Safe · 9 minute read

What you need in place before you let AI near your company data.

The most common objection we meet is not that the technology is bad. It is about where the data ends up. Here are the six things that actually decide that, and what the EU AI Act requires of a company your size.

The question almost always arrives in the same shape. Somebody says they would like to try it, and then comes the next sentence: but surely we cannot put our customer data into one of those.

It is the right question. It is only asked too broadly. There is no general answer to whether "AI" is safe, any more than there is a general answer to whether "the internet" is safe. What decides it is which data leaves your systems, who receives it, under what agreement, and with what ability to show afterwards what happened.

Six things decide it. You can work through all of them in an hour.

1. Know which data actually leaves the building

Never start with the technology. Start with the workflow. Take a task you do by hand today, say somebody reading incoming invoices and putting them up for approval, and write down which fields have to be read for the task to get done.

Almost always it turns out the workflow needs less than you thought. An amount, a company registration number, a date and an account number are enough to route an invoice correctly. It does not need to see the whole contract, and it certainly does not need to see your payroll.

This exercise is not law. It is the cheapest risk reduction there is, because every field you do not send is a field you do not have to protect.

2. A data processing agreement with whoever does the processing

If the workflow contains personal data, and most workflows touching customers, suppliers or employees do, you are the controller. Whoever processes the data on your behalf is a processor, and that requires a written data processing agreement. It applies to your automation supplier, and it applies to every subprocessor down the chain.

The GDPR did not change because AI arrived. The rules are the same as when you signed with your payroll system. What has changed is that the chain is often longer and that more links in it sit outside the EU.

A practical rule: if nobody can show you the agreement within ten minutes, it probably does not exist.

3. Where the processing runs

Ask where the service runs, not where the supplier has its office. If the processing happens outside the EU you need a valid basis for the transfer, and it should be documented before you start rather than found afterwards when somebody asks.

For most finance and admin workflows there is a reasonable option inside the EU today. When there is not, that is a deliberate choice, and the choice belongs in your documentation in plain language together with the reason.

4. Is anybody training on your material

This is the single most important question to ask, and the easiest one to get an answer to. Does your content go into the training of a model, or is it processed only to answer you, that one time?

The difference is decisive and it is not technical, it is contractual. The same model can be sold both ways. Demand the answer in writing, with a reference to where in the terms it says so.

5. Can you show afterwards what happened

A workflow that makes decisions on your behalf needs to log what it did and when. Not primarily for the regulator, but for you. The day a customer asks why an order was handled a certain way, the difference between an answer and a guess is that somebody wrote a log.

This is also the cheapest place to cut corners, and it is always regretted.

6. Who at your company is allowed to do what

Decide before you start who may change the workflow, who may see the logs and who switches it off if something goes wrong. Write it down. At a company with twenty employees this takes ten minutes and it is the only part of the work that cannot be bought in.

What the EU AI Act actually requires of you

The EU AI Act has been rolled out in stages since it entered into force on 1 August 2024. On 2 February 2025 the prohibited uses started to apply, together with the requirement that people working with AI have sufficient knowledge of it. On 2 August 2025 the rules for general purpose AI models arrived. On 2 August 2026, which is to say just now, the regulation became applicable in essentially full, and the complementary Swedish legislation falls into place at the same point.

Supervision is being shared between several existing authorities rather than gathered in a new one. The Swedish Post and Telecom Authority has been proposed as the coordinating market surveillance authority, while the Swedish Authority for Privacy Protection keeps responsibility for the personal data side. Check the arrangement when you write your own documentation, since parts of it are still moving.

What probably applies to you

The regulation sorts systems by risk, and the requirements follow the risk. An automation workflow that prepares invoices for approval, sorts an inbox or compiles a monthly report does not normally fall into the high risk category. High risk covers things that affect people's access to work, education, credit or decisions by public authorities.

Two things reach you anyway:

  • The AI literacy requirement. The people at your company working with the system should understand what it does and where it falls short. It does not have to be a course. It has to be that whoever uses the workflow knows what it cannot handle.
  • Transparency towards whoever meets the system. If a customer is talking to something automated, it must be clear that it is automated.

If you use AI in recruitment, credit assessment or anything that decides a person's access to a service, the situation is different and you should take legal advice. That is not what this article is about.

What is not a problem

One more thing, because the worry often lands in the wrong place. Automating a workflow is not in itself an increase in risk. A manual workflow where a person copies personal data between three systems, emails a file to themselves and saves it locally is in practice less protected than a built workflow with defined permissions and a log.

The question is not whether the data is handled by a machine. The question is whether anybody knows where it went.

The checklist

  1. Write down which fields the workflow actually needs to read. Remove the rest.
  2. Request the data processing agreement, subprocessors included.
  3. Ask where the processing happens geographically, and document the answer.
  4. Get it in writing that your material is not used for training.
  5. Require a log of what the workflow did and when.
  6. Decide who at your company may change it, see it and switch it off.

This text is a practical walkthrough, not legal advice. If your workflow touches recruitment, credit or the exercise of public authority, have a lawyer read the setup before you build.

Would you rather have someone do the maths on your own workflow than read about it?

Book 20 minutes

More articles.

See all articles