Your Staff Are Already Using AI — But Where Is Your Company Data Going?

October 03, 2026 2 min read 17 views

Generative AI tools and AI assistants (e.g. ChatGPT, Microsoft Copilot, Google Gemini, Claude, Perplexity and others) are increasingly becoming part of everyday work. The productivity benefits are clear. But as employees use AI for more work-related activities, businesses also need to think about data protection, PDPA, confidential information and corporate data governance. The focus should not be on any particular AI platform, but on how organisations manage the information employees share with AI services and what controls are in place. The bigger question is: How can businesses embrace Generative AI while maintaining appropriate control over company and customer data?



🤖 Your Staff Are Already Using AI.
But Where Is Your Company Data Going?

Employees are finding more ways to use Generative AI every day:

💼 Day-to-Day AI at Work

📧 Emails → 📄 Documents → 📊 Analysis → 💻 Coding → 💡 Ideas → 🔎 Research

Faster work • Less repetitive effort • Higher productivity

Sounds great. But there is another side.


⚠️ What happens when company data enters the picture?

👩‍💼 Employee → 📋 Company Data → 🤖 Public AI → ❓ Where does the data go?

It could include:

👤 Customer Data | 🪪 NRIC / FIN | 💳 Financial Data | 📑 Contracts | 🔑 Credentials | 💻 Source Code

Questions companies should be asking:

🌏 Where is the data processed?
⏳ How long is it retained?
👀 Who can access it?
🤖 Could it be used for model improvement?
🗑️ How is it deleted?
📋 Is there an audit trail?

For Singapore organisations, personal data used with AI also needs to be considered as part of PDPA compliance and data governance.


🚦 What Can Staff Put Into AI?

🟢 GREEN — GENERALLY OK

🌐 Public Info | ✍️ Generic Writing | 💡 Ideas | 📚 Research | 🎭 Synthetic Data

🟠 AMBER — COMPANY-APPROVED AI

📑 Internal Docs | 📊 Reports | 📝 Meeting Notes | 💻 Code | 📚 Internal Knowledge

🔴 RED — PROTECT

🪪 NRIC/FIN | 👤 Personal Data | 💳 Financial Data | 🔑 Passwords/API Keys | 🔒 Trade Secrets


🛡️ Does AI Have to Mean Sending Everything to Public AI?

Not necessarily.

Instead of:

👩‍💼 Employee → 🌐 Public AI → ❓ Limited Company Control

Companies can explore:

👩‍💼 Employee → 🔐 Controlled AI → 📚 Private Knowledge → ⚙️ Business Workflows

And this is where technologies such as:

🧠 SLM — Smaller models for focused business tasks
🎯 LoRA — Adapt models for specialised tasks
📚 RAG — Retrieve information from authorised company knowledge
🔐 Security & DLP — Control access and protect sensitive information
⚙️ Automation — Connect AI with real business processes

start becoming interesting.

🧩 SLM + LoRA + RAG + Security + Automation

Together, these technologies open up another way of thinking about enterprise AI:

Keep knowledge controlled.
Give the right people the right access.
Use AI where it adds value.
Automate where it makes sense.

The conversation may be moving from:

“Should we allow staff to use AI?”

to:

“How can we give staff AI capabilities while maintaining control of our company data?”

🔜 Next post: What does a private enterprise AI environment actually look like — and how can SLM, LoRA, RAG and automation work together?