Article
Using AI in your tender work? Here is what to know about your data

Where does your data go when you use AI in tender work? We walk through the rules that apply right now, and the questions worth asking your software supplier.
Artificial intelligence has become a natural part of tender work for many teams. But when you upload a previous submission containing price calculations and commercially sensitive descriptions of how you work, it is reasonable to ask where that data actually goes. Here we answer that calmly, set out which rules apply right now, and describe what to check before you trust a tool.
What you are actually sharing
It is worth separating two kinds of documents. The tender documents from the buyer are public, and putting them into a tool is rarely a problem.
Your own material is a different matter. Price calculations and margins, the methodology and process descriptions you have spent years building, internal assessments of your own capacity, and usually personal data as well: the names, roles and CVs of the people you are offering.
When you use an AI tool, you are sending that information out of the building. That need not be risky. But it is worth knowing where it ends up, how long it stays there, and what the supplier is allowed to do with it.
Two sets of rules, not one
It is easy to conflate two things that are connected but do not apply in the same way.
Data protection rules (GDPR) already apply, across the whole EEA. If a tool processes personal data, they apply in full. The regulation leaves room for some national adaptations, but the core obligations are the same everywhere. That makes the assessment easier if you sell in several countries: you can ask a supplier the same questions whether you are bidding in Ireland, Germany or the Netherlands.
The AI Act already applies. The EU's rules on artificial intelligence began to be enforced on 2 August 2026, at the same time as new transparency requirements took effect. Those requirements cover, among other things, telling users when they are talking to an AI rather than a person, and labelling AI-generated content. The heaviest obligations, the ones for so-called high-risk systems, have been deferred to 2 December 2027 and 2 August 2028.
Norway, where we write from, is an exception. There the regulation has not yet been incorporated into the EEA Agreement, and the national act has not been passed. That illustrates a point which applies to everyone: which rules reach you depends on where you and your supplier are based.
The questions to ask your supplier
Before you adopt a tool, ask a few simple questions. They are not technical, and you do not need to be an expert to judge the answers.
- Where is the data stored and processed? Inside the EEA, or elsewhere? Storage outside the EEA is not unlawful in itself, but it requires its own legal basis. Ask the supplier to name it.
- Is the data used to train the model? Or is it kept separate and used only for you? This belongs in the contract, not only in a marketing page.
- Who has access, and how long is the data kept? Ask specifically about deletion and about sub-processors.
- Is there a data processing agreement? If the supplier processes personal data on your behalf, a written agreement is a requirement under Article 28(3) of the GDPR. It is not a formality you can skip.
- Can they document their security work? For example through a certification such as ISO 27001, or an open overview of sub-processors and security measures.
Good suppliers answer this clearly and have the answers ready. If the answers are vague or hard to get hold of, that in itself tells you something.
A note on storage outside the EEA
Many AI tools are American. Transfers of personal data to the United States currently rely mainly on the EU's adequacy decision, the EU-US Data Privacy Framework. It remains valid. The EU's General Court dismissed a challenge to it in September 2025, but that ruling has been appealed, and in July 2026 the European Data Protection Board asked the European Commission to reassess whether the basis still holds.
Our view is that this is not something to lose sleep over. But it is a good reason to know where your supplier stands, and to ask what the plan is if the framework changes.
How the buyer sees it
This is not only your problem. Public buyers are now getting fairly detailed guidance on the same questions. The example below comes from Norway, where we write from.
DFØ, the Norwegian Agency for Public and Financial Management, writes in its guidance on security and information handling in the use of AI that organisations must classify information before it is fed into an AI service. Open and internal information can in many cases be processed in commercial cloud services, sensitive information requires a separate assessment, and classified information should not be entered into commercial AI services at all. Information covered by a duty of confidentiality falls in the same category. The guidance also says that data should as a starting point be processed within the EEA, and that the organisation must actively check that the service is in fact set up that way.
The way we read it, that is worth noting if you are a supplier. The customer on the other side of the table is being asked to think through exactly the same questions you should be putting to your own supplier. Having the answers ready before anyone asks is an advantage. Buyers in other countries work to similar principles, though the specific guidance varies and national practice differs.
What you should do
- Write a simple internal rule of thumb. What can go into which tools? It is unfair to ask each bid writer to make that judgement alone every time.
- Check whether a data processing agreement exists for the tools you already use. Often the answer is no, simply because nobody has asked.
- Keep the documentation in one place. Certifications, procedures and agreements should sit together, ready to be pulled out.
- Ask the supplier directly. You are entitled to an answer you can understand, and you do not have to accept one you cannot.
In closing
You do not need to be a data security expert to make good choices in public procurement. It is enough to know which rules actually apply, ask the right questions, and choose tools that answer them clearly.
At Cobrief we have published our own documentation openly in a Trust Center, so you can check us on the same points we are asking you to check others on. Do get in touch if you would like to talk about using AI in tender work with a clear conscience.