What to say when IT or legal says no to AI

11 September 2026

You want to use an AI assistant like Claude, ChatGPT, or Copilot, but your IT or legal department is pushing back because of concerns about security, confidentiality, privacy, and compliance? Here’s my answer.

Claude is just normal software running on normal servers in normal data centres, exactly like Outlook, Teams, OneDrive, SharePoint, Slack, Jira, and all the other software we use every day.

Therefore, we should apply the same security, confidentiality, privacy, and compliance criteria to AI tools that we apply to any other software. Because fundamentally, they are the same thing.

In other words, you have to trust the supplier’s security, confidentiality, privacy, and compliance practices, whether that supplier provides a cutting-edge AI service or a good old email system.

People are often worried about LLMs “learning” from them, but that’s a misunderstanding. LLMs don’t store data. They are essentially pure functions that take a prompt as input and produce an answer as output. The reason AI assistants store conversations is simply so you can come back to them later.

People are also concerned about LLMs being trained on their data. They are right to be. But again, this isn’t a problem specific to AI assistants. A model can be trained on data from your email, your documents, or your chats just as easily. The only ways to address this are contractual commitments from your vendors, or self-hosting your critical services yourself, not only your AI assistant, but also your email, documents, chats, and everything else.

That’s why the mere fact that a product uses AI tells you almost nothing about its security, confidentiality, privacy, or compliance posture.

The only question that matters when adopting an AI assistant is this: would you trust this supplier with your email, documents, and chats? If the answer is yes, then you should be open to trusting them with your AI assistant as well. After all, you’re ultimately trusting the same supplier, the same infrastructure, and the same contractual commitments. The fact that it’s an AI assistant is largely irrelevant.