What in your work is Crown Jewels?
Now that you've seen what AI sees, where it gets things wrong, and how confidently it fabricates: which of your data assets must never cross that boundary? Drag-and-drop your work assets into four boxes — Crown Jewels, Sensitive, Operational, Public. Get a one-page classification policy emailed to yourself.
Your one-page AI data classification policy
What are "Crown Jewels", and why does this matter for AI?
Not all your data is equally dangerous to lose.
"Crown Jewels" is the security idea that a small slice of what you hold is worth far more — and is far more damaging if it leaks — than everything else. A published price list leaking costs you nothing. A client's NRIC, fact-find, or source-of-funds documents leaking can end a relationship, breach the law, and put your licence at risk. The job is to know which is which before you act.
Why a free AI tool changes the stakes.
When you paste text into a free or consumer AI service, that text leaves your control. It may be stored, used to train future models, or simply held on someone else's servers under terms you never read. For most working material that's a non-issue. For Crown Jewels, it is a PDPA breach waiting to happen — exactly how Samsung leaked its own source code in 2023.
The four tiers.
Crown Jewels never touch a free AI tool — full stop. Sensitive data can be used only after you strip the identifiers (de-identify first). Operational material is generally fine for AI help, as long as no client data has crept in. Public data is free to use anywhere.
The test that always works.
Before pasting anything in, ask: does this identify a specific person, bind someone legally, or breach a duty if it leaks? If yes — it's Crown Jewels. The policy this tool generates is just that question, written down for your own role.