Chat Guardian scans messages and attachments in real time, before they reach the AI model. Sensitive data is caught, the employee gets a warning, and the event lands in a timestamped log.
AI tools create an entirely new data risk
AI raises productivity, but it also creates a category of GDPR risk that traditional compliance tools were never built to handle.
One copy-paste from a breach
Employees paste customer data, contracts and HR records into AI chat tools, often without noticing that the data leaves the company control at that moment.
Files sent to unknown servers
Documents uploaded for summarising or analysis can be stored, processed or used to train models on servers outside the EU.
AI trained on your data
Business-critical and confidential information can end up training external AI models without your knowledge, consent or legal basis.
External AI with access to internal data
When external AI tools process sensitive information, it can constitute a breach of GDPR articles 28, 32 and 44.
How the scan works
Three steps that run in real time, every time an employee hits send.
The employee writes
A prompt, a message or an attached document on its way to the AI assistant.
Chat Guardian classifies
The content is analysed locally against the GDPR data categories and your own data policies.
Sensitive data is caught
The employee gets a clear warning before data leaves the organisation, and the event is stored with a timestamp in the log.
Not a language model. A detection engine.
Chat Guardian is not built on a large language model like ChatGPT or Claude. It uses a purpose-built AI pipeline of several smaller, targeted models, including a Small Language Model, trained to recognise and classify sensitive data.
- All analysis runs locally in your own environment, so the content is never sent anywhere to be assessed.
- Trained on European languages with a taxonomy built on the GDPR definitions.
- Configurable data policies, so you can add whatever your industry and internal requirements treat as sensitive.
- Timestamped warning log that documents to auditors and the data protection authority when there has been a risk.
One product, two specialists
Chat Guardian is what happens where the Grace platform from 2021.AI meets Safe Online data classification.
Grace AI Platform
The European AI platform for governed GenAI, MLOps and governance. Used across law, finance, life sciences, manufacturing and the public sector.
The Safe Online detection engine
Personal data classification trained on European languages with a GDPR-adapted taxonomy. In use since 2019.
Frequently asked questions
How does the scanner know what counts as GDPR-sensitive data?
The scanner ships preconfigured with an understanding of the data categories the GDPR regulates. Recognition is based on the GDPR definitions and current standards, and it can be extended with your own data policies.
How does the warning log help with compliance?
Every warning is stored automatically in a timestamped log. That gives your compliance and security team insight into where and when there has been a risk of data leaking into AI conversations, and makes it simple to demonstrate accountability to auditors and the data protection authority.
Can we define what counts as sensitive data for us?
Yes. The data policies are configurable, so you can tune exactly what gets caught, based on your industry, your legal requirements and your internal standards, without compromising what the GDPR already covers.
Is the scanner built on a language model?
No. Chat Guardian uses a purpose-built AI pipeline of several smaller, targeted models, including a Small Language Model, trained to recognise and classify sensitive data in real time. That makes it fast and independent of an internet connection, because all analysis happens locally in your own environment.
Shall we show you Chat Guardian?
Our Customer Success team sets up a demo where you see the scan, the warning and the log in practice, in under an hour.
