Compliance

Law 09-08 and AI: Can You Trust an Intelligent Assistant With Your QHSE Data?

Équipe Betterfly

The meeting where IT said “no”

This scene is playing out in many Moroccan companies right now. The QHSE manager walks in excited: they’ve seen a demo of an AI assistant that answers questions about non-conformities in plain language, recalculates indicators, and drafts management-review reports. Magic. They want it connected to the QHSE database by next week.

Then the DPO raises a hand. “This data contains employee names, workplace accidents, customer complaints. Where exactly will it be sent? To whom? For what purpose? And will this vendor use it to train their AI?” The room goes quiet. IT is already thinking about the CNDP and Law 09-08.

These questions aren’t a roadblock. They’re the right questions. And the good news is that they have concrete answers — provided you know which ones to demand from your vendor.

What Law 09-08 actually says (and why AI doesn’t change the principles)

Law 09-08 on the protection of personal data, enforced by the CNDP (the National Commission for the control of Personal Data Protection), has governed all processing of personal data in Morocco for years. Your QHSE data almost always contains it: the identity of injured persons, the authors of non-conformities, the signatories of actions, occupational-health data.

Plugging an AI into it doesn’t create a new legal regime. It re-activates principles you already know:

  • Purpose: data is used only for its intended purpose (running your QHSE), nothing else.
  • Proportionality: you only process what is necessary.
  • Security and confidentiality: the data controller must ensure the data doesn’t leak.
  • Governing transfers and processors: if a vendor touches your data, its role must be set out contractually.

If you work with European clients, layer GDPR on top — same principles, same demands on processors. So the question isn’t “am I allowed to use AI on my QHSE data?” The question is: “under what technical and contractual conditions?”

The two risks everyone misjudges

When AI and data come up, two fears recur. They deserve a clear answer.

Risk #1: “My data will train the vendor’s AI”

This is the number-one fear, and it’s legitimate: if your non-conformities were used to train a model, they could in theory resurface elsewhere. The answer to demand is binary.

At Betterfly, no AI model is trained on customer data. The assistant relies on already pre-trained models, accessed through the Azure OpenAI API, governed by a DPA (data processing agreement). Your business data — the data already in your database — is only injected as context at the moment you ask a question (this is the RAG principle: retrieve, then generate). It serves to formulate the answer, in that moment, and then feeds no learning. The machine reads your file to answer you; it doesn’t memorize it into its weights.

Risk #2: “Another customer’s data will mix with mine”

The DPO’s second nightmare: a lateral leak, where one customer’s question surfaces another’s data. The answer here is architectural, not a promise of good behavior.

Betterfly is built on strict per-client isolation: a database-per-tenant architecture. Each organization has its own database. One client’s data never leaks to another, because they don’t share space. This isn’t a setting — it’s the foundation.

Where your data actually lives

A simple question, often forgotten: physically, where is my data stored? For many consumer-grade AI tools, the honest answer is “not quite sure, somewhere in the United States.”

Betterfly is hosted on Microsoft Azure, France Central region — nearby infrastructure, in Europe, on a platform that is itself certified. Exchanges are encrypted in transit (TLS). This matters for your transfer assessment under Law 09-08 and GDPR: you can document where the data goes and under what framework.

The human stays in control — by design

The EU AI Act sets two requirements every cautious buyer should already apply, even outside the EU: human oversight (Article 14) and transparency about the fact that you’re interacting with an AI (Article 50, applicable around December 2026).

This is exactly how BetterAssist is positioned: an AI copilot, never an autonomous agent. The formula we stand behind, word for word:

“BetterAssist augments the expert, it does not replace them. The machine proposes and proves; the human decides and commits.”

Concretely, the human stays in the loop at sensitive points — publishing, signing, closing an action. The AI signs nothing, validates nothing on its own. And every answer from the assistant carries a trace: an identifier, the sources cited, the model used, the cost. This traceability is continuously expanding — we don’t claim it covers everything yet, but the principle is built in from the start.

Let’s be honest: what a QHSE AI should not promise you

A serious vendor also tells you what its AI doesn’t do. Here are our red lines, which you can repeat verbatim to an auditor:

  • BetterAssist is not a replacement for the auditor.
  • It does not certify your compliance.
  • It does not guarantee the absence of non-conformity.
  • It is not the final decision-maker.
  • It does not provide legal advice.

On the data-analysis side, the same rigor applies: with BetterChart, you ask a question in plain language, the AI produces a validated SQL query on your own data, and the result is a chart that is computed, not invented. If the information doesn’t exist, the assistant would rather say “I don’t know” than hallucinate a figure. An AI that knows how to abstain is an AI a DPO can trust.

The 7 questions to ask your vendor before you sign

Print this list. Put it to any QHSE AI vendor. The answers should be clear, written, and contractual.

  1. Do you train your models on my data? (The right answer: no, and it’s in the contract.)
  2. Where is my data hosted, and under what legal framework? (Region, host certifications, AI provider’s DPA.)
  3. How do you guarantee my data won’t mix with another customer’s? (Look for “per-client / per-database isolation.”)
  4. Who validates the AI’s outputs before they commit my company? (The human must stay in the loop at sensitive points.)
  5. Can I trace what the AI answered, from which sources and with which model? (Demand traceability — and honestly ask how far it goes.)
  6. Are you yourselves certified on AI security and governance? (ISO 27001, ISO 42001: a certified vendor lives what it sells.)
  7. What does your AI not do? (If the vendor can’t answer, be wary.)

The vendor applies to itself what it sells you

This is arguably the best guarantee. Betterfly is published by E-Quality Engineering (EQE), a company certified ISO/IEC 27001:2022 (information security) and ISO/IEC 42001:2023 (artificial intelligence management). The very requirements the platform helps operationalize — AI governance, human oversight, traceability, data protection — we live internally. We live what we sell.

And for those who manage their own AI compliance, Betterfly includes an ISO 42001 module: tracking of Annex A controls, the statement of applicability (SoA), and a direct link between each control and its evidence.

So trusting your QHSE data to an intelligent assistant isn’t a matter of faith. It’s a matter of verifiable safeguards. Ask the right questions, demand the right answers — and AI becomes a compliance asset, not one more risk.


Going further:

  • See our Trust & Security page: hosting, per-client isolation, no training on your data, and concrete commitments
  • Discover BetterAssist, the audit-grade AI copilot that augments the expert without ever replacing them
  • #Loi 09-08
  • #CNDP
  • #RGPD
  • #Intelligence artificielle
  • #Protection des données
  • #AI Act