The idea of a massive AI-related GDPR fine used to feel hypothetical. It is starting to feel a lot less so.
Over the last two years, regulators have shifted from curiosity about AI tools to scrutiny. Prompts are no longer seen by regulators as harmless experimentation. They are increasingly being treated as data processing events.
That distinction really does matter. Many organisations still operate as if pasting internal information into a public model is the same as typing a note into a private document. Legally, it isn’t.
The Math Behind the Risk
GDPR Article 83 has always allowed fines of up to 4% of global annual turnover. Recent enforcement trends show regulators focusing heavily on “insufficient technical and organisational measures.” In other words, they are no longer only asking whether a breach occurred. They are asking whether the company put appropriate controls in place to prevent foreseeable misuse.
With the EU AI Act now in force, expectations have increased again. AI literacy, governance, and risk classification have become core compliance obligations.
When something goes wrong, the question regulators will ask is simple: did leadership treat this as a known risk and implement proportionate safeguards? If the answer is no, the exposure multiplies.
Why Prompts Are Not “Private Thoughts”
There is still confusion inside companies about what happens when someone submits a prompt to a public AI model.
From a data protection perspective, that action can constitute a transfer of personal or confidential data to a third party. If no data processing agreement exists, and if no contractual restrictions are in place, the organisation may have limited control over how that data is handled downstream.
Even where providers offer assurances, the legal analysis hinges on documentation, risk assessment, and enforceable agreements. Not assumptions.
This is where many firms are exposed. Employees often treat public AI tools as if they were internal systems. In most cases, they are not.
The Memorisation Question
Another emerging concern is model memorisation. Large language models do not store data in traditional rows and columns, but research has shown that under certain conditions, models can reproduce fragments of training data. This is not guaranteed, and it is not universal. But it is possible.
If multiple employees input similar proprietary material into a public model, that increases theoretical exposure. Whether that exposure materialises into real-world “regurgitation” depends on several variables, including model design and safeguards.
The regulatory question will not be whether memorisation is common. It will be whether the company assessed the risk and implemented reasonable controls.
From Ignorance to Accountability
A few years ago, many organisations could plausibly argue that AI use was experimental and poorly understood. That argument is weaker today.
High-profile incidents, including past corporate source code leaks involving public models, have made the risk visible. Basic governance controls are now widely discussed: prompt filtering, access restrictions, private deployments, logging, and employee training.
Regulators are unlikely to accept “we didn’t realise” as a sufficient explanation if no structured AI governance framework exists.
The Bottom Line
Using AI tools is not inherently reckless. In many contexts, they provide legitimate productivity gains.
The risk arises when organisations treat them as informal utilities rather than regulated data processors.
Every prompt that contains personal data, commercially sensitive information, or confidential material should be treated as a compliance event. That does not mean prohibiting use. It means governing it properly.
If AI adoption outpaces control frameworks, the exposure is not abstract. It is financial, legal, and reputational.
The companies that avoid the mega-fine will not be the ones that avoided AI. They will be the ones that implemented guardrails early and documented their reasoning.

Donal Brady is Co-Founder and Head of Product at Work From Anywhere, a platform to help companies execute a successful workation policy. He has deep expertise and experience in the world of remote work having spent nearly twenty years working in finance leadership roles with global multinationals like PwC, before entering the world of global mobility with International SOS and then pivoting into the software industry with Accel-KKR backed Smart Communications. He walks the walk with Work From Anywhere, speaking 5 languages, having travelled to 65+ countries and worked in 10.






