Nobody can list the AI tools in use
Teams choose assistants, transcription services, design tools and browser extensions independently, with no shared view of what is active.
Somebody is drafting emails in ChatGPT. Another person is summarising a customer document. A third has built a genuinely useful workflow in a personal account. The answer is not panic or a blanket ban—it is visibility, approved tools and clear boundaries around business information.
People are normally trying to save time or improve their work. The risk appears when the business cannot see the tools, information, accounts or decisions involved.
Teams choose assistants, transcription services, design tools and browser extensions independently, with no shared view of what is active.
Prompts, uploaded files and useful workflows sit inside accounts the business does not own, configure or recover when somebody leaves.
Each person decides whether a customer email, contract, employee detail or internal document is safe to enter into a tool.
Some staff verify facts and sources carefully. Others copy a confident-looking answer directly into work the business stands behind.
Information security and acceptable-use rules were written before generative AI, leaving managers and staff to interpret old wording alone.
Useful prompts and workflows are not documented, tested or shared because there is no approved route for turning an experiment into a business process.
The first job is visibility, not enforcement. Understand the current behaviour, then make the safer approved route easier to follow.
If people believe honesty will get a useful tool banned, the most important AI activity will stay invisible.
Run a short, non-punitive discovery exercise covering tools, accounts, repeated tasks, information used and the results people find genuinely valuable.
Separate public material from internal, customer, employee, contractual and otherwise sensitive information, then define which categories can enter each approved tool.
Find the uses that save meaningful time, can be checked by a person and deserve to move from an individual habit into a supported workflow.
UK Government research identifies data security and output accuracy among the common challenges businesses face when deploying AI. The NCSC also recommends integrating security into AI projects and workflows from the beginning rather than treating it as a later technical check.
Sources: UK AI Adoption Research and NCSC AI security guidance.
| What changes | Unmanaged use | Approved approach |
|---|---|---|
| Visibility | People experiment privately | Current tools and useful scenarios are understood |
| Accounts | Business work sits in personal services | Approved work uses managed accounts where appropriate |
| Information | Every person judges sensitivity alone | Simple categories explain what can be shared where |
| Outputs | Checking depends on individual habit | Human review matches the risk and purpose of the work |
| Learning | Good workflows leave with the individual | Useful patterns are documented, tested and improved |
The goal is not a policy nobody reads. It is a small set of decisions that helps people use AI productively without guessing about information or accountability.
Name approved tools, prohibited information, acceptable uses, human-review expectations and the person who answers questions.
Keep ownership, access and offboarding under business control where an experiment has become part of normal work.
Use short feedback sessions to find new risks, share useful workflows and update the rules as tools and business needs change.
The right route depends on whether you need a complete workplace approach, want to bring AI into Microsoft 365 or have a wider concern about protecting business information.
Understand current use, set practical guardrails and turn the best opportunity into an owned, measurable plan.
Build your AI approach → Use a managed work platformPrepare permissions, information and people before bringing AI into Outlook, Teams, Word and the wider Microsoft 365 environment.
Explore Copilot support → Protect the wider environmentBring accounts, devices, email and data under one maintained security approach when AI reveals a broader ownership gap.
Explore managed security →You can protect business information without shutting down the useful experimentation already happening inside the team.
A blanket ban often drives useful experimentation further out of sight. A better first response is to understand current use, identify the information that must be protected, name approved tools and accounts, and make human review and accountability clear.
Not without understanding the tool, account, contract and information involved. Your rules should explain which categories of information are prohibited, which approved services may be used for defined work and who can authorise an exception when the answer is unclear.
It should name the approved tools and accounts, prohibited information, acceptable uses, required human checking, ownership of final decisions, how copyright or source concerns are handled, and where people ask questions or report a problem.
Business-managed accounts make ownership, access, offboarding, configuration and support easier to control. They also reduce the chance that useful prompts, workflows or business information become tied to a personal account the company cannot manage.
Start with a non-punitive discovery exercise focused on learning: which tasks people are improving, which tools they chose, what information they use and where they feel uncertain. Keep the rules short, make approved routes easier than unofficial ones and review them as the tools change.
Owen Williams · Managing Director
Book a relaxed 30-minute call with Owen. Bring the tools people mention, the information concerns and the experiments worth keeping, and we will help you create a safer approved route.
01449 798119 · enquiries@westviewit.co.uk