hansun

architects
返回知識文章
AI Workflow

AI 工作流的資料安全與著作權:先把風險拆開,再決定怎麼用

把「資料會不會外流」和「內容能不能用」分開看,就能少踩雷。本文用常見工作流程示範:從上傳資料、提示詞、模型選擇到留存紀錄,給你可落地的做法與限制。

2026-08-05
HanSun Architects | AI Workflow Handbook
Contents

目錄

01Identify the risk before selecting a tool
02Classify information before uploading it
03Use the minimum information required
04Ask three copyright questions
05Example: an AI-assisted tender presentation
06Build review into the workflow
07Common mistakes
08Limits and professional advice
09A practical next step
10References
Chapter 01

Identify the risk before selecting a tool

For data security, ask whether information may be stored, used for service improvement, accessed by another party or exposed through an internal mistake.

For copyright, ask whether you have the right to use the source material, whether the output can be used commercially and whether attribution or additional permission is required.

A secure transfer does not create copyright permission. A licensed source does not make it appropriate to upload confidential project data.

Chapter 02

Classify information before uploading it

Use a simple three-level model.

1. Public information

Published web pages, public specifications and material already approved for external release generally carry lower confidentiality risk.

2. Internal but non-confidential information

Working sketches, meeting notes and unpublished design versions need a defined workflow. Remove unnecessary identifiers and confirm which AI service and account type may be used.

3. Confidential or protected information

Client contracts, tender documents, personal data, detailed costs, negotiation positions and professional seals should not be uploaded by default.

The issue is not that every AI service will leak data. The issue is that a project team cannot make a blanket guarantee for every provider, integration, account and retention setting.

Chapter 03

Use the minimum information required

When AI is used to summarize regulations, prepare a presentation outline or organize interview notes, reduce the exposure surface.

  1. 01Provide a summary instead of the original file whenever possible.
  2. 02Replace names, sites and budgets with neutral codes.
  3. 03Define a reproducible output, such as a checklist with source fields.
  4. 04Use an approved account or enterprise environment where required.
  5. 05Set a retention rule for conversations, files and generated artifacts.

Prompts are data too. Typing confidential design details, client contact information or cost strategy into a chat is still disclosure, even when no file is attached.

Chapter 04

Ask three copyright questions

Do you have the right to use the input?

Uploading another designer's image, report or drawing may require permission. “It was available online” is not a complete rights analysis.

Can the output be used for this purpose?

Platform terms, source licenses and local law may differ. Internal discussion, public publication, tender submission and commercial sale are not equivalent uses.

What will a responsible reviewer need to verify?

Before external use, the team should be able to identify the source, responsible reviewer, material changes and approval decision.

Chapter 05

Example: an AI-assisted tender presentation

Suppose a team wants AI to generate narrative structure, captions and key messages.

A controlled workflow can look like this:

  1. 01AI proposes the presentation structure and alternative wording.
  2. 02Drawings, numbers, images and quotations come from original or licensed sources.
  3. 03A person reviews every page before external release.
  4. 04The team records the source and reviewer for critical claims.

This creates evidence of process if a client or partner later asks how the material was prepared.

Chapter 06

Build review into the workflow

Compliance work becomes slow when all project information is sent into one step and reviewed only at the end.

A more efficient approach is to use AI for repeatable, lower-risk work; keep high-risk material in controlled systems; and use prompt templates that specify the required sources, uncertainty labels and approval points.

The team then spends time reviewing focused risks rather than rebuilding the entire deliverable.

Chapter 07

Common mistakes

  1. 01Treating typed prompts as harmless. Text can contain the same confidential information as a file.
  2. 02Assuming a plausible output is compliant. Fluent language is not evidence of permission or accuracy.
  3. 03Using one rule for every data class. Public references and client contracts require different controls.
  4. 04Ignoring account and retention settings. Provider, plan, workspace and integration choices affect the data path.
  5. 05Failing to document external use. Public and commercial material needs a source and review trail.
Chapter 08

Limits and professional advice

No responsible workflow should promise that information “can never leak.” Risk depends on provider policy, technical settings, internal access and actual behavior.

Contractual and copyright questions also vary by jurisdiction and use. For material legal decisions, consult qualified counsel. AI can help organize questions; it should not provide the final legal conclusion.

Chapter 09

A practical next step

List the AI uses already present in your organization. For each one, record:

  • -data class: public, internal or confidential;
  • -use: internal, external or commercial;
  • -approved service and account;
  • -human review point;
  • -retention and deletion rule.

This small inventory moves the organization from informal use toward a manageable workflow.

AI is an accelerator. It is not a release from responsibility.

---

延伸主題

把建築與室內設計 AI 轉成可落地的工作流程

想從這篇文章繼續走向實務,可查看建築與室內設計 AI 課程,或認識顏世倫的建築、設計與 AI 教學經歷。

Official LINE

加入 HanSun Architects 官方 LINE

想收到新的知識文章、課程資訊或設計工作流整理,可以加入官方 LINE。文章延伸問題也建議從官方帳號進入,避免資訊分散。

加入官方 LINE

提醒:官方 LINE 僅提供課程、設計諮詢與文章延伸交流。請勿傳送信用卡完整卡號、一次性密碼、帳戶密碼或與本服務無關的大量訊息;HanSun Architects 不會透過 LINE 主動要求轉帳或索取密碼。

HanSun Architects 官方 LINE QR Code