Field notes

Is It Safe to Use AI Tools With Your Company Data?

Most small contractors freeze on AI because deciding whether it's safe feels like an IT-department question. It isn't. Three plain questions about any tool, and a setup a twenty-person firm can actually run.

Every contractor and consulting firm I talk to this year has the same two thoughts about AI, held at the same time. The first is that they should probably be using it for something. The second is that they're not about to paste their bid numbers, their client contracts, or their payroll into a chatbot and hope for the best. Both instincts are correct. The problem is that the second one usually wins, and the firm does nothing, because "is this safe" feels like a question only an IT department can answer, and a twenty-person civil contractor doesn't have one.

You don't need an IT department to answer it. You need to stop treating "AI" as one thing and start asking three specific questions about any tool before it touches your data.

The question isn't "is AI safe," it's "where does my data go"

When people ask whether AI is safe to use with company data, they're usually picturing the worst case: they type something in, and it shows up in another answer six months later, or it trains the next version of the model, or it sits on a server they can't see. Some of that fear is dated, some of it's still valid, and the only way to tell which is to ask where the data actually goes.

Here are the three questions that settle it for almost any tool.

Does this vendor train on my inputs? The free, consumer tier of most AI products reserves the right to use what you type to improve their models. The paid business and enterprise tiers almost always don't, and they say so in the terms. This is the single biggest difference between "risky" and "fine," and it usually costs about twenty to thirty dollars per user per month to cross. If a tool can't tell you in plain language whether it trains on your data, that's your answer about whether to use it.

Where is the data stored, and for how long? A serious vendor will tell you where their servers are, how long they keep your inputs, and whether you can turn retention off. For a Canadian firm with clients who care about data residency, government or First Nations work for example, this matters more than the feature list. Ask before you upload, not after.

What can the tool actually reach? This is the one most people miss. A chatbot you paste into can only see what you paste. But the more useful AI setups, the ones that read your project files or draft from your own documents, are connected to your systems. The right question there isn't whether the connection is scary, it's exactly which folders, which records, and which actions the tool has access to. A tool that can read your shared drive is very different from one that can also delete from it.

Scoping access is the whole game

That third question is where the real safety lives, and it's also where the newer AI tooling has quietly gotten better. The industry has been building standard ways to connect an AI assistant to the systems you actually run, your file storage, your project records, your accounting data, under permissions you set, rather than by copying everything into a database the vendor controls.

Strip out the jargon and the idea is old and boring, which is exactly why it works. It's the same principle as giving a new site hire a key to the trailer but not to the safe. You decide what the assistant can see and do, you can watch what it did, and you can take the key back. An AI that drafts your weekly report should be able to read the daily logs from last week. It has no reason to touch payroll, so it shouldn't be able to, and a well-scoped setup makes that a setting rather than a promise.

This reframes the whole safety conversation. Instead of "can I trust AI with my data," which has no clean answer, you get "what's the smallest amount of access this task needs," which does. Most useful tasks need far less than people assume. Drafting a progress report needs read access to field logs. Summarizing a spec needs the spec. Neither one needs the run of your entire drive.

A setup a small firm can actually run

You don't need to build any of this from scratch, and for most firms you shouldn't. A practical, low-risk starting point looks like this.

Use paid business tiers, never the free consumer version, for anything involving company information. Write one page of plain rules for your team: which tool is approved, what never gets pasted into an unapproved one (client PII, unpriced bids, anything under NDA), and who to ask when unsure. That one page prevents more leaks than any piece of software, because the real risk in a small firm isn't a sophisticated breach, it's a well-meaning coordinator pasting a contract into a random free website to "clean it up."

Then, when you connect an AI tool to your own systems for the higher-value work, scope it tightly and start read-only. Let it draft, summarize, and pull things together from data it can see but not change. Give it the ability to write or send only once you've watched it work and you trust the specific task. You can always widen access. It's much harder to un-leak data you gave away on day one.

Where the tradeoff is honest

None of this is free of tradeoffs, and anyone who tells you otherwise is selling. Paid tiers cost money per seat. Scoping access properly takes an afternoon of thinking about which data is actually sensitive, which most firms have never done. And the tightest, most private setups, the ones that keep everything inside your own systems, take more effort to stand up than signing into a website does.

The payoff is that you get to actually use the technology instead of banning it out of vague fear, or worse, having your team use it anyway on the free tier where the terms are worst. Doing nothing isn't the safe option. It just moves the risk somewhere you can't see it.

If you're trying to figure out where AI could help your operation without putting your data somewhere it shouldn't be, that's a sensible thing to map out before you commit to any tool. On a discovery call we look at what data you actually hold, which tasks are worth automating, and what the smallest safe version of each looks like, on the systems you already run. No leaks, no six-figure platform, just a setup you can trust and turn off if you need to.

Dealing with something like this?

Book a free 30-minute discovery call. No pitch, practical next steps either way.

Book a call