Adopting AI safely

The controls, vendor questions and policies that protect client and company data.

Adopting AI safely

How to evaluate an AI vendor's security: 12 questions for your IT lead

Before any AI vendor touches your clients' data, get clear written answers on six things: how your data is kept apart from other customers, how it's encrypted, what the AI models keep, who approves what, what's been independently audited, and how you get out. The 12 questions below cover all six. A good vendor answers them plainly. A vague answer is itself an answer.

Adopting AI safely

The AI use policy every business adopting AI needs

A written AI use policy answers three questions for your staff: which AI tools they're allowed to use, what client or company data can never go into a tool that isn't approved, and who has to sign off before AI-prepared work reaches a client. Without one, adoption happens anyway — through whatever tool an employee found on their own — and the business has no record of what data went where. A one-page policy, reviewed with the team, closes that gap.

Adopting AI safely

Why data isolation matters when your AI vendor serves other firms

Most AI vendors run one system for many customers, which may include firms you compete with. Data isolation is what guarantees your firm's data, and your clients' data, can never show up in another customer's results. The strongest isolation is enforced by the database and by encryption, not just by the vendor's application code.

Adopting AI safely

Zero data retention, explained: what happens to your data when AI reads it

Zero data retention (ZDR) means the AI model provider doesn't store your prompts or the model's answers once the request is processed, so there's no copy of your data sitting in the provider's logs. It's the single most important term to confirm before client data goes to an AI model. But ZDR is a contract and a configuration, not a feature you get by default, and "available" is not the same as "in effect."