Confidentiality & the Classification Boundary
The one rule that matters most — and the redaction habit that keeps you on the right side of it.
The big idea
Here is the rule the whole course turns on: OFFICIAL information can be used with approved generative AI; OFFICIAL: Sensitive and above must never be entered into public AI tools. This is explicit in the DTA staff guidance and the PSPF Advisory. Because models retain (and sometimes train on) what you type, anything sensitive that goes in may be impossible to get back. The practical habit is redaction: strip names, numbers and capability detail before you ever paste.
Key insight: Ask yourself before every prompt: ‘Would I be content if this appeared in tomorrow's newspaper?’ If not, redact it, generalise it, or use your approved enterprise tool.
This is the rule that matters most
The classification boundary is the single most important habit in this course. Everything that follows — approved providers, vendor checks, incident response — exists to support this one line. When unsure of a classification, treat it as higher and ask your security advisor.
What you'll see
The classification boundary, and what redaction looks like in practice.
Staying on the right side of the line
What the boundary means in practice. Tap to expand.