© All rights reserved to Barnea Jaffa Lande Law offices

AI in organizations: It is no longer enough to say “Do not input confidential information”

Blog Barnea Jaffa Lande

The routine use of AI tools in organizations creates real value, but it also gives rise to privacy, information security and compliance risks from the moment a prompt is entered. To mitigate these risks, the key questions are not limited to whether information is stored or used for training, but also what information was input, where it went, who can access it, and what was done with the output. Below are the main risk areas and practical steps organizations can take to use AI effectively, safely and in a controlled manner.

 

Two cases recently reported in the Israeli media illustrate that what appears to be a private conversation with a chatbot may become part of an investigative file.

In the case of the disappearance of Mali and Liel Yahalomi (who were ultimately found in Argentina and were not suspected of any crime), it was reported that the two women used AI-based search engines, including Gemini, to inquire about purchasing a phone without presenting identification, countries with no extradition treaty with Israel, and applications that might allow them to be located. It was also reported that some of those exchanges had been deleted and later restored, but it was not disclosed how investigators obtained the information or by what means the exchanges were restored.

 

In another case, in which two young men were indicted for the arson of a Japanika restaurant branch in Givatayim, the State noted in its detention application that a forensic extraction of one defendant’s phone revealed questions posed to ChatGPT before the incident, including regarding the seriousness of the offense and the applicable penalty. The chats were presented as part of a broader body of evidence, and the proceedings are still ongoing.

This does not mean that every exchange with an AI tool is exposed, and a prompt by itself does not prove intent or conduct. Its evidentiary weight depends on the user’s identity, the timing, the context and the way the information was generated and stored. Still, the above cases illustrate that an AI prompt may become a digital record of significance in an investigation, legal proceeding, regulatory review or internal organizational inquiry.

What happens inside organizations?

Employees use AI tools to summarize documents, draft letters, analyze data and check code. In that context, they may input resumes, performance evaluations, customer complaints containing medical or financial information, source code, access credentials, draft contracts and other sensitive business information. As a result, the prompt may contain personal  information about customers and employees, trade secrets and material that may also be protected by legal privilege.

From a legal and information-security perspective, risk arises as soon as information is entered into an AI tool, even without an overt leak or an investigation. The act of inputting information may constitute disclosure to an external vendor, use of information for an additional purpose, or the granting of access that was not approved in advance. In appropriate cases, it may depart from the purpose for which the information was collected, the consent given or the duty to inform, confidentiality undertakings, information-security requirements or the terms of engagement with a customer. Uploading information to an unapproved or unsupervised AI tool may also be regarded as a security incident requiring clarification, documentation and mitigation, and, in some cases, assessment of whether reporting to the Privacy Protection Authority is required.

 

There is also no binary answer to the question whether an AI tool “stores” a conversation or “trains” on it. Information may be stored in an account, on a device, with the vendor or in audit logs; transferred to sub-vendors and storage platforms, including outside Israel; and subject to retention periods and permissions broader than those applied within the organization. Deleting a conversation from the chat window does not guarantee immediate deletion from all systems and backups. When the tool is also connected to email accounts, documents, HR systems or CRM systems, the potential exposure also extends to information that the tool can access by virtue of the user’s permissions.

The output of AI tools also requires attention. An AI system may classify a candidate, draw conclusions about an employee’s performance or generate new information about a customer. If the result is saved in a file, transferred to another system or influences a decision, responsibility for its use remains with the organization. Accordingly, organizations should examine whether the use of the information is consistent with the original purpose and notice provided to data subjects, whether the information is accurate, who may access it and whether human oversight is required.

 

For risk-management purposes, organizations should examine three spheres: their obligations toward data subjects; their relationship with the AI provider; and the privacy of employees who use AI tools. The Protection of Privacy Law and the Protection of Privacy Regulations (Data Security) may apply when personal information is entered into an AI tool, stored through it, or used to generate information about an identified or identifiable individual.

 

A generic data processing agreement with the vendor is not enough. Organizations should determine whether the vendor acts only as a “holder” (processor) that processes information solely on the organization’s behalf, or whether it may also use the information for its own purposes, such as service improvement or model training. Organizations should also examine their outsourcing obligations pursuant to Regulation 15 of the Privacy Protection Regulations, their justifications for transferring information outside of Israel, their uses of sub-vendors, retention and deletion periods, their mode of handling of security incidents, and their control capabilities. Vendors’ promises that they are not using information for AI training purposes do not cover organizations’ risk management responsibilities, since they do not address such issues as information access, retention, transfer and deletion.

At the same time, an organization’s technological ability to view employees’ logs or AI chats does not justify blanket monitoring. Controls should be transparent, tied to a defined legitimate purpose, limited to what is necessary, and used accordingly. Organizations should clarify to employees what information is collected about their use of AI tools, who is authorized to review it, for what purposes and for how long, and should, to the extent possible, favor anomaly detection over routine review of the content of employees’ chats.

What should organizations do in practice?

  • Map actual uses of AI tools: identify which AI tools are being used in each unit, through which accounts, what types of information and files are being entered, and  systems each tool is connected to. A list of AI tool names is not enough; the organization needs to understand the data paths from input to output.
  • Establish practical rules: prepare a short table stating what is “permitted,” “requires approval” and “prohibited.” For example, public information may be permitted; redacted information may require approval; and passwords, identifiable sensitive information, access to databases and trade secrets should not be entered into an external AI tool without a pre-approved and protected process.
  • Select and configure approved tools: an enterprise version is not an automatic seal of approval. Define strong authentication, minimum necessary permissions, retention periods, model-training and feedback-sharing settings, administrator access and connections to other systems. Any feature that is not needed should remain disabled.
  • Vet and regulate vendors: before approving an AI tool for organizational use, conduct privacy and information-security assessments and ensure that the agreement with the vendor addresses the purposes of processing, sub-vendors, the data processing locations, retention and deletion periods, and the handling of security incidents. Do not assume that standard terms of use or a generic DPA fully address these issues.
  • Prepare employees for the possibility of mistakes as well: training should include examples relevant to day-to-day work. An employee who uploads data by mistake should know not to conceal the incident or merely  delete the chat, but to report it immediately, so that exposure can be mitigated, the incident documented, and the need for regulatory reporting assessed. These rules and definitions should be reviewed periodically.

 

There is no one-size-fits-all AI policy, and a blanket ban is not a practical solution. A sound policy should align day-to-day AI use with privacy law, information-security requirements, the organization’s binding agreements and employee privacy.

*** 

We help organizations map uses and data flows, classify risks, formulate policies and procedures, review vendors and agreements, and implement controls and training, so they can use technology efficiently without losing control over their information.

Adv. Liav Shapira, a partner in our Privacy, AI and Cyber Department, is available to assist with any questions regarding these matters.

Tags: AI | Privacy

    // load AI chatbot on test page