Safe AI use: govern what your team is already doing
Your team already uses AI. The question is not whether to allow it, but with which tools, which data and which oversight. We bring order: we discover what is actually in use, define the rules and train the people who have to apply them.
The problem is not AI: it is that nobody knows what is leaving the company
AI adoption in companies has not followed the usual path of purchase, evaluation and rollout: it came in from the bottom, person by person, from personal accounts and without going through IT. The result is that almost no organisation can answer three basic questions today: which AI tools are in use, what information has been pasted into them, and who reviews their output before it reaches a client. Banning it does not work —it pushes usage to personal phones, where there is no visibility at all— and doing nothing does not either: every week more information leaves with no record. What works is governing it: discover the real usage, provide convenient approved alternatives, and put in writing which data never leaves.
What the service covers
- Shadow AI discovery: which AI tools are genuinely in use across the organisation, and from where
- Review of AI applications and agents connected to your Google Workspace or Microsoft 365 tenant, and their permissions
- Data classification by level, mapped to which tool may handle each level
- Drafting the AI usage policy, adapted to the team's real workflows
- Definition of the approval process for new tools, with response deadlines
- Employee training on safe use of AI assistants, with examples from the business itself
- Dedicated leadership session on risk, accountability and human oversight
- Review of retention and training settings in the tools you already pay for
How we approach it
- Discovery: We inventory real usage by combining network logs, connected OAuth applications, deployed extensions, subscription spend and an anonymous team survey.
- Risk classification by use case: We group findings by what they are used for, not by tool. The same assistant is minimal risk drafting emails and high risk screening CVs.
- Approved alternatives: For the most frequent legitimate cases we propose a corporate option at least as convenient. Without a substitute, usage returns to the personal account.
- Policy and process: We draft the AI usage policy with approved tools, the data that never leaves and who approves what, in a document people actually read.
- Training and rollout: We train the team with real examples from the business and leave onboarding material for new joiners. A policy without training does not change behaviour.
What you receive
- Inventory of AI usage across the organisation, with risk level per tool and use case
- Exposure report: what kind of information may have left, and through which route
- AI usage policy ready to approve and publish, adapted to your information classification
- One-page matrix of permitted data per tool, for the team to consult daily
- Employee training session: what may and may not be pasted into an AI assistant
- Leadership session on accountability, human oversight and regulatory fit
- Reusable onboarding material for new joiners
When this service makes sense
- Companies where the team already uses AI daily and no written rule exists
- Organisations that have rolled out Microsoft 365 Copilot or Gemini and want to control what it exposes to each user
- Firms, consultancies and companies under contractual confidentiality obligations with their clients
- Companies that need to enumerate their AI systems for an ENS or ISO 27001 audit
- Leadership teams considering banning AI who want to assess first what would be lost and gained
- Teams that have already had a scare: sensitive data pasted into a public chat
Frequently asked questions about safe AI use
Does this make me compliant with the AI Act?
It is its operational prerequisite, not full legal compliance. Without knowing which AI systems your organisation uses and for what, you cannot classify them by risk level or demonstrate human oversight to anyone. This service gives you that inventory and that control. Formal compliance with the regulation —classification, provider or deployer role, technical documentation— is our AI Act consulting service, and it builds on the work done here.
How long does it take and what does it ask of my team?
The assessment and the policy take around three weeks for a mid-sized organisation. The load on your team is concentrated in discovery: read-only access to review connected applications, and a few minutes from each person for the anonymous survey. Training runs as sessions of 45 to 90 minutes depending on the audience.
Are you going to ban the tools we already use?
That is not the goal. In most cases the outcome is the opposite: the tools already in use get formally approved, their retention and training settings get corrected, and only the type of data that must not go in is restricted. Banning without an alternative pushes usage to personal phones and makes visibility worse.
Does it work for a small company with no IT team?
Yes, and it is usually faster. In a small organisation the inventory closes within days and the policy fits on one page. What does not change with size is the risk: pasting a client contract into a public chatbot has the same impact in an eight-person company as in an eight-hundred-person one.
How is this different from auditing the security of our own AI system?
They are different things. This service governs your team's use of third-party AI tools. If what you have is your own product with a model, a customer-facing chatbot or a RAG pipeline, what you need is AI penetration testing, which attacks that system to find its vulnerabilities. Many companies end up needing both, but they solve different problems.