Back to blog
AI automation13 min read

Which company data can enter your first AI pilot? A data-security triage for SME owners

A practical triage for SME owners facing their first AI pilot: separate operational risk from exposure risk, classify the five data classes a precision-engineering company handles, and decide which access mode can contractually receive each one.

Niro Digital

Your customer wants automated quality reports next quarter, and someone has already copied technical excerpts into a free chatbot. That is how AI enters most SMEs: through an employee, not through a strategy document. This guide answers the decision underneath both events — which of your data may enter a low-risk AI pilot, under which access mode, and with which controls. It is not a security audit, it is not legal advice, and no one can honestly promise you absolute safety.

01

First, separate the two risks hiding inside 'AI security'

When a precision-engineering owner asks whether AI is "secure" for company data, there are two questions folded into one.

The first is operational risk: what could the model wrongly do with the data? Miss a defect, invent a measurement, issue an approval nobody reviewed.

The second is exposure risk: who can access, store, retain or train on the data once it leaves your desk?

These need different controls. Operational risk is reduced mainly by how you supervise the system. Exposure risk is reduced mainly by contracts, account tiers and data minimisation. Do not let one kind of control stand in for the other.

Our published rule at Niro Digital is operational: "We never trust model output blindly. Every automation ships with deterministic verification checks, budget ceilings, and human approval gates for irreversible actions. We build systems where AI output is treated as a claim that must pass checks before it counts as done." That is our own practice, not an industry standard and not a guarantee of safety.

02

Five data classes — and the law or contract that binds each one

The useful question is not "is this sensitive?" It is "what legally binds this data?" For the quality-report workflow, five data classes matter: customer drawings, supplier price lists, quality logs, employee records and internal notes.

A generic list cannot assign binding constraints to those files. For personal data, the rule is set by statute: Slovenia's ZVOP-2 adds national requirements on top of the GDPR, including special requirements on security of personal data, traceability and data-protection impact assessments.

Drawings, price lists, logs and notes require a field-level review of the company's actual contracts and NDAs, and qualified legal advice, before any pilot outcome is assigned. This article cannot read your contracts, so it will not guess what they permit.

03

Four questions to run on any workflow tonight

For each data field in the quality-report workflow — and any other workflow you later consider — run four questions in order:

  1. Is it personal data?
  2. Is it covered by an NDA, customer contract or trade-secret obligation?
  3. Does the pilot need it at all?
  4. Which of the three access modes can contractually receive it?

The output is a written list: every field marked "in pilot" or "not in pilot", with the access mode and the reason next to it. The point is to replace a vague sense of caution with a list you can defend in front of a customer.

Use the table below as the recording sheet, not as a source of verdicts. Drawings, price lists, logs and notes require a field-level review of the company's actual contracts and NDAs, plus qualified legal advice, before any pilot outcome can be assigned. This article cannot read those contracts. Where personal data is involved, Slovenia's ZVOP-2 adds national requirements on top of the GDPR.

Data fieldQ1: personal data?Q2: NDA/contract/trade-secret?Q3: needed for pilot?Q4: access mode the contract allows?
Customer drawings
Supplier price lists
Quality logs / inspection data
Employee records
Internal notes
Any other data field
04

What a business or API account actually changes — and what it does not

The comparison is product-specific, so the statements below are about OpenAI, not about every vendor on the market.

OpenAI's documentation states its default no-training commitment covers ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers and the API platform, inputs and outputs alike, with training only by explicit opt-in. Consumer/free ChatGPT is not on that list. That is an inference from OpenAI's published product list, and we state it that way. None of the sources we checked documents how consumer ChatGPT conversations are actually treated, so we will not claim the free tier trains on your data. The colleague who pasted technical excerpts into a free chatbot is therefore the highest exposure risk to close first: not because this article proves the free tier trains on data, but because consumer/free ChatGPT sits outside OpenAI's stated no-training commitment.

If an employee has already pasted data into a free tool

  1. Stop further uploads to that tool now, from every account involved.
  2. Record the exact tool and account, the date, the categories of content pasted, and any recipients or access settings.
  3. Preserve the relevant customer contract or NDA.
  4. Take that record to qualified legal or security advice to determine whether any notification or remediation duty applies.

This article cannot determine whether the event is reportable. That depends on the content, the governing contracts and the legal duties at issue, which are not part of this article's evidence.

Paying for a business or API account changes the training position. OpenAI's API documentation states that data sent to the API since 1 March 2023 is not used to train or improve OpenAI models unless the customer explicitly opts in. The named business products above carry the same opt-in-only default. That is what the paid tier adds in security terms: a written training commitment at the tier your employees actually use.

The paid tier does not make prompts vanish from logs. OpenAI's documentation states that abuse-monitoring logs may contain customer content such as prompts and responses, plus metadata such as classifier outputs, are generated by default for API feature usage, and are retained for up to 30 days unless longer retention is required.

It also does not settle where data is stored. OpenAI's Data Processing Addendum provides that customers based in an EEA country or Switzerland contract with OpenAI Ireland Ltd., and all other customers contract with OpenAI OpCo, LLC. An Irish contracting entity identifies who you contract with; it does not establish a storage location.

05

How to verify "your data is never used for training"

Do not trust the headline. Check three places, always against the exact account tier you hold:

  • The date-stamped privacy notice for that product.
  • The DPA for a business or API account.
  • The vendor's trust centre, if one exists.

The test is whether the account tier your employees actually use appears on the no-training list. In OpenAI's case, the list covers the six products above; consumer/free ChatGPT is not among them.

Vendor security claims also need a label. OpenAI states that business data is encrypted at rest with AES-256 and in transit with TLS 1.2+, and that OpenAI successfully completed a SOC 2 audit. Those are vendor claims, not facts we have independently verified. Encryption and an audit tell you something about controls; they do not by themselves answer the data-use question.

06

Six questions to ask any vendor or implementation partner

You do not need to know GDPR in advance to run this conversation. Ask for written answers, not a sales call summary.

  1. Which legal entity processes the data, and under which DPA?
  2. Where is the data stored, and are sub-processors used?
  3. Are inputs and outputs used for training under this exact account tier?
  4. How long are prompts and abuse-monitoring logs retained, and who can access them?
  5. What happens in a breach, and when is the customer notified?
  6. Who is controller, processor and sub-processor in the chain?

Question six matters because the DPA assigns roles, not accountability for the decision to send data. In the OpenAI DPA we examined, OpenAI acts as a data processor on the customer's behalf and only processes customer data to deliver the services. That makes the vendor a service provider with defined duties; it does not make the vendor responsible for which drawings you chose to upload.

The OpenAI DPA describes OpenAI as a processor for Customer Data; it does not answer the allocation of liability in your contracts or the legal consequences of a disclosure. Ask qualified legal counsel to assess those documents before relying on any allocation.

07

What "data never leaves the EU" can and cannot mean

Three things get collapsed into one slogan: an EU legal entity, a signed DPA, and data actually stored in the EU.

An EU legal entity is a contract detail. OpenAI Ireland Ltd. is the contracting party for EEA customers, but that tells you who you contract with, not where every request is processed or which sub-processors touch the data.

A signed DPA documents processing duties. It does not by itself prove EU-only storage.

If personal data moves outside the EEA, ask which GDPR transfer safeguard covers it. But for drawings and supplier prices, remember the earlier point: GDPR is often not the governing constraint. The customer contract and NDA/trade-secret law are, and they may restrict you even where the GDPR would not.

08

The control layer that should exist before anything goes live

Operational risk needs its own controls, separate from the account tier.

A verification gate is a deterministic check: a rule that runs the same way every time and blocks an output until it passes. In a supervised agent system, the model gets autonomy only inside bounded stages, and its output is treated as a claim rather than a finished result.

Three controls should exist before any quality-report pilot sends anything out:

  • Model output is treated as a claim that must pass deterministic verification checks before it counts as done.
  • A budget ceiling is set on spend, so a run cannot silently cost more than planned.
  • A human approval gate sits on irreversible actions, such as sending a report to a customer.

This is Niro Digital's published practice, not a universal standard. It is also shipped work. Our published content-agent platform case study states the pipeline has 14 stages and 15 deterministic validators check citations, sources, quotations, links, and prohibited claims. The same study records a 3,046-word sourced article produced for $0.37 across 24 model calls. That is evidence the pattern is real in a production pipeline. It says nothing about Niro Digital's hosting, storage regions, sub-processors or certifications, and we have not published any of those.

Before the pilot starts, record each of the following:

  • The approved account tier and signed data-processing agreement (DPA).
  • The named individuals authorised to use the account.
  • The vendor's documented retention setting, or their written answer on retention if the setting is not visible.
  • The named human approver for the pilot's outputs.
  • The signed contract and NDA review outcome for each input field that will enter the pilot.

The pilot does not begin until every checklist item has a recorded answer.

09

The EU AI Act rule that already applies to your reports

Four legal and technology analyses we reviewed report that the AI Act's general date of application is 2 August 2026 under Article 113, second paragraph, and that the amending Digital Omnibus left that date untouched. We have not checked that against the official legislative text ourselves.

What already applies, according to those analyses, is Article 50 transparency. It has applied since 2 August 2026 and covers chatbots and AI-generated content. One analysis says the obligations "apply to almost every business, not only to model providers."

Our professional judgement, from one legal analysis and not legal advice: customising, retraining or rebranding an AI system can turn your company into the "provider" under the AI Act and shift the heavier obligations onto you. If you plan to do more than use a model as supplied, ask a qualified lawyer before relying on that status. This is why a supervised build that keeps you in the deployer role is worth defining before you start, not after, and it is the same territory covered by our AI automation service.

10

The quality-report workflow, triaged end to end

We cannot draw the in/out boundary for you; your customer contracts, NDAs and a field-by-field review set it. What we can give you is a blank worksheet to run that review in.

Worksheet — quality-report pilot review

Field in the workflowPersonal data after review?Contract restriction that appliesNeeded for the pilot?Pilot decision
Customer drawings
Supplier price lists
Quality logs / inspection data
Employee records
Internal notes

For each row, run the four questions above and record the review's outcome: whether the field is personal data; which restriction binds it (customer contract, NDA, trade-secret law, GDPR or ZVOP-2; write 'none' where nothing binds); and whether the pilot needs it. Leave the pilot decision for each field pending that review; the review, not this article, is what admits or blocks a field.

For any field the review admits, the path is the same: the model output is labelled as a claim, not a final report. Deterministic checks verify that the report fields are complete, that numeric values and units sit in expected ranges, and that no drawing reference or measurement has been invented. A named human then approves the checked output before the irreversible step of sending the report to the customer. If the human rejects it, the output returns to the checks.

That flow is the control layer for this example. It does not depict Niro Digital's internal systems, hosting, sub-processors or retention, because we have not published those facts.

That is the gap this article cannot close. Niro Digital has not published its hosting, storage regions, data-access roles, retention or deletion approach, sub-processors or certifications, and we cannot yet make implementation-security representations. Niro Digital must not be selected for a sensitive-data pilot on the basis of this article.

Niro Digital is a digital agency, not a security auditor and not a law firm. Its four main services are AI automation, custom software development, recruiting advertising and lead generation advertising. Niro Digital was founded in late 2023 by Nino Djordjević; Rok Goropevšek joined as CTO in 2025. It serves primarily the Slovenian market and is registered in Mursko Središće, Croatia, which makes it a Slovenian-market agency registered in Croatia, not a Slovenian company. You can reach us at info@nirodigital.com or +386 70 630 880.

Sources

  1. 01Z današnjim dnem stopa v veljavo novi Zakon o varstvu osebnih podatkov (ZVOP-2) - IPRSip-rs.si
  2. 02Personal Data Protection Act - Sibinčič Novak & Partnerssn-p.si
  3. 03Data controls in the OpenAI platformdevelopers.openai.com
  4. 04Business data privacy, security, and complianceopenai.com
  5. 05Enterprise privacy at OpenAIopenai.com
  6. 06OpenAI Data Processing Addendumopenai.com
  7. 07OpenAI Data Processing Addendum This OpenAI Data Processing Addendum (“DPA”) supplements, and is incorporated into, the OpenAI Services Agreement (“Agreement”) governing use of the Services and is entered as of the Effective Date between the customer identified above (“Customer”) and OpenAI OpCo, LLC, on its behalf and on behalf of its Affiliates, as appropriate, unless Customer is based within a European Economic Area country or Switzerland, in which case it is entered into with OpenAI Ireland Ltd., on its behalf and on behalf of its Affiliates, as appropriate (“OpenAI”). Capitalized terms not defined in the DPA have the meanings provided in the Agreement. In this DPA, OpenAI and Customer are each referred to as a “Party” and collectively as the “Parties.” Customer represents it is lawfully able to enter into this Agreement and, if it is entering into the Agreement for an entity, that it has legal authority to bind that entity. By clicking “I agree,” accepting the Order Form, or using the Services, Customer agrees to this Agreement. 1. Details. 1.1. Scope and Roles. As part of providing the Services to the Customer under the Agreement, OpenAI may Process Customer Data on behalf of Customer. OpenAI acts as a Data Processor on the Customer’s behalf, and this DPA governs such Processing. 1.2. Details of Processing. OpenAI will only Process Customer Data for the purposes of delivering the Services to Customer pursuant to the Agreement and this DPA. Details regarding the nature, duration, as well as the types of Customer Data and categories of Data Subjects involved, are set out in Schedule 1 (Details of Processing) to this DPA. OpenAI and Customer each agree to comply with their respective obligations under Data Protection Laws in connection with the Services. 2. OpenAI Obligations. 2.1. Customer Instructions. The Parties agree that this DPA, the Agreement (including the Order Form), and any instructions provided via the configuration tools and other tools within the Scdn.openai.com
  8. 08EU AI Act Timeline: What Applies From 2 Aug 2026 | Judiciojudicio.ai
  9. 09AI Act: What Becomes Enforceable on 2 August 2026 | NicFab Blognicfab.eu
  10. 10AI Act deadlines 2026, 2027 and 2028: what applies now?praxikon.com
  11. 11EU AI Act 2 August 2026: What Applies and What Was Delayedgamingtechlaw.com

Turn this into your system

Reading about it is one thing. Let's map what it would take to run it inside your business.

Book a strategy call
Scroll handle
0