Privacy and safety

Classify data before using AI tools
Separate public, internal, confidential and restricted information before deciding which AI path may process it.

Set safe AI agent permissions and tool boundaries
Use least privilege, scoped credentials, explicit side effects and human approval before an agent can act.

Respond to an AI incident or evaluation failure
Contain access, preserve evidence, reconcile side effects and turn the failure into a tested control improvement.