Artificial intelligence is quickly becoming part of everyday work. Generative AI tools can help draft emails, summarise documents, analyse information, generate ideas and make everyday tasks more efficient.
But using AI can also mean sharing information with an external system.
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) highlights that while AI offers significant opportunities for organisations, it also introduces cyber security and data risks that need to be understood and managed.
This Cyber Security Awareness Month, there’s a simple habit we can all adopt: Take a second, stay secure.
Before you type, paste or upload information into an AI tool, stop and consider what you’re sharing and whether it really needs to be there.
The copy and paste problem
Imagine you need to summarise a lengthy report. Uploading the whole document into an AI tool takes seconds and gives you an answer almost immediately.
But what else was in that document?
Names. Contact details. Financial information. Employee or client information. Internal business information.
The intention wasn't to disclose sensitive information. You were simply trying to get a job done faster.
The risk wasn't necessarily using AI. It was sharing more information than the task required.
ACSC guidance emphasises the importance of protecting sensitive, proprietary and mission-critical data throughout the use of AI systems.
Pause. Check.Protect
The same three steps that can help protect you from scams can also provide a useful habit when working with AI.
Take a second before trusting the answer, too
Protecting what goes into AI is only part of the equation.
AI-generated responses can contain incorrect, incomplete or misleading information. An answer can sound convincing without being accurate.
So the same principle applies on the way out:
Pause before you use it. Check important information. Protect your organisation by applying human judgement.
Important facts, calculations, sources and recommendations should be independently checked, particularly when they could influence financial, operational or organisational decisions.
Five questions before you prompt

Learn more this Cyber Security Awareness Month
Cyber security is a shared responsibility, and staying informed is one of the simplest ways we can strengthen our collective protection.
As part of Cyber Security Awareness Month,
Securing Australia Together 2026 will bring together the National Cyber Security Coordinator and chief security officers from Australia's major banks for a live online panel discussion on cyber security.
Share this article:
Related articles



CDPF Limited, a company established by the Australian Catholic Bishops Conference, has indemnified the Catholic Development Fund ABN 15 274 943 760 (the Fund) against any liability arising out of a claim by investors in the Fund. In practice, this means your investment is backed by the assets of the Catholic Archdiocese of Melbourne. The Fund is required by law to make the following disclosure. Investment in the Fund is only intended to attract investors whose primary purpose for making their investment is to support the charitable purposes of the Fund. Investors’ funds will be used to generate a return to the Fund that will be applied to further the charitable works of the Archdiocese of Melbourne and the Dioceses of Sale and Bunbury. The Fund is not prudentially supervised by the Australian Prudential Regulation Authority nor has it been examined or approved by the Australian Securities and Investments Commission (ASIC). An investor in the Fund will not receive the benefit of the financial claims scheme or the depositor protection provisions in the Banking Act 1959 (Cth). The investments that the Fund offers are not subject to the usual protections for investors under the Corporations Act (Cth) or regulation by ASIC. Investors may be unable to get some or all of their money back when the investor expects or at all and investments in the Fund are not comparable to investments with banks, finance companies or fund managers. The Fund’s identification statement may be viewed here or by contacting the Fund. The Fund does not hold an Australian Financial Services Licence.
