Is monitoring AI prompts a privacy violation or security necessity?
Legal is pushing us to start logging ai prompts company wide. The security half of my brain gets it, we had an incident where someone pasted a whole board deck into some random ai tool and we only found out because that tool got breached months later.
But logging every prompt feels like reading peoples diaries. A lot of what folks ask ai is personal, even on work machines. Idk where the line is and I’m the one recommending an approach to the CISO this Friday.