Using AI services means sending data to them. Organisations need to control what goes where.
How Data Flows Out
- Employees pasting documents, code or customer data into AI chat tools.
- Applications sending prompts containing personal or confidential data to model APIs.
- Browser extensions and plugins with broad access.
- Integrations connecting AI tools to email, files and CRM systems.
Assess Providers
- Is data used for training? Can that be switched off?
- How long is data retained, and where is it stored?
- What security certifications and contractual commitments exist?
- Are there enterprise terms with stronger protections?
Controls
- Approved tools: provide sanctioned AI tools with suitable terms, so staff don't turn to unapproved ones.
- Policies: define what data may be used with which tools.
- Technical controls: data loss prevention, blocking unapproved services, redacting sensitive data before sending.
- Training: explain the risks with realistic examples.
Self-Hosting
For the most sensitive data, consider models hosted in your own environment, weighing capability, cost and operational effort.
Review
Audit AI tool usage periodically, including shadow AI adoption.