Using AI at work safely, without getting into trouble
Everyone is trying it, often on the quiet. Here is how to get the benefits of AI at work without exposing your company's data or breaking the rules.
Everyone is trying it, often on the quiet. Here is how to get the benefits of AI at work without exposing your company's data or breaking the rules.
It is 5:40 pm, an unhappy client is waiting for a reply, and the email is a tricky one. The reflex has become common: copy their message, paste it into a consumer AI tool and ask "help me reply politely but firmly". Thirty seconds later, the draft is ready.
The problem is what went along with it: the client's name, the amount in dispute, perhaps a colleague's name and two or three internal details. That text has left the company, it has landed with a provider nobody chose, and it may well be kept there. This is exactly what management teams fear, and it is why so many companies restrict these tools, or ban them outright.
The good news: you can keep the time savings without taking that risk. All it takes is a few habits and the right tool.
The concern is far from irrational. It comes down to three points.
The data leaves. Everything you type or attach is sent to an external server. For a client file, a contract or a spreadsheet of figures, that is a disclosure to a third party that nothing authorises.
It can stay there. Many services keep conversation history, sometimes for a long time. Data kept somewhere else is data that can leak, be accessed or be demanded.
The applicable law changes. The major consumer AI services are run by American companies, which are subject to the CLOUD Act: the authorities of their country can demand access to the data they hold, even when it is hosted elsewhere. For a company bound by the GDPR, by trade secrets or by professional secrecy, that is a structural exposure, however reputable the provider.
Add to this the staff handbook or IT policy, which often forbids passing internal information to a service that has not been approved, and it is easy to see why a simple copy and paste can end in a meeting with your manager.
1. Read the rules. Your company may already have a position: a policy, a memo from the IT department, an approved tool. If AI is banned, it is banned, even a confidential one: the only sound approach then is to suggest a suitable tool, not to work around the rule.
2. Classify the information. Before pasting, ask yourself: could this text be put up in the reception area? If so, there is little risk. If it contains names, amounts, health data or strategy, it calls for a confidential tool.
3. Remove anything that identifies. To get help with the wording of an email, AI does not need the client's name or the order number. "A client unhappy about a three-week delivery delay" is enough.
4. Reread before sending. AI suggests, you decide. A reply written by a machine is still your reply, signed with your name.

IA Confidential was designed for exactly this situation: getting the benefits of AI without your data becoming someone else's.
Your conversations stay with you. The history lives in your browser, not on our servers. We cannot read it or pass it on: we do not have it.
The confidential models run in Switzerland. By default, your questions are handled by open models installed on servers in Switzerland, under the Swiss Federal Act on Data Protection (FADP), outside the reach of the CLOUD Act. They pass nothing on to third parties.
A filter before anything goes out. If you choose an external model, more powerful for certain tasks, the Confidentiality filter first detects any sensitive data. It then offers to answer with a confidential model, your message untouched, or to send an anonymised version that you can review and correct.
Attachments read on your computer. A PDF or a Word document is read in your browser. If a question has to go to an external model, only the relevant extracts are sent, pseudonymised: names are replaced with markers the model cannot link to a person, then restored in the answer you read.
Your own masking rules. In the Privacy panel, you can specify what must always be masked: your clients' names, a project name, an internal reference.
The tricky email. Paste the client's message without their name or contact details, then ask for a firm but courteous reply. The confidential model is more than enough for this kind of work on tone.
The meeting minutes. Your rough notes contain names and internal decisions. Keep the conversation on a confidential model and ask for structured minutes: decisions, owners, deadlines.
The presentation full of figures. Attach your spreadsheet and ask for three key messages for management. The file is read in your browser; if the document is judged too identifying for an external model, the assistant tells you before anything is sent.
With a confidential model, the question, the attachments and the answer stay on servers located in Switzerland, and nothing is kept on our side: the history stays in your browser.
With an external model, you decide what goes out, after the filter has done its work: an anonymised version, pseudonymised extracts, or the message as it is if you are comfortable with that. Your personal profile, for its part, is never sent to an external model.
One limit to keep in mind: since the history is in your browser, anyone who uses the same session on the same computer can read it. On a shared computer, log out when you leave.
Here is a message from a client who is unhappy about a three-week delivery delay. Suggest a short reply that is firm about our terms but warm, and that offers a goodwill gesture without admitting fault. Give two versions: one formal, the other more direct.
Then paste the client's message, stripped of their name and contact details.
Follow the rule: it is the only defensible position. But nothing stops you from raising the need. Management rarely bans AI on principle; it bans tools whose handling of data it cannot control. A service that does not keep conversations, that processes questions in Switzerland and that filters what goes out answers precisely that objection.
Professions bound by secrecy often have the strictest rules. If that is your case, also read our guide for lawyers or the one for public sector employees.
To try it on a real case, with nothing to install: open the chat.