What data is your company feeding into artificial intelligence?
Over the last few months, I have had several conversations with chief technology officers, operations managers and even fellow lawyers who enthusiastically describe how their organisations have evolved by using AI to draft emails, analyse contracts, clean up client databases or automate customer service. When I ask what specific information is being fed into these tools, the answers are not entirely precise. It is known that the tool works. However, it is not known precisely what personal data has been fed into it, where it has been stored, or under what conditions a third party – the AI platform provider – may reuse it. Nor does the company have an internal policy or guideline for its staff regarding the limits on the use of artificial intelligence as a work tool. So, in light of the new Criminal Code, which introduces criminal liability for companies and defines new offences such as the improper processing of personal data, what stance should Dominican companies adopt in the face of these risks?
This gap between adoption and understanding is, in my view, the most underestimated compliance risk currently facing the Dominican Republic. Not because companies are acting in bad faith, but because the speed at which these tools are being integrated has far outstripped the speed at which internal data protection policies are being updated. A customer service employee copies a conversation with a guest or a patient into a generative AI chatbot to draft a more polished response. A human resources analyst uploads full CVs to an automatic summarisation tool. A marketing team trains a segmentation model using historical customer data, without anyone pausing to ask whether those data subjects gave their consent for that specific use, or whether the model will end up inferring sensitive categories – such as health, financial status or sexual orientation – that were never collected directly.
Current data protection regulations do not distinguish between the ‘traditional’ use of a database and its use to train or feed an artificial intelligence system. The principle of purpose limitation continues to apply with the same force, as data may only be processed for the purpose for which it was collected, and that purpose rarely explicitly includes ‘serving as input for a third-party model’. The same applies to the principles of data quality and security. If a company does not know what data it is providing to an AI tool, it cannot demonstrate that it has fulfilled its obligation to safeguard that data, nor can it identify whom to notify in the event of an incident. You cannot protect what you have not inventoried.
Here it is worth clarifying a nuance that I have discussed in previous articles; much of the artificial intelligence currently used by companies does not analyse an individual’s personal history, but rather aggregated patterns extracted from huge user populations. This distinction matters from a legal perspective, because not every interaction with AI amounts to the processing of personal data in the strict sense. Yet it is precisely this distinction that many organisations invoke—without having verified it—to assume they are in the clear. The problem is not the technology in the abstract; it is the lack of an internal review to determine, tool by tool, whether what is being provided consists of aggregated and anonymised data, or complete records containing names, national identity card numbers, medical histories or locations.
There is also an additional layer that Dominican companies tend to overlook. Most of the generative AI tools used on a daily basis operate under contracts with foreign providers, with servers located outside the country and data retention policies that are rarely read before accepting the terms of service. This turns every data upload into an international data transfer, with the due diligence obligations that this entails. The question every board of directors should be asking is not whether the company ‘can’ use artificial intelligence – clearly it can, and probably should, to remain competitive – but whether there is an up-to-date inventory within the organisation detailing which AI tools are in use, what type of data feeds each one, and who authorised that data flow.
It is worth taking a look at what is already happening in Europe, not as a model to be copied mechanically, but as a reference point for the direction in which the global regulatory debate is heading. Article 50 of the European Artificial Intelligence Regulation comes into force on 2 August 2026, introducing a set of transparency obligations based on a very simple premise: everyone has the right to know when they are interacting with an AI system, when content has been artificially generated or altered, and when a system is subjecting them to emotion recognition or biometric categorisation. These obligations are not limited to ‘high-risk’ systems; they extend to any chatbot, virtual assistant or generative tool that interacts with people, and apply both to those who develop the technology and to those who simply deploy it as part of their day-to-day operations. Non-compliance may result in fines of up to 15 million euros or 3 per cent of the offending company’s global turnover.
What is interesting about the European approach, for the purposes of this discussion, is not so much the amount of the fine as the underlying logic, given that transparency towards the data subject is built upon prior transparency within the organisation itself. A company cannot inform a customer that they are conversing with AI, nor can it label content as artificially generated, unless it first knows precisely which AI systems it uses, what it uses them for, and what information flows through them. Article 50, as mentioned above, in other words, presupposes precisely the sort of internal inventory that many Dominican companies do not yet have. The Dominican Republic does not currently have an equivalent, specific regime for AI, but Law 172-13 already requires (with its practical and enforcement limitations), through its general principles, a level of knowledge and control over data that should lead a serious company to ask itself the very same questions that a European regulator is currently asking: does this organisation know, system by system, what it is providing and to whom? Clearly, more stringent and explicit regulations are on the way; getting ahead of the curve is undoubtedly a competitive advantage.
The solution does not lie in banning the use of these tools, nor in adding a layer of bureaucracy that stifles innovation. It lies in something simpler and, at the same time, more demanding: a policy on the use of artificial intelligence that classifies information according to its sensitivity, defines what can be uploaded to external tools and what must remain within systems controlled by the company, and trains staff to recognise the difference between drafting with the aid of AI and unwittingly handing over a client’s complete file. This is not merely a technical exercise; it is, above all, an exercise in corporate governance, risk management and, increasingly, criminal liability for the organisation itself. The entry into force of the new Dominican Penal Code introduces a change of particular relevance to companies, as certain behaviours relating to the improper processing of personal data may go beyond the administrative or civil sphere and constitute criminal offences, with consequences that may extend to the legal person itself under the new criminal liability of companies.
No company should have to choose between innovating and complying. But it should be able to answer, without hesitation, the question that gives this article its title.