Data privacy and acceptable-use policy: Updating which existing policy area most directly addresses this
Updating data-privacy and acceptable-use policy to govern data entered into external AI directly addresses the exposure.
The question
A company's data-handling rules predate its use of generative AI, and employees now routinely paste customer records into an external large language model to draft responses. Updating which existing policy area most directly addresses this exposure?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Corporate travel and expense policy, to control how staff request approval and reimbursement when they attend external conferences about generative-AI tools and vendors.Plausible but wrong: travel policy has no bearing on customer-data exposure through AI tools.
- Physical badge-access policy, to determine which employees may enter secured areas of the building where generative-AI experimentation and prototyping typically take place.Plausible but wrong: badge access does not control data entered into external LLMs.
- Data privacy and acceptable-use policy, to restrict what customer data may be entered into external AI tools and define approved, compliant handling of such data. ✓Correct: governing what data staff may input to external AI directly addresses the leakage of customer records.
- Brand and marketing-style policy, to standardize the tone and formatting of the customer responses that employees ultimately draft with the help of the external tool.Plausible but wrong: style guidance does not prevent sensitive data from being sent externally.
The trap
Choosing a policy that references AI in passing but does not govern the sensitive data flow. How to remember it
Updating data-privacy and acceptable-use policy to govern data entered into external AI directly addresses the exposure.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Use-case assessment: Which AI life-cycle stage does this control primarily target? →
- Pre-contract due-diligence assessment: Which combination of third-party controls most completely addresses the →
- A general-purpose foundation model: Which term most precisely describes this system? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.