the ai service.
Insights · Doing it safely

Is it safe to put client information into AI?

The honest answer is that it depends entirely on which AI, and on how it has been set up. That sounds like a dodge, but it is actually the good news — because it means there is a real answer, and you can find it in an afternoon. Here is what to check, what to ask, and how to get most of the benefit without sending the sensitive part at all.

People are right to ask this question. Confidential information is confidential for good reasons, and the instinct to stop and check before typing it into a new tool is a sound one. It is not a sign of being behind. It is the same instinct that stops you emailing a password.

The problem is that the question usually gets a useless answer. Say “is AI safe?” and you will be told either that it is perfectly fine or that it is a disaster waiting to happen. Neither is true, because “AI” is not one thing. It is dozens of products from different companies, sold on different terms, with different settings switched on by default.

So the question has to get narrower before it can be answered. Once it does, it becomes surprisingly easy.

The distinction that does most of the work

The single most useful line to draw is between free consumer tools and paid business tiers or direct API access.

Free consumer versions are generally offered on the understanding that the provider may use what you type to improve their own systems. That is usually disclosed somewhere in the terms, and there is often a setting to turn it off — but it is not always off to begin with, and most people have never looked.

Paid business and enterprise tiers, and access through an API, are generally sold on the opposite basis: your inputs are not used to train the provider’s models, and that commitment sits in a contract rather than in a blog post. That is a genuine difference in kind, not a marketing upgrade. It is the reason the same piece of information can be sensible to send through one door and unwise to send through another.

Which brings up the part that catches people out. The free version and the paid business version of the same product can sit under completely different terms. Same name, same logo, same screen — different contract. So “we use that tool, and it’s fine” is not an answer on its own. Which tier, and on whose account, is the answer.

Terms also change, and they vary between providers. So read the ones that apply to the specific tool you are actually using, rather than trusting a summary written by someone else — including this one.

Ask better questions than “is it secure?”

Every provider will tell you their product is secure, and most of them will be telling the truth about encryption, access controls and the rest. That question does not separate anything. Three narrower ones do.

Three questions worth asking any AI provider

  • Do you train on my data? Ask for the specific clause, not a reassurance. A clear no, in writing, on the tier you are actually paying for.
  • Where is it processed? Which countries the data passes through, and whether you can restrict that. This is the one that tends to matter most for UK and EU obligations.
  • How long do you keep it? Whether inputs are stored at all, for how long, who can see them, and whether a zero-retention option exists.

A provider that answers those three quickly and points you at the clause has made your decision easy. A provider that talks around them for ten minutes has also told you something useful.

You usually do not need to send the sensitive part

This is the part that gets missed, and it is the strongest protection available to anyone.

Most of the useful work AI does is structural. It rearranges, summarises, drafts, compares, checks for gaps, turns notes into something readable. Almost none of that depends on the real name, the real account number, the real address or the real reference. Take those out and the output is just as good.

So a long document can be summarised with the names replaced by placeholders. A reply can be drafted around a description of the situation rather than the file itself. A spreadsheet can be analysed with the identifying column removed. You put the real details back at the end, yourself, in thirty seconds.

This costs nothing, needs no contract and requires no permission from anyone. If you do only one thing after reading this, do that one — and you do not need us, or anyone like us, to help you do it.

The safest piece of information is the one you never sent.

Being straight about the risk: it is real, and it is worth the thought you are giving it. But the thing that actually goes wrong is rarely dramatic. It is almost never a break-in. It is ordinary and human — something gets pasted into whatever tool was nearest, on a phone, at speed, because the job needed finishing and that was the quickest route to done.

Which means the fix is mostly ordinary too. Decide which tools are approved. Make sure they are as quick to reach as the unapproved ones. Redact by habit. Check the three questions above before adding anything new. None of that requires a programme of work.

Where the real authority sits

One thing we will not do is tell you what you are legally required to do. We are not lawyers, this is not legal advice, and your situation has details we cannot see from here.

Your obligations come from your own regulator or professional body, from data protection law as it applies to you, and from the contracts you have signed with the people you work for. Those are the authorities on the question, and a solicitor or a data protection adviser is the person to confirm it with. Anyone who tells you confidently what you are allowed to do without knowing any of that is guessing.

What we can do is get you to the point where the answer is easy to give: a short list of approved tools you have actually checked, a habit of taking the sensitive part out before you send anything, and a written note of why each decision was made. With that in place, the question stops being frightening and becomes a thing you can answer in a sentence.

The same discipline sits behind the one rule worth having before any others and why the AI worth having assists the person who signs rather than replacing their judgement. Getting that list of approved tools built properly, checked against your own obligations, is exactly what the audit does.

This is a general explanation rather than advice on your own obligations — if you want the practical side set up properly, that is what doing it safely covers.

Not sure which tools you are already using?

Twenty minutes on the phone, free, no obligation. We can go through the tools in use, tell you which tier each one is on, and give you a straight answer about what is safe to put in.

Book a free 20-minute call