Secure GenAI Adoption for Developers

Developers / DevSecOps

Technical AI Risk

Secure GenAI Adoption for Developers

Threat-model, test, and ship GenAI features securely.

Learning objectives

  • Identify sensitive data that should not be entered into public AI tools
  • Understand approved vs unapproved AI usage
  • Recognize risky prompts
  • Follow company AI policy
  • Report unsafe AI usage

Lesson

Section 1

What is sensitive data?

Personally identifiable information (PII), customer records, contracts, source code, financial data, trade secrets, regulated data (PHI, PCI), and any non-public business information. If you would not post it publicly, do not paste it into a public LLM.

Section 2

Examples of unsafe AI usage

Pasting a signed customer contract into ChatGPT to 'summarize the key terms'. Asking an AI to debug code that contains hardcoded API keys. Uploading internal financials to generate a forecast.

Section 3

Safe prompting practices

Strip identifiers, use placeholder values, and prefer enterprise-tier tools with zero-retention agreements. When summarizing documents, redact first or use an internal AI assistant.

Section 4

Approved tools and workflows

Use ChatGPT Enterprise, Microsoft Copilot, Claude for Work, or the internal AI assistant. Avoid personal accounts. SSO is mandatory. Audit logs are reviewed weekly.

Section 5

What to do if data was accidentally shared

Report immediately via the #ai-incidents channel or security@acme.com. Do not attempt to 'delete' the conversation — the data may already be retained. Speed of disclosure determines containment.