Managing partner or operations director
“Staff are already pasting client data into ChatGPT and we have no policy”
Does this sound familiar?
- Employees use AI tools on work material with no guidance at all
- You want the productivity gains but cannot risk confidentiality obligations
- Nobody can answer where the data goes or how long it is kept
- A client contract or professional obligation restricts disclosure to third parties
- An AI pilot stalled because nobody could sign off the data question
What it costs to ignore
The exposure is already happening — staff adopt these tools regardless of policy, because they work. Doing nothing is not neutral: it means confidential material is leaving through consumer accounts with no contract, no audit trail and no retention control. For regulated or contractually bound firms, that is a disclosure problem that predates any project you approve.
How the engagement runs
- 1
Find out what is already happening
Which tools staff use, on what material, through which accounts. This is almost always more than leadership expects, and it establishes the real starting position.
- 2
Classify the data, not the tools
Some material can safely go to a frontier model under a business agreement. Some must never leave your network. The routing follows sensitivity, not convenience.
- 3
Provide a sanctioned path
Business-tier accounts with contractual exclusion from training, or self-hosted models for sensitive material. People stop using consumer accounts when a better sanctioned option exists.
- 4
Design against prompt injection
Content your AI reads is untrusted input. If it can also take actions or reach confidential data, that is an attack surface — so privilege separation and human confirmation on consequential actions are designed in.
- 5
Log it and write the policy
A record of what was asked, returned and acted on, plus a policy short enough that staff will actually read it.
The exposure is already live
By the time this question reaches leadership, staff have been using these tools for months. Not maliciously — because they work, and because the alternative is doing the task the slow way.
So “should we allow AI?” is the wrong question. The material is already leaving. The real question is whether it leaves through a channel you have a contract with, or through somebody’s personal account.
Classify the data, then route it
The useful distinction is not between tools. It is between kinds of material.
Routine internal work — drafts, summaries, general research — can safely use a frontier model under a business agreement with training exclusion and defined retention.
Confidential client material — privileged documents, personal information, anything under a contractual confidentiality obligation — either stays inside a private deployment, or runs on models hosted on your own infrastructure.
Most organisations need both, routed by sensitivity. We design that routing deliberately instead of sending everything to whichever API was easiest to sign up for.
The security work most vendors skip
An AI system that reads your email and takes actions is a new privileged component in your business. It deserves the same scrutiny as any other: what it can reach, what it can do, what it logs, and what happens when it is uncertain — which should be ask a human, not guess confidently.
That is where our AI practice and cybersecurity practice meet, and it is usually why firms with real confidentiality obligations end up here rather than at an automation shop.
What you get
- A written map of what data goes where, under what contract, kept how long
- A sanctioned AI setup staff will prefer to consumer accounts
- Self-hosted or on-device models where material must not leave
- Prompt injection and access-control design for anything agentic
- Audit logging of prompts, outputs and actions
- A short, readable AI usage policy
Frequently asked questions
Is our data used to train the model?
It depends entirely on which tier you are on, and this is the distinction most people miss. Consumer accounts may use conversations for training. Business, enterprise and API tiers of the major providers contractually exclude your data from training and offer defined retention. Moving staff from personal accounts to a proper business agreement is often the single biggest risk reduction available, and it is largely an administrative change.
Can we run AI entirely on our own infrastructure?
Yes. Open-weight models run on your own hardware or in your own cloud tenancy, and nothing leaves your network. They are less capable than frontier models and need real infrastructure, but for classification, extraction, summarisation and search over sensitive material they are frequently more than good enough — and they remove the disclosure question entirely.
What is prompt injection, in practice?
Instructions hidden inside content your AI reads — an email, a PDF, a web page — being treated as commands. If your assistant can only answer questions, the impact is limited. If it can send email, query a database or take actions, a malicious document can attempt to drive it. That is why anything agentic needs privilege separation and human confirmation on consequential steps.
Should we just ban AI tools instead?
Bans do not work here, and they make things worse. Staff use these tools because they genuinely help, and a ban simply moves usage onto personal accounts and personal devices where you have no visibility, no contract and no logs. A sanctioned path with clear rules beats a prohibition nobody follows.
How do we know the output is correct?
You design for it being wrong sometimes. Human review where errors are expensive, structured outputs that can be validated automatically, citations back to source documents, and honest measurement of accuracy on your actual work rather than trusting a demo.
Services involved
Cybersecurity
Incident response, ransomware recovery, and hardening that holds up under audit.
Learn moreAI & Automation
AI wired into the work you already do, with the security questions answered first.
Learn moreInfrastructure & Backup
Servers, clusters and backups designed so that failure is survivable and boring.
Learn moreTell us what is breaking — or what you are trying to build.
You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.
Active incident? Write “URGENT” in your message and we prioritise it.