Audit the AI tools you used this month

You will build a list of every AI tool you used recently and what data you gave each one.

Think back over the past month and count the AI tools you used. Most people say one or two. Then they remember the meeting app that wrote a summary, the grammar checker in the browser, the photo app that removed a background, the email client that suggested replies, and the assistant a colleague shared a link to. The real number is often closer to ten.

Each of those tools received something from you. This exercise turns that vague sense into a table you can act on. It takes about 25 minutes, and you'll come out of it with at least one setting or habit changed.

Step 1: list every tool

Start with the obvious ones: the assistants you open on purpose, such as ChatGPT, Claude, Gemini or Copilot. Then work through the less obvious places AI turns up.

Look at the AI features built into apps you already use: summaries in your email or video call app, writing suggestions in documents, smart replies in messaging apps. Check your browser extensions, since many grammar, translation and summary extensions send page content to a server. Think about transcription tools, voice notes turned into text, and meeting recorders. Include anything on your work laptop and your phone.

Your browser history and your phone's list of installed apps are good memory aids. If you can't remember whether you used something this month, include it and mark it unsure.

Step 2: fill in the columns

Make a table with one row per tool and these columns: tool, account type, what you gave it, training setting, history and retention, and decision.

For account type, write personal free, personal paid, or work approved, using what you learned in lesson 1.2, Personal, business and enterprise accounts are not the same. If you're not sure whether a work tool is approved, write that.

For what you gave it, be specific. "Emails" is too broad. "Two client emails with names and phone numbers" tells you something.

For training and retention, open the tool's settings or privacy page and write what you find. If you can't find it in five minutes, write "could not find", which is itself useful information.

Step 3: flag the risky rows

Go down the "what you gave it" column and put a flag next to any row where one of these went in: personal data about another person, such as a customer's name, phone number or NRIC number; client or employer information you were told to keep confidential; passwords, one-time codes or bank details; or your own health or financial details.

These are the never-share and approved-account-only groups from lesson 1.1, What happens to the words you type into an assistant. A flag doesn't mean something bad has happened. It means this row deserves a decision rather than a shrug.

A worked example

Here's part of the table Jia Hui, the marketing executive from lesson 1.2, filled in. Her tools and settings are examples.

Row one: ChatGPT, personal free account. She gave it promotion plans, two drafts of a supplier email, and a list of 40 customer names with their order totals to sort. Training was on, because she'd never opened the setting. History was kept. Flagged, because of the customer list and the supplier details. Decision: change. She switched training off, deleted the chat with the customer list, and moved all work tasks to the company's approved assistant.

Row two: Microsoft Copilot through her company's Microsoft 365 account. She gave it internal reports and meeting notes. The company's IT page said this plan was approved for internal documents. Not flagged. Decision: keep as is.

Row three: a free browser extension that rewrites text. She'd used it on emails to customers. She couldn't find any retention policy on its website. Flagged. Decision: stop. She uninstalled it and used the approved assistant for rewording instead.

Row four: the summary feature in the video call app. The meeting host had switched it on, and the summaries were stored in the company's account. Not flagged for her. Decision: keep, and ask her manager whether external clients are told when meetings are summarised.

Notice that her decisions weren't all "stop". Most tools stayed. What changed was which account work went into and one setting she'd never looked at.

Step 4: decide and act

For each row, choose one of three decisions. Keep as is means the tool, account and settings are fine for what you use it for. Change settings means the tool is fine, but something needs switching, deleting or moving to a different account. Stop using means the risk outweighs the convenience, or you can't find out enough to judge.

Then do at least one of the changes today, while the table is open in front of you. A table full of decisions that you'll get to later doesn't protect anyone.

If a flagged row involves customer or client data at work, don't panic and don't hide it. Delete what you can, stop the habit, and if you think it may matter, tell your manager or your data protection officer. Module 2 explains why the company would rather know.

Keep the finished table. You'll come back to it in lesson 8.1, What goes in a personal AI policy, where your keep, change and stop decisions become the first rules of your own policy. Now open a blank table and start with the tool you used most recently.

Fill in an audit table for every AI tool you used in the past month and change at least one setting or habit as a result.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).