The article we published on the U.S. v. Heppner attorney-client privilege ruling last week told small business owners about the problem: AI chatbot conversations are not privileged, uploading a lawyer's advice into an AI tool can waive the privilege on the underlying advice, and consumer AI tools should not receive substantive business data.
The natural follow-up question: what should the policy actually look like? What can go where?
This article is the operational framework — the classification system that turns “don't put sensitive stuff in AI tools” into something a real employee can actually apply on a Tuesday. It's four tiers of data, mapped to which AI tools each tier can go to, written down as a one-page document that becomes the AI-use policy for the business.
The classification takes an afternoon to write and prevents most of what the Heppner article warned about. It's the single highest-leverage compliance action a small business can take on AI tool use.
The four tiers
Almost every business's data sorts cleanly into one of these four categories.
Tier 1 — Public
Definition: Information already public or that you would publish without hesitation.
Examples: Marketing copy, published content, blog posts, public filings, publicly-available research, questions that don't reference proprietary data.
Where it can go: Any tool, including consumer AI tiers. No legal consequence from disclosure.
Practical: Most productivity value from AI lives here. Drafting a blog post, summarizing a public article, generating marketing copy — all Tier 1, all fine on consumer tools.
Tier 2 — Internal
Definition: Business information that isn't secret but that you would not hand to a competitor.
Examples: Draft business plans, internal memos, pricing analyses that don't include customer specifics, ordinary internal correspondence, non-sensitive employee communications, general operations questions using anonymized examples.
Where it can go: Only tools under business terms with training disabled and retention bounded, on a company-administered account. Consumer tiers should not receive Tier 2 material.
Practical: This is where most everyday AI-assisted work sits — drafting an internal memo, brainstorming a sales approach, analyzing a business decision. Business-tier AI subscription for the company, not employee personal accounts.
Tier 3 — Confidential
Definition: Information you are obligated to protect.
Examples: Material under an NDA, client and customer data, personal information of employees and customers, financial records, unreleased product information, anything you would call a trade secret.
Where it can go: Business terms + a data processing agreement listing subprocessors + verification that whatever contract governs the data permits AI vendor disclosure. Chapter 5 of the forthcoming book covers vendor terms; existing client and vendor contracts often need to be checked.
Practical: If a client's engagement letter prohibits sharing client information with third parties (most professional-services engagement letters do), then even a business-tier AI tool is a third party under that engagement. Verify contract permits it before using.
Tier 4 — Restricted
Definition: Privileged communications and attorney work product; protected health information; nonpublic financial information covered by GLBA; biometric data; credentials and security information; material under a protective order or litigation hold; and anything whose disclosure would itself be a reportable event.
Where it can go: Only under an agreement specifically authorizing the use — a BAA for PHI, an enterprise or zero-retention agreement for privileged material with the tool used at counsel's direction, a documented exception approved by whoever owns the risk. Absent that, it does not go into any AI tool.
Practical: For most small businesses, Tier 4 material simply does not enter AI tools. Full stop. The rule is stated that way in the policy: “Tier 4 material is not entered into AI tools.”
What actually goes wrong: five patterns to recognize
Understanding the tiers is the analytical framework. Recognizing the patterns is what changes employee behavior.
Pattern 1 — The deal document. A founder uploads a term sheet, an acquisition letter of intent, or a draft contract to ask what's standard. The document is under an NDA with the counterparty. The upload is a breach — express if the NDA has an AI clause, implied otherwise. Fix: ask the question without the document, or use a tool the NDA permits.
Pattern 2 — The client ledger. A bookkeeper or accountant uploads a client's general ledger, bank statements, or tax documents to find an error or draft a summary. The data is confidential under the engagement letter, potentially GLBA-covered, potentially subject to state privacy law. Fix: business-tier tool under a DPA and an engagement letter that permits it.
Pattern 3 — The recorded meeting. An AI note-taker joins a call, transcribes, and summarizes. The transcript contains confidential and potentially privileged information. In all-party consent states, the recording itself may be unlawful without notice. Fix: notice at the start of every recorded call, business-tier tool, no privileged conversations recorded.
Pattern 4 — The medical visit. Ambient documentation tools listen to clinical encounters and draft notes. Audio and transcript are PHI; vendor is a business associate under HIPAA. Without a BAA, the arrangement is a HIPAA violation from the first visit. California and other states additionally require patient disclosure of generative AI use. Fix: BAA, disclosure, retention terms matching obligations.
Pattern 5 — The personal account. Every scenario above becomes worse when the tool is on an employee's personal account. Consumer terms govern. Training may be on by default. The business has no DPA, no right to the data, no ability to delete anything. Fix: prohibit personal AI accounts for business data, in writing, with the reason stated.
The one-page classification document
The policy artifact this framework produces is short. A page of text, roughly, that any employee can read in five minutes:
Structure:
- Tier definitions (one paragraph each) with examples specific to your business
- Approved tools by tier — a list of which AI tools may receive each tier of data
- The personal account rule — no personal accounts for business data
- The legal work rule — privileged material only at counsel's direction, on a specifically-authorized tool
- What to do if unsure — who to ask when the tier is unclear
Attach the classification to the broader AI-use policy the business maintains. Reference both in employment agreements and independent contractor agreements.
The training that actually works
Written policy without belief change doesn't survive contact with a busy Tuesday. Employees who believe uploads don't matter will not follow a policy that says they do.
The training that works is short (twenty minutes, once, for everyone who touches company data) and specific:
- Explain the assumption employees typically hold (“nobody looks at what I upload”) and why it's wrong.
- Walk through the Heppner case as a concrete example of how litigation reaches AI conversations.
- Present the twenty-million-log leak incidents from major AI providers as examples of the disclosure risk.
- Hand out the tier chart with business-specific examples.
- Answer the “what about X” questions employees will actually ask.
Trainings that focus on policy compliance without belief change produce policy compliance in the moment and violations the next day when the policy is inconvenient.
The implementation sequence
Six steps to implement the framework in a small business:
- Write the four-tier classification with examples from your business. One page.
- Inventory current AI tool use. What tools are employees using? Personal accounts? Business subscriptions?
- Map tools to tiers. Which existing tools may receive which tiers? For any tier that doesn't have an approved tool, either acquire one or state that the tier stays out of AI.
- Move business use to business subscriptions. Company-paid, company-administered accounts on business or enterprise tiers.
- Prohibit personal accounts for business data. In writing.
- Train the belief. Twenty minutes, once, for everyone who touches company data.
Any small business can complete this in a week or two. The cost is trivial. The exposure reduction is significant.
When to consult counsel
Situations where attorney involvement is worth the fee:
- Businesses handling Tier 3 or Tier 4 data regularly (professional services, healthcare, financial services)
- Multi-state operations where regulatory frameworks vary
- Businesses in regulated industries (BAAs for healthcare, GLBA for financial services)
- Any incident where sensitive material has already been uploaded and needs triage
- Any AI-use policy that will govern significant employee behavior
The Silverton view: for businesses with any meaningful Tier 3 or Tier 4 exposure, an attorney-drafted or attorney-reviewed AI-use policy is much cheaper than the incident it prevents.
Frequently Asked Questions
How do I know which tier a specific document belongs in?
Ask two questions: Is this information public or would you publish it? (If yes, Tier 1.) Are you obligated by contract, statute, or professional rule to protect this information? (If yes, Tier 3 or 4 depending on the specific obligation.) Everything else — business information you wouldn't publish but aren't specifically obligated to protect — is Tier 2. Most everyday business data is Tier 2.
Can employees ever use their personal ChatGPT/Claude/Copilot for work?
Under this framework, no — not for anything above Tier 1. Personal accounts operate under consumer terms with different data-handling rules than business subscriptions. Even Tier 2 material shouldn't go to personal accounts. The policy should prohibit personal AI accounts for business data in writing, with the reason stated.
What tools qualify as “business tier with training disabled”?
Most major AI providers (OpenAI, Anthropic, Google) offer business or enterprise tiers with training disabled by default and various retention controls. Some smaller AI-native tools do; some don't. Verify by reading the vendor's data-handling terms — look for explicit “your inputs are not used for training” language plus retention terms you can set.
Does the classification apply to AI features embedded in tools I already use?
Yes. If your CRM has an AI summarization feature, that feature is an AI tool subject to the same classification. Same for AI features in email clients, document editors, accounting software, or any other business tool. Inventory these along with standalone AI tools.
What if a client's contract prohibits using AI tools on their data?
Then you don't use AI tools on their data — no matter what your own AI-use policy says. The client's contractual restrictions govern their data. This is why Tier 3 classification requires checking the governing contract, not just verifying the AI vendor's terms.
This article draws from the forthcoming Silverton Publishing book AI in Business and Law: A Practical Guide to Using Artificial Intelligence Without Getting Sued. It is general information only, not legal advice. AI compliance frameworks require adaptation to specific business circumstances; consult a qualified attorney for guidance on your specific situation. For ongoing updates on AI compliance developments after this article's publication, see silvertonpublishing.com/ai-current.
This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.