bis>
← Back to insights

Security

Where your data goes when you use AI

August 10, 2026 · 2 min read

If you handle client files, patient records, or anything a court could ask you about later, "we use AI" should immediately raise a plainer question: whose computers is this running on, and what happens to my information once it gets there?

Three questions worth asking any vendor

The leak is usually inside the building

In practice the exposure is rarely the vetted vendor. It is a staff member pasting a client's letter into a free chatbot at 11pm to get a draft finished, because nobody gave them a sanctioned way to do it.

You cannot police that with a memo. The fix is to decide what is allowed, provide a tool that covers it, and be specific about the line — which is much easier than it sounds once somebody writes it down.

Design the boundary first

The useful question is not "is AI secure." It is what is never allowed to leave the building, decided before anything is built rather than discovered afterward. Every system we build starts there, and for regulated work it shapes the design instead of getting added at the end.

How we handle your information