Data protection in AI use is about which information may be shared with AI tools, and on what terms – especially personal data, which the GDPR protects, and trade secrets, which contracts protect.

The basic rule is simple: what you type into an AI tool leaves the building – on the vendor's terms. Everything therefore depends on the agreement: a free personal account and a business agreement with a data processing agreement are two very different situations, even if the window looks the same.

Good data protection in AI use is therefore, above all, about clarity: which tools the organisation stands behind, what they may be used for, and what must never be shared – client data, personnel cases, unpublished financials. Lack of clarity is what drives employees into private shadow use.

In practice

A useful everyday rule of thumb: only share what you could comfortably send to an external consultant without an agreement. Anything beyond that requires the organisation's approved tools and agreements to be in place.

How to explain it to management

»The question is not whether we trust the AI – but what agreement we have with whoever runs it.«

Unclear frameworks create shadow AI – and clear frameworks are part of any AI policy.