The firm's "second brain": turning know-how into a searchable asset.
By BoezioAI · Reading time: 9 minutes
Key points
- The real capital of a firm or company — precedents, opinions, templates, judgement criteria — lives scattered across archives and in people's heads: an intellectual asset that is neither transferred nor searchable.
- A "second brain" is a knowledge base built and maintained by AI: every document ingested is connected to the rest, and the value compounds.
- The method exists and is surprisingly accessible: a folder of text files, an AI agent that organises it, four recurring instructions.
- But for a professional firm or a company, DIY is a legal minefield: personal and sensitive data, professional secrecy, GDPR (fines up to 20 million euros or 4% of turnover), the AI Act and Italian Law 132/2025.
- The difference between a project and a risk is who builds it: engineering skills and AI-specialised legal skills are needed together.
Every professional firm and every company owns a second asset besides what appears on its balance sheet: thousands of opinions, pleadings, contracts, appraisals, decisive emails, meeting notes, judgement criteria matured over years of practice. It is the intellectual capital — what makes that organisation different from every other. And in most cases it is scattered: in folders nobody reopens, in paper archives, in the partners' memory. When a senior professional retires, when a colleague moves on, part of that capital leaves with them.
Generative AI now offers a concrete answer to this problem: the "second brain" — a second organisational mind, built and maintained by AI, which ingests the accumulated knowledge and returns it organised, connected and searchable.
1. What a second brain is (and why it is now possible)
The idea is not new — knowledge management systems have existed for decades — but they always failed on the same rock: someone had to feed and maintain them by hand. The novelty is that today that "someone" can be the AI. The method popularised by Andrej Karpathy (one of the fathers of modern AI, formerly OpenAI and Tesla) is disarmingly simple: a folder of plain text files serves as the archive; an AI agent reads, organises and maintains it; a rules document defines how the agent must ingest material, answer and perform maintenance.
The system has two spaces: the sources (all the raw material, never touched) and the wiki (the organised, linked pages the AI writes and updates). Daily work comes down to four gestures: feed it ("I added this opinion to the sources: read it, connect it to what already exists, update every page it touches"); ask it ("using only our archive, brief me on this topic and cite the pages you drew from"); find the gaps ("which topics recur in the sources but have no page yet?"); maintain it ("find contradictions between pages, broken links, outdated content").
📌 The rule that makes the difference: the tenth document is worth more than the first, because it has more to connect to. A second brain's value compounds: it grows with use, like interest on interest.
2. What it means for a firm or an SME
Applied to a professional or business organisation, the second brain changes the nature of know-how. The opinion issued three years ago on a similar question resurfaces in seconds, with updated references. The new colleague does not learn "by osmosis" over three years: they query the firm's method from day one. Quality stops depending on who happens to handle the file: everyone draws on the same asset, at the same depth. And the organisation discovers what it knows without knowing it — connections across matters, sectors and solutions that no individual memory can hold together.
3. Why DIY is a legal minefield
So much for the enthusiasm. Now the part the tutorials do not mention: a firm's or company's material is not an archive of articles read on the web. Opinions, files and contracts contain names, personal histories, health data, financial situations, judicial data. Building a second brain "as per tutorial" — uploading everything to a consumer tool, with no preliminary analysis — means exposure to very concrete risks:
- GDPR and sensitive data — opinions and files contain personal data and often special categories (Art. 9: health, judicial data, orientations). Processing them in AI systems without a legal basis, contractual guarantees and security measures exposes you to fines of up to 20 million euros or 4% of worldwide turnover.
- Professional secrecy — uploading client files to consumer platforms, with no guarantees on where data ends up or whether it trains models, can amount to an ethics violation even before a regulatory one.
- No DPIA, no technical measures — an archive concentrating all of a firm's knowledge is, by definition, high-risk processing: it requires an impact assessment, pseudonymisation or anonymisation where possible, access controls, encryption, traceability. A DIY second brain on a laptop is also a single, magnificent point of failure in a data breach.
- AI Act and Law 132/2025 — professional use of AI requires adequate staff training (AI Act, Art. 4) and, for intellectual professions, compliance with Art. 13 of Law 132/2025: AI as support only, prevalence of intellectual work, informed clients.
- Intellectual property and retention — who owns the wiki? Under which rules is it retained, exported, destroyed? What happens when a partner leaves? Questions to design upfront, not discover afterwards.
⚠️ The second brain paradox: the better the system is built — the more knowledge it concentrates — the more valuable it becomes and, at the same time, the more critical it becomes to protect it. Value and risk grow in the same proportion.
4. How to do it properly
None of this means giving up: it means designing it professionally. A properly built second brain includes: selection and cleansing of material (what goes in, what stays out, what must be pseudonymised or anonymised); professional environments with contractual guarantees on data processing and exclusion from model training; role-based access controls and query traceability; written governance rules (who feeds it, who verifies, how clients are informed); and supervised maintenance, because an archive that ages unchecked produces outdated answers with the same confidence as correct ones.
It is a project that requires two skill sets together: people who can build the system (engineering, security, prompt engineering) and people who know what the law allows you to put inside it (GDPR, professional ethics, AI Act). When the two do not talk to each other, the result is either a useless system or a dangerous one.
Frequently asked questions
Can I try it on my own with free tools?
For personal notes and public material, yes: it is an excellent exercise. For firm or company material — opinions, files, contracts — no: consumer versions do not offer the guarantees required by the GDPR and professional secrecy, and the sanction risk far outweighs the savings.
What should never go in?
Credentials and access keys, sensitive financial documents, special-category data not necessary for the purpose, and in general anything that would not pass a minimisation test: it is a knowledge base, not a safe.
How long does it take?
The technical infrastructure takes days. The value comes with constant feeding: after a month the system starts showing connections nobody had seen. The professional version — with data cleansing, compliant environments and governance rules — is a project of a few weeks.
BoezioAI: the second brain, built right
Searchable knowledge bases are one of our engineering services: we design them with the team's AI engineers and Legal Tech lawyers, so that your firm's or company's intellectual capital becomes an advantage — in full compliance with the GDPR, professional secrecy and the AI Act.
Let's talk: info@boezioai.com · +39 329 7413254
The method described in the first part is freely inspired by the "LLM wiki" system published by Andrej Karpathy. Legal references: Reg. (EU) 2016/679 (GDPR), Arts. 9, 32-35 and 83; Reg. (EU) 2024/1689 (AI Act), Art. 4; Italian Law no. 132 of 23 September 2025, Art. 13.