Your AI Tools Got Better. Did Your Data Rules Keep Up?

A brushed-steel shield with a padlock and glowing circuit traces, as streams of data pass through translucent glass panels behind it
Ian StromIan Strom, Managing Partner7 min readSeptember 2026

Four questions for finance, HR, and delivery leaders putting AI to work.

Think about three ways AI could help your business this week.

A finance manager wants a clearer explanation of a budget variance. An HR officer needs a first draft of an onboarding guide. A delivery manager wants to turn project notes into a customer update.

Each is a useful place to save time. Each also raises a question before anyone pastes information into a chat window: what is the team allowed to share?

A budget file might include salaries. An onboarding example might contain a real employee’s details. Project notes might include an internal discussion that was never meant for the customer.

The person using AI may know exactly what they want it to produce. They also need to know which information belongs in the tool and who checks the result.

Last month, we wrote about why improving AI gives businesses a reason to start learning now. As that use becomes part of everyday work, the next step is giving people clear rules they can follow during a busy day.

Start with the business decision

If you lead finance, HR, or delivery, you already make decisions about confidential information and who can approve work. AI adds another place where those decisions need to be clear.

Your role is to decide what the business wants to accomplish, what information the job needs, and who remains responsible. Your IT team or technology partner can help confirm that the chosen tool supports those decisions.

There is a local reason to revisit this. On May 6, 2026, Canadian privacy regulators published findings about OpenAI’s development and use of GPT-3.5 and GPT-4. Alberta’s commissioner found the complaints unresolved; the federal outcome was conditionally resolved. Read Alberta’s announcement.

Those findings concerned the models investigated. They did not establish a four-question compliance test for businesses using ChatGPT. They do give leaders a useful prompt to look at how their own teams handle information.

Start with one recurring task and work through these four questions.

1. What can our people share?

“Use good judgment” leaves employees to work out the boundaries for themselves.

Give them examples from their actual work. An HR officer drafting an onboarding guide could begin with approved policies and a fictional employee example. There may be no reason to include someone’s personnel file.

In finance, a draft explanation of spending may need totals by department, rather than a spreadsheet containing individual salaries. A delivery update may need agreed milestones and progress notes, with internal commercial discussions left out.

These are starting examples to assess with your team, not blanket approval to upload a category of documents.

Agree what is allowed, what needs approval, and what should stay out. Ask your IT partner to confirm which company-approved tool is suitable for that information. Where employee, customer, or contractual obligations are unclear, involve the person responsible for privacy or legal advice.

The goal is simple: give your employees clear rules they can check before they upload a single file.

2. Are we using the right account for the job?

Two people can both say they use ChatGPT while using different accounts with different protections.

OpenAI says information sent to ChatGPT Business and Enterprise is not used to train its models by default. In plain language, it is not used by default to teach the underlying AI to produce future answers. That is a meaningful protection, but you still need answers about who can access the information and how long it is kept. OpenAI’s business data commitments.

You can ask your IT team or technology partner:

Which account should our team use for this task, what information is approved for it, and who can see what we put there?

Have them check the service and its settings, then give your team a clear answer. Make sure staff can get into the approved account and know where to ask for help.

That gives a manager something they can put into practice without needing to become the system administrator.

3. Who checks the work before we use it?

Our position throughout this series has been consistent: AI takes the first pass. Humans own the final decision.

For finance, that means checking an AI-written explanation against the actual figures before it reaches leadership. For HR, it means checking that an onboarding guide reflects approved policy. For delivery, it means checking dates and commitments before a customer receives an update.

Name the reviewer and spell out what they check. If the AI fills a gap with an assumption, the reviewer needs to resolve it before the work moves forward.

Then measure the whole task. How much time did drafting take? How much checking and correction followed? Did the finished work meet the same quality standard?

A quick draft is useful when it helps the team complete the job well. Counting review time gives you a more honest picture of the value.

4. What happens to the information when the job is done?

A final customer update may belong in the project record. The rough notes uploaded to produce it may serve a different purpose.

Decide what the business needs to keep and why, taking account of the obligations that apply. Then ask your IT partner how the AI service handles uploaded files and conversations, and whether its controls support those requirements. Canadian regulators’ guidance connects responsible AI use with clear purposes and limits on the information kept. Read the guidance.

Assign someone to own the answer. Include copies saved elsewhere, such as shared drafts or downloaded results. Bring in privacy or legal expertise where the requirements need interpretation.

The useful outcome is an agreed rule, a way to carry it out, and someone responsible for checking it.

Bring one task to your next management meeting

Choose a task your team already uses AI for. A budget commentary, onboarding guide, or customer update is enough to start the conversation.

Ask:

  1. What information are we comfortable sharing, and has its use been approved?
  2. Does everyone know which company-approved account to use?
  3. Who checks the result before it becomes a decision or goes to someone else?
  4. What do we keep afterward, and who makes sure that happens?

You may know some answers already. Where one is unclear, assign a person to work through it with your IT partner before expanding the task to more people or more sensitive information.

These questions help organize the work; they do not establish legal compliance. The requirements depend on your business and the information involved.

Your team should leave the discussion knowing how to use AI for a real job, where to get help, and who stands behind the finished work.

Bring One Task to an Architecture Review

Bring one task to a 60-minute architecture review with Davinci AI Solutions. We’ll walk through how your team uses AI, what information it handles, and who checks the result, then identify the next steps with you. Bring the process and your questions; you do not need to prepare a technical diagram.