← Back to perspectives
/Intellicon FDE Team

When Confidential Data Can't Go to Commercial AI, How Should Enterprises Deploy?

Taiwan’s Ministry of Justice is planning a three-tier sovereign AI architecture, with the initial phase focused on prosecutorial and probation work. Enterprises can determine where to deploy systems based on data classification, then identify the points in each workflow where processing must pause for human confirmation.

AIEgentWrX人機協作導入
When Confidential Data Can't Go to Commercial AI, How Should Enterprises Deploy?

Sales teams want AI Agent to access historical quotations, procurement teams want it to compare supplier terms, and customer service teams want it to organize complaint records. Once these tasks involve customers’ personal data, non-public pricing, contract terms, or manufacturing process data, IT teams face the same question: Can the data leave the company? If not, how can AI still be used?

Enterprises should first establish data classifications, permitted uses, and approval mechanisms before deciding between cloud, on-premises, or hybrid deployment. Deployment location determines only where data is stored and processed. The true boundaries of governance also include which data AI Agent may access, whether it can connect to external services, which actions require human confirmation, and whether every operation can be traced afterward.

Start with the Data Flow to Determine Deployment Location

According to iThome, Taiwan’s Ministry of Justice is planning a three-year sovereign AI initiative. With a massive caseload, frontline personnel spend significant time reviewing case files, searching for information, and entering data. However, investigative and probation records contain personal data and case-related information. Even after names are removed, other details may still reveal facts about a case or investigative methods, so original case files cannot be submitted directly to commercial AI services.

The initiative divides the environment into three layers: shared computing resources and a data lake, a justice-specific model inference system, and frontline application services. The plan calls for trials beginning in 2026, broader adoption in 2027, and optimization in 2028. Enterprises can use this layered approach to examine their own data flows. However, government agencies and businesses operate under different cost, network, and compliance constraints, so enterprises do not need to keep all computing resources in their own data centers.

The assessment should trace the entire data journey: where the data comes from, where it is processed, whether it is sent to an external model, where the results are stored, and who can download them. For example, a sales quotation workflow could retrieve historical orders from the internal network and send only the necessary, de-identified fields to an external model for organization. Information involving customer names, floor prices, or special transaction terms should remain within a controlled environment. If bandwidth at a production site is limited, smaller workloads such as OCR and speech-to-text can also be processed on local devices, reducing the need to transmit large volumes of data to a central system.

The first step is to create a “data type × sensitivity level × permitted deployment location” matrix. For each item, specify whether the data may leave the company, which models may be used, whether external connections are allowed, and where outputs may be stored. Next, select a representative use case, run through the complete data flow in practice, and expand only after validation.

Build Human Accountability into the Workflow

The Ministry of Justice limits AI to organizing information, generating initial drafts, and supporting assessments. Prosecutors remain responsible for determining facts, applying the law, and reviewing outputs. Enterprises should likewise turn this principle into rules enforced by the system. Merely stating in training materials or usage policies that “humans retain final responsibility” does not prevent a workflow from sending results without human confirmation.

Consider procurement price comparisons. AI Agent can consolidate quotations, highlight differences in terms, and draft recommendations. However, the workflow should pause when supplier terms conflict, the purchase amount exceeds an internal threshold, or the content is about to be submitted to a manager for approval. The enterprise must specify within the system who is responsible for approval, which source materials the approver may access, and who must make revisions if the item is returned. A purely symbolic consent button is not enough.

Customer service and quality control have similar requirements. AI Agent can organize the context of customer complaints or consolidate inspection records. Once the content involves disclosing personal data, making compensation commitments, releasing products, or issuing external responses, it should wait for confirmation from designated personnel. Enterprises can begin by mapping their current processes, identifying checkpoints involving legal judgments, financial amounts, personal data disclosure, and external publication, then assigning an approval role to each checkpoint and configuring the system so it cannot proceed without approval.

Records Must Show Who Did What and When

One issue remains unresolved in the Ministry of Justice’s plan: which activity records should be retained—and for how long—from login and prompt entry to case-file uploads and the receipt of AI outputs. Enterprises cannot wait until an incident occurs to look for records. The usual problem is not a complete lack of logs, but that data access, model inputs, human approvals, and administrative actions are scattered across different systems, making it impossible to reconstruct the full sequence of events.

Before deployment, enterprises should at minimum identify events such as logins, data access, prompt content, document uploads, AI outputs, human approvals, and administrator downloads. For each event, they should define who may view it, who is responsible for auditing it, and the applicable retention policy. Retention periods should be determined based on the nature of the data and relevant contractual and compliance requirements. Sensitive data should not be copied into logs without limits; otherwise, records retained for investigative purposes may themselves increase the risk of sensitive data exposure.

EgentWrX supports cloud, on-premises, and hybrid deployment. Enterprises can allow AI Agent to access databases in read-only mode through the company’s internal network, while denying external connections by default and explicitly allowing individual domains as needed. The platform can also control which data users may view and which operations they may perform based on their organizational roles. Workflows can pause at designated checkpoints for human approval, while audit logs can be exported and checked for tampering. Enterprises must still define their own data classifications, retention periods, and responsible roles; the platform provides the mechanisms needed to enforce those rules within the system.

Implementation teams can begin by selecting one real-world process that handles sensitive data. They should complete inventories of data, connections, approval checkpoints, and events, then use test accounts to verify that unauthorized access is blocked, unapproved workflows cannot proceed, and auditors can reconstruct the sequence of operations from the records.

FAQ

Must all sensitive data remain on-premises?

Not necessarily. Enterprises can determine processing locations separately for each data classification, keeping original personal data, floor prices, or manufacturing process data within a controlled environment while assessing whether necessary, de-identified content may be processed by external models. The entire data flow must be examined; confirming only where the model is deployed is not sufficient.

Can data be submitted to external AI after names have been removed?

That conclusion cannot be made automatically. Case details, transaction terms, equipment identifiers, or contextual information may still identify specific individuals or entities and may also reveal the company’s operating methods. Enterprises should first test the risk of re-identification and remove fields unrelated to the task before deciding whether the data may leave the company.

Which tasks must pause for human confirmation?

Checkpoints involving legal judgments, financial approvals, personal data disclosure, product releases, and external publication should all require confirmation from designated personnel. Enterprises must also clearly define which supporting information approvers may review, which steps they may send back, and which subsequent actions the system must not execute without approval.

How long should AI activity records be retained?

Retention periods should be set separately based on the nature of the data, contractual obligations, compliance requirements, and investigative needs. Enterprises can begin by identifying records of logins, data access, prompts, outputs, approvals, and administrator downloads. Legal, cybersecurity, and business teams should then jointly determine the appropriate retention periods and regularly verify record integrity and access permissions.

References

30 minutes to map out which work to hand to AI first

Want every employee to have their own AI teammate?

A consultant will be in touch shortly.