The BALMAS blog

Practical guides on working safely with AI: what never to paste, how to anonymize documents, and what privacy law requires.

2026-09-02 · 5 min read

AI agents and your files: the permission-minimization playbook

An AI agent doesn't just answer — it acts: reads email, books meetings, executes tasks on its own. Israel's privacy regulator just published one of the first end-user guides for agents. Here is its playbook.

Read the guide ←
2026-09-02 · 5 min read

The Copilot-only policy: what it solves and what it doesn't

The CISO blocked ChatGPT and Gemini and left only Copilot — and the team is fuming. A single-tool policy isn't absurd: it buys a contract, control and management. But it solves only part of the problem — here is exactly which part.

Read the guide ←
2026-09-02 · 5 min read

Blocking AI at work: why it backfires and what to do instead

The CISO blocked every external AI tool, and the best people are already updating their CVs. The blocking reflex is understandable — but it moves the risk to personal phones instead of removing it. Here is the tiered policy that delivers both security and productivity.

Read the guide ←
2026-09-02 · 5 min read

What is Shadow AI? The risk every ban creates

When a company blocks ChatGPT, employees don't stop using AI — they stop telling anyone. Usage moves to personal phones and private accounts: all the risk, none of the visibility. That's Shadow AI.

Read the guide ←
2026-09-02 · 5 min read

My company blocked ChatGPT — what now?

Security blocked every external AI tool? Before you bypass the ban from your phone — or update your CV — there's a third option security teams can actually approve.

Read the guide ←
2026-08-26 · 5 min read

What is zero-retention — and why not every promise is equal

"We don't store your data" is a promise. "Your data never reaches us" is an architecture. The difference between the two is the difference between trust and certainty — and it matters most when the documents are sensitive.

Read the guide ←
2026-08-26 · 5 min read

Meeting transcripts and AI: how to summarize without exposing the participants

Transcription tools turned every meeting into text, and AI summarizes it in seconds. But a transcript is one of the most exposed documents there is: people speak freely, in full names, about clients and colleagues. Here is how to summarize without exposing anyone.

Read the guide ←
2026-08-26 · 4 min read

Data tokenization: hide the identity, keep the meaning

Delete a name and the document loses its plot. Replace it with PERSON_001 at every occurrence and the document stays whole: you can see who signed, who paid and who promised — without knowing who they are. That is tokenization.

Read the guide ←
2026-08-26 · 4 min read

AI for therapists: writing help that never touches confidentiality

A session note may be the most sensitive document there is: a person's inner world, under their full name. How therapists can use AI for the writing around therapy — without one identifying word leaving the office.

Read the guide ←
2026-08-26 · 4 min read

AI in a startup: maximum speed without breaking NDAs

In a startup everyone pastes everything into AI — code, investor decks, customer contracts. Much of that material sits under NDAs, and the questions about it arrive at the worst moment: due diligence.

Read the guide ←
2026-08-26 · 5 min read

Document redaction done right — and where everyone fails

A black rectangle on the screen is not redaction. 'Redacted' documents keep getting published where anyone can select, copy and paste the hidden text. What real redaction is, the classic failures, and how to do it properly.

Read the guide ←
2026-08-26 · 5 min read

AI for HR and recruiting: screen and draft without exposing people

AI summarizes CVs, drafts feedback and prepares interview questions — but a CV or a performance review is personal data, sometimes of the most sensitive kind. Here is how to use the tools without turning HR into the company's leak source.

Read the guide ←
2026-08-26 · 4 min read

AI for real estate: close deals faster without exposing clients

A lease with both parties' IDs, a mortgage approval with salary and savings — real estate paperwork exposes entire lives. How to get AI's speed without any of it reaching a third party.

Read the guide ←
2026-08-26 · 4 min read

Customer security questionnaires: answering the new AI-usage sections

Nearly every vendor security questionnaire now has a new chapter: AI usage. "We don't use AI" is no longer credible, and "we have no policy" kills deals. How to answer honestly — and what turns the answer into a selling point.

Read the guide ←
2026-08-26 · 5 min read

Pseudonymization vs anonymization: what's the difference?

Both replace the name with an alias — but the difference between them is the whole legal difference in the world: pseudonymized data stays inside GDPR, anonymized data leaves it. The deciding question: who holds the key.

Read the guide ←
2026-08-26 · 5 min read

What is PII? What counts as personal data — with examples

A name is PII. But an IP address? "The CFO of a 40-person software company"? What actually counts as personal data under GDPR and as PII in US usage — and why the answer is broader than most people assume.

Read the guide ←
2026-08-26 · 4 min read

AI for nonprofits: more grants and content, no exposed beneficiaries

AI drafts grant applications, donor reports and social posts — but a nonprofit's raw material is the stories of real people at their hardest moment. Here is how to use the tools without breaking the trust beneficiaries and donors placed in you.

Read the guide ←
2026-08-26 · 5 min read

Data minimization: collect less, risk less

The simplest rule in data protection is also the strongest: what you never collect can't leak, can't be demanded for deletion, and can't earn you a fine. What data minimization means under GDPR — and why it applies to every prompt.

Read the guide ←
2026-08-26 · 4 min read

Document metadata: what your file says without you knowing

The document you edited so carefully carries a whole story you can't see on the page: who wrote it, what was deleted, which comments the editors traded, and where it was saved. That's metadata — and here is how to clean it before it betrays you.

Read the guide ←
2026-08-26 · 5 min read

Medical records and AI — without breaking confidentiality

AI can explain a discharge summary in plain language, organize a medical history and draft questions for your doctor. But a medical record is the most sensitive data there is — feeding it to an external tool is not a casual step.

Read the guide ←
2026-08-26 · 5 min read

Local AI models vs cloud services: which is right for you?

A local model guarantees your data never leaves the building — but costs hardware, maintenance and usually quality. The cloud gives you the strongest models — but your documents travel out. There's a third path that takes the dilemma apart.

Read the guide ←
2026-08-26 · 5 min read

ISO 27001 and AI usage: keeping your certification safe

Your ISMS passed the audit — and meanwhile employees are pasting confidential documents into AI tools nobody assessed. That is exactly the gap an auditor looks for. Here is how to close it without banning the tools.

Read the guide ←
2026-08-26 · 4 min read

AI for insurance agents: faster claims work, zero client exposure

Claim forms, medical summaries and loss reports are among the most sensitive documents in any market. How an agency gets AI's speed without policyholder data ever leaving the office.

Read the guide ←
2026-08-26 · 5 min read

HR documents and AI: contracts, payroll and disciplinary files without exposing employees

AI drafts a solid employment contract and summarizes a disciplinary hearing in seconds — but HR files are among the most sensitive documents an organization holds. How to get the benefit without turning HR into a leak.

Read the guide ←
2026-08-26 · 5 min read

HIPAA and AI tools: PHI, BAAs and de-identification

Pasting a patient record into a chatbot can be a HIPAA disclosure. What counts as PHI, why the BAA question decides almost everything, and how de-identification turns a forbidden document into one you can use with any AI tool.

Read the guide ←
2026-08-26 · 5 min read

AI in the public sector: speed up the work without exposing citizens

AI summarizes minutes, drafts responses to citizens and accelerates staff work — but a public body holds data people had no choice but to hand over, so its duties are heightened. Here is how to adopt the tools without making the agency a leak source.

Read the guide ←
2026-08-26 · 5 min read

Gemini and sensitive data: how to use it without exposure

Gemini doesn't wait for you to paste text — it sits inside Gmail, Docs and Drive, closer to your organization's sensitive data than any chatbot before it. Where the data goes, how consumer and Workspace accounts differ, and what to do before feeding it a document.

Read the guide ←
2026-08-26 · 4 min read

Financial statements, payroll and cash flow with AI — without exposing the numbers

AI can explain a P&L, spot cash-flow anomalies and draft a management summary. But a private company's financials are trade secrets, and a payroll file is employees' personal data. Here is how to get the value without paying in privacy.

Read the guide ←
2026-08-26 · 5 min read

Excel files with IDs, phones and salaries vs. AI: how to analyze without exposing anyone

"It's just numbers" — the sentence that gets organizations in trouble. An ID, phone or salary column in a spreadsheet is personal data in the fullest sense, and one sheet can hold thousands of people. Here is how to let AI analyze the file without transferring any of them.

Read the guide ←
2026-08-26 · 4 min read

Email threads and AI: how to draft and summarize without exposing personal data

"Draft a reply to this email" is one of the most common AI requests — and most people paste the whole thread. But a thread drags an entire history with it: addresses, names, prices and internal remarks nobody meant to pass on.

Read the guide ←
2026-08-26 · 5 min read

AI in education: save hours of work without exposing students

AI drafts lesson plans, writes feedback and summarizes documents — but any document naming a student is data about a minor, among the most protected data there is. Here is how to enjoy the tools while student data never leaves the school.

Read the guide ←
2026-08-26 · 4 min read

DLP vs anonymization: blocking or enabling?

DLP stops a sensitive document on its way out — but the work still has to get done. Anonymization takes the same document and makes it safe to use. How the two approaches differ, and why a smart organization doesn't choose between them.

Read the guide ←
2026-08-26 · 4 min read

Using AI on resumes — without exposing personal details

A resume is personal data by design: name, contacts, employers, dates. How candidates and recruiters can get real help from AI — without handing that identity to an external vendor.

Read the guide ←
2026-08-26 · 4 min read

Customer data exports and AI: how to analyze without exposing anyone

"Export the customers to a spreadsheet and let AI find the patterns" — every company says it. But a CRM export is a portable copy of your customer database, and pasting it into an external tool is a disclosure. Here is the safe way.

Read the guide ←
2026-08-26 · 4 min read

Court documents and AI — without risking privilege

AI drafts, summarizes transcripts and finds contradictions between affidavits — real value in litigation. But court documents carry names, privilege and sometimes sealing orders. Here is how to use the tool without crossing a line.

Read the guide ←
2026-08-26 · 4 min read

Microsoft Copilot privacy: the risk already sitting in your SharePoint

The big Copilot risk isn't data leaking out — it's data flooding in: every forgotten payroll file and contract shared with 'everyone' comes back as a well-written answer. Why over-permissioning is the real problem, and what to do about it.

Read the guide ←
2026-08-26 · 4 min read

Reviewing contracts with AI — without exposing parties, amounts or secrets

AI is genuinely good at reading contracts: flagging risky clauses, summarizing obligations, comparing drafts. The problem — a contract is full of names, amounts and terms bound by confidentiality. Here is how to do it right.

Read the guide ←
2026-08-26 · 4 min read

AI for consultants: all the leverage, zero client exposure

A consultant holds what the client shows no one else: real financials, models, strategic plans. How to use AI for analysis and writing — without any of that material reaching a third party.

Read the guide ←
2026-08-26 · 5 min read

Claude and sensitive documents: how to use it safely

Claude excels at long documents — which is exactly why people upload contracts, case files and financials to it. Before you do: where the data goes, what a business plan really changes, and the workflow that leaves nothing to leak.

Read the guide ←
2026-08-26 · 4 min read

ChatGPT Enterprise privacy: does a business plan fix it?

'We bought Enterprise, so we can upload anything' — heard in many organizations, and only half true. What a business plan really provides, what it cannot provide, and why the gap between a contractual promise and an architectural guarantee is the whole story.

Read the guide ←
2026-08-26 · 5 min read

AI data leaks: the channels, the prevention, the notification

Most data leaks through AI don't start with a sophisticated attack — they start with an innocent paste: an employee summarizing a document by dropping it, names and numbers included, into an external tool. How it happens, how to prevent it, and what the law requires once it has.

Read the guide ←
2026-08-26 · 5 min read

Does AI train on my data?

It's the question everyone asks after pasting something into a chatbot: where does this go? The short answer — it depends on your tier and settings. The more important answer — training is only one of the risk paths, and there is one approach that works across all of them.

Read the guide ←
2026-08-26 · 5 min read

Company AI usage policy: what to include, with a ready outline

Your employees already use AI — with or without permission. A good policy doesn't block; it draws clear lines: which tools are approved, what data must never be entered, and what to do before pasting a document. Ready outline included.

Read the guide ←
2026-08-26 · 4 min read

The EU AI Act: risk tiers, who it applies to, and how to prepare

The EU passed the world's first comprehensive AI law, applying in phases and organized around risk. Like GDPR, its reach extends beyond Europe. Here is what the tiers mean and the preparation that actually matters for most teams.

Read the guide ←
2026-08-26 · 5 min read

AI for accountants: analyze the numbers, not the identities

AI summarizes financial statements, drafts letters to tax authorities and checks calculations — but statements, filings and payroll files contain exactly the data that must never leave the office. Here is the workflow that makes both work.

Read the guide ←
2026-08-25 · 4 min read

What should you never paste into ChatGPT? The complete list

Every paste into ChatGPT sends data to an external server. Here is the full list of what must never go in, what happens to your text after you paste it, and how to still get AI's help with sensitive documents — safely.

Read the guide ←
2026-08-25 · 4 min read

Document anonymization: the practical guide

A black marker is not anonymization. The difference between redaction, pseudonymization and true anonymization, the details you must handle (including the invisible ones), and how to keep the document useful — without the identities.

Read the guide ←
2026-08-25 · 4 min read

AI for lawyers: enjoy the tools without risking privilege

AI drafts, summarizes and finds — but every paste of client material into an external tool touches confidentiality and privilege. What the precedents taught us, and the protocol that lets a firm use the tools safely.

Read the guide ←
2026-08-25 · 4 min read

AI in healthcare: the tools without the confidentiality breach

Medical data is the most sensitive data there is — by law and by breach economics. How clinical teams and health-system admins use AI on summaries and letters, without patient details ever leaving the institution.

Read the guide ←
2026-08-25 · 3 min read

AI for business: adopt it right — without leaking data

AI's upside for business is no longer debated — neither is the risk. What to do so employees get the tools without your customer list, price book or payroll ending up on someone else's server.

Read the guide ←