When leaders ask "is AI safe for our business data?", they are usually asking the wrong question. The right question is: at which level are we running it? The same AI tool can be reckless or compliance-grade depending entirely on how it is deployed. We use a five-level framework to make that conversation concrete.
The framework
Uncontrolled
Personal accounts, no shared rules, no audit trail. Where most companies actually are.
Vendor agreements
Paid business plan, data excluded from training, admin controls.
Managed cloud
Enterprise plan: SSO, retention controls, audit logs.
Private cloud
AI in your own cloud account and region, frontier or open models.
On-premise
Runs entirely on your infrastructure. Maximum control, maximum overhead.
Level 0 · Uncontrolled. Employees use AI individually, on personal accounts, with no shared rules. No governance, no audit trail, no boundaries. This is where most companies actually are, whether they know it or not, and it is the level where business data genuinely leaks: pasted into free tools that may train on it.
Level 1 · Vendor agreements. AI under a paid business plan with standard vendor data agreements: your data is not used for training, and admin controls exist. Two caveats keep this level from being a blanket answer. Governance still depends heavily on configuration and user behaviour. And data residency is usually not yours to choose: prompts may be processed on servers outside your jurisdiction, for example EU personal data processed in the US, which for some businesses rules this level out for that data regardless of the training question. Acceptable for lower-risk workflows with clear guardrails.
Level 2 · Managed cloud. Enterprise plans with single sign-on, centralised identity, retention controls and audit logs. Some vendors also offer regional processing commitments at this tier. Suitable for wider rollout and for workflows that compliance teams need to review. For most growing businesses, this is the sensible target.
Level 3 · Private cloud. AI running inside a cloud environment you control, with organisational authority over data routing, region, logging and retention. This is not only an open-model play: frontier models are available this way too, for example Claude through Amazon Bedrock or similar offerings on Google Cloud and Azure, running in the region you choose inside your own cloud account. Open models like Llama and Mistral extend the same idea without per-vendor agreements. Either route solves the residency problem: your data stays in your environment, in your region.
Level 4 · On-premise. Maximum control: the model runs entirely on your own infrastructure and data never crosses the public internet. Highest governance overhead, justified for genuinely sensitive workloads.
The point of the ladder is not to climb to the top. It is to match each workflow to the right level. Meeting summaries might live happily at Level 1. Contract analysis or customer financial data might justify Level 3 or 4. The failure mode is running everything at Level 0 while assuming you are somewhere higher.
The legal questions to ask before scaling
We are not lawyers and this is not legal advice, but these are the questions we see legal and compliance teams need answered, and asking them early turns legal into an enabler rather than a late-stage veto.
Data protection (UK/EU GDPR): does personal data enter prompts or connected sources? Is there a data processing agreement with the vendor, and has anyone assessed whether a DPIA is needed? What are the retention settings, and in which region is the data processed?
AI-specific regulation (EU AI Act): is there a register of AI use cases, and has anyone checked whether any fall into higher-risk categories that need review before scaling?
Sector rules: regulated industries often have their own layer, from operational resilience expectations to human-review requirements for AI-drafted customer communications. If AI touches a regulated process, someone should own that mapping.
Auditability: if you had to show what the AI saw, did and produced for a given decision, could you? Levels 2 and above exist largely to make the answer yes.
Where to start
Level assignment is a governance exercise, not a technical one, which is why it belongs to layer two of our five-layer implementation stack. If you want a structured read on where you stand, our free AI readiness assessment covers governance alongside the other four layers, or bring the question to a 30-minute diagnosis call.
This article is general information, not legal advice. Ask your legal and compliance advisers to assess your specific situation.