Secure AI adoption: useful, without the data leaking
We put a policy and limits on the use of AI, so employees can use it without company data leaking.
Employees already use AI tools, with or without approval. Every time they paste a contract, a customer list or code, the data leaves your control.
The answer is not to ban AI, but to have rules, approved tools and training. This is work we know from cybersecurity.
- An inventory of the AI tools already in use (shadow AI)
- An acceptable-use policy for AI, in Greek
- Data classification: what is allowed and what is not
- A check of permissions and settings, so AI does not see more than it should
- Risk assessment of tools and suppliers
- Staff training
- Link to GDPR, NIS2 and the requirements of the AI Act, where they apply
Frequently asked questions
Should we ban ChatGPT?
A ban usually does not work: people use it from their phone. Better approved tools, clear rules and training.
Do we need an AI policy?
If employees use AI, yes. It gives clear rules and also protects the employees themselves.
Is it related to NIS2?
Indirectly, yes: managing supplier risk and protecting data are part of risk management. We look together at what applies to you.
How do we get started?
With an inventory of what is already used and which data you want to protect.