Guide

Is our data safe with AI? What to ask before you start

The questions to ask any AI supplier about data, with the honest answers: where data lives, whether it trains models, and what UK GDPR requires.

Updated 2 July 2026

Data is safe with AI when the system is built inside your own accounts and tools so the data stays where it already lives, when model providers are used under API terms that exclude training on your data, when permissions mirror the access people already have, and when every action is logged. Each of those is a build decision made before go-live, which is why the way to assess any supplier is to ask how the system is put together before anything is switched on. The questions below are the ones worth asking, with the answers a good supplier should give.

Where does our data actually go?

The strong answer is that the system is built inside your own accounts: your inbox, your CRM, your document store, your cloud tenancy. The data stays where it already lives and the automation comes to it, rather than your records being copied into a supplier's environment where you cannot see who touches them.

Ask the supplier to draw the data flow: what leaves your systems, where it goes, and what comes back. A model call typically sends the specific content being processed to the model provider and receives the output. Ask which providers are used, under what terms, and where processing takes place, and expect a written answer a data protection review can rely on.

Will our data be used to train someone else's model?

This is the fear behind most data hesitancy, and the answer should be a documented no. The major model providers offer commercial API terms that exclude training on customer data as standard, a different arrangement from the consumer chat products and their broader usage policies. Ask which terms apply to your build and ask to see them; a written answer here is worth more than any verbal reassurance.

The same question applies to the supplier itself. Confirm in the contract that your data, your prompts and your documents are used only to deliver your system.

Who can see what, and how would we know what the system did?

Permissions in a well-built system are enforced, and they mirror the access people already have. If a person cannot open a folder today, the AI does not surface its contents to them tomorrow; retrieval and answers are permissioned at the point of the query. Ask how permissions are enforced and what happens when someone's access changes.

Logging answers the second half. Every action the system takes is recorded with its basis, so you can reconstruct what it did, what information it used, and who approved anything consequential. A system with that log can be audited; a system without it can only be trusted, and trust is a poor control.

What does UK GDPR require before go-live?

UK GDPR treats AI like any other processing of personal data: a lawful basis, a defined purpose, appropriate security, and individual rights all still apply. The extra step arrives when processing is likely to carry a high risk for the people in the data, which is where the data protection impact assessment comes in, and a workflow applying AI to personal data at scale is sensibly treated as sitting in that category.

Timing is the point to hold a supplier to: the assessment is finished and signed off before the higher-risk processing switches on, and it is reopened whenever the system materially changes. A supplier working near regulated sectors should expect the DPIA conversation rather than be surprised by it, and our guide to AI for regulated firms covers what the assessment contains in more detail.

What security baseline should any supplier meet?

The reference point is the National Cyber Security Centre's guidance, and four items matter most in an AI build: multi-factor authentication everywhere the system authenticates, access scoped by role, backups that are both protected and tested, and least privilege as the starting position rather than the exception. Ask a prospective supplier to describe their setup against those four items specifically.

Good security design limits blast radius. When every credential and component reaches only what it needs, one mistake or one compromised account stays small, and the per-action log turns anything unusual into something you can see and trace.

Data safety with AI is a property of how the system is built, which means it can be verified before you start rather than hoped for afterwards. A supplier with good answers will welcome these questions, and the written answers become part of your own governance record: evidence, ready for the day a client, an auditor or a regulator asks you the same things.

Put it to work

Bring us the workflow this applies to

Book an AI audit
The newsletter

AI worth your inbox

The tools, launches and shifts that actually matter, in plain English. No paywall, unsubscribe at any time.