Everyone wants an AI agent but almost nobody is asking where the data goes
Everyone wants an AI agent right now.
Everyone wants an AI agent right now. We want AI that can prepare us for meetings, answer emails, search through our work, update the CRM and eventually just get things done for us. That’s where this is going. AI is moving from something you open when you need help to something that is always there, working alongside you. Less like another tool and more like an AI teammate.But there’s one question we’re not asking enough: Where does all that data go?Because the more useful your AI teammate becomes, the more it needs to know about you and your company. If it’s preparing you for a meeting, it might need access to your calendar, past meetings and documents. If it’s writing an email, it might need access to your inbox. If it’s updating your CRM, it needs access to customer information. And if you eventually want it doing work for you all day, it may need access to almost everything you use at work. The most useful AI teammate may also be the one that knows the most about your work. That’s why security matters so much.Start with some very simple questionsBefore a company gives an AI access to its information, it should know what happens to that information. Is our data being used to train AI models? Where is it stored? How long is it kept? Who can see it? Can we delete it? Can we control what the AI has access to? Can we see what actions it has taken? And what happens when another AI company or model is involved?These sound like basic questions. But as we give AI access to more of our work, they become incredibly important. Security shouldn’t be something companies think about after they buy an AI product. It should be part of deciding which AI products they trust in the first place.Microsoft says Copilot follows a company’s existing permissions and that its business data isn’t used to train its foundation models. Google says Gemini for Workspace follows existing Workspace protections and doesn’t use customer data to train its generative AI models without permission. Zoom says it doesn’t use customer communications to train its own or third-party AI models. There’s a reason companies are starting to make these promises much clearer. Security is becoming part of the product.“Trust us” isn’t enoughThis becomes even more important when AI has access to conversations. Think about what gets discussed in meetings: customers, employees, hiring, strategy, financials and plans that may never be written down anywhere else. Companies should know exactly what happens to that information. At Fireflies, for example, we don’t use customer meeting content to train AI models. We require third-party vendors handling meeting content to follow zero-data-retention requirements. We also maintain SOC 2 Type II, GDPR and HIPAA compliance. “Trust us” isn’t a security policy. Companies should be able to understand where their data goes, who can access it and what controls they have over it.Banning AI isn’t the answer. Some companies may look at these risks and decide the safest thing to do is block AI altogether. I don’t think that solves the problem. People are already using AI to write, research, prepare for meetings and get work done faster. If their company blocks these tools, some employees will simply use personal accounts or other apps the company doesn’t know about. Now the company has even less control over where its data is going.A better approach is to give employees AI products the company has actually reviewed and approved and then set clear rules around what those products can see and what they’re allowed to do.This gets even more important as AI starts taking action. There’s a big difference between drafting an email and sending it. There’s a difference between suggesting a CRM update and making the change. There’s a difference between finding a document and sharing it with someone.The more AI can do on your behalf, the more control you need over what it’s allowed to do.AI needs to earn our trustFor the last few years, everyone has been focused on making AI smarter. Can it answer better questions? Can it understand more? Can it do more work?Those things still matter. But as AI becomes more deeply connected to our work, there’s another question that matters just as much: Can we trust it?Today, a company might use AI to take meeting notes. Tomorrow, that same AI teammate could prepare you for meetings, search your email and Slack, update your CRM, follow up with customers and take care of work across dozens of apps.Every time we give it another ability, we’re also giving it more access. And that means companies need to know that their AI teammate is looking at the right information, for the right reason, and doing only what it has permission to do.The goal isn’t just to build AI that knows more. It’s to build AI that we can trust to do more.By: Krish Ramineni, Co-founder & CEO, Fireflies.aiYou use AI every day. Now get your AI Quotient. Take the AIQ test.
Topics in this story
Gathered from external sources. Rights to this text belong to whoever originally published it.