Artificial Intelligence, General
A version of this question is being asked in most leadership teams right now, usually in a slightly nervous tone. Someone wants to run last quarter’s numbers through an AI tool to save an afternoon, and someone else is not sure whether that is allowed. The instinct is to reach for a yes or a no. Is it safe, or is it not.
That framing is the problem. Safe or not safe treats this as a single decision, made once, by the person with the document open. The more useful question, the one a leadership team is actually accountable for, is quieter: if someone asked you to prove where that information is right now, could you?
The decision is not the one you think it is
When someone on your team pastes a document into a public AI tool, whether it is a draft board pack, a supplier contract, or a list of customers, the important thing that happens is not that an answer comes back. It is that the document has left the building. It now sits on infrastructure you do not own, under terms you did not read, subject to retention and training defaults that vary by vendor and change without notice. You did not decide any of that. You inherited it, in the instant the paste went through.
This is why the safe-or-not framing fails. Safety implies a checkpoint, a moment where you inspect the tool and proceed. But there is no checkpoint. The exposure is not created by a bad tool or a careless person. It is created the moment sensitive information moves somewhere you can no longer account for it, and by then the decision has been made for you.
The number that should give a leadership team pause is not about hackers. In a 2026 survey of office professionals, roughly a third said they had entered financial information, customer data, or confidential documents into public AI tools, most of them believing it was not permitted. Your policy may say one thing. The daily practice of your business says another, and the practice is what governs you.
What you actually gave up
It helps to name the loss precisely, because it is not really about a single leaked file. Three things go at once, and each one is something a leadership team is supposed to hold.
Control of your information. The plainest loss. You can no longer say, with confidence, where a given document is or what has been done with it. That is not a technical inconvenience. It is the answer you owe an auditor, a board member, or an acquirer when they ask what AI has touched, and right now the honest answer is a shrug.
Trust in the answer. A public tool will give you a confident answer whether or not it is right, drawn from a general model that does not know your business and cannot show its work. That is a problem whether the output is a revenue figure, a read on a contract clause, or a summary of an operational report. An answer you cannot trace is an answer you cannot defend, and no leader gets to stand behind work they cannot source.
The freedom to change your mind. Once information is out, you cannot pull it back. You have traded a reversible decision for an irreversible one, usually without noticing you made it.
The test any leader can apply
You do not need to become a security expert to get your hands back on this. You need three questions, and you need to be able to answer yes to all three about any tool your teams put company information into. Not before they paste, because that moment has already passed in most businesses. About what is happening today.
1. Can I say where our information goes, and prove it? Not a reassuring sentence on a marketing page. A stated answer, in writing, about where data is processed and stored, and whether it is used to train a model. If no one can produce that, you do not have control. You have a hope.
2. Can leadership see how AI is being used, and steer it? This is not about monitoring individuals. It is about whether the business has any view of what AI is touching, on what, and to what effect. Usage you can see is usage you can direct. Usage you cannot see is the thing that surfaces later, at the worst possible moment.
3. Is it built to a standard someone else has checked? Independent certifications such as ISO 27001 and SOC 2 Type II are not paperwork. They are third-party evidence that the controls you are being promised actually exist, rather than a vendor’s word for it.
A leadership team that can answer yes to all three has not eliminated risk. It has done something more useful. It has moved from inheriting its AI decisions to making them.
So, can you safely put company numbers into AI?
Yes, when the environment is one you can account for. The problem was never AI. Your teams reach for it because it works, and telling capable people to stop using something that plainly helps them is a losing position. The problem is where the reasoning happens. On someone else’s model, out of your sight, the answer is no. In a private environment built to answer your questions on your own information, without that information leaving your control, the answer changes.
That is what SMITH is for. It is a secure environment where your teams get the speed of AI on your own information, finance, operations, legal, and commercial alike, with every answer anchored to your sources, your information kept private and never used to train another model, usage visible to leadership, and the whole thing built to ISO 27001 and SOC 2 Type II. It is designed around those three questions, not as features bolted on afterward, but as the reason it exists.
The fuller version of this argument, the four things ungoverned AI quietly costs a business and the six questions that put the decision back in leadership’s hands, is set out in our leadership guide, The Intelligence Brief: AI Under Control. A leadership guide to taking back the AI decision from shadow AI.
Prefer to see it on your own information? Start a 30-day trial and put SMITH to work on the documents your teams already produce.
