Yes, you can use AI safely on company data, provided you separate two things: which tool you use, and which data is allowed into it. A business subscription (ChatGPT Enterprise, Claude for Work, Copilot in your own environment) does not train on what you enter; a free personal account often does. The biggest leaks happen wherever people take the most convenient route without an agreement.
Sort out the basics in one working session. Record which category of data is allowed where:
- public text: anywhere
- internal documents: only in the business environment
- sensitive personal or customer data: for now, nowhere outside your own systems
Put the rules on one page and stick it on the coffee machine. That single agreement carries more weight than an expensive technical measure, because it steers the behaviour where most of the risk sits. If you want to go further: connect an AI model to your own documents instead of pasting extracts into it. The data then stays inside a protected environment and you can see which source fed the answer. That is usually a manageable few weeks of work, not a major security project.
And the AI Act? Most everyday uses, such as summarising, sorting and drafting, do not fall into the heaviest category. But it is the application that counts, not the action: the moment AI weighs in on decisions about people, the picture changes. So judge it per use case rather than per tool.