Blog
AI gurus are screwing up your compliance
Automating with AI is not connecting your data to any API and celebrating because it works. If nobody asks what comes out, who can access it, or what happens when it fails, you have a serious mess on your hands.

Francisco Gaona
Founder and technical lead

They show you a forty-second video. A form receives information. AI analyses it. A task is created. An email is sent. The CRM is updated. Everything is automatic. It looks like magic. And it sells like hell. What they do not show you is what data was sent, where it is stored, who can access it, how long it is kept, or what happens when the AI confidently makes up an answer. That part gets fewer views. It is also the only part that matters when the system touches real data.
Building a demo is easy
Connecting a language model to a process is getting easier every day. You can have a working proof of concept in a few hours. That is great for experimenting. The problem starts when someone confuses a demo with a system prepared to work with real information. A company does not only handle anonymous text invented for a tutorial. It handles names, email addresses, documents, conversations, contracts, employee data, customer information, and, in some industries, particularly sensitive data. You cannot send all of that to any service just because the demo looks nice.
“We use AI” does not answer any important question
Which provider processes the information? Where is it processed? Is it used to train models? How long is it retained? Is there an appropriate agreement with the provider? Which users have access? Are operations logged? Can a person review the result? What happens when the system is wrong? If nobody has answered these questions, you do not have an AI strategy. You have an API integration and a fair amount of faith.
GDPR does not disappear because the model is clever
If a process uses personal data, the obligations around that data still exist. It does not matter that the tool is new. It also does not matter that the provider uses words like “enterprise”, “secure”, or “private” on its pricing page. You need to know what information is processed, what it is used for, and under which conditions. European regulation on artificial intelligence also follows a risk-based approach. Not every application receives the same treatment, but that does not mean we can ignore how the technology is used. Summarising internal documentation is not the same as using a system to make decisions that affect a person. Context matters. A lot.
The problem starts before choosing the model
Many companies start by asking whether they should use OpenAI, Azure, Claude, Gemini, or a local model. That is not the first decision. First you need to understand the process. What goes in. What comes out. Who uses it. What level of error is acceptable. What happens if it fails. What information should never leave the system. Once that is clear, you can choose a technical solution. Starting with the model is like buying an engine before deciding what vehicle you need.
Total automation looks great on LinkedIn
But it is often a bad idea. There are tasks where AI can prepare a first result and a person should review it. That does not make the system less intelligent. It makes it better designed. If the cost of an error is small, you can accept more automation. If an error could affect a contract, a hiring decision, a financial decision, clinical information, or a customer relationship, supervision matters much more. Not everything should run without human intervention just because it technically can.
Sometimes you do not need AI
This part particularly annoys the gurus. Sometimes the problem can be solved with a rule. Or with a better-designed form. Or by changing the process. Or by making information structured from the start. Using AI to compensate for a badly designed process usually produces a badly designed process that is now more expensive, less predictable, and much harder to explain. Before automating, you need to understand what the hell you are automating.
An AI strategy can also end with “no”
Our job is not to make every process use artificial intelligence. It is to find where it adds value and where it adds risk, cost, or maintenance without making up for them. Sometimes we recommend a limited test. Sometimes we build a feature. Sometimes we use a simpler solution. And sometimes we recommend not doing it. That “no” can save you a lot of money and more than one headache.
Fewer demos and more uncomfortable questions
Artificial intelligence can save work, classify information, help find documents, and improve products. But connecting an API does not make security, privacy, or responsibility for the result disappear. If someone proposes automating half your company without asking about your data, permissions, or the consequences of an error, they are not moving fast. They are flying blind. And they are probably leaving you with the compliance mess. Nice of them.
You may also find useful
Dealing with something similar?
Tell us what you want to build, fix, or decide. We will tell you what makes sense and what would be a waste of time.
Talk about your project