Signing in

You will be sent to MillerKnoll sign-in.

Data Privacy and What Not to Put in a Prompt

Anything in a prompt is information shared with a system. For M365 Copilot in the MillerKnoll tenant, enterprise protections apply, not the same as public ChatGPT.

Lesson 3

Right tool, right content.

If you would not email it outside the company without approval, do not put it in a public AI tool without checking.

Enterprise Copilot versus public tools

M365 CopilotYour tenant boundaryWork content OKPublic toolsStricter content testNo confidential paste
M365 Copilot stays in your tenant, public tools need a stricter content test.

Core principles

  1. Handle carefully: identifiable personal performance or health data, anonymize where possible.
  2. Confidential business: unreleased financials, M&A, strategy, client pricing, unreleased product details.
  3. Client and customer data, check policies and agreements.
  4. Legal and regulatory content, confidentiality plus risk of AI mistaken for legal guidance.
  5. Most drafting, summarizing, and brainstorming on non-sensitive work is fine, know the sensitive category and apply care there.

Check yourself

What practical rule does this lesson give for deciding whether to use a public AI tool with a piece of content?

Do this in Copilot

Review last five Copilot prompts, any PII, confidential, or client-specific content? Was the tool appropriate?

Paste this into Copilot Chat and work through it before moving on.

Safer generalization

Help me draft talking points about an associate on my team who has had attendance challenges, without using their name or identifying details. Focus on manager actions and HR partnership.
Open Copilot →
  • Anonymization

Did you run this in Copilot? Mark complete when you have tried it.

Next lesson: Responsible Use in High-Stakes Contexts →