AI without risk: how QazCloud builds secure frameworks and teaches businesses to work with technology
On September 8, President Kassym-Jomart Tokayev delivered his Address to the Nation titled “Kazakhstan in the Age of Artificial Intelligence: pressing tasks and their solutions through digital transformation.” He emphasized that artificial intelligence and digitalization should become the key drivers of the country’s development.
On September 8, President Kassym-Jomart Tokayev delivered his Address to the Nation titled “Kazakhstan in the Age of Artificial Intelligence: pressing tasks and their solutions through digital transformation.” He emphasized that artificial intelligence and digitalization should become the key drivers of the country’s development.
We spoke with Sabina Nurlybayeva, Head of the AI Projects Support Department at QazCloud, to find out how these ideas are already being implemented in practice: how secure frameworks for AI adoption are being built, which risks need to be considered, and why employee training is becoming a key success factor.
– Is it true that QazCloud has a department dedicated to AI and security?
Yes, that’s right. We have formed two strategically important areas. The first is information security: colleagues develop regulations, monitor compliance, and track in real time any actions that could harm the company. The second is artificial intelligence: we develop AI projects, support internal initiatives, and build products for clients. For us, these are not just separate teams — they are the foundation of the company’s future, where technology and security go hand in hand.
– What tasks does this department solve within the company and for clients?
Our main goal is to create solutions that truly address business needs. Inside QazCloud, this means building a secure environment for working with AI, and externally — creating products that help clients adopt technology without fear of losing data or facing excessive costs.
Today we are developing a flagship platform that addresses several tasks at once:
- provides a secure framework for working with AI;
- simplifies the management and support of models;
- reduces customers’ costs of maintaining a staff of AI system administrators.
We take the routine off employees’ shoulders — we automate processes, create user-friendly interfaces, and implement “smart” tools. Companies can focus on their business instead of figuring out how to build and maintain complex AI infrastructure.
– What are the main risks if employees carelessly use AI services like ChatGPT?
First of all, the risk of sensitive data leakage. And it’s not only about “classified” documents: even a simple correspondence or work instruction may contain more information than it seems at first glance.
– Are there real cases when employees accidentally leaked important data into open AI platforms?
Yes, such cases exist, though I must stress — not in our company.
In Kazakhstan and worldwide, there have been instances where employees uploaded source codes, financial reports, and internal guidelines to external AI platforms. The consequences were very serious: from reputational losses to multimillion-dollar damages.
– Why can even “ordinary” texts or files be dangerous if uploaded to AI?
Because every document carries traces. These may be metadata, employee names, names of internal systems, process chains. For an outsider, it looks like a collection of small details, but for an attacker, it’s a puzzle that reveals the business picture.
– What is a greater threat to a company — external hackers or its own untrained employees?
I would say these are equally dangerous risks.
External attacks are becoming more sophisticated, but most often it’s human error that opens the door to cybercriminals. An unskilled query or file upload can cost a company as much as an external attack.
– How do you explain to employees that a single wrong request in AI can cost the company millions?
“It all depends on knowledge.” Mistakes happen when a person does not understand how the technology works. That is why we build a system of regular training: workshops, practical cases, real-life examples. We try not to intimidate but to show the real value of the right approach.
– What mistakes do people most often make when working with AI?
- Uploading documents into open services “for convenience.”
- Trusting AI results without critical analysis.
- Believing that AI is always right and knows better.
- Not understanding usage boundaries: what can be entered and what is strictly prohibited.
– What measures does QazCloud implement to ensure employees use AI properly and safely?
We build an internal secure framework, introduce regulations, and most importantly — train our clients’ employees. We have information security products that allow us to track leakage risks, as well as our own expertise in building protected AI platforms.
– How important is a security culture in a company? Can it be even more important than technology?
I am absolutely convinced that security culture is more important than any technology. You can build the most advanced systems, but if employees don’t understand why they are needed and how to use them, it’s all pointless. Without culture, these are just pretty boxes.
– Do you think all employees — from newcomers to top managers — should be trained in proper AI use?
Yes, absolutely. Otherwise, there is a “gap”: some know, others don’t. AI is a universal tool, and it is important that everyone — from interns to top managers — understands both its opportunities and risks.
– What technologies and practices will help companies use AI safely in the future?
- Closed corporate AI frameworks.
- Data labeling and classification systems.
- Zero-trust architecture.
- Automated monitoring tools and DLP systems.
- Regulations + continuous employee training.
– Can the human factor ever be completely eliminated, or is it always about risk mitigation?
It cannot be completely eliminated. The human factor has always existed and will continue to exist. Our task is to minimize risks by creating systems and conditions where mistakes are minimal and will not lead to catastrophic consequences.
– What would you advise businesses in Kazakhstan: how to start using AI without exposing themselves to threats?
Start simple: implement AI where risks are minimal but the effect is clear. At the same time, build culture and regulations. And most importantly — use secure corporate solutions rather than public services.
QazCloud is developing exactly such platforms, and we are ready to be a partner for businesses on this journey.
