Data security in AI implementations: what to settle before you start
The most common question in an audit is not about technology, it is about data: where will it be processed, who has access, and what about GDPR. Rightly so — those decisions have to be made before the pilot, not after it. Below is the list of things we settle with every company before an agent touches the first record.
- Data can stay in your own infrastructure or in a chosen EU region — that is a decision, not a compromise.
- The agent gets the minimum scope of access one process needs, and every action is logged.
- Security is settled before the pilot: region, data processing agreement, roles, and escalation rules.
Where your data physically sits
The first decision is the processing region. There are two models to choose from: your data stays in your infrastructure and only anonymised fragments the model needs leave it — or everything runs in the cloud, in a chosen EU region, with a provider holding the right certifications. We use both models in practice; the choice depends on your industry and what your legal team requires.
One detail worth asking every vendor about: whether your data is used to train models. In the business configurations we work with, it is not — and that is a clause that belongs in the contract, not just in a sales conversation.

The agent's minimum scope of access
An agent does not need access "to everything". It needs exactly the data that serves one process: the ticket inbox, selected ERP tables, one specific document folder. We define that scope through roles and permissions — the same mechanisms you already use to manage people's access.
On top of that come the limits of action: what the agent may do alone, what needs approval, and what it never does. For example: the agent can send a return confirmation up to PLN 5,000; above that it drafts a reply and escalates to a person. We write those rules down with the team in the first week.
Logging and auditing actions
Every action the agent takes leaves a trace: what it read, how it classified the case, where it got the data, and what it sent. You see the full decision history in one place — that is the condition for trusting the system and a requirement if you are ever inspected. The logs are also the basis for the monthly quality review: we check a sample of cases and adjust the rules.
The pre-launch checklist
Processing region. Your own infrastructure or a named EU region — confirmed in the contract with the model provider and in your GDPR documentation.
Data processing agreement (DPA). Who is the controller, who is the processor, which categories of data the process covers, and how long they are retained.
Roles and scope of access. A list of the systems and data the agent can reach, with permissions limited to a single process.
Limits and escalations. Written rules: what the agent does alone, what needs approval, what the escalation path looks like, and who reviews the logs.
All four points can be closed within the audit week — in parallel with calculating the savings. That way the pilot starts with the rules already in place, and your legal team gets a complete set of documents instead of promises.
Frequently asked questions
Is our data used to train AI models?
No. In the business configurations we work with, company data is not used to train models — and the corresponding clause goes into the contract with the provider.
Can AI run entirely inside our own infrastructure?
Yes. Some implementations run on-premise or in a company's private cloud — in that case no data leaves it at all, or only anonymised fragments do. This is the option for industries with heightened requirements.
How does an AI implementation relate to GDPR?
The same way as any other processing arrangement: you need a DPA, a definition of the data categories, a legal basis, and a record of processing activities. We prepare the full set of documents during the audit, before the pilot starts.