RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026Start here · 100 retrospective records ↗
AI Use Field Guide

Start here / Privacy & safety

Privacy & safety / From the archive · 18 July 2024 event · prepared 16 September 2026

A French regulator names what a prompt should never contain

The CNIL's 2024 guidance on generative AI tells organisations and staff what counts as safe to type into a consumer AI tool.

Visual for this record: cnil-recommendations-on-ai-2024
Visual published by cnil.fr, shown for identification of the record. Credit: cnil.fr · source page ↗ Rights: owner-review-pending.

Start here

Before an employee or a student pastes a paragraph into a public AI chatbot, there is a useful question hiding behind the habit: is any of this information something a person is actually allowed to share with a company they do not control? France's data protection authority, the CNIL, put that question at the centre of guidance aimed at people who use generative AI systems, not only the companies that build them.

What the documents say

The CNIL's Q&A on the Use of Generative AI Systems, published 18 July 2024, states that 'end-users should only submit information that they are allowed to share in the prompt or input data,' adding that people 'should never share confidential information such as personal data, company or administrative data... when using a consumer service.' The same answer places legal responsibility on the organisation deploying a tool, not only the individual typing into it, stating that 'the organisation deploying the system will bear the legal liability in case of misuse of AI by its staff,' which is why the guidance recommends training end-users on a system's limits, and treating outputs with scrutiny for accuracy, plagiarism and bias rather than accepting them at face value. The document sits inside wider CNIL AI compliance guidance, which separately covers system design for organisations that build rather than use these tools.

Check this

The mechanism worth testing on yourself: before pasting a document, a client name, a medical detail, or an internal figure into a consumer AI assistant, ask whether you would forward that same paragraph to an outside company by email without your employer's knowledge. If the answer is no, the CNIL's guidance says the prompt should not include it either, because a consumer account offers no contractual promise about who else might see or process that content. This is a check anyone can run in seconds, before typing rather than after.

What holds and what fails

The distinction the CNIL draws holds well as a first filter: separating what a person is personally comfortable sharing from what an organisation has authorised them to share catches a meaningful share of accidental disclosures. It does not hold as a complete safeguard, because the guidance depends on organisations actually training staff and providing input templates for approved tasks, steps it recommends but cannot enforce. Where an employer has done none of that preparation, an individual applies the CNIL's general test without a specific list of what counts as authorised at work. This is an editorial reading; the guidance is addressed to organisations as much as to individual users.

  • Before your next prompt, ask whether you would send the same text to an outside company by email.
  • Ask whether your employer has told you which categories of data are off-limits in AI tools.
  • Treat an AI system's output as a draft to verify, not a finished, sourced answer.

A regulator cannot watch every prompt typed into a chatbot, so guidance like this works by giving a person a portable question to ask themselves first, one more durable than any single company's terms of service.

Sources & reading trail

CNIL's Q&A on the Use of Generative AI Systems ↗

States that end-users should only submit information they are authorised to share and should never enter confidential or personal data into a consumer generative AI service.

Source published: 18 July 2024 · Retrieved: 16 September 2026

AI: how to comply with regulations? ↗

The CNIL's hub page linking its main guiding principles and recommendations for organisations using or developing AI systems, confirming the Q&A sits within a wider guidance programme.

Source published: Not established · Retrieved: 16 September 2026

Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.