What data can you share with an AI: the four confidentiality levels
There are four confidentiality levels for an AI tool: the consumer service, the professional service under contract, European hosting and the model installed on your own premises. You do not have to choose one level for the whole organisation: you choose one per type of data, from public text to a document covered by professional secrecy.
Written by Équipe Skillrung · Reviewed by Équipe Skillrung · Updated on
The question “can we use AI at work?” is badly framed. The right question is: which data, in which tool? The minutes of a public meeting and a medical file do not call for the same answer, and no organisation gains by ruling in a single block for all of its files.
The confidentiality of an AI use is therefore decided in two steps: classify the data, then choose the level of tool that matches it. This guide describes the four levels, from the most open to the most closed, and the grid that links each type of data to one of them.
Content of this guide last checked: 11 September 2026. Offers, contracts and interface settings change quickly: no supplier is named here, and no button label is quoted. Always check the actual state of your own contract.
What are the four confidentiality levels?
Level 1: the consumer service
This is the free or personal account, opened in two minutes with an email address. The service is excellent, and that is precisely what makes it risky: it enters the organisation without going through anyone.
What you need to know: depending on the offer, your exchanges may be used to improve the service, there is no contract negotiated with your organisation, and nobody has validated where the processing takes place. Consequence: keep it for text you would be willing to publish.
Level 2: the professional service under contract
Same technology, different legal framework. The professional offer generally provides, by contract, that your content is not reused for training, a security commitment, and above all a responsible point of contact.
This is the level that suits the majority of internal uses: notes, minutes, drafts, working documents without sensitive data. Provided you have read the contract, and not only the sales page.
Level 3: European hosting
Here, the processing takes place in the European Union, under European law, with an identified hosting provider. This is the level expected as soon as personal data regularly enters the tool, and it often becomes mandatory by ripple effect, when a customer or a client imposes it in their annual security questionnaire.
Beware of the most widespread confusion: what you are buying is the place of processing and the applicable law, not the nationality of the model. A model designed elsewhere can be run in a European data centre, and a European supplier can subcontract outside Europe. Only the contract is authoritative.
Level 4: the model installed on your premises
The model runs on your servers or in your private environment. Nothing leaves. This is the level for data covered by professional secrecy, health data and trade secrets.
The price is real: infrastructure cost, in-house skills, quality sometimes below the best online services, and maintenance at your expense. It is not a “better” level, it is a more closed level.
How do you choose the level for each type of data?
The rule fits in one sentence: you do not choose a level for the company, you choose one per type of data. Here is the matching grid.
- Information that is already public, a brochure, website copy, a job advert: level 1 is enough.
- An internal working document with no person's name and no confidential figure: level 2.
- A document containing personal data, identifiable customers, employees, pupils or patients: level 3 at a minimum.
- Sensitive data within the meaning of the GDPR, professional secrecy, trade secrets: level 4, or no AI at all.
Two habits complete the grid. First, anonymise before sending: a contract whose names, addresses and amounts have been replaced by markers often changes category and drops down a level. Second, switch off training on your conversations where the setting exists: in professional offers, this is generally provided for by contract rather than by a tick box.
What does the GDPR say when a name enters a conversation?
As soon as a person is identifiable, the processing falls under Regulation (EU) 2016/679, adopted on 27 April 2016 and applicable since 25 May 2018. Four obligations apply immediately.
- A legal basis. You must be able to say why you have the right to process this data.
- Minimisation. You send only what the task needs, never the whole file “for context”.
- Informing the people concerned. Data subjects must know that their data may be processed by such a tool.
- A framework for the processor. The AI supplier that processes data on your behalf is a processor within the meaning of Article 28: a written contract is mandatory, and the CNIL, the French data protection authority, details what it must contain.
Two points that are often forgotten come on top: transfers outside the European Union are governed by Chapter V of the regulation, and a data breach must be notified to the supervisory authority within 72 hours of becoming aware of it. The GDPR essentials course walks through these obligations step by step.
Key points
- Four levels: consumer, professional under contract, European hosting, installed model.
- One level per type of data, never a single level for the whole organisation.
- You are buying the place of processing and the applicable law, not the nationality of the model.
- Anonymising before sending often drops the data down a level.
- As soon as a name appears, the GDPR applies: legal basis, minimisation, information, contract.
- An AI supplier that processes data on your behalf is a processor to be framed in writing.
Is AI really the issue?
Often, no. An organisation that worries about what it sends to an AI, but whose computers have no offline backup, no two-factor authentication and no unique passwords, is not dealing with its main risk. For fifteen years, most data has been leaving through far more mundane channels: attachments, USB sticks, shared accounts, improvised file-transfer services.
So ask the five basic questions before the AI one: who has access to what, have the accounts of people who have left been closed, are backups tested, is two-factor authentication on, are the computers up to date. ANSSI, the French national cybersecurity agency, published security recommendations for a generative AI system in April 2024: they treat AI as a component of the information system, not as a separate subject. Our cybersecurity topic covers these foundations.
How do you decide in practice, this week?
Three actions, in this order. List the five AI uses actually practised in your organisation, including those nobody has declared. Classify each one into one of the four levels using the grid above. Write one page: what is allowed, on which tool, for which type of document, and whom to contact in case of doubt. One page that is read is worth more than a thirty-page charter that is ignored.
To understand the mechanisms behind these precautions, start with our guide AI vocabulary in four words, then how to check an AI answer. The course Generative AI at work and the compliance and personal data topic extend this guide with cases from your own job.
Frequently asked questions
Can you use a free AI service at work?
Yes, for content you would be willing to publish: text already released, a draft with no names or confidential figures, help with wording. As soon as a document contains personal data, an amount, a customer's name or information covered by a duty of secrecy, this level is no longer suitable. Move to a professional offer under contract.
Is a European model necessarily safer?
No, and this is the most common confusion. What matters legally is the place of processing and the applicable law, not the origin of the model. A model designed outside Europe can be run in a European data centre, and a European supplier can subcontract elsewhere. Only the contract, read carefully, answers this question.
Do you have to inform people whose data passes through an AI?
Yes. Informing the people concerned is a GDPR obligation, independent of the technology used. In practice, this means updating your privacy policy and, where relevant, your internal information notices, to state that an AI tool is used and for what purpose. The CNIL, the French data protection authority, publishes dedicated practical guidance.
Is anonymising a document enough to remove the risk?
It reduces the risk considerably, without always removing it. Taking out names is not enough if the content still allows a person to be identified by cross-referencing, which happens quickly in a small organisation or a narrow sector. Also remove indirect identifiers: precise dates, addresses, file numbers, unusual amounts, unique job titles.
Who decides the authorised level in an organisation?
The decision belongs to the controller, that is to say the management, advised where applicable by the data protection officer. What matters is that the rule is written, short and known: which tools, for which types of documents, and whom to contact in case of doubt. An unwritten rule is not applied.
Sources
- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD) : EUR-Lex, Union européenne,
- Les fiches pratiques IA : CNIL,
- Travailler avec un sous-traitant : CNIL,
- Recommandations de sécurité pour un système d'IA générative : ANSSI,