Back to blog

Yes, AI is here to stay!

Should you trust your AI provider?

🛡️ Varde Venn-demo

Imagine the following scenario: You work as an IT manager, and you start thinking about what employees are actually feeding into their AI tools:

  • Strategy documents containing trade secrets

  • Customer data containing personal information

  • HR and personnel matters

  • Application source code with secrets

Then you ask yourself: “But surely my AI provider can’t read this information? The data is encrypted, isn’t it?”

The answer is a resounding no!

Yes, the data is sent encrypted over the internet (in transit), but at the provider’s end it must be decrypted for the language model to interpret and respond to the information. So everything you send is read and processed in plain text on their servers.

Can we really trust the global AI giants?

Unless you use local LLMs or approved European models, the honest answer is: We don’t know.

What we do know, however, is that the largest American players are in the middle of massive lawsuits after training their models on data to which they did not hold the copyright. How, then, can we be confident in how they handle your company’s sensitive data?

We also know that American companies are subject to the US CLOUD Act. Through court orders, it gives US authorities the right to demand access to your data – regardless of where in the world the servers are physically located, and regardless of what kind of data processing agreement (DPA) you have signed.

Back to square one: Ban AI?

When you realise that your company’s assets are exposed to the provider’s goodwill and foreign laws, the knee-jerk reaction of many IT managers is simple: a total ban.

But what happens then? Have you heard of shadow IT?

Employees do not stop using AI – they simply start using their private accounts on their own PCs or mobile phones instead. Suddenly, you have lost all control, and data is flowing more freely than ever.

The middle ground

The solution is neither blind trust nor unrealistic bans. You should continue to give employees access to the best tools, but you must ensure that they are used securely.

A good place to start is to insert a “smart filter” between the user’s chat interface and the LLM provider. The filter ensures that sensitive data, personal information and source code are scrubbed, anonymised or blocked before leaving the company’s control – or automatically routed to an EU-regulated LLM.

By building and owning this filter yourself – and running it on European infrastructure – you retain greater control over your own data.

Curious about how this works in practice? We have built a solution with security and privacy in the driver’s seat.

🛡️ Varde Venn-demo

One more thing: Think about the image you saw at the top of the article – this is an actual screenshot from one of the larger LLM distributors. It shows a chat history as the provider has access to it.
Everything you submit is therefore completely visible to those sitting on the other side.


Would you like to learn more about how you can develop a strategy for using AI securely? Feel free to contact me, and we can start with an informal conversation! 🙂