A manager asks an employee to use the organisation’s approved AI tool to summarise a sensitive document before a meeting.
The request is legitimate. The deadline is close. The tool has already been approved, and the employee has used it successfully for other tasks.
They open the document, bring up the tool and prepare to attach the file.
Then they pause.
There is no obvious policy breach. Nobody is asking them to bypass a control or use an unapproved account. The instruction has come from someone with the authority to give it, and using the tool would save time when time is genuinely limited.
But the document contains information about another person. Its details are sensitive. The summary could shape how that person is discussed in the meeting and what happens afterwards.
The employee knows they are allowed to use the tool. What they cannot tell, at least not immediately, is whether using it in this particular way would be appropriate, proportionate and fair.
That is where digital ethics begins at work: not when somebody deliberately breaks a rule, but when the rule has taken the decision as far as it can.
Approval does not settle every use
Policies are essential. They create boundaries, restrict harmful practices and give people a reliable starting point. Without them, employees would have to make fundamental decisions about security, privacy and acceptable use every time they opened a digital tool.
But policies normally govern categories.
They can approve a platform, define who may access it, restrict certain information and require human review. They can say that confidential material must be handled carefully or that AI outputs must not be treated as automatically correct.
Real work happens in more specific combinations.
The question facing the employee is not simply whether the organisation permits AI. It is whether this document needs to be processed in full, whether the information within it is necessary for the task, how the summary will be used and what may happen if important context disappears.
A policy can tell someone that an approved tool is available. It cannot decide every future use of that tool in advance.
That gap is not necessarily a failure of policy. It is a feature of work that changes faster and contains more variation than any rulebook can capture. Digital ethics helps people reason through the part that remains.
The employee is not thinking about abstract principles. They are trying to prepare something useful before a meeting.
The document is long. The manager needs the key points. The AI tool can produce them quickly. Every signal in the situation points towards using it.
That matters because the decision does not feel risky. It feels efficient, helpful and aligned with what the organisation expects.
Pausing may feel harder to justify than proceeding. The tool is approved, the request is real and the meeting will not move itself. Asking whether the use is fair may sound excessive when everybody else sees a straightforward administrative task.
The pressure does not need to be dramatic to shape the decision. A deadline, a familiar tool and a legitimate request are often enough. Together, they create a convincing line of reasoning: the organisation approved the tool, the manager asked for the summary and the output will help the meeting, so using it must be acceptable.
Most of the time, shortcuts like this allow work to continue efficiently. People rely on familiar tools, trusted colleagues and established processes because they cannot reconsider every decision from first principles.
The problem appears when a reliable shortcut is treated as a complete answer in a situation where something important has changed.
Here, the tool may be familiar, but the information is more sensitive. The task may be routine, but the output could influence a consequential discussion. The manager’s request may be legitimate, but the person described in the document is not part of the decision about how their information is processed.
Nothing about the employee’s reasoning is careless. The decision simply contains more than the immediate task makes visible.
Who receives the benefit, and who carries the consequence?
Uploading the document takes seconds. The effects may continue long after the meeting.
The employee saves time. The manager gets a shorter version to work from. The organisation benefits from faster preparation.
The person described in the document may experience something else entirely.
A grievance, complaint, safeguarding record, performance discussion or client concern often contains uncertainty, disagreement and context. People explain events in different ways. Details that appear minor may show why something happened or why a person responded as they did.
A summary removes detail by design. That is what makes it useful.
It is also what makes the use ethically significant.
The generated version may become cleaner and more confident than the source material. Contradictions may be compressed. Uncertainty may sound settled. Comments made in one context may appear to stand alone. Information included for one purpose may be reused for another.
The summary may then shape the meeting. The meeting may shape a record. The record may influence a later decision.
The employee who uploaded the document may never see that full chain. The person affected by it may not know that AI was involved, what information was included or which details were lost. They may have no realistic opportunity to correct the interpretation before it begins influencing other people.
Digital tools can increase the reach, speed and persistence of an ordinary decision while separating the person taking the action from the person living with its consequences.
That distance matters.
The ethical question is not only whether the organisation gains a useful summary. It is whether the convenience gained by one group creates an unseen burden for another.
Start with the purpose, not the tool
The employee cannot judge whether the use is necessary until the task is more precise.
“Summarise this before the meeting” sounds clear, but it can describe several different needs.
Perhaps the manager only needs a chronology. Perhaps they need the actions already taken, the issues still unresolved or a list of questions to explore. Perhaps the meeting requires a careful understanding of the whole account, including its ambiguity and surrounding context.
Those are not interchangeable tasks.
If the purpose is to extract dates and agreed actions, the full document may not need to be uploaded. Selected passages could be sufficient. Names and unrelated personal details may add nothing.
If the purpose is to understand somebody’s experience, conduct or credibility, reducing the document to a generated summary may be much harder to justify. The details removed may be central to a fair reading of what happened.
Purpose changes what information is necessary. It also changes the level of review the output requires.
Responsible use cannot begin with the question, “What can the tool do?”
It has to begin with, “What does the work actually need?”
Once that is clear, the organisation can consider whether the proposed use is proportionate. Processing an entire sensitive document because it is quicker than selecting the relevant sections may be convenient, but convenience alone does not make the additional use of information necessary.
The more sensitive the material and the greater the influence of the output, the stronger the justification should be.
Accuracy is only part of fairness
Much of the discussion around AI-generated content focuses on whether the output is correct.
That is important, but a summary can contain no obvious factual error and still create an unfair impression.
Imagine that the source document contains five pages describing a difficult workplace incident. It includes uncertainty about the sequence, an explanation of the pressure the person was under and a disagreement about what a manager had previously instructed them to do.
The generated summary may accurately state the final action without preserving the conditions surrounding it. Nothing in the sentence is false. Yet the shorter account may make the action look more deliberate, isolated or unreasonable than it appeared in the original.
This is not merely a technical problem with AI. Any act of summarising involves selection. The ethical concern is that generated text can hide that selection behind fluent, confident language.
A polished output does not show the reader which details were difficult to reconcile, what the tool treated as unimportant or where the original remained ambiguous.
Meaningful human review therefore requires more than checking that the summary looks right.
The reviewer needs the original document, enough understanding of the situation and the authority to question what the summary has emphasised or left out. They need to look for missing context, false certainty and changes in tone, not only incorrect facts.
Most importantly, somebody must remain responsible for what happens next.
AI may assist with preparing the material. It cannot take responsibility for how a person is represented, how the summary is interpreted or what decisions are made because of it.
The employee should not carry the whole judgement alone
The person about to upload the document has an immediate responsibility. They need to notice that tool approval does not answer every question about the use in front of them.
But the organisation has already shaped the decision.
It selected the tool, decided how staff would be encouraged to use it and created the guidance available when uncertainty appeared. The deadline, the manager’s request and the speed of the approved route all influence whether pausing feels responsible or obstructive.
Telling employees to “use their judgement” may sound empowering. In practice, it can leave them carrying a difficult decision without agreed criteria, sufficient authority or access to timely advice.
If staff are expected to use AI with sensitive information, they need more than a general reminder to be careful.
They need to understand what should be removed, when the original needs to remain central, what level of review is expected and who owns the decision when the answer is not obvious.
Otherwise, the organisation approves the technology while leaving responsible use to improvisation.
One way to test the reasoning is to imagine explaining the decision to the person whose information is involved.
The organisation should be able to say why the tool was used, what the meeting required and why that amount of information was necessary. It should be able to explain how the material was protected, how the output was checked and who remained responsible for the judgement that followed. There should also be a realistic way to correct an error or restore missing context before the summary causes further harm.
Not every internal process can or should be disclosed in full. Confidentiality, legal duties and the rights of other people may place sensible limits on what can be shared. Even so, the exercise exposes weak reasoning quickly.
Saying that the tool was approved explains permission. Saying that the deadline was close explains pressure. Saying that the manager requested it explains authority.
None of those, on their own, explains why this particular use was necessary, proportionate or fair.
A defensible decision should make sense from the perspective of the person carrying its consequences, not only from the perspective of those receiving the convenience.
Before the upload button
The employee does not necessarily need to refuse the task. They need to slow the decision down just enough to make the purpose and responsibility clear.
The first conversation may be simple:
“What do you need from this document for the meeting?”
That question could reveal that only a timeline or a small set of actions is required. The employee may be able to extract those from selected passages without processing the full document.
Information that does not contribute to the purpose should not be included simply because uploading everything is easier. Names, contact details, references to unrelated people and case-specific information may be removable, although deleting a name does not automatically make material anonymous. The remaining circumstances may still identify the person.
The employee should also ask how the output will be used.
A rough working aid that will be checked carefully against the original presents a different level of concern from a summary that will become the main account used in a formal meeting.
Where the output may influence employment, care, safeguarding, discipline, access, reputation or legal rights, the original material should remain visible and the level of review should reflect the possible consequence.
If the employee cannot confidently decide what is necessary, the judgement should move to someone with the authority and context to own it. Depending on the situation, that may be the manager responsible for the outcome, the document owner, HR, a safeguarding lead or an information-governance specialist.
The title matters less than the fact that the route is clear, available and quick enough to use.
An escalation process that takes several days is little help when the meeting begins in twenty minutes.
Organisations do not need a separate policy for every document and every possible AI use. They do need to understand where uncertainty appears in their own work.
A broad instruction such as “do not share sensitive information unnecessarily” may be accurate, but it leaves the hardest word unresolved: unnecessarily.
What counts as necessary depends on the purpose, the information, the people affected and what the output will influence.
Practical guidance should therefore use the situations staff already face: complaints, employee records, client reports, meeting transcripts, safeguarding information, performance discussions and internal investigations. Those examples can show where using an AI tool may be reasonable, where only selected material should be processed and where summarisation is too likely to remove context that matters.
The organisation also needs to decide what human review means in each situation. For routine, low-impact assistance, a straightforward check may be sufficient. For material that could affect another person significantly, review must be closer, better informed and clearly owned.
Technical controls can help. Approved environments, access restrictions, retention settings and warnings around sensitive information can reduce some of the burden on employees.
But controls cannot replace judgement entirely. Nor should the organisation pretend that judgement belongs only to the person using the tool.
Managers shape whether staff feel able to pause. Processes shape whether a safer route is practical. Deadlines shape whether advice can be sought. Leadership signals shape whether responsible challenge is welcomed or treated as delay.
A useful review would begin with a handful of real tasks involving an approved AI tool. For each one, the organisation can ask what the task requires, what information is genuinely needed, who may be affected, how the output will be checked and who owns the final judgement.
That conversation may reveal that the main problem is not a missing rule. It may be unclear responsibility, weak examples, unrealistic expectations about redaction, insufficient review or a process that gives people no workable route when permission stops being a complete answer.
Training matters here too.
Traditional training often concentrates on firm instructions: use approved tools, do not enter restricted information, check generated outputs and follow the policy.
Those instructions matter. They are also easiest to apply when the situation is obvious.
The harder decision comes when the tool is approved, the task is legitimate and the ethical concern sits inside the particular use.
People need opportunities to work through those moments before they face them under real pressure. They need to examine how a sensible shortcut can affect somebody beyond the immediate task, how a summary can alter meaning without containing a clear factual error and when a decision has moved beyond their authority.
They also need confidence that raising the question is part of doing the job properly.
The aim is not to make people hesitant about every digital tool or turn routine work into a philosophical debate. It is to help them recognise the point at which efficiency, responsibility and fairness need to be considered together.
From permission to justification
The employee in the opening moment should not upload the whole document simply because the tool is approved and the deadline is close.
They should clarify what the meeting needs, use no more information than that purpose requires and consider how the resulting summary may affect the person represented within it.
The output should be checked against the original by somebody who understands the context and remains responsible for what follows.
Where the use still cannot be confidently justified, the decision should move to someone authorised to own it.
That is the difference between permission and justification.
Permission asks whether the organisation allows the tool to be used.
Justification asks whether it should be used in this way, with this information, for this purpose and with these possible consequences.
Policies can establish the first.
Digital ethics helps organisations answer the second.
When that answer is clear, the employee has more than approval. They have a decision that can be explained and defended.
When it is not, the work is not yet ready for the upload button.
Director of Training and Development, Cyber Rebels.
Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure.
With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices.
He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments.
Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.