We only use AI to answer questions

· · AI Security

There is a sentence we hear a lot when the subject of AI at work comes up, and it is always said with relief: "We only use it to answer questions. We never let it change anything." The person means they have been careful. They have not connected the AI to anything it could break, they read its answers themselves, and they copy across only what they want. It sounds like the safe way to use the technology, and for one specific risk it is. For another, it misses the point entirely, because the leak does not happen in the answer. It happens in the question.

How a modern assistant actually answers

Ask an older chatbot a question and it replied from memory. Ask a current AI assistant, the paid, "we do not train on your data" kind included, and it often does something different: it goes and looks. To answer well, it runs its own web searches, reads the pages that come back, and sometimes searches again based on what it found. This is the feature you are paying for. It is also the part nobody pictures when they say "just answering questions".

Here is the moment that matters. Suppose you upload a contract and ask a benign question: "Can you spot any errors in this document?" To check its work, the assistant may search the web for the company names, the clauses, the figures. The instant it does, whatever it put into that search has left your control. It has gone to a search provider you did not choose, been logged somewhere you cannot see, and been kept for a period nobody told you. You have not read a single line of the answer yet, and your customer's name, or the value of the deal, is already sitting in a third party's records.

The uncomfortable part is that the question is often the confidential thing. For an accountant, a recruiter, or a solicitor, "is Acme Ltd heading for insolvency" is not an innocent search. The query is the secret, whatever the answer turns out to be. Old professional instinct understood this: you did not type a client's undisclosed deal into a public search box. The new twist is that the searches are run for you, several per answer, reworded each time, and you never see them.

Why "no write access" does not cover this

The relief in "we only use it to answer questions" comes from a real and correct idea: an AI that cannot change anything cannot delete your files or email your clients by mistake. That is worth having. But it guards the wrong door. Not giving the AI write access stops it from changing the outside world. It does nothing to stop it from telling the outside world what it has seen, because searching and reading are how it answers, and both are outbound. Information leaves whether or not the AI can write anywhere. We covered the sharp end of this in the companion filing on NCSC's agentic AI guidance: an assistant that can read private data and reach the web has everything it needs to leak, with no write access anywhere in the chain.

There is a nastier version worth knowing about, though it is not the everyday risk. If a booby-trapped web page or document can slip instructions to the assistant while it reads, an attacker can steer what it searches for and where it sends the result. That is prompt injection, and it turns the same outbound channel into a deliberate exfiltration route. For most businesses, though, the plain version is the one to fix first: no attacker required, just an assistant doing its job and carrying your data out with it.

There is a data protection angle, too

Put a customer's name into an AI assistant that forwards it to a search provider, and you may have shared personal data with a company you never assessed, under no agreement, with retention you cannot state, that appears nowhere in your privacy notice. Whether that matters legally depends on the data and the provider, and this is not the place for a verdict on your specific setup. But "our AI might be making disclosures our paperwork does not cover" is a sentence worth being able to rule out rather than assume away. Our filing on why an AI policy should actually say something is the place this belongs.

What to do

Know which tools are switched on. In the assistants your team uses, find out whether web search or browsing is enabled, and in which mode. Many products let you turn it on and off per conversation. The safe default for anything touching client data is off.

Separate "AI with our data" from "AI with the web". The riskiest combination is an assistant that has both your confidential document and live web access in the same session. Where you can, keep those apart: use search-enabled AI for general questions, and a search-disabled mode when you are working with anything sensitive.

Ask the vendor two plain questions. Whose search does it use when it looks something up, and what is kept. A serious provider can answer. If your assistant is bundled into a bigger product, the reseller should be able to find out. How quickly the answer arrives tells you how much thought went into it.

Say it out loud in your AI rules. Most staff have simply never been told that asking a question can send data outwards. A single line in your AI guidance, do not paste client names, contract values, or personal data into an assistant that can search the web, prevents most of this at no cost.

How Steelwise can help

Working out which of the AI tools already in use across your business can reach the web, and what that means for the confidential things people are typing into them, is the kind of AI review we do. Get in touch.

Further reading

← All filings