All posts
15 May 2025 · ai · security · 4 min read

Is AI a Security Risk? Or Are We Just Not Using It Right?

So, let's not shy away from AI. Let's just use it wisely.

Is AI a Security Risk? Or Are We Just Not Using It Right?

AI is rapidly becoming part of our daily operations, from handling emails to building quotes and simplifying admin. But despite its time-saving potential, many in the glazing sector are still asking one vital question: Is my data safe?

It’s a fair concern. We deal with sensitive customer details, pricing, and business plans. The last thing anyone wants is for those to end up in the wrong hands. But here’s the thing: when it comes to security, AI isn’t the risk we think it is. If anything, the real risk lies in how we’re already using technology today.

So how does AI compare to tools you already use?

You wouldn’t think twice about sending a quote by email, updating a file on OneDrive, or storing job photos on your laptop. These are everyday actions that all come with risk that we rarely acknowledge...

Email: Still the most targeted and exploited system. Already in 2024, the UK has seen over 57 million email accounts breached, mostly via phishing or human error. Emails are often unencrypted, easy to forward, and almost impossible to fully retract once sent.

Cloud storage: These platforms are encrypted and protected, but only if your passwords are strong, devices are secure, and sharing is managed correctly. A shared link with no expiry date is like leaving your front door open.

Local servers and laptops: You might feel safer keeping files “in house”, but theft, hardware failure, or out-of-date security patches can expose everything in one go.

AI tools like ChatGPT (Enterprise or API): These are not data storage systems. They process information to generate language, but they don’t hold your data long-term. When used correctly, AI is no riskier than email or file sharing. In many cases, it’s safer.

So why does AI feel riskier?

As humans, we’re wired to mistrust what’s new. Our default is caution. And when something we don’t fully understand comes along, like AI, it’s easier to fear it than to fact-check it.

We also tend to project ideas onto AI that don’t apply. The myth that “AI might leak our data” feels real, even if the actual risk is lower than sending a misaddressed email. We fear machines being smarter than us, or systems behaving in ways we can’t control. But in truth, AI does exactly what we tell it. Nothing more, nothing less.

The irony? Many businesses are using email and cloud storage daily without a second thought, despite email being responsible for most data breaches worldwide. Meanwhile AI, when set up properly, has no publicly reported breach history and is built with far more control.

Remember: the weakest link is still human

The recent M&S cyberattack, which caused nationwide disruption and is forecast to cost the company over £300 million, wasn’t caused by AI. It was the result of human error and social engineering, where attackers tricked people, not systems.

This highlights the uncomfortable truth: the biggest risk to your business isn’t the tool—it’s how your team uses it.

Weak passwords. Clicking suspicious links. Uploading sensitive info into online tools without checking the settings. These behaviours are what put your business at risk—not the platforms themselves.

What you can do: get ahead of the risk

AI needs a few sensible ground rules to be used safely and confidently. Here’s what we recommend to all glazing businesses:

Create a simple AI usage policy

Set clear internal rules on:

  • When and where AI can be used
  • Ensuring chat history is turned off
  • Avoiding entry of private customer data unless using secure enterprise versions
  • Naming approved tools and discouraging “free AI apps” found online

Educate and empower your team

  • Run regular training sessions (available via GlazePro AI membership)
  • Explain how AI works, where it stores data (or doesn’t), and what to avoid
  • Encourage curiosity—but matched with caution

Treat AI like any other business tool

  • Use strong passwords and enable two-factor authentication
  • Don’t let AI feel separate from your systems - it should be part of your workflow, not a mysterious side-tool
  • Apply the same discipline you would with client emails or finance documents

Final thought: secure by habit, not by fear

AI isn’t a security threat waiting to happen. In fact, when used with intention, it’s one of the most secure tools available to a modern business. But just like email, laptops, or shared files, it requires a bit of thought, a few good habits, and the right setup.

Fear is a natural reaction to change. But progress comes from moving past that fear, asking the right questions, and creating systems that help people feel confident.

So, let’s not shy away from AI. Let’s just use it wisely. We have created a free online AI Policy Generator to get you started. Try it out here; https://thinkivity.co.uk/free-ai-policy-generator/ or scan the QR Code to use on your phone.

Originally published in Glass & Glazing Products.