{"id":13105,"date":"2026-08-24T08:59:49","date_gmt":"2026-08-24T06:59:49","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=13105"},"modified":"2026-08-24T08:59:55","modified_gmt":"2026-08-24T06:59:55","slug":"politici-de-guvernanta-a-datelor-in-domeniul-ia-la-nivel-de-intreprindere-pentru-prompturi-date-de-antrenare-si-informatii-sensibile","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/","title":{"rendered":"Guvernan\u021ba datelor \u00een domeniul IA la nivel de \u00eentreprindere: politici privind prompturile, datele de antrenare \u0219i informa\u021biile sensibile"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Enterprise AI data governance sets the rules for how a business collects, classifies, enters, stores, reviews, and removes data used with generative AI. It applies to public AI tools, enterprise copilots, internal models, and agent workflows. The main goal is to prevent confidential or personal information from being used without a clear business purpose, approved access, and an appropriate review process.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#What_data_governance_covers_in_AI_workflows\" >What data governance covers in AI workflows<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Classify_prompts_files_and_model_data_before_use\" >Classify prompts, files, and model data before use<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Set_different_rules_for_each_AI_environment\" >Set different rules for each AI environment<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Make_retention_and_model_training_explicit\" >Make retention and model training explicit<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Control_access_review_and_vendor_use\" >Control access, review, and vendor use<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Prepare_an_AI_data_incident_response_process\" >Prepare an AI data incident response process<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/enterprise-ai-data-governance-policies-for-prompts-training-data-and-sensitive-information\/#Make_employee_use_practical_and_consistent\" >Make employee use practical and consistent<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_data_governance_covers_in_AI_workflows\"><\/span>What data governance covers in AI workflows<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An AI model is a system trained to perform specific tasks using data and machine learning techniques. Models learn patterns, relationships, and rules from training data, then use that knowledge to analyze new information, make predictions, or generate content. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/ce-este-un-model-ai-arhitecturi-operationale-de-baza-si-mecanica-ciclului-de-viata\/\">Learn more about AI models<\/a>.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-682408711\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Governance should cover every data flow, not only the final model. A typical flow can include an employee prompt, attached documents, retrieved company records, model processing, generated output, logs, human review, and possible use of the data for evaluation, fine-tuning, or future training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use one policy for the whole flow, while applying stricter controls to higher-risk data. The policy should identify who may submit data, which system may receive it, how long it may be retained, whether a vendor may access it, and whether it may be used to improve or train a model.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Classify_prompts_files_and_model_data_before_use\"><\/span>Classify prompts, files, and model data before use<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Classification gives employees and systems a clear rule for deciding what can be entered into an AI service. A simple four-level scheme can support consistent decisions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Public:<\/strong> Information already approved for public release. It may be used in an approved AI tool when the use follows the tool&#8217;s business rules.<\/li>\n\n\n\n<li><strong>Internal:<\/strong> Routine business information that is not intended for public release. Limit it to approved enterprise services and authorized users.<\/li>\n\n\n\n<li><strong>Confidential:<\/strong> Business information that could harm the organization or another party if disclosed. Require an approved use case, restricted access, and a defined review path.<\/li>\n\n\n\n<li><strong>Sensitive:<\/strong> Personal data, regulated information, authentication data, secrets, or material covered by a duty of confidentiality. Block it from public AI tools unless a documented exception and suitable safeguards exist.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Apply the classification to prompts, uploaded files, retrieved records, conversation history, generated outputs, and evaluation datasets. A prompt can become sensitive when combined with other information, even if each individual part appears harmless.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Set_different_rules_for_each_AI_environment\"><\/span>Set different rules for each AI environment<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Environment<\/th><th>Policy focus<\/th><th>Default data rule<\/th><\/tr><\/thead><tbody><tr><td>Public AI tools<\/td><td>Vendor access, retention, and model-training settings<\/td><td>Use public data only unless an approved exception applies<\/td><\/tr><tr><td>Enterprise copilots<\/td><td>Identity, permissions, connected data, and logging<\/td><td>Use only data the user is already authorized to access<\/td><\/tr><tr><td>Internal models<\/td><td>Training data, fine-tuning, evaluation, and deployment access<\/td><td>Use approved datasets with documented ownership and purpose<\/td><\/tr><tr><td>Agent workflows<\/td><td>Tool permissions, retrieved data, actions, and human review<\/td><td>Give each agent only the access and action rights required for its task<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">These environments should not be treated as interchangeable. A control that is suitable for a controlled internal model may not be suitable for a public tool that receives data through an external service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Make_retention_and_model_training_explicit\"><\/span>Make retention and model training explicit<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every approved AI service should have a written data-retention decision. Define whether prompts, attachments, outputs, logs, and feedback are stored; the business reason for storing them; who can access them; and when they are deleted or reviewed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retention and model training are separate decisions. A service may retain data for logs or support without using it to train a model, while another service may use submitted data for improvement. The approval record should state whether business data may be used for training, evaluation, fine-tuning, or prompt improvement. If the setting is unclear, prohibit confidential and sensitive data until the service has been reviewed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fine-tuning requires a separate approval because it places selected business data into a model-development process. Record the dataset owner, purpose, classification, access scope, removal process, and test results before the tuned model is made available to users.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Control_access_review_and_vendor_use\"><\/span>Control access, review, and vendor use<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Require a named business owner for each AI use case and dataset.<\/li>\n\n\n\n<li>Use role-based access so users receive only the data and functions required for their work.<\/li>\n\n\n\n<li>Review permissions for enterprise copilots and agents when a user&#8217;s role changes.<\/li>\n\n\n\n<li>Require human review before sensitive outputs are used for important business decisions or external communication.<\/li>\n\n\n\n<li>Record the AI service, data classification, purpose, reviewer, and approval status for each higher-risk use case.<\/li>\n\n\n\n<li>Review vendor access, retention, and model-training terms before connecting company data.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">GDPR governs how personal data is collected, processed, stored, and protected, and applies to organizations that process personal data of people located in the European Union. It entered into effect on May 25, 2018. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/ce-este-gdpr-si-de-ce-site-ul-dvs-trebuie-sa-fie-conform\/\">Learn more about GDPR and website compliance<\/a>. AI governance should therefore route personal-data use through the organization&#8217;s privacy and compliance process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Prepare_an_AI_data_incident_response_process\"><\/span>Prepare an AI data incident response process<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Define an incident as any suspected or confirmed use, disclosure, retention, or transfer of AI data outside the approved policy. The response process should give employees a clear reporting channel and preserve the details needed for review.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Report:<\/strong> Record the tool, account, time, data involved, prompt or workflow, and generated output when available.<\/li>\n\n\n\n<li><strong>Contain:<\/strong> Stop the affected workflow, revoke unnecessary access, and prevent further submissions while the case is reviewed.<\/li>\n\n\n\n<li><strong>Assess:<\/strong> Classify the data, identify vendor or internal access, determine whether retention or training may have occurred, and identify affected people or business records.<\/li>\n\n\n\n<li><strong>Escalate:<\/strong> Send personal-data cases to the privacy or compliance function and involve security, legal, and the system owner as required by internal procedure.<\/li>\n\n\n\n<li><strong>Correct:<\/strong> Remove or restrict data where possible, update permissions or settings, and record the decision.<\/li>\n\n\n\n<li><strong>Improve:<\/strong> Update the classification rule, training, approval record, or technical control that allowed the incident.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Make_employee_use_practical_and_consistent\"><\/span>Make employee use practical and consistent<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Employees need short rules that match the tools they use. State which data is allowed in each environment, when anonymization or redaction is required, which outputs need human review, and how to report an incident. Apply the same rules to prompts, files, copied text, screenshots, retrieved records, and agent inputs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A durable policy connects classification, access, retention, vendor review, training decisions, human review, and incident response. This gives each AI use case a clear owner and gives employees a consistent answer before business data enters an AI workflow.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[],"class_list":["post-13105","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13105\/revisions"}],"predecessor-version":[{"id":13106,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13105\/revisions\/13106"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=13105"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=13105"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=13105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}