Choosing an AI tool without risking your data: a checklist

AI tools are multiplying and many teams adopt them without approval. This eight-point checklist helps you choose with your eyes open.

The checklist

  • Does the contract exclude training on your data?
  • Where is the data hosted, and can it leave the European Union?
  • Will the provider sign a GDPR (opens in a new tab) compliant processing agreement?
  • How long is the data kept?
  • Is access protected by strong authentication?
  • Can you export and delete your data?
  • Does the provider publish its security measures?
  • Is the intended use classed as high risk under the AI Act (opens in a new tab)?

Official resources

ENISA (opens in a new tab) publishes threat analyses on AI, and data protection authorities such as the ICO (opens in a new tab) publish practical guidance. The European Commission explains the AI regulatory framework (opens in a new tab) and the role of the European AI Office (opens in a new tab).

When an in-house solution is better

Health data, legal files, trade secrets: in these cases private AI removes the transfer question altogether. For overall compliance, see our AI Act support.

Frequently asked questions

Are free AI tools risky?

They often use conversations to improve the service. For professional use, choose a business plan or a hosted solution.

Who should approve AI tools in the company?

Ideally a designated person, together with the DPO if there is one. Keeping an up-to-date inventory is part of AI Act good practice.

Related services

Let’s talk about your project

A free first conversation, with no commitment, to see what would really help your business.