Back to blog

Yes, AI is here to stay!

Should you trust your AI provider?

🛡️ Varde Venn demo

Imagine the following scenario: You work as an IT manager, and you start thinking about what the employees are actually feeding their AI tools:

  • Business and strategy documents

  • Customer data containing personal information

  • HR and personnel matters

  • Application code containing passwords

Why does all of this end up in the chat? Because it works.
The marketing manager wants to sharpen the strategy, customer service wants to respond to a complaint, HR wants to summarise meeting minutes, and the developer wants to debug code – where the API key unfortunately got included in the copy-and-paste.
They are not doing it to break the rules, but to get the job done faster.

Then you ask yourself: “But surely my AI provider has no way of gaining insight into this? The data isn't read – it's encrypted, isn't it?”

The answer is a resounding no!

Yes, the data is sent encrypted over the internet, but at the provider it has to be decrypted for the language model to work. Everything is processed in plain text on their servers – which means that they actually have every opportunity to read everything you submit.

Can we really trust the global AI giants?

Unless you use local LLMs or approved European models, the honest answer is:

We don't know.

What we do know, however, is that the largest American players are in the middle of huge lawsuits after training their models on data to which they did not own the copyright. How, then, can we feel confident about how they handle your company's sensitive data?

We also know that American companies are subject to the US CLOUD Act. It gives the US authorities the right, through court orders, to demand access to your data – regardless of where in the world the servers are physically located, regardless of what kind of data processing agreement (DPA) you have signed, and without your company ever being informed.

Let's conduct a small political thought experiment:
What if geopolitical tensions or a trade conflict arises between Europe and the provider's home country? They would need neither cyberattacks nor spies to map our key industries.
When thousands of employees paste tenders, board documents and strategic uncertainties into the chat every day, it creates a unique real-time picture of European business. Should the authorities there demand access on the grounds of national security, the other party would suddenly have a complete overview of companies' margins and weaknesses – long before anyone has sat down at the negotiating table.

Back to square one: Ban AI?

When you realise that your company's assets are left open to the provider's goodwill and foreign laws, the knee-jerk reaction for many IT managers is simple: a total ban.

But what happens then? Have you heard of shadow IT?

The employees do not stop using AI – they simply start using their private accounts on their own PCs or mobile phones instead. You have then suddenly lost all control, and the data flows more freely than ever.

The golden mean

The solution is neither blind trust nor unrealistic bans. You should continue giving employees access to the best tools, but you must ensure that they are used securely.

A good starting point is to place a “smart filter” between the user's chat interface and the LLM provider.

What you write

Can you summarise the complaint from Marte Kirkerud (marte.kirkerud@example.com)? It refers to case SAK-2026-4471.

What Varde Vern forwards

Can you summarise the complaint from [NAME_863a1dad3df0] ([EMAIL_8cfddd764973])? It refers to case [CASE_f0bd46ce7e63].
Varde Vern — masking in transit

The filter ensures that sensitive data, personal information and source code are scrubbed, anonymised or stopped before leaving the company's control – or automatically routed to an EU-regulated LLM.

By building and owning this filter yourself – and running it on European infrastructure – you retain greater control over your own data.

Curious about how this works in practice? We have built a solution with security and privacy in the driver's seat.

🛡️ Varde Venn demo

One more thing: Think about the image you saw at the top of the article – this is an actual screenshot from one of the larger LLM distributors. It shows a chat history as the provider has access to it.
Everything you submit is therefore completely visible to those sitting on the other side.


Would you like to learn more about how you can use AI securely? Feel free to contact me, and we can start with an informal chat! 🙂