized to review it, for what purposes, and for how long. To the extent possible, they should also favor anomaly detection over routine review of employees’ chat content.

 

What Should Organizations Do in Practice?

  • Map actual uses of AI tools

Identify which AI tools are used in each unit, through which accounts, what types of information and files are entered, and which systems each tool is connected to. A list of AI tool names is not enough; the organization needs to understand the data paths from input to output.

 

  • Establish practical rules

Prepare a short table stating what is “permitted,” “requires approval,” and “prohibited.” For example, public information may be permitted, redacted information may require approval, and passwords, identifiable sensitive information, database access, and trade secrets should not be entered into an external AI tool without a pre-approved, protected process.

 

  • Select and configure approved tools

An enterprise version is not an automatic seal of approval. Define strong authentication, minimum necessary permissions, retention periods, model-training and feedback-sharing settings, administrator access, and connections to other systems. Any feature that is not needed should remain disabled.

 

  • Vet and regulate vendors

Before approving an AI tool for organizational use, conduct privacy and information-security assessments and ensure that the vendor agreement addresses processing purposes, sub-vendors, data processing locations, retention and deletion periods, and the handling of security incidents. Do not assume that standard terms of use or a generic DPA fully address these issues.

 

  • Prepare employees for the possibility of mistakes as well

Training should include examples relevant to day-to-day work. An employee who uploads data by mistake should know not to conceal the incident or simply delete the chat, but to report it immediately so that exposure can be mitigated, the incident documented, and the need for regulatory reporting assessed. These rules and definitions should be reviewed periodically.

 

There is no one-size-fits-all AI policy, and a blanket ban is not a practical solution. A sound policy should align day-to-day AI use with privacy law, information-security requirements, the organization’s binding agreements, and employee privacy.

 

We help organizations map AI uses and data flows, classify risks, formulate policies and procedures, review vendors and agreements, and implement controls and training, enabling them to use technology efficiently without losing control of their information.

 

***

 

Adv. Liav Shapira is a partner in the firm’s PrivacyCyber and AI Department.

Tags: AI | AI Regulation

    Barnea
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

    // load AI chatbot on test page