Blog · August 4, 2026 · Updated on August 25, 2026 · 4 min read

AI and Privacy: What the AI Gets to See

Smartphone with a chain and combination lock on a wooden table
Photo: Towfiqu barbhuiya / Pexels

When I talk about my AI employees, the most common question isn't "how does that work?" but "are you even allowed to do that, with client data?". It's a fair question. If you carelessly dump client data into some AI tool, you do in fact have a privacy problem. But the answer isn't "AI is off the table". The answer is: set rules, like you would for any employee.

Up front, so it's clear: I'm a developer, not a lawyer. This isn't legal advice. It's the working practice I use to handle the topic in my own business.

The real problem: the consumer reflex

The privacy risk usually doesn't come from the AI. It comes from how it's used: a personal free account, client data copy-pasted into the chat, no idea what the provider does with the inputs. That's roughly like sending client documents to an acquaintance over your personal messenger because he's "good with this stuff".

With a human employee, you'd never do it that way. There's a framework: contract, confidentiality, clear rules about which data the job requires. My AI employees get exactly that framework.

The three questions before any input

My rule-of-thumb check before data goes anywhere near an AI:

  1. Does the employee need this data for the job? Data minimization is half the battle. For a proposal draft, the AI needs the content of the inquiry, not the complete client history. For a call summary, the transcript without real names is often enough.
  2. What framework does the tool run in? Business terms instead of a personal free account: a plan where the provider contractually commits to what happens with the data, and where inputs aren't used to train the models. Check your plan's data-usage settings before the first client record flows, not after.
  3. What happens in the worst case? For some data, the answer is "nothing bad" (public company data, anonymized patterns). For other data (health data, financial data, anything deeply personal), the answer is: it has no business being in a cloud chat, period.

What this looks like with my employees in practice

Anonymize wherever the name has no job to do. For most tasks, the real name is irrelevant. Turn "Ms. Meier from Meier GmbH" into "client, mechanical engineering, 12 employees". The result doesn't get any worse, and the risk drops massively.

You decide what the AI sees at all. At the advanced stage, my employees work with Claude Code directly in my folders: they read the files the assignment requires, instead of me bulk-pasting everything into a browser chat. Important for an honest assessment: the content that gets read is still processed by the provider. The difference is data minimization and control, because the work instructions spell out what an employee may access and what it may not.

The rules live in the personnel file. Every one of my employees has their limits documented alongside their job: no secrets in plain text, no sensitive data in drafts, certain folders off limits. That's the advantage of the employee approach over the chat reflex: rules get written down once and then always apply, instead of you hoping at every input that you thought of everything. What a personnel file is: What is an AI employee?

Consent, where it belongs. For call recordings and their analysis: ask first, document it. That's not an AI thing. It was true before AI too.

When to bring in professionals

There are situations where rules of thumb aren't enough: you process special categories of data (health, say, as a coach working close to therapy), you have a data protection officer, or a major client puts requirements on your data processing. Then the topic deserves to be set up properly once, with someone qualified. The good news: even then, the outcome is almost never "no AI", it's "AI with a clear framework".

The point that gets lost

For AI employees, privacy isn't a brake. It's a quality marker of good management. If you treat your AI like an employee, meaning documented rules, data minimization, and approval steps, you almost automatically work cleaner than the casual copy-paste chat on the side. Fear of a GDPR violation is not a reason to wait. It's a reason to set things up properly.

How to approach that in a structured way from day one: Hiring an AI employee: the complete process. And which tasks to delegate in the first place: Which tasks you can hand off to AI.

Kevin Welter

Kevin Welter

Developer, IT architect, author of technical books (Kubernetes, cloud infrastructures) and speaker. Runs his business with an AI workforce of eight AI employees and shows solo business owners in his community how to hire their first AI employee.

More about AI employees

Your first AI employee up and running within an hour

Join the community