AI · 4 min read

AI in your company, safely: where your data ends up

For every AI tool, ask three things: which data goes in, where it is stored, and who can reach it. Most problems don't come from the model, but from the fact that nobody asked these questions before rolling it out.

A server room — where company data actually ends up

For every AI tool, ask three questions: which data goes in, where it is stored, and who can reach it. Once you can answer all three before you let the tool near your documents, you have most of the security handled. Because most problems don’t come from the model “leaking” — they come from the fact that nobody asked these questions before rolling it out.

What to watch for when choosing a tool

A free chatbot and a business tool running the same model are not the same thing. The difference isn’t intelligence, it’s the terms. When choosing, look at three things in the fine print.

Is the model trained on your input? The free versions of many tools reserve the right to use whatever you type into them for further training. Business and paid plans usually turn this off — but you need it confirmed in the terms, not guessed.

Where does the processing physically run? Some providers offer processing in the EU, others send data to the US. For sensitive data this is a difference for a lawyer to weigh in on, not only a technician.

Is there a data processing agreement? A serious provider will sign a data processing agreement (DPA) with you. If they refuse it or don’t know what it is, that is itself an answer.

A practical rule: don’t put anything into a tool you have no contract with that couldn’t be public. Clients’ personal data, contracts, source code and internal figures belong only where you’ve read the terms.

Access and logging

Even a safe tool can be deployed unsafely. What matters is who sees what.

Stick to the lowest necessary access. An AI agent for processing invoices needs to see invoices — not the entire accounting system, and not payroll. The wider the access you grant, the larger the surface that can break or be abused.

The second thing is logging. When an automation processes an order, replies to a customer or pulls a value from a document, a record should remain of what it did and with which data. Without a log a problem can’t be traced, and in an audit you have nothing to show for what happened. A log is boring until you need it — and then it’s the only thing that saves you.

For sensitive steps, leave the decision to a human. AI prepares the material, a person approves it. Not because the model is dumb, but because someone has to bear responsibility for the decision.

What GDPR and the European AI regulation say

Two frameworks that concern you even if you’re not a large company.

GDPR applies whenever personal data goes into a tool — and that happens more often than companies think. An email address in an inquiry, a name on an invoice, a note about a client in the CRM. You need to know the legal basis on which you process it, how long it is retained, and whether the provider acts as a processor. Moving personal data into a tool without a contract is a breach regardless of whether anything “happened”.

The European AI regulation (AI Act) classifies systems by risk. Most common business automations — support, sorting inquiries, document processing — fall into lower categories with lighter obligations. Higher requirements arrive where AI makes decisions about people: hiring, employee evaluation, access to services. The obligations phase in gradually — bans on the riskiest practices apply from February 2025, rules for general-purpose AI models from August 2025, and most obligations for high-risk systems from August 2026. Before deploying, verify which category your solution falls into.

We are not a law firm and this is not legal advice. It’s a list of questions you bring to a lawyer already prepared.

A practical procedure

When you’re considering an AI tool or automation, go through these five steps in this order:

  1. Write down which data will go in. Specific fields, not “client data”. Only when you see it on paper can you judge how sensitive it is.
  2. Choose the tool by its terms, not by the demo. Training on input turned off, processing where you need it, DPA on the table.
  3. Set the lowest necessary access. Better to add access when it’s missing than to revoke it when it’s too late.
  4. Turn on logging and decide who checks the output. For sensitive steps, a human approves.
  5. Run a pilot on one process, with measurement. A small scope means small damage when something turns out differently than you expected.

Security with AI isn’t one big task, it’s an order of steps you don’t skip. Most of the companies that got burned didn’t do anything dramatic — they just started at step five.

← All insights
No strings, free

We do not start with a pitch, but with an audit.

We tell you where you lose money and what we would fix first in your place. Even if you then have it built elsewhere.

We reply within 24 hours.