How to Use AI Without Putting Your Company Information at Risk
I build AI for a living, and sometimes I still catch myself handing it more than I should.
When I'm coding with AI, it often asks for a file, a config, or a key, and the fastest way to keep moving is to give it what it wants. More than once, I've had to stop myself before an API key ended up somewhere it didn't belong because I was trying to move too fast. Convenience makes those decisions easy to justify when you're in the middle of the work, and that's exactly why companies need clear agreements in place before they start using AI.
So let me say the reassuring thing up front, as someone who works on this every day. You can absolutely put AI to work without putting your company's data at risk. A lot of it comes down to choices your company can control, including which tools people use and what information they share.
Most data exposure doesn’t happen because the technology goes rogue. It happens in ordinary moments like mine, where oversharing is the path of least resistance. Someone's trying to move fast, the AI asks for more context, and sensitive information gets shared before anyone stops to consider whether the tool should have access to it.
The good news is situations like this can be prevented. When your leadership team sets the standard and when your people understand how sensitive information can be exposed, your company can use AI to work faster and make better decisions without creating unnecessary risk.
Where Information Gets Exposed
There are two common ways company information gets exposed. Once you know what they are, it’s much easier to avoid the risks and protect sensitive information.
The first risk comes from what a tool does with the information you provide. Many of the most widely used consumer AI tools use your conversations to train their models by default, and turning that off means knowing how to hunt down a setting most people never even open. The remedy is simple: Choose AI tools that don't train on your data (ideally by default) so no one has to remember to protect it.
The second risk comes from a very human instinct. When a tool asks for more context, people provide it because they think better context will give them a better answer. So without thinking too much about what they're sharing, it's common for someone to upload a spreadsheet, paste part of a contract, or share an API key to solve a problem faster.
Even thoughtful, well-run companies have made this mistake. Samsung employees reportedly shared confidential source code with a public chatbot while trying to troubleshoot an issue. That example is a reminder that good intentions aren’t enough to keep your data safe.
The right foundation makes AI use safer and easier for your team. With clear policies, approved tools, and role-specific training, the fast path can also become the safe path. And when that happens, your people can use AI to move quickly without putting your company’s information at risk.
What Keeps Your Information Safe
Keeping company information safe with AI comes down to the controls built into the tool and the judgment of the people who are handling your information.
Start with the controls because they're the part you can verify. A trustworthy tool:
-
Doesn't use your information to train public AI models
-
Is backed by real security standards like an independent SOC certification
-
Lets you control which team members can access which information
With a lot of consumer tools, protecting your data means finding the right setting and changing it yourself, usually in a menu you have to know exists in the first place. The safer setup is one where that protection is already in place so there’s no hidden setting to find and no switch to forget.
But even with the right protections in place, a tool can’t tell you whether the information you’re sharing belongs there. That part comes down to judgment.
Leadership teams should set clear standards for what information their team members can share with which tools, and those standards should be communicated and reinforced as people find new ways to use AI in their work. That starts with recognizing that not all company information carries the same level of risk. Information that’s already approved for external use is very different from internal plans, customer data, financial details, employee information, or private conversations. Your team members need to understand those differences and know what belongs in an approved AI tool and what should stay out.
At the same time, your AI provider needs to make equally thoughtful decisions about how your information is stored, accessed, and protected. That’s harder to measure than a security setting, but it matters just as much. When you choose an AI provider, you’re not just choosing a product. You’re also choosing the people, priorities, and judgment behind it, so do your research to be sure they treat your company’s information with the same care you do.
.png?width=1000&height=427&name=Illustrations_Ask_Maz_Seperate3%20(1).png)
How We Think About This With Maz
When we built Maz, the AI companion inside Ninety, we followed the principle that your company’s information should be protected by default.
Ninety is SOC certified, and we have built in protections that other AI tools may require you to find and configure yourself. There’s no setting to search for and no option that allows your company’s information to train a public model. We made those decisions at the product level so your team can log in to Ninety and get straight to work..png?width=450&height=410&name=Ask_Maz_Landing_Christine2%20(1).png)
When someone on your team uses our newest AI feature Ask Maz to get an answer to a question they have about the business, there's no need to provide any additional context because Ask Maz works where your company information already lives. Ask Maz only draws from information that team member is authorized to access in Ninety, which becomes even more useful as your team grows and managing access across departments gets more complex.
When it comes to judgment, our goal is to treat your company’s data with the same care you would. That's why Maz doesn’t currently have access to some of the most sensitive information in Ninety, like details from Quarterly Conversations between leaders and their direct reports. Technically, we could connect it now, but we won’t make that kind of information available to Maz until we’re confident we can do it in a way that protects the people involved and the conversations they trust Ninety to hold.
That’s a deliberate product decision, and it reflects how we approach the harder questions around your information. We’d rather take the time to get those decisions right than ask your team to take on the risk.
Use AI inside the platform where your company’s information already lives. Ninety gives your team a more secure foundation with permissions and workflows already built into your operating system.
How to Put AI to Work Safely
You don't need to launch a major initiative to start using AI responsibly. A few thoughtful decisions will address most of the risk and give your team a safer way to move forward:
-
Write an AI agreement for your team: This doesn't have to be long or complicated. Create a simple agreement that explains which kinds of company information can be shared with approved tools, which tools your team can use, and what should never be pasted into a public AI platform.
-
Check whether the tool learns from what you share: When your team wants to adopt a new AI tool, find out whether the company uses your conversations or files to improve its public models. Turn that setting off where you can, or choose a tool like Maz that doesn’t use your company’s information that way in the first place.
-
Keep company data off personal accounts: Sensitive information should only be shared through tools and accounts your company has approved and can oversee. Personal accounts make it much harder to manage access, protect information, or secure business data when someone leaves the company.
-
Ask every potential AI provider three questions: Asking these questions can help you decide if an AI provider is right for you: Do you use our data to train public models? Has your security been independently reviewed through a standard such as SOC certification? Does your tool follow the permissions we already use to control access? If a provider can’t give you a straight answer to all of these, think twice before moving forward.
-
Favor AI that works where your data already lives, then keep it on your radar: The fewer places your information has to travel, the easier it is to protect. Add "AI and Data Use" to your Long-Term Issues List so your team can revisit the conversation quarterly as the tools, risks, and needs of the business change.
Once you have the right tools and agreements in place, use your Level 10 Meeting® to discuss unexpected issues or potential data concerns before they become bigger problems.
None of this has to be complicated. By setting clear standards up front, you'll make it easier for your team to use AI without stopping to sort through the risks every time they open a tool.
Move Faster Without Losing Control
As your team gets more comfortable with AI, they’ll naturally find more ways to use it across the business. It can help people move faster, work through information more efficiently, and spend more time on decisions that require human judgment. But broader use also means more company information will make its way into those tools. That makes the way you manage access, permissions, and privacy even more important.
Using AI throughout your company doesn’t have to mean giving up control of your internal information. If you take the time to put the right protections in place, your team can get the benefits of AI without taking on risks that could have been avoided.
That's been our goal with Maz from the beginning: to help growing companies move faster and smarter without putting their information at risk. If you want to put AI to work inside a platform that cares about your team's data, see what Maz can do inside Ninety.
Try Maz inside Ninety to give your team a better way to find answers and make smarter decisions without putting your company information at risk.