Privacy guide · 10 min

Using AI with confidential data: essential controls

Pasting a document into an AI service creates data processing. Before choosing a model, establish what enters, where it travels, how long it remains and who can access it.

Laptop and folders on a private desk
AI-generated illustration.
Key points

The short answer

Do not send sensitive material to a consumer service without an approved framework. Classify and minimise data, use an approved or local environment, check contracts and logs, then test with fictional data before production.

  • Minimise before transfer
  • Validate the complete data path
  • Test with fictional data

Build a controlled data path

  1. 1. Classify information

    Separate public, internal, confidential, personal and legally protected data. Give each level a clear rule: allowed, anonymise first, dedicated environment or prohibited.

  2. 2. Minimise inputs

    Send only necessary extracts. Replace names, numbers, addresses and identifiers with fictional values where meaning can be preserved. Remember that reversible pseudonymisation is not anonymisation.

  3. 3. Map the journey

    Document the application, model provider, extensions, connectors, logs, backups and subprocessors. Risk may sit in a peripheral integration rather than the main model.

  4. 4. Check the framework

    Read the terms and contractual documents for the exact plan: training use, retention, processing locations, deletion, access control and incident notification. Marketing language is not a binding commitment.

  5. 5. Choose the architecture

    Depending on risk, use a professionally governed service, private instance, local model or no AI processing. Local operation reduces some transfers but does not remove configuration, logging or endpoint risks.

  6. 6. Monitor and delete

    Limit accounts, enable useful audit logs, define retention, test deletion and review access. Assign an owner and an emergency stop procedure.

Put the method to work

Practical case

A team wants to analyse an internal contract. First prepare a fictional document with the same structure but no real names or amounts.

Evidence to keep

Map who receives the file, retention settings, administrator access and deletion or export procedure.

Make the decision

Move to the real contract only when these points are documented and compatible with your organisation’s rules.

Four checks before deployment

Necessity

Is each data item essential to the expected result?

Journey

Which services, countries, people and logs receive it?

Commitments

What do the contract and selected plan actually guarantee?

Control

Can you restrict, audit, export and delete?

6 starting points

Local, open and professional options

The directory helps explore different architectures. Inclusion is not legal or security approval: verify the exact offer, documentation and your own configuration.

How is this selection produced?

Active services are distributed across guide-related categories, then ordered by editorial highlighting and internal score. This does not assess security, compliance or performance on your use case. Methodology.

Explore the full category

Explore tools for this task

  • Duck.ai — Explore ideas, rephrase non-sensitive text or compare answers without installing a model. For documentary research, require accessible references instead of treating fluent answers as evidence.
  • Ollama — Test a model on your computer or provide a backend for a local application. Check hardware compatibility and model licensing first.
  • AWS Bedrock — Evaluate models inside an AWS application, connect a corpus or organize calls with access controls. Define region, latency, budget and supervision requirements first.
  • ChatGPT — Prepare a note from two public reports or explore a table with known totals. Specify columns, units, dates and passages to preserve. Writing tasks and calculation tasks require different checks.
  • Claude — Prepare texts following one style guide or analyze a reference dossier. Separate background documents, style rules and task-specific instructions so you can understand what influences the output.
  • Gemini — Read a report or query a limited set of authorized files. Define whether the answer must cover prose, numerical data or comparisons. Do not confuse file contents with a web search.

All profiles organized by family →

Comparison frameworks and cost per accepted result →

Related tool families

Frequently asked questions

Is a local tool always confidential?

No. It can reduce external transfers when processing is truly local, but endpoint security, logs, backups and access controls remain essential.

Can a document be anonymised automatically?

Software can help find identifiers, but context may still permit re-identification. Human review and risk-based policy are required.

What should be tested first?

Use fictional data to verify permissions, logs, exports, deletion, model failures and the shutdown procedure before real data is introduced.

The references below expand on the concepts and checks discussed. Scenarios and trial frameworks remain editorial proposals; provider documentation describes its own product rather than an independent benchmark.

Official sources

Continue with another guide