Blog · Governance

The five levels of AI security

Oliver Ramirez · DeltaOps Consulting · March 2026

When leaders ask "is AI safe for our business data?", they are usually asking the wrong question. The right question is: at which level are we running it? The same AI tool can be reckless or compliance-grade depending entirely on how it is deployed. We use a five-level framework to make that conversation concrete.

The framework

L0

Uncontrolled

Personal accounts, no shared rules, no audit trail. Where most companies actually are.

L1

Vendor agreements

Paid business plan, data excluded from training, admin controls.

L2

Managed cloud

Enterprise plan: SSO, retention controls, audit logs.

L3

Private cloud

AI in your own cloud account and region, frontier or open models.

L4

On-premise

Runs entirely on your infrastructure. Maximum control, maximum overhead.

Level 0 · Uncontrolled. Employees use AI individually, on personal accounts, with no shared rules. No governance, no audit trail, no boundaries. This is where most companies actually are, whether they know it or not, and it is the level where business data genuinely leaks: pasted into free tools that may train on it.

Level 1 · Vendor agreements. AI under a paid business plan with standard vendor data agreements: your data is not used for training, and admin controls exist. Two caveats keep this level from being a blanket answer. Governance still depends heavily on configuration and user behaviour. And data residency is usually not yours to choose: prompts may be processed on servers outside your jurisdiction, for example EU personal data processed in the US, which for some businesses rules this level out for that data regardless of the training question. Acceptable for lower-risk workflows with clear guardrails.

Level 2 · Managed cloud. Enterprise plans with single sign-on, centralised identity, retention controls and audit logs. Some vendors also offer regional processing commitments at this tier. Suitable for wider rollout and for workflows that compliance teams need to review. For most growing businesses, this is the sensible target.

Level 3 · Private cloud. AI running inside a cloud environment you control, with organisational authority over data routing, region, logging and retention. This is not only an open-model play: frontier models are available this way too, for example Claude through Amazon Bedrock or similar offerings on Google Cloud and Azure, running in the region you choose inside your own cloud account. Open models like Llama and Mistral extend the same idea without per-vendor agreements. Either route solves the residency problem: your data stays in your environment, in your region.

Level 4 · On-premise. Maximum control: the model runs entirely on your own infrastructure and data never crosses the public internet. Highest governance overhead, justified for genuinely sensitive workloads.

The point of the ladder is not to climb to the top. It is to match each workflow to the right level. Meeting summaries might live happily at Level 1. Contract analysis or customer financial data might justify Level 3 or 4. The failure mode is running everything at Level 0 while assuming you are somewhere higher.

Ask yourself: if a regulator asked which level each of your AI workflows runs at, could anyone in your business answer?

The legal questions to ask before scaling

We are not lawyers and this is not legal advice, but these are the questions we see legal and compliance teams need answered, and asking them early turns legal into an enabler rather than a late-stage veto.

Data protection (UK/EU GDPR): does personal data enter prompts or connected sources? Is there a data processing agreement with the vendor, and has anyone assessed whether a DPIA is needed? What are the retention settings, and in which region is the data processed?

AI-specific regulation (EU AI Act): is there a register of AI use cases, and has anyone checked whether any fall into higher-risk categories that need review before scaling?

Sector rules: regulated industries often have their own layer, from operational resilience expectations to human-review requirements for AI-drafted customer communications. If AI touches a regulated process, someone should own that mapping.

Auditability: if you had to show what the AI saw, did and produced for a given decision, could you? Levels 2 and above exist largely to make the answer yes.

Where to start

Level assignment is a governance exercise, not a technical one, which is why it belongs to layer two of our five-layer implementation stack. If you want a structured read on where you stand, our free AI readiness assessment covers governance alongside the other four layers, or bring the question to a 30-minute diagnosis call.

This article is general information, not legal advice. Ask your legal and compliance advisers to assess your specific situation.

Common questions
What are the five levels of AI security?

Level 0 uncontrolled individual use, Level 1 vendor agreements on a paid business plan, Level 2 managed cloud with enterprise controls, Level 3 private cloud, Level 4 on-premise. Risk depends on deployment level, not on the tool itself.

Which level does my business need?

Match the level to the workflow: low-risk tasks are fine at Level 1, wider rollouts usually justify Level 2, and sensitive or residency-constrained data may warrant Level 3, via frontier models in your own cloud (such as Claude through Amazon Bedrock) or self-deployed open models.

Is ChatGPT or Claude safe for company data?

On free personal accounts, assume not. On business and enterprise plans, vendors contractually exclude your data from training and provide admin controls, which moves you to Level 1 or 2. The tool matters less than the deployment.

Get started

Find your weakest layer.

Ten questions, three minutes, a score for each of the five layers including governance and security.

Take the free assessment