Data and Security

Information security for AI adoption: what the whole company needs, not just you

Getting your own AI habits right is step one. Making sure the rest of your company doesn't undo it is step two — and it's the step most SMEs skip.

Mohamed Lotfy٦ أغسطس ٢٠٢٦3 min read

هذا المقال متوفر باللغة الإنجليزية. تتم إضافة الترجمات العربية تدريجياً.

Small office team working together at their computers
في هذه الصفحة

If you've already read our checklist on what to ask before pasting anything into an AI tool, you've got the individual habits covered — the five questions to run through before you personally paste a document into a chatbot. This piece is about the layer above that: what happens when it's not just you, but a whole company, adopting AI at the same time.

Individual discipline doesn't scale by itself. The person in your technical office who's never seen the five-questions checklist is going to paste a client BOQ into whatever free tool shows up first in a search result — not because they're careless, but because nobody told them there was a decision to make.

The gap between "I'm careful" and "my company is careful"

A single careful person using AI well protects exactly one person's inputs. A construction SME typically has multiple people touching sensitive material — drawings, client data, pricing, subcontractor terms — and AI tools are now cheap and easy enough that anyone on the team can start using one without asking first.

That's not a hypothetical risk. It's the default outcome of doing nothing.

What company-wide steps actually look like

A short, real policy — not a 20-page document nobody reads. One page: which AI tools are approved for company data, which categories of information are off-limits for any AI tool (client-confidential material, anything under an NDA, pricing before a bid is submitted), and who to ask when someone's unsure.

Approved tools, chosen once, communicated clearly. Rather than everyone independently choosing whatever free tool they find, pick a small number of vetted tools with acceptable data handling (paid tiers with training opt-out, clear retention policies — the same criteria from the individual checklist, just applied as a company decision instead of an individual one).

A default answer to "can I paste this in?" The honest default for most construction SMEs, absent a specific policy: if it's client data, subcontractor data, or anything under confidentiality terms, the default is no — check first, don't assume yes.

Basic account hygiene. Shared logins for AI tools are a bad habit that's easy to fall into and hard to audit later. Individual accounts, even for a free tier, mean you can actually tell who did what if something goes wrong.

A short onboarding note for anyone new, covering the same ground as the individual checklist, so the knowledge doesn't live only in one person's head.

Why this is worth doing before a problem, not after

The individual checklist protects you. A company-wide version protects your business — and your clients, who are trusting you with their information under an assumption of confidentiality that predates AI tools even existing. A leaked BOQ or a client's project details showing up somewhere they shouldn't isn't just an internal problem; it's a trust problem with the client whose data it was.

The realistic starting point

You don't need a compliance department to do this. Write the one-page policy this week. Pick two or three approved tools. Tell your team, in plain language, what the individual checklist already covers — and that it now applies to everyone, not just whoever happens to be careful by instinct.

Getting your own habits right was step one. Making sure your company's habits don't quietly undo them is the step most SMEs skip — and the one that actually determines whether AI adoption is safe at the scale of a whole business, not just one careful person.

Mohamed Lotfy

مهندس · مقاولات · الرياض، السعودية

شارك