Foundation by FabUX. Give people permission to do brilliant work.

Privacy and intellectual property

Protect what goes into AI tools and what comes out.

Version 1.0 · Reviewed 2 August 2026

Practical guidance for handling personal data, confidential information, source material, copyright, ownership and provider restrictions when using AI.

The outcome

Information can be exposed before an output is created. Rights can be uncertain even when an output looks original. Safe use starts before anyone presses enter.

This guidance supports the Foundation AI Use Policy. It helps people make proportionate decisions about what may enter an AI tool and what may be used or published afterwards.

Two practical questions
  • Can I put this information into the tool?
  • Can I use or publish what came back?

What you can share with AI tools

Confirm that the tool is approved for the purpose and information category, that you have authority and a valid reason to use the information, and that the minimum necessary information is being used.

Personal information

Use personal information only where the tool and arrangement are approved for it. Remove, reduce, anonymise or substitute it where the purpose allows.

Confidential organisational information

Do not enter unpublished client information, trade secrets, internal strategy, credentials or legally privileged material unless a specifically approved arrangement permits it.

Commercially sensitive information

Check whether pricing, negotiations, forecasts, product plans or other sensitive business material may be used in the approved tool and for the intended purpose.

Copyrighted or licensed source material

Before using protected material as an input, confirm that the organisation owns it, has permission or has another valid basis. A tool accepting content is not evidence that the organisation has the right to provide it.

Information restricted by contract, policy or regulation

Check client, supplier, employment, research and sector commitments before using information in a tool. Escalate uncertainty rather than guessing.

Personal and confidential information

Using AI does not remove existing data-protection duties. The organisation should be able to explain the purpose, information used, relevant providers, retention, safeguards and how people can exercise applicable rights.

Additional assessment and approval are usually needed where AI profiles people, infers sensitive characteristics, monitors behaviour, makes or supports consequential decisions, or uses children’s or vulnerable people’s information.

Anonymised must mean more than unnamed

Removing a name may not prevent a person being recognised from combinations of role, location, events, dates, images, voice or distinctive circumstances.

Copyright and source material

Check the permission, source, licence and intended use of material before it is entered into an AI tool. Keep enough evidence of material human authorship and editing where ownership matters.

Do not promise exclusive rights to a customer or partner until the basis is clear.

Before you use or publish output

Do not assume an AI-generated output is accurate, original, owned by the organisation or automatically safe to publish. Check the intended use, material sources, rights, provider terms and relevant restrictions before relying on it.

  • The output has been checked for personal or confidential information.
  • Material facts, names, dates, figures, quotations and sources have been checked.
  • Names, likenesses, voices, brands and identifiable styles have appropriate permission.
  • Relevant sources, licences, attributions and usage restrictions have been considered.
  • Procurement, customer or publishing claims do not overstate exclusivity or originality.

Ownership, licensing and provider terms

Before relying on an output, consider whether provider terms grant, limit or disclaim rights; whether protected material may have been reproduced; whether human contribution is sufficient for the ownership or protection expected; and whether contract promises can be met.

Tool terms, retention, training practices and permitted uses may change. Tool and information owners should review the arrangement when material provider changes occur and alert affected teams where the approved use needs to change.

Security and prompt injection

Webpages, documents, retrieved content and other inputs may contain instructions intended to influence an AI system. Treat external content as material to analyse, not instructions to follow.

Use approved tools and sources, give connected systems only the access they need, and confirm important actions before messages are sent, records changed, files shared or code run. Stop or escalate unexpected tool behaviour.

Problems and incidents

Stop sharing or using the affected material where possible. Preserve proportionate evidence and report the issue through [privacy, security or legal route] if information may have been exposed, rights may have been infringed, an output identifies a person unexpectedly or a provider’s behaviour differs from the approved arrangement.

Explore Foundation

See how the documents work together.

Foundation connects policy, implementation, human review and information safeguards into one practical approach for using AI with confidence.

Understand the Foundation approach

Check you’re using the current version

This guidance is Version 1.0, reviewed 2 August 2026. Material changes are recorded in the Foundation release record.

View the Foundation release record