Former employees probably already use AI to simplify and streamline their everyday lives. But when AI use takes place through private accounts without common guidelines, shadow IT, security risks, and costs that are difficult to overview arise. Here we list five things you should never share in a public AI.

This could include strategy documents, financial forecasts, customer lists, or internal memos. If entered into a public AI service, the information leaves your control and may be used as training data. Consider, would it be a problem if this appeared in a competitor's prompt response?
From a GDPR perspective, you are the data controller. Inputting personal identification numbers, email addresses, HR matters, or customer data into a public AI without a data processing agreement and legal basis is practically an incident waiting to be reported as a data breach.
Simply pasting a contract clause into a public AI service to "get help interpreting it" can violate the confidentiality clause of said contract. This can lead to legal consequences such as claims for damages. But above all, it causes a breach of trust that can be difficult to repair.
This is a common mistake among developers. They paste code for simple debugging. But it includes hardcoded keys, tokens, or connection strings to production environments. A single exposed API key can open the door to your entire cloud environment.
Network architecture, firewall rules, vulnerability scans, incident reports are gold to a malicious attacker and a public AI service is by definition an unreliable third party from a security perspective.
If you wouldn't shout it out loud on the subway, don't write it in a public AI
AI maturity is relatively low in Sweden. We are curious and eager to get started, but knowledge varies and management often lacks insight. That is why we at Nordlo developed our very own Nordlo AI Hub, which brings together several AI models in a common and secure platform. This means:
One platform, multiple models. Nordlo AI Hub provides access to the market's leading AI solutions, including ChatGPT, Claude, and Gemini, through a common platform. The entire organisation gets access without separate licences and subscriptions.
Secure handling in a private cloud. Data and results from queries and prompts are stored in Nordlo's private cloud with full traceability. Sensitive information remains within the organisation and is not shared with external parties, even though the processing itself takes place with the LLM provider.
Build and share AI agents. Create your own AI agents tailored for sales, finance or support and share them with the entire business. What one employee builds can benefit everyone.
Insight and control for management. Getting an overview of how AI is used in the organisation is a prerequisite for steering, prioritising and ensuring responsible use.
