
You would not hand a new contractor the keys to every filing cabinet on their first morning. You would check who they are, decide what they need to see, and keep the rest locked away. Yet many organisations are doing the digital equivalent with AI: connecting new tools to contracts, HR records and strategy documents without asking the questions they would ask of any other software.
The appetite for AI is clear. Microsoft's 2024 Work Trend Index found that 75% of knowledge workers already use generative AI at work, and 78% of those users bring their own tools rather than waiting for approved ones. That is how shadow AI takes hold: useful tools, adopted quickly, sitting outside the checks that govern everything else.
This article sets out three questions to ask of any AI tool before it goes near sensitive content, and why each one matters.
An enterprise AI tool for knowledge management is only as useful as the content it can reach. That is the whole point: it reads across your documents so people can find answers without trawling through folders. It is also the risk. A tool that can read everything can, if poorly controlled, surface anything to anyone who asks the right question.
The cost of getting this wrong is measurable. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a data breach at a record US$4.99 million, a 12% rise on the previous year. Among organisations that reported an AI-related breach, IBM found that 92% lacked proper AI access controls.
Closer to home, the UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses experienced a cyber breach or attack in the previous 12 months, rising to 69% of large businesses. Of the businesses using, adopting or considering AI, only 24% had cyber security practices in place to manage AI risks.
The gap is not enthusiasm for AI. It is AI governance, and frameworks such as ISO/IEC 42001 for AI management systems exist to close it.

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification means an independent auditor has checked that a supplier takes a structured, risk-based approach to protecting information, covering everything from how staff access systems to how incidents are handled, and that the approach is maintained and reviewed rather than written once and filed away.
For a buyer, this shifts the conversation from "trust us" to "here is the evidence". An AI supplier with ISO 27001 has had its security processes examined by someone outside the business. It can also speed up procurement, as many security questionnaires map directly to controls within the standard.
What to ask: is the certification current, and does its scope cover the service you will actually be using?
Where ISO 27001 looks at how security is managed across a business, Cyber Essentials focuses on the technical basics. Backed by the UK Government and overseen by the National Cyber Security Centre (NCSC), Cyber Essentials is described as the minimum standard of cyber security recommended for organisations of all sizes. It covers five controls: firewalls, secure configuration, security update management, user access control and malware protection.
These are fundamentals, and that is exactly why they matter. Many attacks exploit basic weaknesses rather than sophisticated ones. Yet adoption remains low: the same government survey found that just 5% of UK businesses hold Cyber Essentials certification, rising to 35% among large businesses. If a supplier holds it, you know its foundations have been independently checked.
Together, ISO 27001 and Cyber Essentials give you two complementary views: one of how security is governed, and one of whether the essential technical defences are in place.
This is the question that separates a secure AI tool from a risky one, and it is the one most often overlooked.
Certifications tell you the supplier protects its own systems. Permissions decide whether the tool protects your content from the wrong people inside your organisation. Without them, an AI search tool can become a shortcut around every access rule you have built. A new starter asks a simple question and receives an answer drawn from a board paper, a salary review or a confidential client contract, simply because the tool could read it and never checked whether that person should.
Good access controls follow the principle of least privilege: people, and the processes acting on their behalf, get the minimum access they need to do their job. In practice, this usually means role-based access control, where permissions follow a person's role rather than being granted document by document.
What to look for:
This is not only good practice. Under UK GDPR, organisations must put appropriate technical and organisational measures in place to keep personal data secure, and the Information Commissioner's Office (ICO) sets out what that looks like in its guidance on data security. An AI tool that ignores your permissions makes that obligation much harder to meet.
For MyContentScout, the answer to each question is yes.
Beyond that, all data is encrypted at rest and in transit, and each customer's data is stored separately. Answers are drawn from your organisation's own documents, with links back to the source, so people can check where information has come from rather than taking it on trust.
The result is a knowledge management platform that makes information easier to find without making it easier to leak. HR sees HR files. Legal sees contracts. The leadership team's strategy documents stay with the leadership team.
Before your next renewal, or before a new tool is connected to your shared drives, run through these questions:
For deeper due diligence, the NCSC's guidelines for secure AI system development are a useful reference for both buyers and suppliers.
Most businesses would never let a new piece of software near their contracts, HR files and internal strategy documents without asking who else can see them. AI should be held to exactly the same standard.
So, does your current AI tool measure up?
See how MyContentScout keeps your organisation's knowledge secure. Explore our security approach or book a demo today.
Get in touch with our team to arrange a demo of MyContentScout and see how it could transform your workflow with AI search, content analysis and categorisation, saving you time and providing smart insights from various sources.
