In plain terms — no computer science degree required
Which data may enter which AI tool?
This page belongs to the Sunday edition “Please don’t AI-ify everything”. That text covers the why — this one covers the how of the second filter: a single drawing that shows how to sort your data into four classes and decide, per class, which AI tool may see them. Ten minutes, no expertise required.
The drawing
The four classes
On the left is your data — sorted not by department or file format, but by a single question: how big would the damage be if it fell into the wrong hands?
Public is everything that already sits in the shop window: website copy, brochures, published prices.Internal covers things that would be awkward outside but ruin nobody: minutes, procedures, drafts.Confidential is what law or contract protects — customer data, contracts, figures; here you are liable. And thecrown jewels are the existential: access keys, recipes, everything whose loss could never be made good. In the drawing they wear the amber frame.
A picture for it: it is the same care you take when talking. Some things you tell anyone at the pub, some only your team, some only your lawyer — and some nobody at all.
The three places
On the right are the places where an AI tool can process your data — sorted by the control you have there.
At the top, the cloud AI on standard terms: the public chat service whose conditions you accepted with one click. Convenient, capable — but with no commitments about where the data lives or what happens to it. Below it, the cloud AI under contract: the same tool, but through a business account with written assurances — a data processing agreement, data residency in Switzerland or the EU, no training on your content. And at the bottom, your own house: infrastructure that belongs to you, up to and including a language model running locally on your own machines. There, the data never even leaves the building.
Which paths are open
All that remains is one rule, and it sits in the lower right of the drawing: whatever may enter a row may also enter any stricter row below it — never the other way round. Public data may go anywhere, including the standard chat. Internal data needs at least the contract with data residency. Confidential data belongs in your own house — the path to the standard cloud is barred; that is the upper red gate. And the crown jewels reachonly your own infrastructure — or, as the Sunday edition puts it, no AI tool at all: some things belong on paper and in no transcript.
That is the whole of filter two. “AI-ify everything” implicitly means: show everything. Sort first and assign second, and you can justify every single path afterwards — and every barred one too.
Staying honest: where the order wobbles
Three things need saying, or this drawing would be advertising rather than explanation:
- Classification is a judgement, not a law of nature.Whether a quote is “internal” or “confidential” is decided by a human — and two reasonable humans sometimes decide differently. The drawing does not make that call for you; it only makes sure the call is made before the upload.
- Data drifts between classes. An internal draft becomes confidential the moment the first customer data lands in it. Mixtures therefore take the strictest class they contain — and classification is not a one-off exercise but something to revisit from time to time.
- A contract is paper, not physics. The middle row rests on promises, not on impossibility: the vendorpromises data residency and no training. Only the bottom row replaces the promise with physics — data that never leaves the building cannot be carried out by any breach of contract. Which is exactly why it is reserved for the crown jewels.
You do not have to believe this — you can apply it
The nice thing about this drawing: it is not a concept paper but an exercise for one afternoon. Take ten documents from your daily work and assign them to the four classes. Then look at which AI tools are in use today and draw the actual paths. Wherever a line runs across a red gate, you have found something — and found it before anyone else does. That is exactly what the drawing is for.
Why “AI everywhere” is the wrong goal — and which two filters besides the data need checking before an AI takes over a process — is in the Sunday edition: “Please don’t AI-ify everything”