More and more companies set limits on cloud AI
According to Cisco’s 2024 Data Privacy Benchmark, based on over 2,600 security and privacy professionals in 12 countries, 27% of organisations had banned generative AI, at least temporarily, over privacy and security risks. 63% limited what data can be entered and 61% limited which tools employees can use.
It is not that they distrust AI: they cannot control where the data they give it ends up.
Even with rules, data leaks
In the same Cisco study, almost half of respondents admitted entering non-public company information into generative AI tools. And a Harmonic Security analysis of the prompts and files employees sent to AI tools in 2025 found sensitive information in more than 4% of prompts and around 22% of files: code, credentials, customer and employee data or financial information.
What ISO 27001 requires
ISO/IEC 27001 does not ban ChatGPT, Gemini or Copilot. It requires every tool that handles company information to be identified, assessed and controlled within the management system. In practice it mainly affects these controls of the 2022 version:
- 5.10 Acceptable use: which tools may be used and with which information.
- 5.12 Classification: which confidentiality level each tool may handle.
- 5.19 to 5.23 Suppliers and cloud services: every external AI is a supplier to assess, contract and monitor.
- 8.12 Data leakage prevention: measures to keep confidential information in.
The usual outcome is that cloud AI is allowed with public or internal information and restricted, or banned, with confidential information. To manage AI itself there is also a dedicated standard, ISO/IEC 42001, already certified in Spain by bodies such as AENOR, SGS or Bureau Veritas.
The public sector and its suppliers: the ENS
Spanish public bodies and the companies that serve them follow the National Security Framework (ENS, Royal Decree 311/2022). The National Cryptologic Centre has published specific guides to configure cloud AI services to the requirements of its HIGH category. In other words: cloud AI can be used there, but only with specific configuration and controls.
The example of Spain’s data protection authority
Spain’s data protection authority (AEPD) published its own policy for using generative AI in November 2025. It distinguishes between external systems, such as ChatGPT or Microsoft 365 Copilot, and those deployed on its own infrastructure with open-weight models such as Llama, Qwen, Gemma or Mistral.
Among the risks of external systems it lists disclosure of confidential information to third parties, lack of control over data flows and unilateral changes to terms of use. For platforms it does not control, it provides for an express ban on entering personal, confidential or unpublished information. Systems on its own infrastructure, by contrast, can be audited and let it control where information travels.
The way out: AI inside your perimeter
Private AI is exactly that second model: the server is in your company, the models are open and documents never leave your network. For your management system it is one more internal asset, not a cloud AI supplier to assess, and there are no international data transfers.
- Documents and questions are processed on your server, and it can work without the internet.
- Each person has their own account and sees only the document collections you assign.
- Access is logged, and any remote access goes through an encrypted channel that you enable.
- We give you a description of the architecture and data flows to include in your management system.
| Cloud AI | Private AI | |
|---|---|---|
| Where data is processed | On the provider’s servers | On your server |
| AI supplier to assess (5.19 to 5.23) | Yes | No |
| International transfers | Possible, depending on the provider | No |
| Access logs | Depending on the plan | On your server |
| Changes to terms | Decided by the provider | Decided by you |
Private AI does not replace your management system: it is included in it like any other server, with its inventory, access control and backups. What it does solve is the underlying problem: confidential data stops leaving the company. ACD&CO private AI is set up and configured for €770, with no monthly fees: you pay for the hardware, outright or on renting, and the set-up once.
Sources: Cisco Data Privacy Benchmark 2024 · Harmonic Security (SC Media) · AEPD generative AI policy (27-11-2025) · CCN-CERT, CCN-STIC 884D guide.
Related hardware and services
Frequently asked questions
Does ISO 27001 ban ChatGPT?
No. It requires every tool that handles company information to be identified, assessed and controlled. In practice, many certified companies allow it only with non-confidential information.
Does private AI get us certified?
No: certification applies to your management system. Private AI makes it simpler, because confidential data never leaves your network and there is no external AI supplier to assess.
What about ChatGPT Enterprise or Microsoft 365 Copilot?
They offer contracts and privacy commitments, and can fit a lot of information. They are still external services to assess as suppliers; for the most sensitive information, many companies prefer it never leaves.
Does your company work under ISO 27001 or ENS?
Tell us which standards you apply and which documents you work with. We will propose a private AI that fits them.