Information
What is being submitted and how sensitive or valuable is it?
Institutional AI
Employees, researchers and students can adopt powerful AI tools faster than institutions can establish governance. The resulting risk is often not malicious behaviour—it is useful technology operating outside institutional visibility and control.

A researcher summarizes unpublished findings. A developer shares proprietary code for debugging. A professor works with sponsored research. An employee uploads an internal report. A student asks an external AI service for help with research material.
Depending on the service, account, contract, configuration and information involved, these actions can raise questions about confidentiality, retention, privacy, intellectual property, contractual obligations and records management.

Avoid simplistic claims. The actual risk depends on the environment and workload.
What is being submitted and how sensitive or valuable is it?
What contractual and technical controls apply to the specific AI service?
How long can prompts, files, outputs or logs persist?
What research, confidentiality, sponsorship or IP obligations apply?
Who is authorized to use the information and for what purpose?
Can the institution determine where sensitive information is travelling?
Blanket prohibition can sacrifice the benefits of AI and may push useful work into unsanctioned channels. A more durable strategy is to provide approved AI environments that are capable enough to be adopted.
The goal is not to make every workload private. It is to make workload routing, approved tools and institutional boundaries clear enough that people can choose appropriately.
People should not have to choose between the intelligence of AI and the protection of institutional knowledge.
