SecuFocus
Try it yourselfBrowsing & the web

Use AI without handing it the keys to your life

What can you send to an assistant, how do you check its answer, and which permissions should an agent have? Examples to help you use AI without unnecessarily exposing your data.

Concept illustration: paper strips inspected through a lens in front of a smoked-glass mechanism.

Original AI-generated illustration · SecuFocus

At a glance

Key points

For a draft or an explanation, send only the information needed. Check the facts before using the answer. If the assistant can change files or send messages, limit its access and review its proposed actions before authorising them.

Choose tasks you can check

Rewording a letter, explaining a computer error, suggesting ideas for a project: an assistant can help you get started. You can review the result before using it. That step still matters when the answer reads clearly.

Consider two requests. In the first, you ask for a clearer version of a message whose facts you already know. In the second, you ask whether a clause lets you cancel a contract, then immediately send the suggested letter. The tool is the same, but the consequences of an error are not. Choose your level of supervision according to what could go wrong.

For an important medical, legal or financial decision, an assistant may help you prepare questions. The decision itself needs reliable evidence and, where appropriate, a qualified person. A paid subscription and a confident tone do not change that requirement.

Intended useA useful check
Suggest titles for a family albumRead and choose. Do not upload the photos if a description will do.
Explain a difficult passageKeep the original open and compare it with the explanation.
Modify files or send a messageReview the content, destination and action before execution.

A convincing sentence can still be wrong

Models can produce incorrect claims with considerable confidence. NIST identifies this behaviour among the risks of generative AI. A bibliographic reference, a precise number or a quotation is therefore not evidence simply because it appears in an answer.

If an assistant says a program encrypts all files by default, check the documentation before recommending it. Does that apply to your edition, local storage or synchronisation? Do you have to turn it on? An answer that is correct for one version may be wrong for another.

A second assistant can help find objections. Its agreement is not independent validation: it may repeat the same mistake or draw on the same material. When a fact matters, go back to a source that can actually establish it.

Provide useful context, keep the rest

Before attaching a document, ask which details the task really needs. To improve a letter, an assistant rarely needs your full address, customer number and signature. CNIL advises against putting personal or confidential information into consumer services without suitable safeguards.

To request a replacement for a coffee maker that arrived damaged, for example, a short note is enough: “product: coffee maker”, “problem: cracked reservoir”, “requested solution: replacement”, “order: ORDER_A”. Let the assistant draft from those details, then add your contact information and order reference in your email app.

This avoids uploading the complete invoice. It also separates the information needed to understand the problem from the information used to identify you. If “last week” is enough context, there is no reason to add your travel history to explain the delivery.

Replacing a name with an initial does not necessarily anonymise a story. An employer, a small town and an unusual situation may identify someone together. A black rectangle placed over a PDF can also leave the original text recoverable. For this kind of task, creating a clean excerpt without sensitive details is often the simplest approach.

History, training and retention periods

A setting that excludes conversations from training does not necessarily mean they are never stored. A conversation missing from your history may follow separate retention rules. Removing a detail from an assistant’s personalised memory does not establish that every copy has been erased.

Before a sensitive use, read the policy for your specific plan. Find out what is sent, who can access it, how long it is kept and how deletion works. Check attachments, voice conversations and connected services separately. An integration may introduce another recipient that the conversation alone did not have.

If the policy leaves a point crucial to your request unclear, remove sensitive information or use another method. Read the conditions attached to a “private” setting, particularly for attachments and connected services.

Question for the providerWhat the answer needs to clarify
Are my conversations used to improve models?The plan concerned, available settings and exceptions.
How long is my information stored?Conversations, attachments, logs and the deletion process.
What can a connection to my cloud access?Accessible folders and permitted operations.

Two example prompts

A useful request sets out the source material, the desired result and what should remain uncertain. It makes the response easier to check. It does not guarantee that the model will follow every instruction.

For the fictional letter: “Using the facts below, draft a courteous 120-word message requesting a replacement. Do not add dates, promises from the seller or legal arguments. Mark missing details in square brackets.” Then review every fact and commitment. You are still the person signing it.

For a public document: “Explain this passage to a beginner. Separate what the text says from your inferences. For each important point, identify the paragraph where I can check it. Say when the document does not answer the question.” Actually open the referenced passages. An invented paragraph number is still possible.

When learning a technique, introduce a constraint: ask for a hint, make your own attempt, then compare. That small amount of friction helps stop an easy answer from replacing an understanding of the problem.

Check dates, numbers and quotations

Rereading a response to see whether it sounds right is not enough. Identify the claims that could change your decision: prices, dates, technical features, service conditions, quotations and calculations. That is where verification time is best spent.

In the encryption example, keep a short note: claim, official link, relevant version, supporting passage and anything still uncertain. If the documentation contradicts the assistant, correct the text. If it does not settle the issue, keep that uncertainty visible.

For a calculation, enter the values into a calculator or spreadsheet and check the units. For a quotation, find the original text. For news, check when the event happened, not just when the page was published. An older source may be accurate in its context but unsuitable for your present question.

  1. Extract the two or three claims that matter most.
  2. Open the sources and check their authors, dates and supporting passages.
  3. Compare the result with the original document or data.
  4. Remove unverified details and review the final version before sharing it.

Limit agent permissions

An AI that drafts a message and one that can browse your inbox, modify your cloud files or send that message have different powers. OWASP describes excessive agency: too many functions, excessive permissions or insufficient human oversight can amplify a mistake.

To organise a photo folder, start with copies of unimportant files. Ask for a proposed structure, inspect it, then permit only the required operations. Read access is sufficient for preparing an inventory; it does not need to include deletion.

“Do not delete anything” in a conversation is not a technical restriction. Look for genuinely limited permissions in the connected service. Before sending or publishing, check the recipient, attachments and complete text. A button approving a hundred unseen actions does little to keep you in control.

A document can carry a hostile instruction

A web page or file read by an assistant can contain instructions intended to redirect its behaviour. This is indirect prompt injection. OWASP notes that models remain exposed to this problem, including when documents are retrieved to enrich their answers.

Imagine an assistant asked to summarise an attachment. The document claims that other files must be sent to an outside address to complete the analysis. That request comes from the document, not from you. It should remain material to examine, never become permission to act.

Limit connections to relevant folders, avoid granting unrestricted inbox access and retain approval for sensitive outputs. Telling an assistant to ignore hidden instructions may help, but cannot guarantee the outcome. Permission to transmit information needs controls beyond the conversation’s wording.

Generated images, publishing and learning

Label a generated image when it could be mistaken for a photograph of a real event. Similarly, do not use someone’s voice or face without permission to make them appear to say something they never said.

Examine the shortcuts in the result too: who is portrayed as competent, dangerous, vulnerable or trustworthy? An image or list of examples can reproduce a stereotype without a single grammatical error. Ask for different representations, then use your own judgement.

With children and teenagers, discuss uses and limits, check the service’s age conditions and avoid uploading an entire class’s work. UNESCO places human agency, privacy and age-appropriate use at the centre of its educational approach.

After a learning session, try explaining the idea without reopening the answer. If you get stuck, ask for a shorter exercise or a counterexample. That will show you what still needs work.

Check what stays local when running AI on your computer

Running a model on your computer can avoid sending prompts to a remote server. That depends on the application actually processing them locally. The initial model download, telemetry, web searches, extensions and any cloud fallback are separate exchanges to examine.

For an advanced setup, inspect network settings, documentation and where conversations are saved. A local model indexing your entire drive also gains broad access to your files. Prefer a selected folder, encrypt sensitive storage and keep the software updated.

Local processing reduces some transfers; it does not automatically fix incorrect answers, prompt injection or operational mistakes. The same verification habits still apply.

Before sending, then before using the answer

Before sending, remove unnecessary details and review the tool’s permissions. Consider how you will check the answer: against an original document, with a calculation or with a qualified person, depending on the subject.

When using the answer in a message or a decision, check the facts, commitments and recipients in particular. You will be using the result, including any mistakes it contains.

  • Remove unnecessary personal information and secrets.
  • Check decisive facts against identifiable sources.
  • Review recipients and attachments before an action.
  • Label artificial creations when they could be mistaken for real events.
  • Keep meaningful uncertainty rather than smoothing it away.

Frequently asked questions

Practical questions

Is an answer reliable just because it includes links?

No. A link may be broken, outdated or unrelated to the claim. Open the source, find the relevant passage and check its date. For an important decision, compare the explanation with the original documents.

Read more: Check dates, numbers and quotations #Link to this answer

Does an AI running on my computer always keep data local?

The model may run locally while an extension, web search or another component contacts an external service. Check enabled features and how the application behaves. The word “local” alone does not describe the whole system.

Read more: Check what stays local when running AI on your computer #Link to this answer

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.