Control over AI
Blog

Using AI at work, without the data leaks.

Practical guides and clear-eyed analysis on AI privacy and sensitive data, for the privacy, security, and operations teams helping their people work safely with AI.

Abstract ring as a portal above waves
AI governance 9 min read

What is AI governance, and what does it mean for everyday AI use?

AI governance sounds like a topic for teams that build models. For most organisations it is about something else: which AI tools staff actually use, what has been decided about them, and whether that decision holds during the working day.

AI governance is the set of decisions, agreements and evidence an organisation uses to handle AI responsibly. For most organisations that is not about building or validating models. It is about the everyday use of existing AI services by employees. The questions that come with it: which tools are actually in use, which are allowed, which have no decision yet, what sensitive information passes through, do people know the decision at the moment they open a tool, and can you show afterwards that the policy was applied. That takes figures at organisation level, not oversight of individuals.
Read the article
Abstract skyline above hills
Compliance and AI 6 min read

How do you demonstrate AI literacy?

An attendance list says something about the day of the course. An auditor asks about the Monday after. Three kinds of evidence, what each does and does not show, and what you honestly call not substantiated.

Read the article
Abstract blurred tiles in teal
AI governance 6 min read

Which AI tools may employees use?

The answer is not printed on the tool. It is a decision the organisation takes. How to build a list that matches what is already in use, and what to do with the tool that turns up tomorrow.

Read the article
Abstract frames with rounded corners
GDPR and workplace AI 5 min read

Do you need a DPIA for AI tools at work?

The GDPR requires a DPIA when processing is likely to result in a high risk. Generative AI at work often meets several of the criteria at once. When it is required, what goes in it, and why the DPIA describes but does not demonstrate.

Read the article
Abstract ring as a portal above waves
AI governance 9 min read

AI governance without monitoring employees

An organisation can know which AI tools are in use, whether its policy lands and where the risk sits, without a single person appearing in the figures. That is not a compromise but a design, made of five choices you make up front.

Read the article
Abstract skyline in mist, teal and sand
Compliance and AI 5 min read

Does every employee need AI training?

Article 4 of the AI Act asks for measures per role and context, not one course for everyone. What does apply to every employee, what differs per role, and why the explanation only works once the decision is also visible at the moment of work.

Read the article
Abstract soft rectangles in teal and gold
Compliance and AI 6 min read

Is an AI register mandatory under the EU AI Act?

No, not as one universal register for every organisation. There are registration and documentation duties that depend on your role and the systems you deploy, and the GDPR asks for its own record. What the law says, and why organisations keep a register anyway.

Read the article
Abstract ascending blocks in teal
Compliance and AI 6 min read

Is AI literacy mandatory?

Yes, since 2 February 2025. Article 4 of the AI Act asks organisations to take measures towards a sufficient level of AI literacy among the people who use AI on their behalf. What it does not contain: a certificate, a course or an hour norm.

Read the article
Abstract ring as a portal above waves
GDPR and workplace AI 6 min read

When must the works council be involved in AI?

An AI policy that only says which tools are allowed calls for consultation. An arrangement that processes employee data or can observe behaviour calls for consent. Where the line runs under Dutch law, and how to bring the works council in before it stalls.

Read the article
Abstract skyline above hills
Compliance and AI 5 min read

ChatGPT and the AI Act: what changes for users at work?

The heavy obligations of the AI Act sit with OpenAI as the provider, not with the employee who uses ChatGPT. Three things change for you at work: your organisation has to explain, a few applications are prohibited or high-risk, and a chatbot facing the public has to make clear it is AI.

Read the article
Abstract contour lines with a route
AI governance 6 min read

Which KPIs do you use for AI adoption?

A board wants to know whether AI is used, whether it runs through the agreed route, and whether the agreements work. Eight KPIs that answer that, with for each one what it says, what it does not say, and whether it can be measured without a user id.

Read the article
Abstract soft hills under a sun
Safe AI adoption 5 min read

What is safe AI adoption in an organisation?

Safe AI adoption is not as little AI as possible. It is use the organisation knows about, through a fitting account, with sensitive data kept out of the prompt, with a decision that is known when someone opens the tool, and with figures that show it.

Read the article
Abstract circle with an orbit of points
AI governance 6 min read

AI register in Excel or in software?

A spreadsheet is enough while the list is short, changes little and one person keeps it. It breaks in four places: discovering new tools, reviews, getting the decision to the person at work, and versions. Software only fixes that if the rows come from somewhere else.

Read the article
Abstract route with nodes through soft shapes
Safe AI adoption 5 min read

Allow or ban ChatGPT at work?

Allow or ban are two of four options, and the two that work least well. Limited use with a condition, and a business account named as the preferred route, keep the use visible and give it a decision.

Read the article
Abstract spiral with data points in teal
Safe AI adoption 9 min read

The hidden risks of AI chat logs

You delete a ChatGPT conversation and assume it is gone. But the chat log outlives the chat. A deleted conversation is not instantly nowhere, AI memory carries context forward, and on business plans an admin can read along. The one place you actually control this is the moment of pasting, not the settings afterwards.

Read the article
Abstract soft hills under a sun
AI governance 6 min read

An AI policy for accounting firms

A firm's AI policy can be short, but it must answer the question that lands on the floor: is this tool allowed, with this file, on this account. Which questions it answers, what the compliance officer does, and how it reaches the floor.

Read the article
Abstract network of connected tiles in teal and sand
Comparisons 6 min read

CASB versus AI governance

A CASB sees traffic to cloud services and can step in. Governance of AI use sees which AI tools are opened, records a decision per tool and shows it where the work happens. What each misses, and when a CASB is the better choice.

Read the article
Abstract dunes under a low sun
AI governance 6 min read

An AI register for education organisations

An AI register at a school has the same fields as any register, plus three that weigh more: the processing agreement, the pupil data and the school where the tool runs. It also covers the AI features inside learning tools the school already had.

Read the article
Abstract sphere with rings
AI data leakage 10 min read

Grok at work: the chatbot that publishes

Grok lives inside X, a network built for publishing, and in 2025 its share button quietly turned hundreds of thousands of private conversations into Google-indexed web pages. When the AI sits inside a social network, 'share' and 'publish' blur, and so does the line between a work tool and a personal account.

Read the article
Abstract sphere between translucent panels
AI governance 6 min read

Which AI tools may lawyers use?

The professional rules name no tools, they name core values. Which AI tools a lawyer may use is therefore a firm decision: a list with statuses, conditions and alternatives, and a route for the tool that is not on it yet.

Read the article
Abstract double waves in teal and sand
Email privacy 11 min read

WhatsApp at work: why end-to-end encrypted doesn't mean safe

WhatsApp messages are end-to-end encrypted, which makes the app feel private. But encryption protects the message in transit, not who you send it to, which personal phone it lands on, or whether work data should be in a consumer channel at all. The biggest risks sit in the chat box, not the cryptography.

Read the article
Abstract circle with an orbit of points
Comparisons 6 min read

AI governance software versus classic GRC software

GRC software manages policies, risks and controls, and for many organisations it is where an auditor finds the evidence. Governance of AI use supplies what a GRC suite cannot produce itself: the observation of what is used, and the moment staff see the decision.

Read the article
Abstract floating tiles in teal and sand
AI governance 6 min read

How do you build a list of approved AI tools?

Start from what is already in use, not from a blank document. Record the account and the data per tool, give every tool a status and an owner, and publish the list where people work. Why a list without "no decision yet" is not finished.

Read the article
Abstract route with nodes through soft shapes
AI data leakage 8 min read

How AI memory works (and how to manage it)

AI tools now remember things between conversations. Useful for preferences, risky for work: a client name or case detail you typed once can resurface in an unrelated chat weeks later. Here is how to view, manage, and delete memory in each tool.

Read the article
Abstract contour lines in teal and sand
AI governance 6 min read

Shadow AI in accounting firms

A survey in April turns up eleven AI tools. By June the list is wrong: a new transcription tool, an AI note in the compilation software, a contract analysis tool a colleague recommended. How a firm keeps track without following its staff.

Read the article
Abstract frames with rounded corners
AI governance 6 min read

Who is responsible for the AI register?

The board carries the final responsibility, but a register that sits with one person is out of date within a quarter. The roles of the DPO, CISO, IT, procurement and the business, and why "the DPO will handle it" fails.

Read the article
Abstract frame above a still lake
GDPR and workplace AI 8 min read

Can an admin read your AI chats?

It depends on your account. On a free or personal account there is no employer admin above you, only the vendor. On a business or enterprise account, an admin can often reach your conversations through compliance and eDiscovery tooling.

Read the article
Abstract ring as a portal above waves
AI governance 6 min read

AI governance roles: who does what?

Nobody owns AI in the organisation, and that is fine as long as every decision has one owner. What the board, DPO, CISO, IT, procurement, HR, team leads, works council and employees each decide, deliver and see.

Read the article
Abstract sphere between translucent panels
AI governance 6 min read

An AI register for law firms

A law firm uses more AI than the research database it licenses: chatbots, dictation software, contract analysis, the AI features inside the legal database. Which tools belong in the register, and which fields carry more weight for a firm than elsewhere.

Read the article
Abstract dark wave with light points
Safe AI adoption 9 min read

Data sovereignty starts in the prompt field

Your data sits in a European data centre, so you're sovereign? Not necessarily. As long as the provider is American, the US government can reach it, wherever the servers are. And that choice isn't made by procurement, it's made by the employee who pastes something into a prompt.

Read the article
Abstract double waves in teal and sand
AI governance 6 min read

An AI register for accounting firms

In an accounting firm, AI runs in the chatbot, the bookkeeping package and the audit software. Which register fields a firm needs on top of the usual ones, and why the register is only right once you also look at what is actually opened.

Read the article
Abstract crossing waves in teal and sand
AI data leakage 8 min read

Why AI makes things up

Hallucination is not a fault in the system, it is a property of how the system works. And once the invention concerns a real person, it becomes a GDPR question.

Read the article
Abstract skyline above hills
Compliance and AI 5 min read

Who is responsible for AI literacy: HR, IT or the DPO?

Article 4 of the AI Act places the duty on the organisation, not on a department. In practice HR carries the explanation, IT the register and the moment of work, and the DPO the advice. Who does what, who keeps the evidence, and why "the DPO will handle it" does not work.

Read the article
Abstract hills with one continuous line
AI governance 6 min read

Shadow AI in financial services

A firm that has rolled out Copilot has not settled its AI use. Next to it run ChatGPT, Perplexity, transcription and tools that read files, mostly without a decision. Why that weighs more under supervision and DORA, and how to keep track without following employees.

Read the article
Abstract translucent panels forming a skyline
Compliance and AI 6 min read

Can one AI tool be both low and high risk?

Yes, and there is nothing contradictory about it. An AI tool's risk depends on what you use it for, which data goes in and which account it runs under. The AI Act looks at the purpose of an application, not the name of the tool.

Read the article
Abstract double waves in teal and sand
AI data leakage 8 min read

What you can and cannot share with AI

A practical checklist of data you should never put in an AI tool, what is usually fine, and the rule of thumb that helps you decide in borderline cases. It applies beyond chatbots, to meeting AI, email assistants, and transcription too.

Read the article
Abstract translucent panels forming a skyline
Compliance and AI 7 min read

AI governance and the BIO baseline: where AI use fits

The BIO, the information security baseline for Dutch government, never mentions AI. It does not need to: everyday use of chatbots and summarising tools in a municipality lands in four themes it already has, classification, supplier management, awareness and logging.

Read the article
Portrait of Rens Timmermans of BeeSensible

Would you rather someone showed you?

Rens, BeeSensible

I am happy to give you a twenty-minute tour. Leave your details and I will find a moment that suits you. Calling or emailing works just as well.

Rather talk to someone first? Book a call.

Want a live demo, or a quote for 100+ users? Leave your details and we'll be in touch within one business day.