Pyyan The AI Index ← All boxes

For anyone who has to make this call

Can I put this
into AI?

You keep hearing you should be using this. You also have client contracts, last year's accounts, staff salaries and a tender you cannot afford to leak. So the real question is the one nobody answers plainly: if I type this in, who else can read it? Can the AI company see it? Could a competitor? Could a court demand it later? Here is the honest answer, in plain words, and what to do about it on Monday.

Who can read it. Your information sits in the middle. Every AI tool sits on one of these rings, and the ring it sits on decides who else gets to see what you typed. That is nearly the whole of the security question, and it is a choice you make, not something the AI decides for you.
TL;DR

No, you cannot hand it anything blindly, and no, it is not all dangerous either. The same model is safe or unsafe depending on the door you walk it through. Through your organisation's own account it sits under the contract you already signed: your text is not used to train anybody's model, it is held on your terms, and it is auditable. Through a personal login it sits under none of that. So the decision is smaller than it feels. What kind of information is this, which account am I using, and what is the thing allowed to do once it has it.

Three questions, every time
  1. 1 Can this information go in?
  2. 2 Which AI am I allowed to use?
  3. 3 Can I trust the answer?

Part IWho can actually read what you type

1 · It depends which account you are logged into

Here is the part that matters, before anything else. The same sentence typed into the same model is either governed or ungoverned depending on the account it goes through. On your organisation's own paid account your text is not used to train the model, it is kept on the terms you set, and there is a log of it. On a personal free login none of those three things is true. That difference is written into an agreement rather than left to trust, and it is the single biggest lever you have.

Which is why the usual meeting gets stuck. Somebody asks whether staff may use ChatGPT, somebody else says absolutely not, our data would leave the company, everyone nods, and the meeting ends without anybody having named which account they were talking about.

Then everyone goes back to their desk and:

Nobody signs off on any of that any more. It was decided years ago, and it was the right decision. Your data has been outside your building for a decade.

The real line is one every employee already understands:

Nobody needs to be taught the left-hand column. Everybody already knows not to email a tender from their personal Gmail. That instinct is exactly right, and it transfers without modification: the question is not whether the data leaves the building. It is whether it lands inside your contract or outside it.

2 · You are already sending this over WhatsApp

This next part is context rather than an answer, and it is worth one minute because it tends to calm a room down. While the AI meeting is happening, a great deal of the actual business is being done on WhatsApp. Drawings photographed and sent. Quotations forwarded. Prices discussed. Decisions made and recorded nowhere else. That is not a reason to relax about AI. It is a reason to apply the same standard to both.

Compare the two honestly, on the things that actually matter for governance:

This is not an argument for banning WhatsApp. It is an argument for proportion. An organisation that agonises over ChatGPT while running its tenders through a consumer messaging app has aimed its policy at the wrong target, and everybody in the room knows it, which is exactly why the policy gets ignored.

3 · Most of your data never reaches the AI at all

Ask most people what happens when you use AI on a document and they will describe something like this: the file goes into the AI, the AI absorbs it, your data is now inside the model forever.

That is a fair description of one specific way of using AI badly. It is not a description of a properly built system.

In a built system, the model is an orchestrator, not a database. It does not read your spreadsheet. It decides what should be done with it, and ordinary code does the doing. Searching runs where your files already live. Only the paragraph that matched travels.

Which matters most for anyone touching numbers

Language models are genuinely bad at arithmetic. They do not calculate. They predict what a plausible answer looks like, which is a different activity that occasionally coincides with being right.

So the wrong instruction is “add up this bill of quantities.” The right one is “write the calculation”, and then real code runs it and returns a real number.

This also fixes the advice nobody can actually follow. “Always verify AI output” is useless. Verify it how? But you can check a five-line formula far more reliably than you can check a number the model simply asserted. Verify the method, not the answer.

Where this stops being true

Everything above describes a system somebody built. It does not describe a person pasting a PDF into a chat box. Four things worth stating plainly, so nobody quotes this section to justify carelessness:

  1. Retrieval reduces exposure; it does not remove it. The paragraph that matched still crosses. If that paragraph is the confidential clause, the clause went.
  2. “It runs in a sandbox” is not “it stayed home.” Some sandboxes are the provider's. Your file was uploaded to it. A sandbox inside your own cloud account is a completely different thing.
  3. Tool results land back in the conversation. A tool that returns two hundred payroll rows has just put two hundred payroll rows into the context.
  4. None of it helps if somebody pastes the salary table in anyway.

Which turns the whole question around. You are not choosing between using AI unsafely and not using AI. You are choosing between everybody pasting into a consumer chat box, and building it so the data never needs to travel.

Part IIThree questions to ask before you paste anything

Everything above is context. This is the part a department head needs in their head: three questions, asked in order, every time.

Gate 1 · Can this information go in?

Most AI policies are a list of forbidden actions. That list is incomplete the day it is written and out of date the week after, because somebody always invents a new way to be careless.

The durable design is the opposite: classify the information once, and let the rules follow. Your organisation almost certainly already classifies documents: public, internal, confidential, restricted. AI policy should ride on that rather than inventing a second vocabulary nobody remembers.

Four answers, not two:

A worked classification

The kinds of things that actually arrive on a department head's desk:

“Just remove the sensitive bits”, and why that usually fails

Sanitising sounds simple and rarely is. Three ways it goes wrong:

Gate 2 · Which AI am I allowed to use for this?

Here is the thing most people do not know exists, and it dissolves most of the anxiety in the average AI policy meeting.

Proportion, please

A bill of quantities. An invoice. A bank statement. These are already sitting in your Drive. Running them through your own Bedrock account is not a new risk decision. It is the same decision you made years ago, honoured consistently.

Running a model on your own computers, so nothing ever leaves the building, is for the case where the information is the company. An unreleased formula. A bid somebody would pay to see. Not a purchase order.

Which means Gate 1 and Gate 2 are not two questions. They are one decision with two halves: how sensitive the information is tells you which of those four places it may go.

Gate 3 · Can I trust the answer it gave me?

The dangerous failure is not the obvious one. AI does not usually produce visible nonsense. It produces fluent, confident, well-formatted, plausible wrongness, which is far harder to catch, because everything about it looks like the work of someone competent.

This is already settled law, not a future risk

Air Canada argued in a tribunal that its chatbot was “a separate legal entity” responsible for its own statements. It lost. That is the whole principle in one sentence: the organisation owns the output. Always.

Verification proportional to consequence

Not everything needs the same scrutiny. Three levels is enough:

Part IIIWhen it starts doing things, not just answering

Everything so far assumed a person asking a question. The moment AI is connected to your systems, able to read files, update records, send things, the question changes from what can it see to what can it do.

4 · Treat it like a new employee, not a tool

The fear is that AI will see everything. It sees exactly what you granted it, and granting is something every organisation already knows how to do.

You do not give the new procurement hire access to payroll. You do not let a site engineer approve payments. They get a role, the role has permissions, the system enforces it, and their actions are logged. An agent is a new starter who never goes home. Same treatment.

The trap almost everybody walks into

This is the most likely bad day, and it is worth understanding before it happens rather than after.

Somebody shared a salary band document “just internally” in 2021. It is still readable by every employee in 2026. Nobody ever found it, because nobody could search well enough. Then an AI assistant arrives, somebody asks an entirely innocent question about pay ranges, and there it is.

Blast radius

Three levels, and most arguments end once somebody names which one they are actually arguing about.

One genuinely new risk appears at the moment an agent gains tools: a document can become an attack. If an agent reads an incoming PDF and that PDF contains instructions, the agent may follow them. Your file server never did that. The engineering detail is here →

5 · Start it read only, and let it earn more

Nobody hands a new hire the payment approval on their first morning. The same restraint applies, for the same reasons.

Most organisations should live happily at stage two for months. Drafting the email but not sending it is a complete, useful, low-risk deployment, and it is where the majority of the value is anyway.

This also answers a question that usually gets a bad answer. Where does human verification remain mandatory? It is not a fixed list. It is a function of which stage you are at.

6 · Who checks its work, and how hard

“AI checking AI” is real, but the popular version is the weakest one. A model marking its own homework mostly measures its own fluency, and research is fairly blunt about this: models do not reliably self-correct without an outside signal.

What does work, cheapest first:

One inversion worth knowing

Agents can be governed better than people. You cannot reconstruct why a manager decided something at four o'clock on a Tuesday. You can replay exactly what an agent read, what it chose and what it did, with timestamps.

Provided somebody reads the logs. Most organisations switch on audit logging and never look at it again, so the policy has to name who reviews, how often, and what triggers escalation, or it is theatre.

Part IVMaking it real on Monday

What each part of your business can safely do today

Generic advice helps nobody. These are shaped by role rather than industry: whoever in your organisation handles bids, contracts, money, people, suppliers, drawings and programmes.

Why banning it does not work

It is worth being clear-eyed about what a ban actually achieves, because the numbers are not ambiguous:

A ban does not remove the behaviour. It moves it to personal phones and personal accounts, where you have no logs, no contract, no retention control and no idea it is happening. You cannot block your way out of this at the network edge. It is a visibility and control problem.

And there is a quieter point. Most organisations debating whether to adopt AI have already adopted it: it is in Word, it is in Gmail, it is in WhatsApp. The decision in front of you is not whether. It is whether it is governed.

A policy that fits on one page

A thirty-page policy is a document that has been read by its author. Six lines that people can remember will do more:

If you want a framework to hang it on rather than inventing one: ISO/IEC 42001 is a certifiable management standard for AI, the NIST AI Risk Management Framework is the flexible risk companion, and the EU AI Act's high-risk obligations took effect on 2 August 2026. You do not need all three. You need to have chosen one deliberately.

Try it: can this go in?

This is the exercise I run in the room, and it is the fastest way to find out whether a policy is actually understood. Ten items. Four possible answers. No trick questions, although two of them reliably split a room.