Control over AI
Blog

Using AI at work, without the data leaks.

Practical guides and clear-eyed analysis on AI privacy and sensitive data, for the privacy, security, and operations teams helping their people work safely with AI.

NIS2 at a glance: the key milestones from directive to the Dutch Cyberbeveiligingswet
Compliance and AI 9 min read

The Netherlands has its NIS2 law: what applies from 15 August

Almost two years late, NIS2 is now Dutch law. From 15 August 2026, the duty of care, the reporting duty, and the registration duty apply to more than 8,000 organisations. The timeline, the duties, and what to arrange now.

The Cyberbeveiligingswet is the Dutch transposition of the European NIS2 directive and applies from 15 August 2026. More than 8,000 organisations across eighteen sectors get three duties: a duty of care (demonstrably manage cyber risks with appropriate measures), a reporting duty (an early warning within 24 hours and a full report within 72 hours of a significant incident), and a registration duty (register through mijn.ncsc.nl). The board must approve the measures itself and oversee them, and can be held liable for serious negligence. Maximum fines reach 10 million euros or 2 percent of global annual turnover.
Read the article
A deleted AI conversation is not instantly gone: the chat log outlives the chat itself
Safe AI adoption 9 min read

The hidden risks of AI chat logs

You delete a ChatGPT conversation and assume it is gone. But the chat log outlives the chat. A deleted conversation is not instantly nowhere, AI memory carries context forward, and on business plans an admin can read along. The one place you actually control this is the moment of pasting, not the settings afterwards.

Read the article
Grok open inside the X app, illustrating how an AI assistant built into a social platform can publish conversations
AI data leakage 10 min read

Grok at work: the chatbot that publishes

Grok lives inside X, a platform built for publishing - and in 2025 its share button quietly turned hundreds of thousands of private conversations into Google-indexed web pages. When the AI sits inside a social network, 'share' and 'publish' blur, and so does the line between a work tool and a personal account.

Read the article
WhatsApp Web open in a browser with a draft message flagged for sensitive personal data, illustrating privacy risks of work messaging
Email privacy 11 min read

WhatsApp at work: why end-to-end encrypted doesn't mean safe

WhatsApp messages are end-to-end encrypted, which makes the app feel private. But encryption protects the message in transit - not who you send it to, which personal phone it lands on, or whether work data should be in a consumer channel at all. The biggest risks sit in the chat box, not the cryptography.

Read the article
An employee typing into an AI tool that remembers context from earlier conversations
AI data leakage 8 min read

How AI memory works (and how to manage it)

AI tools now remember things between conversations. Useful for preferences, risky for work: a client name or case detail you typed once can resurface in an unrelated chat weeks later. Here is how to view, manage, and delete memory in each tool.

Read the article
Admin reviewing a dashboard of AI usage at work
GDPR and workplace AI 8 min read

Can an admin read your AI chats?

It depends on your account. On a free or personal account there is no employer admin above you, only the vendor. On a business or enterprise account, an admin can often reach your conversations through compliance and eDiscovery tooling.

Read the article
Data in a European data centre still falls under US law when the provider is American
Safe AI adoption 9 min read

Data sovereignty starts in the prompt field

Your data sits in a European data centre, so you're sovereign? Not necessarily. As long as the provider is American, the US government can reach it, wherever the servers are. And that choice isn't made by procurement, it's made by the employee who pastes something into a prompt.

Read the article
Someone checking an AI answer for accuracy
AI data leakage 8 min read

Why AI makes things up

Hallucination is not a fault in the system, it is a property of how the system works. And once the invention concerns a real person, it becomes a GDPR question.

Read the article
Employee typing a prompt and checking which data it contains
AI data leakage 8 min read

What you can and cannot share with AI

A practical checklist of data you should never put in an AI tool, what is usually fine, and the rule of thumb that helps you decide in borderline cases. It applies beyond chatbots, to meeting AI, email assistants, and transcription too.

Read the article