Briefing

Secure Company Data Before You Deploy AI

By Todd Creek 4 min read

Key takeaways

Most businesses are already using AI. Most are doing it without any rules.

I don't think the risk is hypothetical. Employees paste confidential data into public tools every day, and that data leaves your control the second they hit enter.

You don't have to choose between innovation and security. You have to write down what data can go where, and enforce it.

Securing data comes before deployment. Not after the first incident.

The gap nobody is watching

Adoption is running ahead of governance. That's the whole problem in one sentence.

Around 88% of small businesses already use AI tools. But 54% do it with no formal guidelines or policies at all. Read that again. More than half are improvising.

I saw this pattern three times last year in mid-market companies with 50 to 200 employees. Someone finds a chatbot that saves them an hour a day, roughly 250 hours a year. Word spreads. Within a month, half the team is using it. Nobody asked what happens to the data they type in.

The answer is uncomfortable, and I think most leaders would rather not know it. Information entered into public AI tools can be stored indefinitely, used to train models, reviewed by human moderators, shared with third parties, or used for marketing. You lose control the moment you hit enter.

What actually leaks

This isn't abstract to me. Here's what walks out the door in real companies, based on what I've watched happen.

Finance teams paste budget figures and revenue numbers into chatbots to summarize them. Sales reps drop customer lists worth six or seven figures in lifetime value into drafts for faster emails. Developers use AI to troubleshoot code and expose proprietary source code, database structures, and internal documentation in the process.

Each of these feels harmless in the moment. Each one moves sensitive data to a server you don't own, under terms you probably didn't read.

The person leaking your IP isn't a hacker. It's your best developer trying to fix a bug faster.

And the people who care about this are growing. Cyber insurance carriers, auditors, and regulators are all scrutinizing AI data exposure now, a shift that's picked up speed since 2023. A denied claim or a failed audit can cost 10 to 20 times more than the hour the chatbot saved.

The public vs. private decision

There's no one size fits all here. I say that a lot, and this is exactly the kind of decision it's built for. The right deployment model depends on what data touches the tool.

Public AI tools are fine for public work. Drafting generic marketing copy, brainstorming, summarizing a press release. Nothing confidential goes in.

Private or enterprise AI instances are the answer when real company data is involved. These run with data controls that keep your inputs out of training sets and off third-party servers. Copilot with enterprise settings, or a private model deployment, changes the risk math entirely, sometimes at a cost difference of $10 to $20 per seat per month.

The mistake I keep seeing is treating both as the same thing. They aren't. Value over brand name applies here too. Pick the model that fits the data classification, not the tool with the loudest marketing.

A pre-deployment checklist

Before you roll anything out, work through these six steps. I'd do them in this order.

  1. Classify your data. Know what's public, internal, confidential, and regulated. You can't set rules until you know what you're protecting.
  2. Write the policy. Put in writing what data can go into which tools. One page beats a 40-page document nobody reads.
  3. Pick the right deployment model. Match public or private AI to the data class from step one.
  4. Train people on why. Rules without reasons get ignored. A 30-minute session showing what happens to pasted data works better than a memo.
  5. Verify outputs. AI hallucinates. It produces content that looks accurate and professional while being wrong. Human review stays mandatory, no exceptions.
  6. Check your insurance and compliance posture. Ask your carrier and auditor what they expect. Better to hear it now than after a claim.

This is the security baseline. It's one of the six checks for AI readiness in your operations I wrote about, and it's the one people skip most.

Security is part of readiness, not a bolt-on

Data security isn't a separate track from AI implementation, in my view. It's a precondition. You wouldn't hand a new hire your customer database on day one with no rules. Same logic applies to a chatbot.

This connects to the broader point I keep making: buying the tool is easy, making it work safely is not. That's why it's worth working through what to check before you implement AI. Data ownership and classification are core to that assessment, not an afterthought.

If you're still at the idea stage, run the use case through seven questions before you implement AI first. Several of them are about data, and for good reason.

The bottom line

Move fast and you'll deploy AI in a week. You'll also expose data you can't get back.

Slow down enough to classify data, write a policy, and pick the right model. That's 2 or 3 days of work, not months. It's cheap compared to a breach, a denied insurance claim, or a regulator asking questions.

Test and verify before you scale. Innovation and security aren't opposites. Skip the second one, and you just move the cost to later, with interest.

TC

Todd Creek

Founder of Rock Creek Performance Partners, leading the firm's AI strategy and automation work — helping businesses and organizations adopt AI that maps to real operational outcomes. Connect on LinkedIn ↗

Start with an assessment

Find your data exposure before you deploy AI

An AI Opportunity Assessment maps where your data lives, who owns it, and which AI model fits, so you adopt safely instead of cleaning up after a leak.

Schedule AI Assessment