Here is a question very few businesses have asked themselves, and the ones who have often do not like the answer. When your staff paste client information into an AI tool — to summarise a document, draft a reply, analyse a spreadsheet — where does that data go, and what right did you have to send it there? If you handle personal data and operate under GDPR, that everyday convenience may be a data-protection breach you have not noticed, happening many times a day.
What actually happens when client data goes into an AI tool
When a staff member enters client data into a public AI tool, that data leaves your business and is processed by a third party — the company that runs the tool. Under data-protection law, that is not a neutral act. If you are the one responsible for that personal data, sending it to an outside processor brings obligations: you need a proper legal basis, the third party should be bound by an agreement governing how they handle it, and you need to know where the data goes and what is done with it, including whether it might be used to improve the tool.
In most businesses, none of that has happened. Staff adopted the tools themselves, with no agreement in place, no legal basis considered, and no idea what the provider does with what is entered. The data has simply left, quietly and repeatedly.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
The data processing agreement nobody put in place
The piece that is almost always missing is the agreement that should govern the relationship between your business and any third party that processes personal data on your behalf. When you use an established, sanctioned business tool, that agreement is normally part of the arrangement. When a staff member signs up to a free AI tool and feeds client data into it, there is no such agreement — and often the consumer terms explicitly allow the provider to use what is entered. You have, in effect, shared your clients’ data with a third party on terms you never reviewed and a basis you never established.
This is why it is a data-protection question before it is an AI question. The technology is new; the obligation is not. The rules about sending personal data to third parties have applied for years. AI tools have simply created a fast, invisible new way to breach them.
Why nobody is asking yet — and why that will not last
The reason this exposure is widespread is that it is invisible. There is no alert when a staff member pastes client data into a chatbot. It does not show up in any system. It feels like using a helpful tool, not like transferring personal data to an unvetted processor. So it goes unexamined — until a client asks how their data is handled, a regulator takes an interest, or a breach makes the data flows visible after the fact. The question nobody is asking yet is exactly the kind that becomes urgent the moment someone finally does.
What to do
The fix is governance, not a ban — bans push the behaviour into the dark, where the exposure still exists but you can no longer see it. Find out which AI tools are actually being used and what data is going into them, the same discovery that addresses shadow IT generally and staff already using AI specifically. Then set a clear, enforced rule about what client and personal data may never go into a public tool, route the legitimate needs through tools that come with proper data-handling terms, and write it into an AI policy backed by brief training. Treating it as a data-governance problem — knowing what data you hold and where it is allowed to go — is what closes the gap properly.
If your staff are using AI tools on client data without an agreement in place governing it, you have a GDPR exposure sitting unmeasured in your business. This is the conversation to have now, before someone else starts asking the question. We will find out where your client data is actually going and bring it back under control.
Start a ConversationFree interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming