Usage map
Department by department, we learn which AI services are in use and which categories of information flow into them.
AI is new; the dangers are not. Confidential text typed into a prompt, reliance on a third-party platform, accountability for data belonging to customers. Add the EU AI Act, which among other things expects anyone using AI at work to have a reasonable grasp of how it behaves.
Department by department, we learn which AI services are in use and which categories of information flow into them.
What is fine to paste, what is off limits and which tools are sanctioned. A single page with examples instead of a ban nobody follows.
Microsoft 365 Copilot, ChatGPT Enterprise or another business edition. Before choosing, we check in the contract terms whether the provider may use your data for model training.
Copilot surfaces everything a user has permission to open. So before it goes live we rein in oversharing across SharePoint, OneDrive and Teams and apply sensitivity labels.
A data processing agreement, confirmation of where the provider handles the data, and a paper trail for anything that leaves the EEA.
Occasionally data may not leave your estate under any circumstances. For that, a model hosted in your own Azure tenant in an EU region.
Step one is an honest look at reality. Prohibition without a replacement fails; staff carry on and simply go quiet about it.
Defender for Cloud Apps shows us traffic to AI services, and conversations with each team fill in the gaps. Actual use often exceeds what the directors expect.
We put the rules in writing and explain them through real cases from your industry in a brief live online workshop.
Your people get a sanctioned assistant; tools outside the list can be blocked or shown with a warning banner.
We track usage, adjust the rules and update the list of permitted services, since the market shifts quickly.
Whoever processes the personal data, the legal responsibility remains yours. Paste a debtor list with PESEL numbers into a free chatbot and you have disclosed personal data to an outside party, perhaps beyond the EEA and with no processing contract. Get the rules agreed before any software is switched on.
Ones sold under business terms in which the vendor promises not to use your content for training, and where somebody on your side has genuinely read that promise. Free consumer tiers do not belong on the list, however handy they are.
Details of identifiable individuals, PESEL numbers, medical records, contract terms agreed with clients, source code of internal systems, passwords and API keys. Keeping the list this short is precisely what makes it memorable.
It works within the permissions you already have, and the terms of data processing, including location, are set out in Microsoft documentation worth reviewing with your DPO. The real weak point is oversharing: leave the payroll folder open to everyone and Copilot will cheerfully summarise salaries for whoever asks. Permissions get cleaned up before launch for exactly that reason.
Seldom. A business subscription to a hosted service, combined with sensible rules, covers most needs. Hosting your own becomes worthwhile when law or a client agreement bars data from leaving your systems, as can happen at a law firm or a clinic.
The regulation expects an adequate level of AI literacy among staff but does not prescribe one format. A sensible approach is a short session tailored to how each department uses the tools, along with a record of who has completed it. Confirm the scope of the duty for your company with a lawyer.
Explain what you hope AI will do for you and how sensitive the information is. Our proposal could be anything from a written policy to a model hosted in your own cloud.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.