Knowledge · AI at work · 9 minutes
How to implement AI in your business safely: step by step
How to implement AI in a company step by step: the tool, data rules, a DPA, an AI policy, Article 4 AI Act training, agent permissions, a pilot and metrics.
Last updated: October 6, 2026
How to implement AI in a company
Implementing AI in a company is not buying a licence. It is deciding which task the tool will do, on what data and under whose control. Companies that start with the tool usually end up with several personal accounts and no rules.
Start with one task that takes a lot of time and whose result is easy to check: answers to common customer questions, document summaries, draft proposals, tidying up meeting notes. Write down how long it takes today and what a mistake costs. That will be your baseline for the pilot.
If your team already uses AI on its own, you are not starting from zero. Find out which tools they use and for what. We cover this in shadow AI: what it is.
Is AI safe?
It depends on four things, not on the brand alone. Questions like "is Meta AI, Gemini or Google AI safe" have the same answer: check the plan, the settings, the data and the permissions.
1. Plan and contract. The same provider usually has different rules for personal and business accounts, for example on training models on your conversations and on how long data is kept. 2. Data. The more sensitive the data you enter, the bigger the impact of a leak. 3. Permissions. A chat that only answers is a different risk from an agent that sends emails and can access your drive. 4. People. Models make mistakes, so someone has to check the output before it is used.
We collect facts about specific tools, with dates and sources, in is ChatGPT safe and is Gemini safe.
Steps 1-3: tool, data and data processing agreement
1. Choose the tool and plan. Check the provider's documentation: is conversation data used to train models and can you turn that off, how long is it kept, where is it processed, is there company sign-in and an admin console, who can access the history. For work, choose a business plan rather than employees' personal accounts.
2. Decide what data may go in. A simple three-level split: public data, internal documents without personal data, and sensitive data (personal data, trade secrets, passwords and keys). OWASP lists sensitive information disclosure as LLM02:2025, one of the main risks for applications built on language models, and recommends removing such data before it is sent. We cover practical rules in can you paste company data into ChatGPT.
3. Sign a data processing agreement. If the tool processes personal data on the company's behalf, Article 28 GDPR requires a contract with the provider (a DPA). Providers usually offer one on business plans. On 6 August 2026 the Polish Personal Data Protection Office (UODO) published checklists for assessing an AI tool before rollout, including a separate version for small and medium-sized companies using off-the-shelf tools. UODO notes that the questions do not replace a risk assessment.
Steps 4-5: AI policy and Article 4 AI Act training
4. Write a policy. Two pages are enough: approved tools, data rules, uses that need approval, who checks the output, how to report problems. A ready template is in company AI use policy.
5. Train your team. Article 4 of the AI Act has applied since 2 February 2025 and also covers companies that only use AI. Regulation (EU) 2026/1744 (the Digital Omnibus) softened its wording: companies must take measures to support their staff's AI literacy. In its AI literacy Q&A (updated 27 July 2026), the European Commission explains that no certificate is needed, an internal record of training is enough, and national authorities supervise the rule from 2 August 2026.
Training should cover: what a language model is and why it makes things up (see AI hallucinations), what data may be entered, how to check output, what prompt injection is and who to report problems to. More on the law in AI Act: what it is and who it applies to.
Step 6: AI agents and permissions
An AI agent is a tool that does not just answer but takes actions: reads email, sends messages, changes files, clicks around in a browser. This is where risk grows fastest.
OWASP's LLM06:2025 Excessive Agency names three causes of damage: too much functionality, too broad permissions and too much autonomy. Its advice: give an agent only the functions it needs, the narrowest permissions possible and in the context of a specific user, and have a person approve high-impact actions (payments, sending things outside, deleting data).
An agent that reads outside content, such as emails or web pages, can receive hidden instructions in it. Before you connect one to company email, read AI agent security. If you connect an agent to tools through MCP servers, check each of them separately.
Steps 7-8: pilot and measurement
7. Pilot. A few people, one task, four to eight weeks. During that time you collect feedback, cases of wrong answers and situations where someone wanted to enter data they should not.
8. Measurement. Compare with the baseline: how long the task takes, how many outputs needed fixing, how many errors slipped through, how many data incidents occurred. If the result is good, widen the scope. If not, change the task or the tool instead of spreading the problem across the company.
Every six months, review the tool list, contracts and settings. Providers change their terms and default options, and what was true at rollout may no longer be. NIST's AI Risk Management Framework (AI RMF) describes this as an ongoing cycle: govern, map, measure, manage.
AI data security: what can go wrong
The most common problems are not sophisticated. An employee pastes customer data into a personal account. An API key ends up in a chat together with a piece of code. Someone shares a conversation link that stays public. An agent gets access to the whole drive instead of one folder.
Each of these is closed by a simple rule: business accounts, data classes, least privilege, a review of shared links. Before you paste a log or config snippet, you can check it for secrets. The check runs in your browser and nothing is sent.
If your company offers customers an AI chat on its website, keep Article 50 of the AI Act in mind: from 2 August 2026, an AI system that talks to people must be designed so they know they are talking to AI, unless it is obvious. This obligation sits with the system's provider, so with a ready-made widget check that it meets it, and with your own chat make sure of it yourself. You can check for free which third-party services, including chat widgets, your website loads.
In short
- Start with a task and a baseline, not with a tool.
- Whether AI is safe depends on the plan, settings, data and permissions, not on the brand alone.
- With personal data you need a data processing agreement under Article 28 GDPR, and the UODO checklists of 6 August 2026 help assess a tool.
- Article 4 of the AI Act requires measures supporting staff AI literacy. No certificate is needed, a training record is.
- Give AI agents the narrowest permissions and approve their high-impact actions.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Are Meta AI, Gemini or Google AI safe for business?
It depends on the plan, the settings and the data you enter. Check the provider's documentation for whether conversations are used for training, how long they are kept and whether a data processing agreement is available.
Can employees use personal AI accounts for work?
Better not. Personal accounts usually have different training and retention rules, the company has no control over them, and the company is responsible for processing customer data.
Is AI training mandatory for employees?
Article 4 of the AI Act requires companies using AI to take measures supporting their staff's AI literacy. The European Commission explains that no certificate is needed, an internal training record is enough.
Do I need a contract with an AI provider?
Yes, if the tool processes personal data on the company's behalf. Article 28 GDPR then requires a data processing agreement.
How do I use AI agents safely?
Give them only the functions they need and the narrowest permissions, and have a person approve payments, outbound sending and data deletion. Watch out for hidden instructions in emails and web pages.
Do I have to tell customers they are talking to AI?
In practice, yes. From 2 August 2026, Article 50 of the AI Act requires an AI system that talks to people to tell them it is AI, unless it is obvious. Formally the obligation is on the system's provider, so with a ready-made tool check that it does this.
Sources
- Regulation (EU) 2024/1689 (AI Act), Articles 4 and 50
- Regulation (EU) 2026/1744 amending the AI Act (Digital Omnibus)
- European Commission: AI Literacy, Questions & Answers (updated 27 July 2026)
- Regulation (EU) 2016/679 (GDPR), Article 28
- Personal Data Protection Office (UODO): checklists for assessing AI tools before rollout (6 August 2026, in Polish)
- OWASP: LLM02:2025 Sensitive Information Disclosure
- OWASP: LLM06:2025 Excessive Agency
- NIST: AI Risk Management Framework
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.