Things to Consider Before Inputting Data to Prevent Information Leaks to Generative AI [Small Business Communication]
In this article, we start by considering the issue of information leaks during acting or singing practice using conversational generative AI, as raised by the Japan Actors Union to performers. Rather than discussing whether or not to ban convenient tools, we focus on how much work-related information is being passed to external services. From the perspective of Tsuyoshi Watataru, I have organized thoughts on the 'judgment before input' that becomes difficult to see in the shadow of convenience.
AI provides quick responses.
It doesn't look annoyed even when you're tired, and it doesn't complain no matter how many times you redo the same part. I can somewhat understand the urge to use it as a partner for acting or singing practice.
However, if what you are using for that practice is an unreleased script, the story changes.
The Japan Actors Union has called on performers to be cautious when handling information about unreleased works or roles.
The message is that practicing acting or singing with conversational generative AI like ChatGPT as a partner could lead to unexpected information leaks, so please check the service's terms and settings to ensure safety.
What caught my attention here is not the idea that 'you must not use AI'.
For the person practicing, a script is something to be read. You speak the lines, interpret them, and coordinate with your partner. When AI naturally enters that workflow, doesn't the sense that you are inputting the script into an external service fade away?
Because it appears as a convenient partner, the awareness that you are handing over information recedes into the background.
Hello. I am Tsuyoshi Watataru.
Under the business name 'Netarie,' I provide support for small businesses to communicate via note.
I pick up material such as work memos, audio, past articles, and daily insights, and organize them into note articles that are searchable and convey the person's character.
Today, I am thinking about what needs to be confirmed before convenience when incorporating AI into work.
Information leaks in generative AI are harder to see when 'handing over' than when 'saving'
When we talk about information management, we think of scenarios like setting passwords on files, not losing devices, or not opening suspicious emails.
All of these are important.
However, the situation is a bit different with generative AI.
Because you are inputting text yourself and receiving convenient replies, the sense that you are sending information outside is easily weakened.
This is not just a story for actors and singers.
Even in small businesses, information that has not yet been made public can get mixed into the material you want to consult with AI about.
Interactions with customers, products not yet announced, materials received from business partners, and consultations regarding staff.
What may seem like just 'consultation content' to the person who wrote it might be information that others never intended to entrust to anyone.
For example, there is the scenario where you paste a long email received from a customer directly into an AI to create a draft reply.
As a task, this is very natural. Since I also work with text, I understand the feeling of wanting to have long content organized for me.
However, simply deleting names may not be enough. When store names, dates and times, symptoms, or contract details are combined, it may be possible to infer who the person is.
The problem is not that AI is a dangerous tool, but that it is so integrated into daily tasks that it is difficult to confirm 'what exactly you are handing over' at that moment.
Decide in advance what information is acceptable to input into generative AI
The first thing needed when using AI is not clever prompts, but deciding the scope of what is acceptable to input.
Checking service terms and settings is essential.
However, if you end your judgment there, you might drift toward the idea that 'since the settings seem fine, it's okay to input anything.'
Here, there is still a layer of human judgment that remains before that point.
Work information needs to be sorted before being input into AI, rather than trying to protect it after it has been input.
Mask proper nouns. Do not paste the original text; generalize the situation. Do not input materials before they are public or documents entrusted by third parties. If there are organizational or business partner rules, do not proceed based solely on personal judgment.
I do not think it is necessary to stop all AI usage.
Shortening already published text, practicing with fictional settings, or organizing your own ideas.
If you choose the information you handle, there are many situations where you can be helped.
On the other hand, safe usage methods vary depending on the service, contract, and type of information. In highly confidential work, simply adjusting settings for personal services may not be enough, and there may be cases where confirmation from your organization or a dedicated environment is required.
AI will not look at the circumstances you have input and stop you every time by saying, 'That is a secret entrusted to you by someone else.'
That is precisely why the pause before pressing the send button remains a human task.
I have also organized information in another article regarding how to separate the processes to leave to AI and the processes where humans should retain judgment.
Summary: Is that information really okay to give to generative AI?
Does the text you are about to consult with AI today contain information entrusted to you by someone else?
It might be a good idea to not just remove proper nouns, but to rephrase the content into a form that allows for consultation without providing the original text.
I would like to introduce two tools (SourceNext) that I have been interested in recently.
This is the top contender: AI that runs on a local PC.
However, it requires quite high PC specifications. My PC might not be able to handle it.
Perhaps this is a more realistic option?
Preparation before handing data to AI. This is a tool specialized for masking. It seems like it could work if you take a moment to process files like PDFs before uploading them.
Having read this far, some of you may have thought about the text you usually provide to AI.
In actual work, there are times when you cannot immediately judge whether it is okay to input something. I will organize the uncertainties that tend to remain outside the main text a bit more concretely.
If I remove the name, is it okay to input customer emails into generative AI?
Removing the name alone is not necessarily enough.
By combining multiple pieces of information such as store names, dates and times, symptoms, and contract details, it may be possible to infer the identity of the person. Before pasting the original text as is, you need to consider whether you can generalize only the situation necessary for the consultation.
If I turn off generative AI learning, is it safe to input confidential information?
While the setting to stop use for learning is one item to check, it does not necessarily mean you can input any confidential information. You need to make decisions based on service contracts, storage methods, the type of information, and the rules of your organization.
If you want to organize your basic knowledge and risks regarding generative AI, this article is a good starting point.
When I want to organize pre-release materials using generative AI, what should I check?
First, check if that material is information for which you alone can decide how to handle it.
If it is a document entrusted to you by a third party or material received as part of organizational work, it is important not to input it into external services based solely on your own judgment. If the original text is not required, you can consult by replacing it with fictional settings or generalized situations.
If I want to input a document received from a business partner into AI, who should I check with?
If your organization or business partners have usage rules, check those rules first.
Even if the information seems like just material for drafting a reply to you, it might be information the other party never intended to be shared with an external service. When in doubt, it is safer to rephrase it so that you do not have to input the original text.
How should I organize my thoughts to consult with generative AI without providing the original text?
In addition to removing proper nouns and specific dates and times, generalize the situation you want to consult about in a concise manner.
For example, instead of pasting the customer email itself, convey only the purpose, such as: 'I want to reply calmly to an inquiry expressing strong dissatisfaction while verifying the facts.'
Even if you reduce the information you provide to the AI, you may still be able to get advice on how to organize your thoughts or the direction of your reply.
This is not about giving up convenience, but about confirming the scope of what can be used.
When you have information you are unsure about handling, it is a good idea to start by rephrasing it into a form that allows you to consult without providing the original text.
Thank you for reading.
You can find a summary of how Tsuyoshi Watataru approaches supporting communication and article creation here.
→ Self-introduction and Service Guide
If you would like to try it yourself first, click here.
→ For those who write notes but don't see results in their work | A diagnostic tool to find bottlenecks and decide on your 'next step'
If you would like to receive ideas on communication and updates for free, click here.
→ Free Newsletter
[About Production] This article is based on the structure, notes, and research of Tsuyoshi Watataru, using AI as an assistant for drafting and organizing, with final confirmation and editing done by the author himself. The angle of the article, what content to keep, what to cut, and the decision to publish are all handled by Tsuyoshi Watataru.
#SmallBusinessCommunication #GenerativeAI #AIUtilization #InformationLeakage #InformationManagement #InformationSecurity #ChatGPT #ConversationalAI #JapanActorsUnion #Actor #Performer #Acting #VocalPractice #Script #ConfidentialInformation #PersonalInformation #WorkTechniques #BusinessImprovement #AILiteracy #DigitalLiteracy #SoleProprietor #SoloCEO #SmallBusiness #NoteCommunication #Netarie #TsuyoshiWatataru
