{"id":39702,"date":"2026-02-13T04:32:51","date_gmt":"2026-02-13T04:32:51","guid":{"rendered":"https:\/\/www.insentragroup.com\/nz\/insights\/uncategorized\/governance-in-the-age-of-genai-because-chatbots-arent-bound-by-ndas\/"},"modified":"2026-02-13T06:19:05","modified_gmt":"2026-02-13T06:19:05","slug":"governance-in-the-age-of-genai-because-chatbots-arent-bound-by-ndas","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/nz\/insights\/not-geek-speak\/generative-ai\/governance-in-the-age-of-genai-because-chatbots-arent-bound-by-ndas\/","title":{"rendered":"Governance in the Age of GenAI: Because Chatbots\u00a0Aren\u2019t\u00a0Bound by NDAs"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The Rise of GenAI<\/h2>\n\n\n\n<p>Let\u2019s be honest: GenAI platforms like Copilot, ChatGPT, Claude, Gemini and whichever new one appears while you\u2019re reading this are incredible. They summarise, rewrite, translate, predict, hallucinate confidently like an intern on their first day&nbsp;and are basically the answer to \u201cI need to write&nbsp;a script for&nbsp;a&nbsp;complex automation task&nbsp;whilst creating a PowerPoint presentation for the board in the next 30mins\u201d.&nbsp;<\/p>\n\n\n\n<p>But&nbsp;as Hollywood movies,&nbsp;cartoons and some wise people throughout history have said\u2026with great power comes great responsibility\u2026or at least a couple of sleepless nights wondering whether someone just pasted your company\u2019s FY26 roadmap into a random chatbot&nbsp;or whatever that guy did from a US cybersecurity agency\u2026no really\u2026ask GenAI to find you the article.&nbsp;Proper facepalm moment!&nbsp;<\/p>\n\n\n\n<p>As organisations integrate GenAI to improve productivity, automate processes, and reduce the number of meetings that \u201ccould have been an email\u201d, they\u2019re also waking up to a harsh reality: these systems consume data, and not all data is created equal. Sensitive, confidential, regulated, personal, or \u201cplease don\u2019t let Legal find out\u201d data must be governed like a toddler at a chocolate fountain.&nbsp;<\/p>\n\n\n\n<p>The real challenge?&nbsp;Most&nbsp;users&nbsp;don\u2019t know what\u2019s safe to share with an AI model.&nbsp;Just because the chatbot is polite doesn\u2019t mean the architectural drawings of your new vault are safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">GenAI and Your Data: No Black Magic, Just Predictive Maths on Steroids&nbsp;<\/h2>\n\n\n\n<p>Some people think GenAI is like shouting into a void and getting wisdom back. Others think it\u2019s like feeding secrets to a hyperintelligent cyborg. The truth is somewhere in between.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"404\" height=\"533\" src=\"https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2026\/02\/image-3.png\" alt=\"\" class=\"wp-image-39703\" srcset=\"https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2026\/02\/image-3.png 404w, https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2026\/02\/image-3-227x300.png 227w\" sizes=\"(max-width: 404px) 100vw, 404px\" \/><\/figure>\n\n\n\n<p>GenAI models&nbsp;operate&nbsp;using prompts and context data. Depending on the platform, data may be:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Processed temporarily<\/li>\n\n\n\n<li>Logged for quality\/control<\/li>\n\n\n\n<li>Used to finetune models (not in enterprise-grade solutions)<\/li>\n\n\n\n<li>Stored in data centres within or outside your region<\/li>\n\n\n\n<li>Protected or not protected by enterprise-grade isolation&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>This is why governance matters!&nbsp;<\/p>\n\n\n\n<p>For example:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Microsoft Copilot for M365<\/strong>&nbsp;uses the Microsoft Graph with strong tenant boundaries.&nbsp;Basically,&nbsp;your&nbsp;data stays&nbsp;as&nbsp;your data. No training, no leakage, no data going for a walk into a different tenant<\/li>\n\n\n\n<li><strong>Public ChatGPT<\/strong>&nbsp;(free or&nbsp;Plus) is consumer-grade, which means content may be stored,&nbsp;reviewed&nbsp;and used to improve models<\/li>\n\n\n\n<li><strong>ChatGPT Team\/Enterprise<\/strong>&nbsp;has stronger controls but still requires clear data handling rules<\/li>\n\n\n\n<li><strong>Unapproved AI tools<\/strong>&nbsp;(the shadow IT kind)&nbsp;turn \u201cwe didn\u2019t know\u201d into&nbsp;a very expensive&nbsp;sentence&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Without governance, sensitive information can slip into systems that were never meant to hold it. And once&nbsp;it\u2019s&nbsp;in,&nbsp;you\u2019re&nbsp;relying on the vendor\u2019s goodwill and privacy policy and&nbsp;let\u2019s&nbsp;be honest, those documents are written in a dialect only lawyers and ancient Sumerians understand.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Big Governance Checklist: Because Hope Is Not a Strategy<\/h2>\n\n\n\n<p>Governance&nbsp;isn\u2019t&nbsp;about stopping people from using GenAI\u2026it\u2019s about making sure they can use it safely without causing a data breach so catastrophic that your CISO moves to a remote farm and raises alpacas.&nbsp;<\/p>\n\n\n\n<p>Here\u2019s&nbsp;what&nbsp;organisations should consider&nbsp;putting in place:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A&nbsp;clear GenAI&nbsp;acceptable&nbsp;use&nbsp;policy\n<ul class=\"wp-block-list\">\n<li>Basically, your&nbsp;users need to know what they can and&nbsp; can\u2019t upload into GenAI platforms and have a clear understanding of what platforms are approved for use&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data&nbsp;classification &amp;&nbsp;labelling&nbsp;that&#8217;s&nbsp;actually&nbsp;used&nbsp;\n<ul class=\"wp-block-list\">\n<li>If your organisation has a classification framework that nobody remembers, now is&nbsp;a great time&nbsp;to dust it off and make it simple enough for humans&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Technical&nbsp;controls\n<ul class=\"wp-block-list\">\n<li>So&nbsp;this is your DLP and label controls, approved and unapproved GenAi platforms, shadow IT\u2026and the list goes on.&nbsp;Basically, policies&nbsp;without the technical controls&nbsp;is&nbsp;just expensive poetry&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vendor&nbsp;assessment &amp;&nbsp;transparency\n<ul class=\"wp-block-list\">\n<li>Sit the vendor down in a room and interrogate them about their platform.&nbsp;Don\u2019t&nbsp;leave until you have a clear understanding of where they store data, are prompts used for training the platform, data retention\u2026I could go on but you catch my drift&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Human&nbsp;oversight\n<ul class=\"wp-block-list\">\n<li>AI&nbsp;isn\u2019t&nbsp;Neo or The Oracle\u2026so everything it&nbsp;produces must be reviewed by humans. And&nbsp;don\u2019t&nbsp;ask it for financial advice unless you are sure that the Caymen Islands account&nbsp;it suggests&nbsp;is&nbsp;legitimate&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Protecting Sensitive Data (If Legal Would Panic,&nbsp;Don\u2019t&nbsp;Paste It)&nbsp;<\/h2>\n\n\n\n<p>Let\u2019s&nbsp;talk about the stuff that keeps CIOs awake at night:&nbsp;sensitive data leakage.&nbsp;GenAI&nbsp;platforms&nbsp;become a risk when employees paste things like:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Customer PII<\/li>\n\n\n\n<li>Financial forecasts<\/li>\n\n\n\n<li>Legal documents<\/li>\n\n\n\n<li>The&nbsp;blueprint to the next generation Android phone&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>So,&nbsp;what can you do to avoid this from happening in your organisation?&nbsp;&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Implement AI DLP&nbsp;policies\n<ul class=\"wp-block-list\">\n<li>Purview&nbsp;DLP can detect sensitive content&nbsp;being uploaded into&nbsp;Gen AI platforms. The catch\u2026you just need to&nbsp;determine&nbsp;what is sensitive data.&nbsp;It&nbsp;doesn\u2019t&nbsp;just automagically&nbsp;just happen. DLP (aka the gatekeeper) needs to know what to look for<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Use Purview&nbsp;sensitivity&nbsp;labels&nbsp;everywhere&nbsp;(where possible and&nbsp;where&nbsp;supported by your friendly neighbourhood IT guy)\n<ul class=\"wp-block-list\">\n<li>Labels follow data even when used in Copilot prompts\u2026which means your AI assistant&nbsp;won\u2019t&nbsp;surface restricted data to the wrong person.&nbsp;So no, a prompt of \u201cwhat&nbsp;is the salary of our CEO\u201d will surface absolutely nothing\u2026if labelled correctly<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Provide an&nbsp;approved,&nbsp;secure AI&nbsp;environment\n<ul class=\"wp-block-list\">\n<li>Just because the site has a .ai domain,&nbsp;doesn\u2019t&nbsp;mean&nbsp;it\u2019s&nbsp;safe and approved!&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Educate,&nbsp;educate&nbsp;and educate some more\n<ul class=\"wp-block-list\">\n<li>Even the best controls will fail if Bob from Finance&nbsp;uploads&nbsp;a spreadsheet labelled \u201cQ4 Salaries \u2013 Do Not Share\u201d<\/li>\n\n\n\n<li>Training should include:\n<ul class=\"wp-block-list\">\n<li>What\u2019s&nbsp;acceptable to&nbsp;upload<\/li>\n\n\n\n<li>What\u2019s&nbsp;never acceptable<\/li>\n\n\n\n<li>How to verify outputs<\/li>\n\n\n\n<li>How to detect hallucinations<\/li>\n\n\n\n<li>How to report AI misuse&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>If you&nbsp;don\u2019t&nbsp;train your&nbsp;users,&nbsp;don\u2019t&nbsp;be surprised when someone tries to get ChatGPT to write next year\u2019s board strategy paper using actual board data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">In Closing: Do This Right and&nbsp;You\u2019ll&nbsp;Sleep Better<\/h2>\n\n\n\n<p>GenAI&nbsp;isn\u2019t&nbsp;going away. If anything,&nbsp;it\u2019s&nbsp;accelerating like someone strapped a rocket engine to&nbsp;Clippy&nbsp;and yelled, \u201cGood luck, mate!\u201d Organisations that use it responsibly will innovate faster,&nbsp;operate&nbsp;smarter, and leave competitors behind so dramatically&nbsp;you\u2019d&nbsp;think they were still arguing over who gets to use the office fax machine.&nbsp;<\/p>\n\n\n\n<p>Those who ignore governance?&nbsp;<\/p>\n\n\n\n<p>Well\u2026let\u2019s&nbsp;just say the Privacy Commissioner has cancelled their lunch plans, brewed a family\u2011sized thermos of chamomile tea, and is&nbsp;absolutely ready&nbsp;to have a&nbsp;\u201cfriendly little chat\u201d&nbsp;about your organisation\u2019s creative approach to data handling. Bring biscuits.&nbsp;You\u2019ll&nbsp;need them.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.insentragroup.com\/nz\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">Contact us<\/a>\u00a0to design a secure, practical governance framework tailored to your organisation.\u00a0<\/p>\n\n\n\n<p>Or accelerate your journey with our\u00a0<a href=\"https:\/\/www.insentragroup.com\/nz\/services\/generative-ai-series\/sprint-1\/\" target=\"_blank\" rel=\"noreferrer noopener\">Generative AI Sprint<\/a>, where we help you rapidly assess risk, define guardrails, implement\u00a0controls\u00a0and unlock value from GenAI with confidence.\u00a0<\/p>\n\n\n\n<p>And remember:&nbsp;<\/p>\n\n\n\n<p><strong>&#8220;The future depends on what you do today.&#8221; \u2014 Mahatma Gandhi<\/strong>&nbsp;<\/p>\n\n\n\n<p>Until next time\u2026&nbsp;<\/p>\n\n\n\n<p>Pure Awesomeness signing off!&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GenAI boosts productivity but increases risk. Learn how to govern AI use and protect sensitive data the right way. <\/p>\n","protected":false},"author":52,"featured_media":39705,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[295],"tags":[],"class_list":["post-39702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-generative-ai","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/39702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/comments?post=39702"}],"version-history":[{"count":2,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/39702\/revisions"}],"predecessor-version":[{"id":39707,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/39702\/revisions\/39707"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media\/39705"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media?parent=39702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/categories?post=39702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/tags?post=39702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}