← Writing

Strategic Leakage Is Not a Privacy Problem

Privacy frameworks protect personal information. They say nothing about the operational knowledge your teams push into AI tools every day. That gap has a cost.

The AI industry rewards usage. Vendors price in tokens and sell dashboards that show adoption climbing. Inside organisations this becomes a kind of token maxing: teams are measured and praised on how much AI they use, with little attention paid to what is being shared or what institutional knowledge is exported along the way.

Usage is easy to count. What leaves with it is not.

Your rostering workarounds, funding interpretations, incident thresholds and internal decision rules are not generic business content. They are how your organisation operates. Pushed into tools without boundaries, they stop being yours alone.

The gap in the frameworks you already have

Boards already understand privacy. Personal information gets protected and cyber incidents get reported. The frameworks exist and most providers take them seriously.

Strategic leakage is a different risk, and the privacy frameworks don’t catch it. Every safeguard you have is built around one question: is personal information protected? Operational knowledge fails that test in reverse. It contains no names, so it passes every review, and it carries the most competitively valuable thing you own.

The question is no longer only whether your data is safe from attackers. It is whether your operational knowledge is being absorbed into systems you don’t control, on terms you haven’t examined.

Three questions for the next board meeting

Can your data improve someone else’s model? If the provider can use your prompts, documents or interactions to improve its models or services, you are contributing value to a product your competitors can also buy. That may be an acceptable trade. It should be a decision, not a default.

Can you audit what happened? When AI contributes to a clinical, operational or compliance decision, you need to be able to say what the model was given and who signed off on what it produced. A black-box answer is not a defence in front of a regulator.

Do you own the intelligence you’re creating? The prompts, workflows and review processes your team builds inside a vendor’s ecosystem are intellectual property. If the vendor changes its pricing or its direction, can you take that knowledge with you? If not, your organisation is becoming dependent on intelligence it doesn’t own.

Sovereignty is not abstinence

None of this argues for banning AI. In care settings the gains are real: lighter administrative load and more reach for scarce clinical expertise. Walking away from that would be its own strategic error.

Sovereignty means using AI on your own terms. Knowing which data can go where, and where human accountability sits. It means treating AI as a component in a governed system rather than an external consultant anyone can brief with sensitive context.

A governed AI system builds your institutional value. An ungoverned AI habit exports it. What the boundaries of a governed system look like in practice is the final post in this series.