How can I let staff use AI without losing control of company information?
15 August 2026
How can I let staff use AI without losing control of company information?
You can let staff use AI safely if the business controls the accounts, the data and the workflow. For most UK SMEs, the right first move is not banning AI. It is moving people away from personal free accounts and into approved tools with clear rules about client data, personal data, contracts, financial records, passwords, files and decisions that need human review.
What does losing control actually mean?
Losing control does not usually start with a dramatic breach. It starts with ordinary staff trying to work faster. Someone pastes a client email into a free chatbot to tidy the wording. A manager uploads a spreadsheet to summarise sales performance. A project lead asks an AI meeting tool to transcribe a call that includes a pricing discussion. A browser extension gets installed because it looked helpful. None of those actions feel reckless in the moment, but together they create shadow AI: tools the business has not approved, accounts the business does not own, data flows nobody has checked and outputs nobody is responsible for.
The risk is bigger than model training. Staff may expose personal data, contract terms, passwords, financial records, strategy documents, supplier prices, complaints, HR notes or customer details to services with unclear settings. They may also create new information risks by relying on unverified summaries, copying hallucinated clauses into proposals or letting AI make decisions that should stay with a trained person.
The UK government's Cyber Security Breaches Survey 2025 reported that 43% of UK businesses identified a cyber breach or attack in the previous 12 months, with phishing experienced by 85% of businesses that had a breach or attack. That matters because AI use does not sit outside cyber risk. It adds new places where information can leak, credentials can be targeted and staff can be tricked. Source: Cyber Security Breaches Survey 2025.
Start with approved accounts, not personal AI use
The simplest control is account ownership. If staff use personal AI accounts for work, the business cannot reliably manage retention settings, audit access, remove access when someone leaves, apply single sign-on, check what data is being uploaded or enforce acceptable use. That is why the first step should be an approved-tool list with managed business accounts. For many SMEs, that may mean Microsoft 365 Copilot for teams already working in Microsoft, ChatGPT Team or Enterprise for general reasoning and drafting, Gemini for Google Workspace users, or a controlled internal assistant connected only to approved knowledge sources.
Do not approve a tool just because it is well known. Check four things before it touches company information: who owns the account, whether your data is used for model training by default, where admin controls live and whether you can remove access quickly. Also check file upload behaviour. A tool that is fine for rewriting public marketing copy may be wrong for contracts, HR notes or customer records.
Put the rules in plain English. A useful version is: approved AI tools may be used for low-risk drafting, summarising, planning and analysis. Personal accounts may not be used for client data, personal data, contracts, financial records, credentials or confidential company material. New tools need approval before use. That gives staff a route to say yes safely instead of guessing in private.
Classify data so staff know what can go into AI
Most AI policies fail because they say things like 'do not upload sensitive data' without defining what sensitive means in daily work. Your team needs a short data classification they can remember. Use three buckets. Green data is public or low-risk information, such as a published web page, public product description or anonymised example. Amber data is internal business information, such as process notes, meeting summaries, non-sensitive reports and draft documents. Red data is restricted information, such as client personal data, employee records, contracts, financial records, passwords, API keys, legal advice, complaints, supplier pricing and anything covered by confidentiality.
The rule can be simple: green can go into approved AI tools. Amber can go into approved business tools if there is a clear work reason and the output is reviewed. Red does not go into general AI tools unless the owner has approved the specific workflow, the tool settings have been checked and there is a record of what is being processed.
This aligns with the ICO's AI and data protection guidance, which emphasises accountability, governance, transparency, lawfulness, fairness, accuracy, security, data minimisation and individual rights when AI involves personal data. In plain English, if AI touches personal data, you still need to explain why you are using it, minimise what you use, protect it and be able to justify the decision. Source: ICO guidance on AI and data protection.
Control access before connecting AI to business systems
The moment AI can read files, email, CRM notes, tickets, accounts data or project boards, the risk changes. A chatbot that answers from public information is one thing. An assistant with broad access to SharePoint, Google Drive, HubSpot, Xero, Slack or your inbox is another. The goal is not to avoid connected AI forever. The goal is to connect it narrowly, test it, and widen access only after it proves useful and safe.
Start with read-only access wherever possible. Give the AI one job, one dataset and one owner. For example, let it summarise support tickets from the last 30 days, but do not let it email customers. Let it draft a CRM follow-up note, but require a salesperson to approve it. Let it search approved policy documents, but do not let it browse every folder in the company drive. Keep permissions tied to existing roles. If a junior employee should not see payroll information, their AI assistant should not be able to retrieve it either.
The UK government's AI Cyber Security Code of Practice sets out baseline principles for securing AI systems and the organisations that develop and deploy them. It is aimed at a broader audience than small businesses, but the practical lesson is relevant: treat AI systems as part of your security environment, not as harmless productivity toys. Source: AI Cyber Security Code of Practice.
What should managers check before approving AI use?
Managers do not need to become AI engineers, but they do need a basic approval checklist. Before a team uses AI in a workflow, ask: what problem does this solve, what data will be used, which approved tool will process it, who owns the output, what can go wrong, how will a human review it and how do we stop the workflow if it causes problems? If nobody can answer those questions, the workflow is not ready.
Use a lightweight approval record. It can be a spreadsheet or project-management form with columns for tool, owner, purpose, data category, permissions, review step, risk level and next review date. Review high-use workflows monthly at first. You are looking for drift: staff using a tool for more sensitive data than originally approved, outputs being copied without review, costs creeping up, or a manual workaround becoming an unofficial business process.
Training matters here. A 60-minute policy briefing is not enough. Staff need examples from their own work: what they can paste, what they must anonymise, what needs approval, what outputs must be checked and what to do if they accidentally share the wrong information. The honest cost is usually small compared with the risk. For an SME, budget a few hours of manager time per team plus £500 to £1,500 for practical external support if you need help designing the rules and training.
When this does NOT apply
This approach is not enough for safety-critical decisions, regulated advice, employment decisions, credit decisions, medical triage, legal conclusions or anything where an automated output could materially affect someone's rights, money, health, job or access to a service. In those situations, AI may still help with preparation, summarisation or retrieval, but final judgement should stay with a qualified person and the process needs stronger governance.
It also does not apply if your business has no basic cyber hygiene. If passwords are shared, leavers still have access, files are stored in personal drives, multi-factor authentication is missing and nobody owns data protection, adding AI will amplify existing weaknesses. Fix those basics first. AI governance cannot compensate for unmanaged systems.
Finally, do not use this as a way to monitor staff secretly or push responsibility onto them. If the business approves AI tools, the business owns the risk. Staff need rules, training and support, but leadership needs to provide the approved tools, make the trade-offs and keep the policy current as products change.
Is This Right For You?
This is right for you if staff are already using ChatGPT, Copilot, Gemini or AI browser tools and you want a practical control model rather than a blanket ban. It also applies if you handle client files, personal data, contracts, sales records, operational reports or commercially sensitive information.
It is not right for you if you need formal regulated-sector assurance, safety-critical AI controls or enterprise security architecture. In those cases, use this as a starting point, then get specialist legal, data protection and cyber security advice before expanding access.
Frequently Asked Questions
Should I ban staff from using free AI tools at work?
Do not rely on a ban unless you can enforce it. A better first step is to approve safer business tools, explain what data cannot go into personal accounts and give staff a route to request new tools.
Can staff put client emails into ChatGPT?
Not into a personal or unmanaged account. Client emails may contain personal data, confidential information or commercial context. Use an approved business tool only if the data rules, settings and review process have been checked.
Do we need an AI usage policy?
Yes, but keep it short enough to use. Cover approved tools, banned data, review rules, new tool approval, ownership, incident reporting and examples of green, amber and red data.
Who should approve AI tools in a small business?
Usually the owner or operations lead, with input from whoever handles data protection, IT or finance. The approver should understand the business risk, not just the software feature list.
What should we do if someone has already pasted sensitive data into an AI tool?
Record what happened, identify the tool and account used, check whether deletion or opt-out options exist, assess whether personal data was involved, take data protection advice if needed and update training so it does not happen again.
Is Microsoft Copilot automatically safe because it is inside Microsoft 365?
No tool is automatically safe. Copilot can be a good option for Microsoft-first businesses, but it can also surface files users already have permission to see. Poor SharePoint permissions become an AI problem very quickly.
How often should we review AI access?
Review new workflows after two to four weeks, then quarterly once stable. Also review immediately when staff leave, permissions change, a tool changes its terms or the workflow starts using more sensitive data.