Half of UK business founders have shared sensitive company or client data through AI tools, according to new research from Startups.co.uk, and the uncomfortable twist is that most of them don't actually trust the tools they're using. That is not a technology problem. That is a behaviour problem, and it is happening right now inside Scottish SMEs, GP practices, school admin teams, and one-person consultancies across Edinburgh.
The data leak isn't dramatic. There's no hacker, no breach notification, no ICO letter landing on the mat. It's quieter than that: a founder pastes a client contract into an AI summariser to save twenty minutes. A practice manager drops patient referral notes into a chatbot to draft a letter. A teacher feeds a pupil's assessment data into an AI to generate feedback. None of it feels like a leak. All of it can be one. The Information Commissioner's Office has been explicit that personal and commercially sensitive data processed by third-party AI tools may not meet UK GDPR obligations, particularly where that data is used to train future models or stored on servers outside the UK.
The Startups.co.uk report found that distrust of AI is widespread among founders, yet the convenience of these tools is winning the daily battle against caution. That gap, between what people believe is safe and what they actually do under deadline pressure, is where data protection risk lives. The UK's National Cyber Security Centre has flagged this exact dynamic in its guidance on AI and data security, noting that employees and founders consistently underestimate what counts as sensitive information when interacting with AI systems.
For Scottish SMEs, there is a specific compliance dimension worth flagging. Businesses operating in healthcare or education, two sectors where AI adoption is accelerating fastest in Scotland, are handling data that sits under stricter regulatory frameworks. The Scottish Government's Digital Health and Care Strategy actively promotes AI-assisted workflows in NHS Scotland, and rightly so, but that ambition only works if the data hygiene keeps pace. A community pharmacy in Leith using an AI tool to manage stock queries is in a different risk category to one using it to process repeat prescription requests, even if the interface looks identical.
The fix is not to stop using AI. That ship has sailed, and the productivity gains are real. The fix is to build a thirty-second habit before every AI interaction: ask yourself whether the text you are about to paste would cause a problem if it appeared in a third-party system. If yes, anonymise it first. Strip client names, reference numbers, medical identifiers, and financial details before the content goes anywhere near a model. Tools like ChatGPT's enterprise tier and Microsoft Copilot for Business offer contractual data processing agreements that offer stronger protections than free-tier products, and for most Scottish SMEs the cost is negligible against the compliance exposure. The ICO's guidance on AI and data protection, available at ico.org.uk, is worth bookmarking and actually reading, not just filing.
