A data boundary is the explicit rule stating which categories of information may and may not be placed into an AI system. It is the single most useful governance artefact for staff, because it converts an abstract instruction to be careful into a list they can actually check against.
Why it matters for a UK business
It is the first governance decision worth making, and the one that resolves most of the others. Once you have decided what a model may and may not see, the policy, the tool choice and the training all follow from it.
What it looks like in practice
A written line between data a model may see and data it may not, with the reasoning. Client contracts, yes, in the governed tool. Payroll, never, anywhere. Anything under NDA, only in a zero-retention arrangement.
What to do about it
Draw it before deploying anything, and make it specific enough that a new starter could apply it without asking. Then confirm the vendor arrangement in writing rather than assuming the tier you bought gives you the boundary you want.
Related terms
Read next
Where your AI data is actually stored → · All 22 terms in the glossary · The resource library
If this is the term that has come up in your business and you want it worked through against your own situation rather than in the abstract, that is a conversation, not a page.
Speak to ChrisWritten by Chris Duffy. Last reviewed .