Your Staff Are Probably Already Using AI – Does Your Business Have an AI Policy?

AI is already changing the way people work. But does your business know how employees are using it? Here's why every business should consider an AI policy.

Your employees may already be using AI

Here's a question for business owners:

Do you know your employees are using AI?

  • You might assume the answer is no.
  • But perhaps someone is using ChatGPT to write an email?
  • Or someone else is using Microsoft Copilot to summarise a meeting.
  • Another employee is asking Claude to analyse a spreadsheet.
  • Someone might even be uploading a document to an AI service because they want it rewritten more professionally.

None of those people may be doing anything malicious.They may simply be trying to save time.

But if your business hasn't provided any guidance, you may not know what information is being entered into these systems and they could be makingyou non-complient and possible open to fines.

That's why businesses increasingly need to think about an AI policy.

AI isn't the problem

Let's make one thing clear.

AI can be incredibly useful for businesses.

Used properly, it can help employees:

  • Draft emails
  • Summarise information
  • Brainstorm ideas
  • Analyse data
  • Create first drafts
  • Organise information
  • Automate repetitive tasks
  • Create reports
  • Improve productivity

WYSIWYG is already helping businesses successfully implement solutions such as Microsoft Copilot to work smarter.  We also runs training and webinars around Microsoft 365 and productivity.

The problem isn't employees using AI.

The problem is employees using AI without direction from the business.

What is shadow AI?

You may have heard the term "shadow IT".

It describes employees using technology that hasn't been formally approved or managed by the business.

AI has created a new version of this:

Shadow AI.

An employee finds an AI tool online.

They create an account.

They start using it for work.

Nobody in the business knows.

The IT team doesn't know.

Management doesn't know.

And there may be no policy explaining what information can and cannot be entered.

That's where problems can start.

What information should employees never put into an AI tool?

This is one of the most important questions your AI policy should answer.

For example, employees should be cautious about entering:

  • Customer personal information
  • Employee personal information
  • Passwords
  • Authentication codes
  • Confidential contracts
  • Financial information
  • Private business information
  • Commercially sensitive information
  • Unpublished intellectual property
  • Sensitive client documents

The exact rules will depend on the AI service and your company's requirements.

The Information Commissioner's Office provides guidance for organisations on AI and data protection, including how UK GDPR principles apply when organisations use AI systems.

The key point is simple:

If you wouldn't normally send the information to an unknown third party, don't casually paste it into an AI tool.

What about Microsoft Copilot?

This is where things become particularly interesting for Microsoft 365 businesses.

Microsoft Copilot is designed to work within your Microsoft ecosystem and can provide powerful assistance across applications and organisational information.

But that doesn't mean businesses should simply switch it on without thinking about their data.

Before introducing AI across your organisation, you should understand:

What information can employees access?

Are permissions correctly configured?

Are old SharePoint sites still accessible?

Can employees access documents they no longer need?

Are sensitive files appropriately protected?

AI can make finding information easier.

That's exactly why good information management becomes even more important as AI adoption increases.

AI could expose a problem that already exists

Imagine your company has a SharePoint site containing documents from the last ten years.

Over time, permissions have become messy.

People have moved departments.

Employees have left.

Old groups haven't been removed.

Documents have been shared widely.

Nobody has really reviewed the structure.

Then you introduce an AI assistant.

Suddenly, employees are presented with information across the company that shouldn't have access to, and previously didn't realise they did have access to.

The AI hasn't necessarily created the original security problem.

It has simply made the underlying permissions issue more visible.

That's why AI adoption should go hand in hand with:

  • Permission reviews
  • Data classification
  • Good SharePoint structure
  • Sensible access controls
  • User training
Top-down view of a diverse team collaborating around a wooden table with laptops, tablets, notebooks, and coffee cups.

Your AI policy doesn't need to be complicated

Some businesses hear "AI policy" and imagine a huge legal document.

It doesn't have to be.

A useful policy can be straightforward.

It should answer practical questions such as:

Which AI tools can employees use?

For example:

  • Microsoft Copilot
  • Approved business AI tools
  • Other tools specifically authorised by the company

What can employees use AI for?

Examples might include:

  • Drafting
  • Brainstorming
  • Summarising
  • Research
  • Productivity

What information can they enter?

Clearly define what is acceptable and what isn't.

What must employees check?

AI can produce incorrect information.

Employees remain responsible for checking the output before using it.

Who is responsible?

Employees should know where to go if they're unsure.

AI can be confidently wrong

There's another important issue.

AI can produce information that sounds convincing but is incorrect.

It might:

  • Invent information
  • Misinterpret data
  • Produce outdated information
  • Make incorrect calculations
  • Misrepresent sources

This is particularly important if AI is being used for customer communications, financial information, legal material or technical decisions.

Your AI policy should therefore make one principle clear:

AI output should be reviewed by a person .

AI security is becoming a bigger issue

AI isn't just changing productivity.

It's changing cyber security too.

The NCSC and other Five Eyes agencies have warned that AI is rapidly transforming cyber risk.

That means businesses have two related responsibilities:

Use AI safely.

And:

Protect themselves from AI-enabled attacks.

Those two things should be considered together.

Seven things your AI policy should cover

If you're creating an AI policy for your business, start with these seven areas.

  1. Approved AI tools

Tell employees which services they are allowed to use.

  1. Confidential information

Clearly explain what information must never be entered into AI systems.

  1. Personal data

Make sure employees understand the implications of entering personal information into AI tools.

  1. Human review

Make it clear that AI-generated information needs to be checked.

  1. Intellectual property

Consider how AI-generated content interacts with your company's intellectual property and third-party material.

  1. Security

Explain how employees should protect accounts and report suspicious AI-related activity.

  1. Training

Don't simply publish a policy and expect everyone to understand it.

Show employees what good AI use looks like.

Hand holding a magnifying glass over a document icon with a checkmark, symbolizing document verification or audit.

Don't ban AI. Manage it.

Trying to completely ban AI may not be realistic.

Employees will use these tools because they're useful.

Instead, businesses should provide clear boundaries.

Think of it like any other piece of technology.

You wouldn't give every employee unrestricted access to your financial systems and say:

"Just use your common sense."

AI deserves the same level of consideration.

AI should be part of your wider IT strategy

The best approach isn't to treat AI as a completely separate subject.

It should fit into your wider technology strategy.

That means considering:

Cyber security

Are accounts and devices protected?

Data protection

Do you understand what information is being used?

Microsoft 365

Are permissions and data structures properly managed?

User training

Do employees know how to use AI safely?

Productivity

Are you using AI to solve genuine business problems?

Governance

Do you know which AI tools are being used and why?

Is your business ready for AI?

AI is moving quickly.

The businesses that benefit most aren't necessarily the ones using the most AI.

They're the ones using it purposefully and safely.

If your employees are already experimenting with AI, that's not necessarily a problem.

It could actually be a great opportunity.

The next step is to understand what's happening, establish some sensible rules and identify where AI can genuinely improve the way your business works.

We help businesses across Kent and Medway make better use of Microsoft 365, Copilot and modern technology while keeping security and practical business needs in mind. Our user training is designed around the systems businesses actually use, rather than generic technology lessons.

If you're wondering how AI could work for your business, or how to introduce it safely, Ask WYSIWYG.

Download our Free AI Policy Template

Managed Services

Take a look at our Managed services to see how we can help you

Laptop with speech bubble

Microsoft 365 Solutions

we work with our clients to find out how their business and them work, and shape 365 to help them

User Training

Empowering your team to work smarter, faster, and more securely. Making your business more efficient and profitable.