Skip to content

What is safe to put into AI tools? How we approach it

Safe comes before fast. How B43 starts from your data and your compliance before bringing AI in, and the habits we teach so nobody has to guess.

Bryce Murray, PhD

Bryce Murray, PhD · Founder of B43

5 min read, September 2026

This is how B43 works with teams. It is not legal advice, and it does not replace your own policies, your counsel, or the terms of the tools you use.

Unsure what's safe

You're not sure what's safe to put into these tools. It is one of the pains we hear about, and it explains another one: people worry about getting it wrong, so they avoid trying at all. On a team, that fear does not stay private. It becomes the reason a whole team stays at the shallow end while the work that would actually benefit stays untouched.

The answer is not a longer list of forbidden things. It is a clear line, decided before the work starts, that everyone on the team can repeat.

Safe comes before fast

We start from what is safe for your data and your compliance, then bring AI in without breaking what already works. That order is deliberate. Building something impressive first and sorting out the rules later is faster, and it is how a team ends up with a workflow it cannot use.

So the first conversation is about the work, not the tools: what information the task actually touches, who it belongs to, what your policies and your tool agreements already allow, and which tools your team is approved to use.

Two commitments come straight from our engagement terms. We use your information only within tools and workflows approved for the engagement. And the work happens inside the AI platforms your team already approved, while the decision about whether those platforms suit your data, security, and compliance requirements stays with you.

The line, with a worked example

The clearest version of the line we use comes from our work with real estate agents, where the sensitive data has a name. The standing rule there: no protected MLS data ever goes into an AI tool. Every skill an agent builds runs on public links and sanitized numbers, so no protected data ever leaves their hands.

Your line will be different. It might be client files, patient records, contracts, or anything with a name attached. What matters is that it exists, that it was decided before the first prompt, and that everyone on the team can say it in one sentence. A rule people can repeat is a rule people follow.

One more step belongs at the start, not the end. Set up the privacy settings on the tools together, so no one's data is training anyone's model. It is a small thing to do once and a strange thing to leave to chance.

The sanitize-and-verify habit

Sanitize means the tool never sees the real thing when it does not need to. Shift the numbers, drop the names, keep the structure. The tool drafts from what is left.

Verify means nothing leaves your hands on trust. The trick we teach came from a working agent in our pilot session, who invented it himself: shift every number by the same amount, then check that the output shifts to match. If it does, the tool is working from your figures. If it does not, it isn't, and you found out before a client did.

The tool drafts. You verify. Everything client-facing carries your judgment.

Our engagement terms say the same thing in plainer language: AI systems may produce inaccurate, incomplete, or unexpected outputs, so human review comes before relying on AI-generated work for material business decisions. If you don't understand it, you don't send it.

It works in the other direction too. AIM Recycling brought AI into a spreadsheet the business relies on by asking it to review the work before replacing any of it: check the data against known rules, flag inconsistencies, surface anything that deserves a second look. The human still owns the judgment. Read the AIM Recycling case study →

What this looks like on a team

The safe way has to be the easy way, or it will not survive a busy week. That is where Standardize matters: a shared template, prompt, or process someone already built, with the sanitize step and the verify step written into it, so the output is consistent no matter who on the team produced it. The alternative is AI output nobody checked.

For teams in legal, insurance, and healthcare, this is the whole game: move forward without risking client data or compliance, and get more than your one approved tool can give. For everyone else it is simply how the fear of getting it wrong turns into a habit the team can trust.

To say it once more, plainly: this is how B43 works with teams, not legal advice. Legal, regulatory, compliance, and cybersecurity review or approval are outside what we provide, and they stay with your counsel and your security team. The approach above is built to sit inside their decisions.