# AI Security Quick Reference Card

## Data Classification Tiers

| Tier | AI Rule | Examples |
|------|---------|----------|
| **PUBLIC** | Full AI use OK | Marketing, job posts, published research |
| **INTERNAL** | Approved tools only, no training | Meeting notes, timelines, internal comms |
| **CONFIDENTIAL** | Isolated AI only, no external | Financials, strategy, pricing |
| **RESTRICTED** | No AI without exec approval | M&A, IP, PII, PHI |

---

## Vendor Checklist

- [ ] Do you train on customer data? (Must be NO)
- [ ] Where does data reside? (Your region, deleted after use)
- [ ] Who accesses prompts/outputs? (Only our users)
- [ ] Certifications? (SOC2 Type II, ISO 27001, HIPAA if needed)
- [ ] Breach response? (Immediate notice, defined SLAs)

---

## Red Flags to Watch

- Employee using personal AI accounts for work
- "We may use aggregated data to improve models"
- AI vendor without SOC2 or equivalent certification
- No AI tools on your sanctioned list (means shadow AI)
- Vendor requires "trust and safety" access to your data
- AI-generated code deployed without human review

---

## Block / Gate / Allow

```
BLOCK: Restricted data, unvetted tools, personal accounts
GATE:  Confidential data + approved tools + review workflow
ALLOW: Public/internal data + approved tools + light monitoring
```

---

## Emergency Escalation

**AI Data Exposure Suspected:**
1. Do not use the tool further
2. Document what data was shared
3. Contact: CISO / Security Team
4. Legal hold may be required

**Incident Response:**
- Security hotline: [YOUR NUMBER]
- CISO direct: [YOUR CONTACT]
- Legal/Compliance: [YOUR CONTACT]

---

## Monday Morning Question

> "Can you show me every AI tool our employees used last month and what data they put into it?"

---

*Pocket Card | AI Security for Leaders | v1.0*
