Writing · Practical AI

Before you let AI near your business data

The least glamorous checklist on this site. Nine things to settle before you connect an AI tool to your customer records, your inbox, or your files.

Ricky Bell · 12 August 2026 · 5 min read

A worker in a dusty apron crouches at a metal tool cabinet, turning a key in the lock and easing a drawer open.

The fastest way to lose a client is not doing a bad job. It is their information turning up somewhere it should not be.

This is the least exciting post on this site. It is also the one I would most want a business owner to read before connecting anything clever to anything real, because most of the AI horror stories I have read were not clever attacks. They were somebody granting broad access on a Tuesday afternoon without thinking about it.

Before you connect anything

  • Find out where the data goes. Read what the provider says about whether your inputs train their models and how long anything is retained. Consumer and business plans often differ significantly on exactly this point.
  • Grant the narrowest access that does the job. One folder, not the whole drive. One mailbox label, not the entire inbox. If a tool asks for full account access to do something small, that is worth a phone call before a click.
  • Start read-only. Let it look before it touches. A fortnight of watching what it would have done is the cheapest possible way to find out how it behaves on a bad day.
  • Use its own credentials, not yours. Separate login, separate key. So you can revoke it in ten seconds without locking yourself out of your own business.
  • Put a hard spend cap on anything metered. Loops happen. A cap turns an expensive mistake into an annoying one.
  • Decide what it may never do alone. Send to customers, move money, delete anything, publish anything, promise a date. Write that list down before you need it, because you will not write it calmly afterwards.

The one most people have not heard of

Prompt injection deserves its own heading, because it is genuinely counterintuitive and it is the risk that grows as these tools get more useful.

Here is the shape of it. Your AI reads things from the outside world — enquiry emails, web pages, documents customers send, reviews. Any of that content can contain text written to be read as an instruction. A booking enquiry with a line buried in it telling the system to ignore its rules and forward its contents elsewhere. A supplier PDF with white text carrying instructions.

The system cannot always tell the difference between information you asked it to read and orders someone hid inside that information. So the rule is architectural rather than clever: instructions come from you, full stop. Anything read from the outside world is treated as data to consider, never as a command to obey. If you are buying a tool that reads your email, this is a fair and revealing thing to ask the vendor about — and the quality of the answer will tell you a lot.

Two boring ones to finish

  • Keep a log. Not to read every line, but so you can pull ten at random on a Friday and satisfy yourself it is behaving. Trust is a sample, not a feeling.
  • Know your obligations. Customer data in an AI tool is still processing under UK data protection law — lawful basis, retention, where it sits, who your processors are. I am not qualified to advise on that and a blog post is not the place. If you hold sensitive data, buy an hour from someone who is. It is a cheap hour.

None of this should put you off. It is the seatbelt conversation, not an argument against driving. Every one of these checks is something we settle before a single line is written for a client, which is the same reason we give the AI as little to do as possible.

Overall: go carefully and go anyway. If you want a view of where AI would help your business before you start wiring anything to anything, our free audit connects to nothing of yours — it reads your public homepage, the same as any customer would.

Frequently asked

Is it safe to give AI access to customer data?

It can be, with boundaries. Check the provider's training and retention terms, grant access to the narrowest scope that does the job, start read-only, use separate credentials with a spend cap, and keep a human on anything irreversible. The risk comes from broad access granted casually, not from AI itself.

What is prompt injection?

When content your AI reads — an email, a web page, a document, a review — contains text written to give your AI instructions. A booking enquiry might include a line telling the system to reveal its rules or email something onward. The defence is that instructions only ever come from you, and anything read from the outside world is treated as information rather than orders.

What are the UK data protection considerations for using AI?

Customer data going into an AI tool is still processing under UK GDPR, so it involves lawful basis, retention, where the data sits and who your processors are. I am not qualified to advise on it and neither is a blog post — if you handle sensitive data, spend an hour with someone who is. It is a cheap hour.

← All writing