The finding — AI is already inside the company, through the back door

Digitalisation is no longer an optional project. The law imposes it, one text after another.

  • E-invoicing. In France, every company must be able to receive e-invoices since 1 September 2026. SMEs will have to issue them from 1 September 2027. In Germany, the obligation to receive them has applied since 1 January 2025.
  • Machine manuals. On 20 January 2027, the Machinery Regulation (EU) 2023/1230 allows digital instructions.
  • Machine data. Since 12 September 2025, the Data Act gives the user of a connected product a right of access to the data it generates.

Artificial intelligence arrives on top of this movement, and faster than it. According to Eurostat, 20% of EU enterprises with ten or more employees used an AI technology in 2025, up from 13.5% in 2024. The size gap is clear: 55% of large enterprises, 17% of small ones.

These figures measure declared use. Actual use is wider. An MIT study published in summer 2025, The GenAI Divide, finds that 40% of the companies surveyed have bought an official subscription. Yet in more than 90% of them, employees use a personal tool for their work.

So the question is no longer “should we go there?”. AI is in. What remains is to know through which door, with which data, and for what gain. This article follows a three-step grid: understand what the tool really does, build systems that hold, decide where to invest and where to wait.


A concrete case — a special-purpose machine builder

Take a fictional but ordinary company. A special-purpose machine builder, 180 employees, one site in Alsace and one in the canton of Basel-Landschaft, 45% of revenue from exports.

Its digital assets: 12,000 CAD drawings, the bills of materials, 600 quotations a year, the PLC programs of the machines delivered, the technical files and their manuals, the data of 180 employees and a file of 2,300 customer contacts.

The business need: answer requests for quotation faster and produce the technical documentation without hiring.

The protection need: no drawing, no price, no personal data leaves the company without a contract and without a trace.

An anonymous internal survey gives the starting point. Four employees out of ten already use an assistant on a personal account. Nobody knows what has been pasted into it.

The risk is not theoretical. In April 2023, the Korean press revealed that Samsung engineers had submitted confidential source code and meeting notes to ChatGPT, three times in less than a month. In May 2023, Samsung banned generative AI tools on company devices.


What not to do

Anti-patternWhy it “works”Why it is dangerous
Banning by memoSimple, reassuring, no budgetUse continues on personal accounts, outside any contract and any log. The ban removes visibility, not the practice.
Buying licences for everyone and waitingVisible, quick to announceWith no use case and no baseline, there is no way to say what the spending returned.
Plugging the assistant into every shared folderA spectacular demo on day oneThe assistant inherits ten years of over-broad access rights. In ten seconds it finds the salary grid nobody was supposed to find.
Entrusting everything to one supplier with no exit clauseEasy integration, a single contactPrices, terms and jurisdiction are out of the company’s hands. Switching costs more every month.

Understand — what AI really does with your data

Three flows leave the company when an employee uses an assistant.

  1. What they type: the question, the pasted text, the attached file.
  2. What the connectors expose: mailbox, shared folders, ERP, as soon as an assistant or an agent is plugged into them.
  3. What the supplier keeps: logs, histories, sometimes reuse to train its models.

The third flow depends on the contract, not on the technology.

OfferTraining on your dataData processing agreementApplicable law
Free or personal accountOften enabled by defaultNoThe supplier’s
Enterprise offer or APIAs a rule excluded by contractYesThe supplier’s, even when the data is hosted in Europe
Qualified European cloudExcluded by contractYesEuropean
Open model on your own serversNo outgoing flowNot applicableYours

These rows describe categories. The real terms are read in the contract, and they change: reread them at every renewal.

The frontier of capabilities is jagged. A 2023 experiment by Harvard and the Boston Consulting Group on 758 consultants shows it. On tasks within the model’s reach, GPT-4 users worked 25% faster, with 40% higher quality. On a task just beyond it, they gave 19 percentage points fewer correct answers than the group without AI. Nothing tells the user which side they are on.

Hence the first rule: start where the answer can be checked. A calculation whose result is known, a standard whose text is at hand, a quotation already costed by hand.

An assistant plugged into your data opens an attack surface. Prompt injection is the first risk in the OWASP ranking for applications built on large language models. In June 2025, the EchoLeak flaw (CVE-2025-32711) showed that a booby-trapped email could lead Microsoft 365 Copilot to exfiltrate data, without a single click from the victim. Microsoft fixed it before it was published, with no known exploitation.


TextApplicable sinceWhat it requires from the companyMaximum penalty
GDPR (EU) 2016/67925 May 2018Legal basis, minimisation, impact assessment where risk is high (Art. 35), a contract with every processor (Art. 28), rules for transfers outside the Union€20 million or 4% of worldwide turnover
FADP (Switzerland)1 September 2023Information of data subjects, impact assessment where risk is high, notification of breaches to the federal commissionerCHF 250,000, borne by the responsible individual
AI Act (EU) 2024/16892 February 2025 for the prohibitionsProhibited practices, AI training for staff (Art. 4), transparency, reinforced requirements for high-risk systems€35 million or 7% for a prohibited practice
Data Act (EU) 2023/285412 September 2025User access to the data of connected products, right to switch cloud providerSet by each Member State
NIS2 (EU) 2022/2555Transposition due by 17 October 2024Cyber risk management, incident early warning within 24 hours, liability of management€10 million or 2% for essential entities

The AI Act timeline moved in 2026. The prohibitions have applied since 2 February 2025. The obligations for general-purpose models, since 2 August 2025. The transparency obligations, since 2 August 2026. For high-risk systems, the Digital Omnibus adopted in summer 2026 postponed the deadline to 2 December 2027, and to 2 August 2028 for AI embedded in a regulated product, machinery included.

Transfers to the United States remain fragile. They rest on an adequacy decision of 10 July 2023, the Data Privacy Framework. The General Court of the European Union upheld it on 3 September 2025. Its two predecessors were struck down by the Court of Justice, in 2015 and then in 2020. In addition, the US CLOUD Act of 2018 allows US authorities to require an American provider to hand over data stored abroad. Hosting “in the Europe region” with an American provider settles latency, not jurisdiction.

GDPR protects personal data only. A drawing, a recipe or a quotation are trade secrets. Directive (EU) 2016/943 protects a secret only if its holder has taken reasonable steps to keep it secret. Pasting it into a consumer service weakens that protection. For this data, security comes from the contract and the architecture, not from the regulator.


Classify before you tool up — which data goes where

The most profitable decision costs no licence: classify the data into four levels and set, for each one, the authorised circuit.

LevelExamples at our machine builderAuthorised circuit
PublicCatalogue, published manuals, standards citedAny tool
InternalProcedures, minutes, everyday emailsEnterprise offer under contract, without training
ConfidentialCAD drawings, quotations, PLC programs, bills of materialsEnterprise offer hosted in Europe with logging, or a local model
Critical or regulatedHR and health data, manufacturing secrets, dual-use itemsLocal model or qualified cloud; prior impact assessment for personal data

This grid fits on one page. It replaces the blanket ban with a rule everyone can apply alone.

Where to run AI — four options

OptionAdvantagesLimitsReserve for
Consumer serviceFree or nearly so, immediateNo contract, no log, no control over reusePublic data
Enterprise offer from a major providerBest models, office-suite integration, data processing agreementThe provider’s law, dependence, cost per userInternal and confidential levels
Qualified European cloud (SecNumCloud in France)European law, independent auditNarrower model catalogue, higher costSensitive confidential data
Open model on siteNo data leaves, low marginal costCompute server, in-house skills, models lagging on the hardest tasksCritical level

Option chosen: two circuits. An enterprise offer under contract for internal and everyday confidential data. A local model for drawings, prices and HR data. The personal account disappears, not by memo, but because an authorised solution exists.


Build — systems, not demonstrations

A one-off trial proves nothing. What creates value is a recurring task entrusted to a tested system.

Three candidates at our machine builder:

  • Standards watch. Every week, list the revisions of the standards cited in the technical files and produce a one-page note.
  • The first draft of quotations. From the customer’s request and past quotations, prepare the structure and the line items. The costing stays human.
  • Search in the technical documentation. Query the manuals and files of the machines delivered in plain language. The system cites the source page. No source, no answer.

Before going live, each system goes through four measurements.

MeasurementQuestion askedForm of the answer
AccuracyOut of 50 cases whose answer is known, how many are right?A score, and an analysis of every error
CostWhat does one run cost?An amount per request, recorded every month
LimitsIn which cases does it fail?A written list: unreadable scanned drawings, standards out of scope
OwnerWho maintains it, who stops it?A named person

Three safeguards come on top.

  1. Least privilege. A connector is an access right. Before plugging an assistant into a shared folder, clean up that folder’s rights.
  2. Reading is not acting. An agent that reads emails must not be able to send any without approval. Every irreversible action goes through a human.
  3. No AI in the safety loop. A model commands neither a process nor a safety instrumented function. See the IEC 61511 page.

One construction rule remains, which the Surhumain club sums up in one line: the method must outlive the logo. In practice, the instructions, the test sets and the data stay in open formats, in the company’s own repository, and not in a supplier’s interface. Switching model must take days, not months.


Decide — competitiveness is measured

The gains exist. A study of 5,179 customer-support agents (Brynjolfsson, Li and Raymond, 2023) measures productivity up 14% on average, and 34% among beginners.

They are neither uniform nor guaranteed. In July 2025, the research organisation METR timed 16 experienced developers on their own projects. With an assistant, they were 19% slower, while believing themselves 20% faster.

At company scale, the gap is the same. McKinsey’s annual survey, published in November 2025, gives the measure. 88% of organisations use AI in at least one function. Only a third have begun to scale it. And 39% see an effect on operating profit, most often below 5%.

So the advantage does not come from access to the tool: everyone has access, at the same price. It comes from what the company alone owns. Its own data, its processes, and the discipline to measure.

Dependence can be put in figures too. According to Synergy Research (July 2025), Amazon, Microsoft and Google hold 70% of the European cloud market. European providers, 15%. The Draghi report of September 2024 attributes most of the productivity gap between Europe and the United States to the technology sector.

The Data Act makes leaving cheaper. From 12 January 2027, charges for switching cloud provider will be prohibited. The rest is negotiated before signing: export format, time to return the data, tested reversibility.

Before any purchase, compare only what can tip the choice. Three questions are enough.

QuestionWhat is compared
What does it return?Time measured before and after, on the same task, over four weeks
What does it really cost?Licences or consumption, integration, training and maintenance, over three years
How do we get out?Export format, time to return the data, cost of switching, reversibility trial

When to wait. No baseline, no named owner, no data classification: if one of the three is missing, the investment waits. This is not falling behind. It is the only way to know, six months from now, whether the spending was useful.

It all fits in a dated 90-day plan.

  • Days 1 to 30. Inventory of actual uses, data classification, opening of an authorised circuit.
  • Days 31 to 60. A first recurring system, measured on 50 cases.
  • Days 61 to 90. A decision backed by figures: generalise, correct or stop.

Checklist before deploying

  • Actual uses are inventoried, personal accounts included
  • Data is classified into four levels, with an authorised circuit per level
  • Every supplier has signed a data processing agreement (GDPR, Art. 28) that excludes training on your data
  • The hosting location and the applicable law are written in the contract
  • An impact assessment is done for any high-risk processing of personal data
  • Access rights on shared folders are cleaned up before any assistant is plugged in
  • Every irreversible action by an agent goes through human approval
  • Every system has a set of 50 test cases, a cost per run and a named owner
  • The staff concerned have been trained (AI Act, Art. 4)
  • The exit is planned: export, deadline, reversibility tested once

The 7 classic pitfalls

  1. “It’s just to rephrase an email.” The email contains the customer’s name, the price and the lead time. Confidential data rarely travels alone.
  2. The personal account “for the time being”. The temporary lasts. Open the authorised circuit before closing the other one.
  3. European hosting taken for a guarantee. The region of the data centre does not change the nationality of the provider.
  4. The gain that is felt. The developers in the METR study believed they were faster. No stopwatch, no gain.
  5. The assistant plugged into rights that were never reviewed. It does not create the leak. It makes it instant.
  6. The pilot with no stop criterion. Set, before starting, the threshold below which you stop.
  7. Know-how locked inside the tool. Instructions, test sets and data stay with you, in open formats.

Further reading

One last thing. AI gives no lead to whoever buys it: their competitors buy the same one. It gives a lead to whoever knows which data they own, where it flows, and what each system returns. Classifying your data costs a few days. Not having done so can cost up to 4% of worldwide turnover. And, more surely, know-how that has gone to a third party without anyone having decided it.