[ Blog ]

Security and privacy when using AI: practical rules

  • 11 September 2026
  • 4 min read

80% of professionals in the Icelandic labour market use AI at work, but only 34% have received training from their employer (Viska 2025). That means the majority of staff make security decisions about company data every day, without any guidance. The good news: safe use comes down to a few clear rules that can be taught in a single day.

A ban list does not work. Data classification does.

The most common corporate response is to ban AI, or to ban "sensitive data" without defining what that means. Both fail. A ban simply moves the usage into personal accounts where nobody can see it, and an undefined ban means every employee interprets it in their own way.

What works is a simple data classification that everyone understands. Three categories are enough for most companies:

Green. examples: public information, general texts, your own drafts without personal data · rule: may be used in all approved tools

Amber. examples: internal data without personally identifiable information, processes, draft quotes · rule: only in a company subscription with data protection

Red. examples: personal data, national ID numbers, health information, payroll data, customer data · rule: never goes into chat tools, only into dedicated solutions with a data processing agreement

When an employee knows which category the data belongs to, they know what is allowed. The rule fits on a single A4 sheet and hangs on the wall. That is the whole trick.

A company subscription is the cheapest security measure

The single biggest difference between safe and unsafe use is which subscription is used. The free versions of the main chat tools generally reserve the right to use the data entered to train models. Company subscriptions (Team, Business and Enterprise editions) do not do so by default, and they offer admin access, access control and data processing agreements that meet GDPR requirements.

In practice this means: an employee who pastes text into a free account on their phone and an employee who does exactly the same in a company subscription are in completely different risk positions. Same task, same text, a completely different legal position for the company.

The cost of a company subscription is a fraction of the cost of a single data breach. If your company does not yet have an approved tool on a company subscription, that is the first step, ahead of all other training.

Anonymisation is step zero in every task

A large share of daily tasks can be done with AI without personal data ever coming into the picture. The key is to make anonymisation an automatic habit for staff, not an exception.

Instead of pasting an email from "Jóna Sigurðardóttir at Festi" straight in, the employee takes ten seconds to replace the name, company and other identifiers: "a customer at a retail company". The answer the AI returns is just as good, but the risk is gone. The same applies to national ID numbers, phone numbers, email addresses and case numbers.

This is exactly why safety needs to be part of the curriculum, not a disclaimer in an email. Habits are formed by practising on real tasks, not by reading rules.

Verification and the EU AI Act: the other two obligations

Safety is not just about what goes into the tools, but also about what comes out. AI can give a wrong answer with complete confidence, and research shows that untrained use can make experienced people slower and more confident in the wrong answer. That is why every team needs a simple verification rule: who is responsible for the result, what must always be reviewed manually, and when the tool must not be trusted at all. Numbers, references, legal texts and anything that leaves the building for customers belong on that list.

Then there is the regulation. The European Union's AI regulation, the EU AI Act, is coming into force in stages and will apply in Iceland through the EEA. For most Icelandic companies the core is manageable: an obligation to ensure adequate AI literacy among staff who use the tools, transparency about usage, and stricter requirements if the use is considered high-risk, for example in recruitment or credit assessment. A company that trains its staff and documents its usage rules is already most of the way there.

What you can do right now

  • Put together a one-page data classification. Three categories, green, amber and red, with three examples from your own business in each. Send it to everyone and hang it on the wall. It takes an hour and eliminates most of the uncertainty immediately.
  • Find out which subscriptions are actually in use. Ask the teams which tools they use and whether it is through a personal account or a company subscription. If the answer is personal accounts, buying a company subscription is your most urgent security task.
  • Create a verification checklist for one team. Pick the team that uses AI the most and write five lines with them: what can go straight out, what always needs a human review, and what the tool must never see. Use it as a template for the other teams.

[ Get in touch ]

Book a free assessment

90 minutes that pay off immediately: we map your AI usage, risks and 3 to 5 automatable workflows, and deliver a report within a week. No commitment.

No commitment

[ Direct contact ]

hallo@vestra.is+354 863 7496

Bolholt 8
105 Reykjavík, Iceland