1. Home
  2. /
  3. Knowledge bank
  4. /
  5. Five things you should never share in a public AI

What should I not share in a public AI?

1. Company-sensitive and business-critical information.

This could include strategy documents, financial forecasts, customer lists, or internal memos. If entered into a public AI service, the information leaves your control and may be used as training data. Consider, would it be a problem if this appeared in a competitor's prompt response?

2. Personal data of your customers, employees, or end users

From a GDPR perspective, you are the data controller. Inputting personal identification numbers, email addresses, HR matters, or customer data into a public AI without a data processing agreement and legal basis is practically an incident waiting to be reported as a data breach.

3. Client and supplier contracts under confidentiality

Simply pasting a contract clause into a public AI service to "get help interpreting it" can violate the confidentiality clause of said contract. This can lead to legal consequences such as claims for damages. But above all, it causes a breach of trust that can be difficult to repair.

4. Internal code snippets and API keys

This is a common mistake among developers. They paste code for simple debugging. But it includes hardcoded keys, tokens, or connection strings to production environments. A single exposed API key can open the door to your entire cloud environment.

5. Infrastructure and security details

Network architecture, firewall rules, vulnerability scans, incident reports are gold to a malicious attacker and a public AI service is by definition an unreliable third party from a security perspective.

If you wouldn't shout it out loud on the subway, don't write it in a public AI

Safe AI Use with Nordlo AI Hub

AI maturity is relatively low in Sweden. We are curious and eager to get started, but knowledge varies and management often lacks insight. That is why we at Nordlo developed our very own Nordlo AI Hub, which brings together several AI models in a common and secure platform. This means:

  • One platform, multiple models. Nordlo AI Hub provides access to the market's leading AI solutions, including ChatGPT, Claude, and Gemini, through a common platform. The entire organisation gets access without separate licences and subscriptions.

  • Secure handling in a private cloud. Data and results from queries and prompts are stored in Nordlo's private cloud with full traceability. Sensitive information remains within the organisation and is not shared with external parties, even though the processing itself takes place with the LLM provider.

  • Build and share AI agents. Create your own AI agents tailored for sales, finance or support and share them with the entire business. What one employee builds can benefit everyone.

  • Insight and control for management. Getting an overview of how AI is used in the organisation is a prerequisite for steering, prioritising and ensuring responsible use.

You can read more about Nordlo AI Hub here

5 common questions and answers about what can be shared in a public AI

  • Why shouldn't sensitive information be shared in a public AI?
    Information entered into a public AI service leaves the organisation's control domain and can potentially be used as training data, stored on servers outside the EU, or exposed in other users' responses. This creates security risks, GDPR violations, and the risk of breach of confidentiality agreements.
  • What type of data is the most dangerous to share in a public AI?
    API keys, access tokens, and connection strings to production environments are among the most dangerous. A single exposed key can give an attacker access to your entire cloud infrastructure. But personal data, strategy documents, and confidentiality-protected agreements can also cause serious damage.
  • Can GDPR be violated by using ChatGPT or other public AI?
    Yes. If an employee enters personal data, such as personal identity numbers, email addresses, or HR matters, into a public AI without a data processing agreement and a legal basis, it is effectively a personal data incident that may need to be reported to the Swedish Authority for Privacy Protection (IMY).
  • What is shadow IT and how is it related to public AI usage?
    Shadow IT arises when employees use technology and AI services via private accounts without the IT department's knowledge or approval. This makes it impossible for the organisation to monitor what information is shared, control costs, or ensure compliance with policies and regulations.
  • How can companies use AI without risking sensitive information leaks?
    By centralising AI usage in a shared, secure platform, such as Nordlo AI Hub, where all data and results are stored in a private cloud with full traceability. This gives employees access to multiple AI models while management gains oversight and control – without risk of sensitive information being shared with external parties.
En person i grå hoodie ler medan hen tittar på en mobiltelefon utomhus.

Subscribe to our newsletter!

Related articles

Blog
Security

EDR, XDR and Exposure Management: Three layers of protection against today’s cyber threats

Blog
Guide
Software as a Service
Cloud and infrastructure
Security

Guide: Security Architecture for Leading SaaS Companies

Blog
Guide
Software as a Service
Cloud and infrastructure

Scalable cloud architecture for SaaS: How to avoid lock-in and build for growth

This website uses cookies and personal data

When you visit https://nordlo.com, we at Nordlo Group AB use cookies and your personal data. Some cookies and some processing of personal data are necessary, while you choose whether to consent to others. You make your choice below. Your consent is entirely voluntary.

You have certain rights, such as the right to withdraw your consent and the right to lodge a complaint with a supervisory authority. Read more in our cookie policy and our privacy policy.

Manage your cookie-settings

Cookies and personal data that we use for analysis

Check to consent to the use of Cookies and personal data that we use for analysis

To analyse how you use our website, we use cookies from Google and HubSpot's analytics service. We also process your personal data, e.g. your encrypted IP address, your geographical location and other information about how you use the website. 

Cookies and personal data that we use for marketing

Check to consent to the use of Cookies and personal data that we use for marketing

We use cookies and your personal data to display relevant marketing and to follow up on such marketing when you visit other websites or social media. We do this with the aid of Google, Facebook, HubSpot and LinkedIn. The personal data that we process for marketing purposes include your IP address, information about how you use the website and information that these services already have about you.  

Ad measurement user cookies

Check to consent to the use of Ad measurement user cookies
In order to show relevant ads we place cookies to tailor ads for you

Personalized ads cookies

Check to consent to the use of Personalized ads cookies
To show relevant and personal ads we place cookies to provide unique offers that are tailored to your user data