Service · Cybersecurity

Secure use of AI

Contracts, quotes and spreadsheets full of customer data are already going into AI chatbots, usually through personal accounts and without the directors being aware. Banning it will not help; the habit simply moves to people's phones. The better approach is to find out which information is walking out of the door and hand staff a tool that does the same job safely.

Discovery
what already leaves the firm
Tool
data processed in the EU
Rules
short, with examples
Oversight
of real usage

Included in this service

AI is new; the dangers are not. Confidential text typed into a prompt, reliance on a third-party platform, accountability for data belonging to customers. Add the EU AI Act, which among other things expects anyone using AI at work to have a reasonable grasp of how it behaves.

Talk the scope through with an engineer

Usage map

Department by department, we learn which AI services are in use and which categories of information flow into them.

Rules

What is fine to paste, what is off limits and which tools are sanctioned. A single page with examples instead of a ban nobody follows.

Sanctioned tool

Microsoft 365 Copilot, ChatGPT Enterprise or another business edition. Before choosing, we check in the contract terms whether the provider may use your data for model training.

Tidying up before Copilot

Copilot surfaces everything a user has permission to open. So before it goes live we rein in oversharing across SharePoint, OneDrive and Teams and apply sensitivity labels.

Contracts and GDPR

A data processing agreement, confirmation of where the provider handles the data, and a paper trail for anything that leaves the EEA.

Model in your own cloud

Occasionally data may not leave your estate under any circumstances. For that, a model hosted in your own Azure tenant in an EU region.

How we work together

Step one is an honest look at reality. Prohibition without a replacement fails; staff carry on and simply go quiet about it.

01

Discovery

Defender for Cloud Apps shows us traffic to AI services, and conversations with each team fill in the gaps. Actual use often exceeds what the directors expect.

02

Rules

We put the rules in writing and explain them through real cases from your industry in a brief live online workshop.

03

Alternative

Your people get a sanctioned assistant; tools outside the list can be blocked or shown with a warning banner.

04

Oversight

We track usage, adjust the rules and update the list of permitted services, since the market shifts quickly.

Whoever processes the personal data, the legal responsibility remains yours. Paste a debtor list with PESEL numbers into a free chatbot and you have disclosed personal data to an outside party, perhaps beyond the EEA and with no processing contract. Get the rules agreed before any software is switched on.

Questions and answers

Ones sold under business terms in which the vendor promises not to use your content for training, and where somebody on your side has genuinely read that promise. Free consumer tiers do not belong on the list, however handy they are.

Details of identifiable individuals, PESEL numbers, medical records, contract terms agreed with clients, source code of internal systems, passwords and API keys. Keeping the list this short is precisely what makes it memorable.

It works within the permissions you already have, and the terms of data processing, including location, are set out in Microsoft documentation worth reviewing with your DPO. The real weak point is oversharing: leave the payroll folder open to everyone and Copilot will cheerfully summarise salaries for whoever asks. Permissions get cleaned up before launch for exactly that reason.

Seldom. A business subscription to a hosted service, combined with sensible rules, covers most needs. Hosting your own becomes worthwhile when law or a client agreement bars data from leaving your systems, as can happen at a law firm or a clinic.

The regulation expects an adequate level of AI literacy among staff but does not prescribe one format. A sensible approach is a short session tailored to how each department uses the tools, along with a record of who has completed it. Confirm the scope of the duty for your company with a lawyer.

Let us talk about secure AI

Explain what you hope AI will do for you and how sensitive the information is. Our proposal could be anything from a written policy to a model hosted in your own cloud.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.