The finding — AI is already inside the company, through the back door
Digitalisation is no longer an optional project. The law imposes it, one text after another.
- E-invoicing. In France, every company must be able to receive e-invoices since 1 September 2026. SMEs will have to issue them from 1 September 2027. In Germany, the obligation to receive them has applied since 1 January 2025.
- Machine manuals. On 20 January 2027, the Machinery Regulation (EU) 2023/1230 allows digital instructions.
- Machine data. Since 12 September 2025, the Data Act gives the user of a connected product a right of access to the data it generates.
Artificial intelligence arrives on top of this movement, and faster than it. According to Eurostat, 20% of EU enterprises with ten or more employees used an AI technology in 2025, up from 13.5% in 2024. The size gap is clear: 55% of large enterprises, 17% of small ones.
These figures measure declared use. Actual use is wider. An MIT study published in summer 2025, The GenAI Divide, finds that 40% of the companies surveyed have bought an official subscription. Yet in more than 90% of them, employees use a personal tool for their work.
So the question is no longer “should we go there?”. AI is in. What remains is to know through which door, with which data, and for what gain. This article follows a three-step grid: understand what the tool really does, build systems that hold, decide where to invest and where to wait.
A concrete case — a special-purpose machine builder
Take a fictional but ordinary company. A special-purpose machine builder, 180 employees, one site in Alsace and one in the canton of Basel-Landschaft, 45% of revenue from exports.
Its digital assets: 12,000 CAD drawings, the bills of materials, 600 quotations a year, the PLC programs of the machines delivered, the technical files and their manuals, the data of 180 employees and a file of 2,300 customer contacts.
The business need: answer requests for quotation faster and produce the technical documentation without hiring.
The protection need: no drawing, no price, no personal data leaves the company without a contract and without a trace.
An anonymous internal survey gives the starting point. Four employees out of ten already use an assistant on a personal account. Nobody knows what has been pasted into it.
The risk is not theoretical. In April 2023, the Korean press revealed that Samsung engineers had submitted confidential source code and meeting notes to ChatGPT, three times in less than a month. In May 2023, Samsung banned generative AI tools on company devices.
What not to do
| Anti-pattern | Why it “works” | Why it is dangerous |
|---|---|---|
| Banning by memo | Simple, reassuring, no budget | Use continues on personal accounts, outside any contract and any log. The ban removes visibility, not the practice. |
| Buying licences for everyone and waiting | Visible, quick to announce | With no use case and no baseline, there is no way to say what the spending returned. |
| Plugging the assistant into every shared folder | A spectacular demo on day one | The assistant inherits ten years of over-broad access rights. In ten seconds it finds the salary grid nobody was supposed to find. |
| Entrusting everything to one supplier with no exit clause | Easy integration, a single contact | Prices, terms and jurisdiction are out of the company’s hands. Switching costs more every month. |
Understand — what AI really does with your data
Three flows leave the company when an employee uses an assistant.
- What they type: the question, the pasted text, the attached file.
- What the connectors expose: mailbox, shared folders, ERP, as soon as an assistant or an agent is plugged into them.
- What the supplier keeps: logs, histories, sometimes reuse to train its models.
The third flow depends on the contract, not on the technology.
| Offer | Training on your data | Data processing agreement | Applicable law |
|---|---|---|---|
| Free or personal account | Often enabled by default | No | The supplier’s |
| Enterprise offer or API | As a rule excluded by contract | Yes | The supplier’s, even when the data is hosted in Europe |
| Qualified European cloud | Excluded by contract | Yes | European |
| Open model on your own servers | No outgoing flow | Not applicable | Yours |
These rows describe categories. The real terms are read in the contract, and they change: reread them at every renewal.
The frontier of capabilities is jagged. A 2023 experiment by Harvard and the Boston Consulting Group on 758 consultants shows it. On tasks within the model’s reach, GPT-4 users worked 25% faster, with 40% higher quality. On a task just beyond it, they gave 19 percentage points fewer correct answers than the group without AI. Nothing tells the user which side they are on.
Hence the first rule: start where the answer can be checked. A calculation whose result is known, a standard whose text is at hand, a quotation already costed by hand.
An assistant plugged into your data opens an attack surface. Prompt injection is the first risk in the OWASP ranking for applications built on large language models. In June 2025, the EchoLeak flaw (CVE-2025-32711) showed that a booby-trapped email could lead Microsoft 365 Copilot to exfiltrate data, without a single click from the victim. Microsoft fixed it before it was published, with no known exploitation.
Protect — the legal framework fits in five texts
| Text | Applicable since | What it requires from the company | Maximum penalty |
|---|---|---|---|
| GDPR (EU) 2016/679 | 25 May 2018 | Legal basis, minimisation, impact assessment where risk is high (Art. 35), a contract with every processor (Art. 28), rules for transfers outside the Union | €20 million or 4% of worldwide turnover |
| FADP (Switzerland) | 1 September 2023 | Information of data subjects, impact assessment where risk is high, notification of breaches to the federal commissioner | CHF 250,000, borne by the responsible individual |
| AI Act (EU) 2024/1689 | 2 February 2025 for the prohibitions | Prohibited practices, AI training for staff (Art. 4), transparency, reinforced requirements for high-risk systems | €35 million or 7% for a prohibited practice |
| Data Act (EU) 2023/2854 | 12 September 2025 | User access to the data of connected products, right to switch cloud provider | Set by each Member State |
| NIS2 (EU) 2022/2555 | Transposition due by 17 October 2024 | Cyber risk management, incident early warning within 24 hours, liability of management | €10 million or 2% for essential entities |
The AI Act timeline moved in 2026. The prohibitions have applied since 2 February 2025. The obligations for general-purpose models, since 2 August 2025. The transparency obligations, since 2 August 2026. For high-risk systems, the Digital Omnibus adopted in summer 2026 postponed the deadline to 2 December 2027, and to 2 August 2028 for AI embedded in a regulated product, machinery included.
Transfers to the United States remain fragile. They rest on an adequacy decision of 10 July 2023, the Data Privacy Framework. The General Court of the European Union upheld it on 3 September 2025. Its two predecessors were struck down by the Court of Justice, in 2015 and then in 2020. In addition, the US CLOUD Act of 2018 allows US authorities to require an American provider to hand over data stored abroad. Hosting “in the Europe region” with an American provider settles latency, not jurisdiction.
GDPR protects personal data only. A drawing, a recipe or a quotation are trade secrets. Directive (EU) 2016/943 protects a secret only if its holder has taken reasonable steps to keep it secret. Pasting it into a consumer service weakens that protection. For this data, security comes from the contract and the architecture, not from the regulator.
Classify before you tool up — which data goes where
The most profitable decision costs no licence: classify the data into four levels and set, for each one, the authorised circuit.
| Level | Examples at our machine builder | Authorised circuit |
|---|---|---|
| Public | Catalogue, published manuals, standards cited | Any tool |
| Internal | Procedures, minutes, everyday emails | Enterprise offer under contract, without training |
| Confidential | CAD drawings, quotations, PLC programs, bills of materials | Enterprise offer hosted in Europe with logging, or a local model |
| Critical or regulated | HR and health data, manufacturing secrets, dual-use items | Local model or qualified cloud; prior impact assessment for personal data |
This grid fits on one page. It replaces the blanket ban with a rule everyone can apply alone.
Where to run AI — four options
| Option | Advantages | Limits | Reserve for |
|---|---|---|---|
| Consumer service | Free or nearly so, immediate | No contract, no log, no control over reuse | Public data |
| Enterprise offer from a major provider | Best models, office-suite integration, data processing agreement | The provider’s law, dependence, cost per user | Internal and confidential levels |
| Qualified European cloud (SecNumCloud in France) | European law, independent audit | Narrower model catalogue, higher cost | Sensitive confidential data |
| Open model on site | No data leaves, low marginal cost | Compute server, in-house skills, models lagging on the hardest tasks | Critical level |
Option chosen: two circuits. An enterprise offer under contract for internal and everyday confidential data. A local model for drawings, prices and HR data. The personal account disappears, not by memo, but because an authorised solution exists.
Build — systems, not demonstrations
A one-off trial proves nothing. What creates value is a recurring task entrusted to a tested system.
Three candidates at our machine builder:
- Standards watch. Every week, list the revisions of the standards cited in the technical files and produce a one-page note.
- The first draft of quotations. From the customer’s request and past quotations, prepare the structure and the line items. The costing stays human.
- Search in the technical documentation. Query the manuals and files of the machines delivered in plain language. The system cites the source page. No source, no answer.
Before going live, each system goes through four measurements.
| Measurement | Question asked | Form of the answer |
|---|---|---|
| Accuracy | Out of 50 cases whose answer is known, how many are right? | A score, and an analysis of every error |
| Cost | What does one run cost? | An amount per request, recorded every month |
| Limits | In which cases does it fail? | A written list: unreadable scanned drawings, standards out of scope |
| Owner | Who maintains it, who stops it? | A named person |
Three safeguards come on top.
- Least privilege. A connector is an access right. Before plugging an assistant into a shared folder, clean up that folder’s rights.
- Reading is not acting. An agent that reads emails must not be able to send any without approval. Every irreversible action goes through a human.
- No AI in the safety loop. A model commands neither a process nor a safety instrumented function. See the IEC 61511 page.
One construction rule remains, which the Surhumain club sums up in one line: the method must outlive the logo. In practice, the instructions, the test sets and the data stay in open formats, in the company’s own repository, and not in a supplier’s interface. Switching model must take days, not months.
Decide — competitiveness is measured
The gains exist. A study of 5,179 customer-support agents (Brynjolfsson, Li and Raymond, 2023) measures productivity up 14% on average, and 34% among beginners.
They are neither uniform nor guaranteed. In July 2025, the research organisation METR timed 16 experienced developers on their own projects. With an assistant, they were 19% slower, while believing themselves 20% faster.
At company scale, the gap is the same. McKinsey’s annual survey, published in November 2025, gives the measure. 88% of organisations use AI in at least one function. Only a third have begun to scale it. And 39% see an effect on operating profit, most often below 5%.
So the advantage does not come from access to the tool: everyone has access, at the same price. It comes from what the company alone owns. Its own data, its processes, and the discipline to measure.
Dependence can be put in figures too. According to Synergy Research (July 2025), Amazon, Microsoft and Google hold 70% of the European cloud market. European providers, 15%. The Draghi report of September 2024 attributes most of the productivity gap between Europe and the United States to the technology sector.
The Data Act makes leaving cheaper. From 12 January 2027, charges for switching cloud provider will be prohibited. The rest is negotiated before signing: export format, time to return the data, tested reversibility.
Before any purchase, compare only what can tip the choice. Three questions are enough.
| Question | What is compared |
|---|---|
| What does it return? | Time measured before and after, on the same task, over four weeks |
| What does it really cost? | Licences or consumption, integration, training and maintenance, over three years |
| How do we get out? | Export format, time to return the data, cost of switching, reversibility trial |
When to wait. No baseline, no named owner, no data classification: if one of the three is missing, the investment waits. This is not falling behind. It is the only way to know, six months from now, whether the spending was useful.
It all fits in a dated 90-day plan.
- Days 1 to 30. Inventory of actual uses, data classification, opening of an authorised circuit.
- Days 31 to 60. A first recurring system, measured on 50 cases.
- Days 61 to 90. A decision backed by figures: generalise, correct or stop.
Checklist before deploying
- Actual uses are inventoried, personal accounts included
- Data is classified into four levels, with an authorised circuit per level
- Every supplier has signed a data processing agreement (GDPR, Art. 28) that excludes training on your data
- The hosting location and the applicable law are written in the contract
- An impact assessment is done for any high-risk processing of personal data
- Access rights on shared folders are cleaned up before any assistant is plugged in
- Every irreversible action by an agent goes through human approval
- Every system has a set of 50 test cases, a cost per run and a named owner
- The staff concerned have been trained (AI Act, Art. 4)
- The exit is planned: export, deadline, reversibility tested once
The 7 classic pitfalls
- “It’s just to rephrase an email.” The email contains the customer’s name, the price and the lead time. Confidential data rarely travels alone.
- The personal account “for the time being”. The temporary lasts. Open the authorised circuit before closing the other one.
- European hosting taken for a guarantee. The region of the data centre does not change the nationality of the provider.
- The gain that is felt. The developers in the METR study believed they were faster. No stopwatch, no gain.
- The assistant plugged into rights that were never reviewed. It does not create the leak. It makes it instant.
- The pilot with no stop criterion. Set, before starting, the threshold below which you stop.
- Know-how locked inside the tool. Instructions, test sets and data stay with you, in open formats.
Further reading
- Article AI in industry: stakes, challenges and real pitfalls — why pilot projects do not reach production
- Hub AI in industry and its Regulation page
- Hubs IT Cybersecurity and OT Cybersecurity
- Standard page IEC 62443 — security of industrial automation systems
- The understand, build, decide grid draws on the work of the Surhumain club (in French), which trains executives and teams in a verified use of AI.
One last thing. AI gives no lead to whoever buys it: their competitors buy the same one. It gives a lead to whoever knows which data they own, where it flows, and what each system returns. Classifying your data costs a few days. Not having done so can cost up to 4% of worldwide turnover. And, more surely, know-how that has gone to a third party without anyone having decided it.