AI tools such as ChatGPT and Microsoft Copilot are now part of everyday business life, helping employees draft emails, summarise documents, analyse information and speed up routine tasks.
Used properly, they can save significant time. But every business needs to answer one important question: what information should employees be allowed to put into AI tools?
Banning AI altogether is unlikely to work. A better approach is to set clear rules around what can, and cannot, be shared.
In This Guide
The problem isn’t AI. It’s the data.
The biggest risk is often what an employee puts into an AI tool. They may paste in a customer email containing contact and account details, upload an HR document with sensitive personal information, or share a confidential proposal containing pricing.
They are simply trying to work efficiently, but sensitive information has now entered an external service. That is why businesses need an AI acceptable-use policy, rather than telling staff to “be careful”.
What is safe to put into AI?
A simple starting point is to divide information into three categories: green, amber and red.
Green: Generally safe
Non-confidential information that would not cause a problem if shared externally, such as:
- Public website content and information
- Generic marketing ideas and brainstorming topics
- Draft social media posts
- General business questions
- Non-confidential writing and proofreading
Amber: Use caution
Internal information that is not highly sensitive but should not automatically be uploaded, including:
- Internal procedures, reports and correspondence
- Business plans and non-public project details
- Unpublished financial or supplier information
- Anonymised customer information
Ask whether the AI really needs the information. Removing names, addresses, account numbers and other identifiers can significantly reduce risk.
Red: Keep it out of unapproved AI tools
Some information should be off limits unless the organisation has approved the service and understands how the data is handled:
- Passwords, credentials and encryption keys
- Payment card or customer financial information
- Sensitive personal or disciplinary data
- Confidential legal documents, trade secrets and commercially sensitive information
- Information covered by contractual or regulatory restrictions
If you would not email the information to an unknown third party, do not paste it into an unapproved AI tool.
Is Microsoft Copilot secure?
Microsoft 365 Copilot is designed for business environments and can work with organisational data that a user already has permission to access.
That makes existing permissions more important than ever. If somebody can already access a sensitive file in SharePoint or OneDrive, Copilot may make it easier to find.
An AI rollout should therefore include a review of:
- Microsoft 365, SharePoint and OneDrive permissions
- Sensitive information and data retention
- Conditional Access and multi-factor authentication
- Data Loss Prevention policies
What about ChatGPT?
ChatGPT can also be suitable for business use. The key is the version, configuration and governance around it. OpenAI states that data from ChatGPT Business and Enterprise is not used to train its models by default.
Businesses should still control which accounts employees use, what they upload, who can access conversations, how information is retained, which integrations are enabled and whether appropriate contractual and data-processing arrangements are in place.
A business-grade AI service is only part of the solution. You also need governance.
Don’t forget UK GDPR
UK data-protection law applies when personal data is used in AI systems. Organisations need to understand what is being processed, why it is needed and whether the processing is lawful and appropriate.
Data minimisation, security, transparency and governance remain essential. A useful question is: “Do I need to include this personal information at all?” If not, remove it.
Give employees rules, not fear
A blanket “Do not use ChatGPT” message is likely to be ignored. Give employees simple, practical guidance instead.
Employees can:
- Use approved AI tools for drafting, rewriting and brainstorming
- Work with public or anonymised information
- Check AI-generated content before using it
Employees should not:
- Enter passwords, credentials or sensitive personal information
- Upload confidential documents or customer databases to unapproved services
- Use personal AI accounts for confidential company work
- Assume AI-generated information is accurate
AI output must always be reviewed by a human. It can sound convincing while being inaccurate or incomplete, so it should support, not replace, professional judgement.
Your MSP can help make AI safer
AI is not going away. The opportunity is to introduce it responsibly with a governance framework covering people, technology and data.
- Create an AI acceptable-use policy and approve suitable tools
- Review Microsoft 365 permissions and security controls
- Configure Copilot safely and check data-protection requirements
- Train employees and establish an approval process for new AI tools
- Monitor how AI is being adopted across the business
The aim is not to stop employees using AI. It is to help them use it productively without exposing sensitive business information.
The bottom line
AI can be one of the most useful productivity tools your business adopts, but it needs clear boundaries:
- Public information? Usually fine.
- Internal information? Think before you paste.
- Confidential or personal information? Keep it out unless the tool, use case and safeguards have been approved.
If your business is rolling out ChatGPT, Microsoft Copilot or another AI tool, now is the time to review your security, permissions and policies.
The question is not whether employees will use AI. It is whether your business is ready for them to use it safely.