BL.
§ Data & AI

Is My Data Safe with AI?

The question clients always ask. Treat the model like any other vendor, and know what the new EU rules actually change.

Almost every time I talk to a client, some version of this comes up. "But is our data safe if we send it to an AI?" People are worried, and the worry is real. It's also, most of the time, pointed at the wrong thing.

There are two separate questions tangled together here. One is about handing data to a provider. The other is about the new EU rules everyone has half-heard about. They deserve different answers, so I'll take them one at a time.

§01 / the data question

An AI model is just another vendor

You already trust dozens of companies with your data. Your email lives on Google's servers. Your customers sit in a CRM someone else runs. Payments go through Stripe. You send documents to a lawyer and card numbers to a bank. None of that keeps you up at night, because at some point you decided those vendors were worth trusting and you moved on.

An AI provider is the same kind of relationship. The word "AI" makes it feel like a new category with new dangers, but the actual question hasn't changed.

The question isn't "is it AI?" It's "does this tool need this data to do the job I hired it for?" You already know how to answer that.

Take an agent that books a cab. To book the ride, it needs the destination address. That address isn't leaking anywhere it shouldn't. It is the input, the same way it would be if you typed it into a maps app or read it to a driver. Withholding it doesn't make you safer. It just makes the task impossible. Data a tool genuinely needs to do its job is data you were always going to hand over.

So the real checks are the boring ones you'd run on any supplier. Who is the provider? What does the contract say they can do with your data? Do they train their models on it, or retain it, and for how long? Is it encrypted in transit and at rest? These are answerable, and the answers are usually reassuring.

There is one difference worth knowing, and it's the practical one. On free, consumer-grade tiers, some providers may use what you type to improve their models by default. On their business, enterprise, and API tiers, the major providers contractually commit not to train on your data. So the fix is never "avoid AI." It's use the business tier and read the data-processing terms, exactly what you already do for every other piece of software. The rest is basic hygiene: don't paste in data the task doesn't need. That was true of every tool you've ever used, long before any of them were called AI.

§02 / the regulation

What the new EU rules actually mean

The second worry is the EU AI Act, the first serious law aimed at regulating this stuff. The headlines make it sound like a wall. It's more sensible than that once you see the shape of it.

The Act doesn't regulate "AI" as one blob. It sorts uses into risk buckets, and the obligations scale with the risk. There are four:

  • Banned. A short list of uses the EU considers unacceptable, like social scoring of citizens or certain manipulative and biometric systems. Already in force. Almost certainly not you.
  • High risk. AI making consequential decisions about people: hiring, credit, education, medical devices, critical infrastructure. This is where the real weight sits, with documentation, human oversight, and risk management required.
  • Limited risk. If people interact with an AI, or you publish AI-generated content, you have to say so. Label the chatbot. Label the synthetic media.
  • Minimal risk. Everything else, which is most business software. No new obligations at all.
The Act scales with risk. Most of what a normal business does with AI sits in the bucket with no new obligations at all.

It also matters which side of the table you're on. If you build and sell a model, you're a "provider," and most of the heavy, headline-grabbing obligations land on you. If you're a normal business using a tool someone else built, you're a "deployer," and your load is far lighter. When you use Claude or ChatGPT through their business tiers, the provider is carrying the bulk of the compliance weight, not you.

On timing, one recent change is worth knowing, because it's the opposite of what people fear. The banned uses and the rules for general-purpose models are already live. The big date everyone circled, 2 August 2026 for high-risk obligations, has just been pushed back. The EU's "Digital Omnibus" simplification package is now adopted as Regulation (EU) 2026/1744 and in force since 27 July 2026: standalone high-risk systems have until 2 December 2027, and high-risk AI built into regulated products until 2 August 2028. If you're doing something genuinely high-risk, you have more runway, not less.

// action · from 2 august 2026

The one deadline that did not move is transparency. If your users are talking to an AI, or seeing AI-generated content, you have to disclose it. Label the chatbot. Label the synthetic media.

It's the single near-term to-do for most businesses, and a small one: cheap to meet, and the part everyone forgets while they're worrying about the deadlines that just got pushed back.

So the honest summary: figure out which bucket your use falls in. It's almost always minimal or limited. If it's limited, add the disclosure. If it's genuinely high-risk, get proper advice, and know you now have until late 2027. Don't let the acronyms stop you shipping the boring, useful stuff in the meantime.

Both worries, the data one and the regulation one, shrink the moment you stop treating AI as a special category and start treating it as software you're accountable for. Same due diligence. Same contracts. Same one honest question: does this tool need this data to do the job? If it does, you're fine.

// sources · eu ai act

The plain version

§ recap
01 / the vendor test

Does it need the data?

If the tool needs the data to do the job you hired it for, sending it is fine. That's a SaaS question, not an AI one.

02 / use the business tier

Read the terms

Enterprise and API tiers contractually don't train on your data. Check the data-processing terms, like any vendor.

03 / find your bucket

Almost always minimal

The EU Act scales with risk. Consequential decisions about people are the high-risk exception, not the rule.

04 / label it

Disclose from August 2026

If users talk to an AI or see AI-generated content, say so. The one near-term thing that didn't get delayed.

Not sure which bucket you're in?

// I help teams use AI safely, without the theatre or the panic

Start a conversation →