Guide
AI and company data: the 12 questions a board should ask
Before connecting ChatGPT or Claude to company data, a board should get written answers on twelve points, from where the data is stored to reversibility, including model training and where the data is processed. At C-Esium, AI assistants access the internal software read-only, for authorised users only, and every access is logged.
Connecting an AI assistant to company software means opening your customers, quotes, invoices and sometimes your staff data to it. Here are the twelve questions to ask before signing, to C-Esium as to any provider: the short answer, what to require, and what C-Esium does. Reference example: the MCP connector of Tech-O, in production, with around 35 tools, all read-only.
1. Where is our data, and who owns it?
In your internal software’s database. When an employee queries the assistant, the data needed for the answer is sent to the model provider (OpenAI, Anthropic…).
Require: the host’s name and the hosting country written into the contract, and the list of every provider that receives data.
At C-Esium: the database, the project source code and the documentation are assigned to the client. For clients in the UAE, by default: AWS (Amazon Web Services) in its Middle East (UAE) Region, so the data stays in the country. A European region is possible on request. The connector does not create a second database: the assistant queries your software on demand.
2. Which AI models, from which provider?
An MCP connector is not tied to one model: the same access can serve several assistants.
Require: the names of the plans used (not just “the AI”) and the ability to change provider without rebuilding.
At C-Esium: your data can be queried from Claude, ChatGPT or the chat built into the application.
3. Is our data used to train the models?
Not with business plans, by default:
- OpenAI does not train its models on data from ChatGPT Business, Enterprise and the API, unless you choose to share it (Enterprise privacy, updated 8 January 2026, accessed 4 October 2026). API abuse-monitoring logs are kept for up to 30 days by default (Data controls, accessed 4 October 2026).
- Anthropic commits not to train its models on content from its commercial offerings (Commercial Terms, accessed 4 October 2026). API inputs and outputs are deleted within 30 days, with exceptions (a zero-retention agreement, usage-policy violations, legal obligations) (Anthropic Privacy Center, accessed 4 October 2026).
The common exception is voluntary feedback (thumbs up or down). At Anthropic, the conversation concerned is kept for up to 5 years and may be used for training; the administrator of a Team or Enterprise workspace can disable this button (Anthropic Privacy Center, accessed 4 October 2026).
Require: a business plan, never a personal account; voluntary feedback disabled; a signed data processing agreement.
At C-Esium: we recommend ChatGPT Business or Enterprise, Claude Team or Enterprise, or the API, and the framework is set out in the contract.
4. Can the AI modify our data, and is there a trace?
Not if the connector is read-only. A technical detail: the MCP specification asks applications to treat a tool’s annotations, including the “read-only” hint, as untrusted unless they come from a trusted server (MCP, Tools, accessed 4 October 2026). Read-only must therefore be enforced by the server, not just displayed.
Require: the list of exposed tools and an access log you can consult.
At C-Esium: at Tech-O, the tools cover the dashboard, today’s jobs, quotes, unpaid invoices and the cash position, among others. None of them changes anything, and every access is logged.
5. Does every employee see everything?
They should not. MCP’s authorisation specification is based on OAuth 2.1 (MCP, Authorization, accessed 4 October 2026), and its security best practices recommend granting minimal permissions at first, widened only when needed.
Require: who can use the assistant, on what scope, and how an access is withdrawn.
At C-Esium: only the users you authorise can access the data from an AI assistant.
6. Who is responsible for the data?
Your company remains responsible for what is done with its data. The software provider and the AI provider, when they process data on your behalf, act on your instructions. Require a written data processing agreement: the provider acts only on documented instructions, brings in no other subcontractor without your written authorisation, deletes or returns the data at the end of the service and accepts audits. OpenAI (ChatGPT Business, Enterprise, API) and Anthropic offer such an agreement (DPA).
Require: the full chain of subcontractors, AI included.
7. Does our data leave the country?
It can. The data returned by the connector goes to the AI provider, which may process it in another country depending on the plan. OpenAI offers control over the processing region for eligible API customers, with a 10% surcharge on models released since 5 March 2026 (OpenAI, Data controls, accessed 4 October 2026).
Require: the processing location and the safeguards, written into the data processing agreement, in line with the rules that apply to you.
At C-Esium: where the software is hosted and where the AI processes data are two separate questions. Both are answered before launch, and the framework is set out in the contract.
8. What do our employees need to know?
An assistant connected to real data is still an AI: its answers can be wrong, and every user should know it. Write the rules before the roll-out: authorised uses, how answers are checked, and data never to be entered in a personal account.
At C-Esium: training and onboarding for all users are part of the method, and change management is led by Cyrille Fantino. That is the right time to write these rules.
9. Is the MCP connector an entry point for an attacker?
Like any exposed interface, it can be if it is badly designed. MCP’s security best practices describe the known attacks: the “confused deputy”, token passthrough (explicitly forbidden), server-side request forgery (SSRF), state handle hijacking, over-broad token scopes (MCP, Security Best Practices, accessed 6 October 2026).
Require: authentication, minimal permissions, revocation, a log. Read-only limits the impact of a stolen token: it allows reading, not modifying.
10. How much does AI cost in use?
Two models coexist. The per-seat subscription: Claude Team, for example, costs $25 per standard seat per month on monthly billing (Claude pricing). The API is billed by the volume of text processed, per million “tokens”: from $1 to $10 input and from $5 to $50 output at Anthropic, depending on the model (API pricing), and from $0.10 to $10 input and from $0.50 to $50 output for OpenAI’s flagship models (API pricing). Price lists accessed 4 October 2026.
Require: a monthly estimate calculated on your real volumes.
At C-Esium: the software has no per-user licence; AI usage is a separate cost item, estimated before launch. To start without changing software, an AI connector on your current tools is a focused project, from AED 40,000 excluding VAT.
11. Can we take everything back if we change provider or AI supplier?
Yes, if the contract says so. Have it state that the provider deletes or returns the data at the end of the service, at your choice.
At C-Esium: code, data and documentation are transferred to you; you can evolve the software with us, with another provider or in-house (rent or own your business software).
12. And health data?
Health data follows specific rules, which depend on your activity and where you operate.
At C-Esium: the hosting arrangement is defined at scoping, in line with the applicable health-data rules, and so is the scope of the AI. By default, AI assistants only access data that is not health data.
The grid to hand to the board
| Question | Answer to get in writing |
|---|---|
| Data | Host, country, owner of the database |
| Models | Plans used, ability to change |
| Training | Business plan, voluntary feedback disabled |
| Writing and traces | Read-only enforced by the server, access log |
| Permissions | List of authorised users, withdrawal procedure |
| Responsibility | Data processing agreement, subcontractors listed |
| Location | Processing location, safeguards |
| Staff | Written rules, training tracked |
| Security | Authentication, minimal permissions, revocation |
| Cost | Monthly estimate on your volumes |
| Reversibility | Return of the code, the data and the documentation |
| Health | Arrangement defined at scoping, AI kept away from health data by default |
When is it too early to connect AI to your data?
- Your data is scattered across files and tools: the assistant can only answer on what it can reach. Bringing the data together comes first.
- Nobody can say who should see what: settle permissions before opening access.
- You only need help writing or summarising documents: a business plan of ChatGPT or Claude, without a connector, may be enough.
- Your provider cannot answer the questions above in writing.
To see how these answers translate into real software, read how to connect ChatGPT and Claude to your company data or book a 30-minute call.
Frequently asked questions
Do ChatGPT Business and Claude Team use our data to train their models?
No, not by default. OpenAI states that it does not train its models on data from ChatGPT Business, ChatGPT Enterprise and its API, and Anthropic’s commercial terms rule out training on content from its business offerings (Claude Team, Enterprise, API). The main exception is feedback a user chooses to send (thumbs up or down), which the administrator of a Claude Team or Enterprise workspace can disable.
Can a read-only MCP connector modify our data?
No: a read-only connector only exposes consultation tools, provided that this limit is enforced by the server itself and not merely declared. At C-Esium, AI assistants access the software read-only, for authorised users only, and every access is logged.
Does our data leave the country when we query ChatGPT or Claude?
It can. The data returned by the connector is sent to the AI provider to produce the answer, and may be processed in another country depending on the plan chosen. Have the processing location and the safeguards written into the data processing agreement, in line with the rules that apply to you.
Do we have to change software to connect AI to our data?
No. C-Esium’s focused project, from AED 40,000 excluding VAT (€10,000 in France), includes an AI connector on your current tools: you query your existing tools from ChatGPT or Claude, through a read-only, logged MCP connector, without changing software.
Read next
Connect ChatGPT and Claude to your data
How read-only MCP access works.
ReadAI for business: the 4 levels
From a ChatGPT licence to the 2030-ready company.
ReadWhere should you host your business software: AWS in the UAE or in Europe?
Hosting business software for a UAE company: AWS’s UAE Region by default, Europe on request, the US CLOUD Act, health data, and a hosting account in your name.
ReadYour software, built for your company.
30 minutes to understand your organisation, your tools and what an internal software with AI would change for you. No commitment.