Data security when using AI – 6 things to settle before putting company documents in

The biggest risk when using AI usually comes not from the technology but from habit: someone pastes a customer list or a contract into a tool nobody has vetted.
1. Classify your data
Split documents into three groups: public, internal, and sensitive (customers' personal information, finances, contracts). State clearly which group may go into which AI tool.
2. Read the tool's terms
Check whether the vendor uses the data you enter to train its models, how long it is kept, and whether you can turn that off. Free and business plans often differ on this point.
3. Use company accounts
Avoid letting staff use personal accounts for company work. Company accounts let you manage access and revoke it when someone leaves.
4. Mask personal information when it isn't needed
If the task doesn't require real names, phone numbers or emails, delete them or replace them with placeholders before giving the text to AI.
5. Limit what the AI is allowed to do
When AI is connected to email, spreadsheets or sales software, grant only the permissions it needs. Actions such as sending email outside the company or deleting data should have a human approver.
6. Write a short policy and train people
One easy-to-read page of rules is more useful than a long document nobody reads. Repeat it in training sessions and whenever new staff join.
This article is general guidance and does not replace legal advice. For customers' personal data, businesses should consult the personal data protection regulations currently in force.