Article
October 5, 2026
12
Min Read

Would You Trust New Software With Your HR Files? Then Why Trust AI Blindly?

Chris Lynham
would-you-trust-new-software-with-your-hr-files-then-why-trust-ai-blindly

You would not hand a new contractor the keys to every filing cabinet on their first morning. You would check who they are, decide what they need to see, and keep the rest locked away. Yet many organisations are doing the digital equivalent with AI: connecting new tools to contracts, HR records and strategy documents without asking the questions they would ask of any other software.

The appetite for AI is clear. Microsoft's 2024 Work Trend Index found that 75% of knowledge workers already use generative AI at work, and 78% of those users bring their own tools rather than waiting for approved ones. That is how shadow AI takes hold: useful tools, adopted quickly, sitting outside the checks that govern everything else.

This article sets out three questions to ask of any AI tool before it goes near sensitive content, and why each one matters.

Why AI deserves the same scrutiny as any other software

An enterprise AI tool for knowledge management is only as useful as the content it can reach. That is the whole point: it reads across your documents so people can find answers without trawling through folders. It is also the risk. A tool that can read everything can, if poorly controlled, surface anything to anyone who asks the right question.

The cost of getting this wrong is measurable. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a data breach at a record US$4.99 million, a 12% rise on the previous year. Among organisations that reported an AI-related breach, IBM found that 92% lacked proper AI access controls.

Closer to home, the UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses experienced a cyber breach or attack in the previous 12 months, rising to 69% of large businesses. Of the businesses using, adopting or considering AI, only 24% had cyber security practices in place to manage AI risks.

The gap is not enthusiasm for AI. It is AI governance, and frameworks such as ISO/IEC 42001 for AI management systems exist to close it.

Question 1: Is it ISO 27001 certified?

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification means an independent auditor has checked that a supplier takes a structured, risk-based approach to protecting information, covering everything from how staff access systems to how incidents are handled, and that the approach is maintained and reviewed rather than written once and filed away.

For a buyer, this shifts the conversation from "trust us" to "here is the evidence". An AI supplier with ISO 27001 has had its security processes examined by someone outside the business. It can also speed up procurement, as many security questionnaires map directly to controls within the standard.

What to ask: is the certification current, and does its scope cover the service you will actually be using?

Question 2: Is it Cyber Essentials certified?

Where ISO 27001 looks at how security is managed across a business, Cyber Essentials focuses on the technical basics. Backed by the UK Government and overseen by the National Cyber Security Centre (NCSC), Cyber Essentials is described as the minimum standard of cyber security recommended for organisations of all sizes. It covers five controls: firewalls, secure configuration, security update management, user access control and malware protection.

These are fundamentals, and that is exactly why they matter. Many attacks exploit basic weaknesses rather than sophisticated ones. Yet adoption remains low: the same government survey found that just 5% of UK businesses hold Cyber Essentials certification, rising to 35% among large businesses. If a supplier holds it, you know its foundations have been independently checked.

Together, ISO 27001 and Cyber Essentials give you two complementary views: one of how security is governed, and one of whether the essential technical defences are in place.

Question 3: Can you control exactly who sees what?

This is the question that separates a secure AI tool from a risky one, and it is the one most often overlooked.

Certifications tell you the supplier protects its own systems. Permissions decide whether the tool protects your content from the wrong people inside your organisation. Without them, an AI search tool can become a shortcut around every access rule you have built. A new starter asks a simple question and receives an answer drawn from a board paper, a salary review or a confidential client contract, simply because the tool could read it and never checked whether that person should.

Good access controls follow the principle of least privilege: people, and the processes acting on their behalf, get the minimum access they need to do their job. In practice, this usually means role-based access control, where permissions follow a person's role rather than being granted document by document.

What to look for:

  • Permission-aware answers. The AI should only draw on content the person asking is allowed to see. If they could not open the file, the answer should not be built from it.
  • Alignment with your identity management. Your IT team already manages who works where through an identity and access management system, such as Microsoft Entra ID. An AI tool that works with that setup means joiners, movers and leavers are handled once, not in two places.
  • Flexibility to set permissions directly. Not every organisation, team or project runs everything through one identity platform, so the option to configure access within the tool matters too.
  • Clear data handling. Know where your data is stored, whether it is encrypted, and whether it is ever used to train models outside your organisation.

This is not only good practice. Under UK GDPR, organisations must put appropriate technical and organisational measures in place to keep personal data secure, and the Information Commissioner's Office (ICO) sets out what that looks like in its guidance on data security. An AI tool that ignores your permissions makes that obligation much harder to meet.

How MyContentScout answers all three

For MyContentScout, the answer to each question is yes.

  • ISO 27001: certified.
  • Cyber Essentials: certified.
  • Tailored permissions: only the right people see the right content, managed through your existing identity management system or set up directly in the platform.

Beyond that, all data is encrypted at rest and in transit, and each customer's data is stored separately. Answers are drawn from your organisation's own documents, with links back to the source, so people can check where information has come from rather than taking it on trust.

The result is a knowledge management platform that makes information easier to find without making it easier to leak. HR sees HR files. Legal sees contracts. The leadership team's strategy documents stay with the leadership team.

A quick checklist for your current AI tool

Before your next renewal, or before a new tool is connected to your shared drives, run through these questions:

  1. Is the supplier ISO 27001 certified, and does the scope cover this service?
  2. Does it hold Cyber Essentials or Cyber Essentials Plus?
  3. Does it respect permissions, so answers only draw on content the user can already access?
  4. Can it work with your identity management system, or let you configure permissions directly?
  5. Is data encrypted at rest and in transit, and kept out of public model training?
  6. Do you have an AI governance policy covering which tools staff can use, and for what?

For deeper due diligence, the NCSC's guidelines for secure AI system development are a useful reference for both buyers and suppliers.

The real question

Most businesses would never let a new piece of software near their contracts, HR files and internal strategy documents without asking who else can see them. AI should be held to exactly the same standard.

So, does your current AI tool measure up?

See how MyContentScout keeps your organisation's knowledge secure. Explore our security approach or book a demo today.

Contact Us

Get in touch

If you’d like to discuss a project or explore how we can support your organisation, we’d love to hear from you. Send us a message and a member of our team will be in touch shortly.

Thank you!
Your submission has been received!
Oops! Something went wrong while submitting the form.
Close Button

Book a Demo

Book your Demo Today!

Get in touch with our team to arrange a demo of MyContentScout and see how it could transform your workflow with AI search, content analysis and categorisation, saving you time and providing smart insights from various sources.

Thank you! Your submission has been received!
Something went wrong while submitting the form.
MyContentScout Boundless Branded Screens