Expertise Technical assistanceProject managementCustom solutions Industries BankingInsuranceFinance Approach Commitments Insights About Join Pronaxis
Contact us Français

AI and client data: the rules we set ourselves

Public AI tools, GDPR, the EU AI Act: the rules Pronaxis applies to use AI without exposing its clients' data.

Pronaxis9 October 20265 min read

Generative AI tools are now available to everyone, often free of charge, from a simple browser. For a consultant, the temptation is real: summarise a document, rephrase a specification, analyse an extract of code or an error log.

In a bank or an insurer, these actions raise precise questions. Where does the data go? Who can access it? Is it retained, and for what purpose? This article sets out the rules we apply in our engagements, and the reasoning behind them.

What is at stake

The data handled in a financial IT department comes in several forms:

  • personal data about customers, employees or prospects;
  • information covered by the professional secrecy that applies to banking, or by confidentiality obligations specific to insurance;
  • source code, architectures and configurations that form part of the company’s assets and may reveal vulnerabilities;
  • internal documents: strategies, budgets, audit reports, correspondence with regulators.

Entering these items into an external tool means passing them to a third party. Depending on the service’s terms of use, the data may be retained, accessed by the vendor or used to improve its models. It may also be processed outside the European Union.

GDPR

Any operation on personal data is processing within the meaning of the GDPR. Copying personal data into an external AI tool is therefore processing, which requires a defined purpose, a legal basis, information to the individuals concerned and, where relevant, safeguards for transfers outside the EU.

A consultant working on behalf of a client acts within the framework that client has set. It is not for the consultant to decide alone on a new processing operation or a new recipient of the data.

The EU AI Act

Regulation (EU) 2024/1689 on artificial intelligence entered into force in August 2024. Its obligations apply in stages, on a timetable that spans several years. It classifies AI systems by level of risk and imposes proportionate obligations.

Some uses specific to the financial sector are expressly covered, such as creditworthiness assessment of natural persons, and risk assessment and pricing in life and health insurance. The regulation also requires organisations to ensure a sufficient level of AI literacy among the people who use these systems.

The text primarily concerns the entities that deploy or provide AI systems. For a provider, it confirms a direction: the use of AI must be governed, documented and understood by those who rely on it.

The client’s internal rules

Beyond the legislation, each institution sets its own policy: authorised tools, prohibited tools, conditions of use. These rules apply to consultants as they do to internal staff.

Our rules

We apply the following rules to all our consultants and all our work.

1. No client data in a public AI tool

No client data, personal or otherwise, is entered into a consumer AI tool or into any external service the client has not approved. This includes document extracts, screenshots, technical logs and datasets, even partial ones.

2. No client code outside the client’s environment

Client source code is not copied, not submitted to an external assistant and not stored on personal equipment. Work on code takes place in the environments the client provides.

3. Data stays in the client’s environment

When the client provides AI tools within its own environment, approved by its security and compliance teams, our consultants use them in line with the client’s rules. The choice of tool belongs to the client.

4. A person checks everything produced

Text, code or analysis produced with the help of AI is reviewed and checked by the consultant, who remains accountable for it. AI can be wrong with confidence; checking is part of the job.

5. Transparency with the client

If a deliverable was prepared with the help of an authorised AI tool, we can say so when the client wishes. We answer questions about our practices openly.

6. When in doubt, ask

When a situation is not covered by the client’s rules, the consultant asks before acting.

Using AI responsibly

These rules set the conditions for using AI. Within a controlled framework, AI tools can be genuinely helpful:

  • structuring a first draft of a document from an outline;
  • rephrasing a note for a different audience;
  • exploring a technology or concept from public sources;
  • generating fictitious test data.

These uses share one feature: they require no client data, or they take place in a tool the client has chosen and controls.

For the tools we build

When we build a custom tool for a client, the same logic applies. We design the solution to run in the client’s environment, or in an environment the client has approved, under its own access rules. If an AI component is under consideration, its provider, where processing takes place and what happens to the data are presented to the client before any decision is made.

In short

The underlying rule fits in one sentence: client data stays under the client’s control. Tools change quickly; this principle does not, and it makes it possible to benefit from AI without creating risk for those who entrust us with their systems.

All insights Français

A project, a team to reinforce, a question?

Tell us what you need. Our management team will reply.