Your Staff Are Probably Already Using AI. Do You Know What They're Putting Into It?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
A practical, calm starting point for UK SME owners who want to understand which AI tools staff already use, what work they use them for and what information goes into them. It explains Shadow AI without blame, then gives you a 10-minute discovery check, three simple rules and a sensible boundary between DIY governance and more formal help.
Ask a business owner, “Does your company use AI?” and you might hear: “Not really.” “We haven't bought Copilot.” “We're looking at it.” “Only a couple of people use ChatGPT.”
Ask the employees individually, “Have you used an AI tool for work during the last month?” and the answer may be different. Someone may have rewritten an email with ChatGPT, summarised a document with Claude, researched with Gemini, used Copilot inside Microsoft 365, transcribed a meeting, created a marketing image, analysed a spreadsheet or installed an AI browser extension.
None of that is necessarily bad. Some of it may be extremely useful. The problem begins when the business does not know it is happening — or does not know what information is being put into the tools.
The first AI question is not “What should we buy?”
It is: “What AI are we already using?”
You cannot set a sensible boundary around tools, accounts or data that nobody has thought to list. Start with discovery, not a procurement exercise.
Welcome to Shadow AI
Shadow AI is the use of AI tools for work without the organisation necessarily approving, managing or sometimes even knowing about them. It might be a personal account, a free account, an AI browser extension, a third-party meeting assistant or a new AI button inside software the business already pays for.
Shadow AI is not automatically malicious. Most employees are not trying to bypass security. They are trying to work faster, write something better, summarise a long document, solve a problem or avoid repetitive work. The tool is useful, so they use it.
If your AI policy is simply “don't use AI”, there is a reasonable chance you have created Shadow AI rather than stopped AI.
That does not mean every use is acceptable. It means the first job is to make current use visible enough to assess. The existing Shadow AI guide covers deeper discovery methods such as a formal amnesty, browser and single-sign-on review, expense checks and an ongoing register.
Read next: Shadow AI — The Tools Your Team Isn't Telling You About →
The real question is what goes in
The risk is not simply that someone used ChatGPT, Copilot, Gemini or Claude. Context matters. “Give me five ideas for our Christmas party” is a different activity from “Here is our customer database — analyse it.”
| A lower-risk starting point | Pause before entering this |
|---|---|
| Ideas for a team event | Customer names, contact details or account history |
| Rewrite generic public-facing copy | A customer complaint containing personal or confidential details |
| Summarise a public report | A contract, legal letter or non-disclosure agreement |
| Help with a formula using made-up figures | Real payroll, pricing, banking or financial information |
| Brainstorm a process using a fictional example | Passwords, credentials, source code or security information |
Before a business approves a use, it should understand the information involved and the service receiving it. That includes the provider's current terms, the account type, relevant privacy controls, access, retention and any connected services. Providers do not all treat submitted data identically, and a setting or product promise can change.
As a practical starting list, ask whether staff are entering:
- Customer or prospect information
- Personal data or employee information
- Contracts, legal correspondence or client material
- Financial information, pricing or business plans
- Commercially confidential information or intellectual property
- Security information, passwords or other credentials
- Source code, meeting transcripts or customer complaints
Passwords, API keys and recovery codes do not become safe because an AI tool says it will help. Keep credentials in the system or password manager they belong to.
Free account or business account?
The same AI brand can appear through very different routes. A member of staff may be using a personal account, a free account, a company-managed workspace, a business or enterprise subscription, or an AI feature built into another application.
| Account route | Questions for the business |
|---|---|
| Personal or free account | Who owns it? Can access be removed when someone leaves? Which terms and data controls apply? |
| Company-managed account | Who administers it? Can the business manage users, access, shared history, settings and deletion? |
| Business or enterprise subscription | What contractual protections, retention terms, access controls and audit features apply to this exact plan? |
| AI inside another application | What information can the application send to the AI feature, and which administrators can control it? |
These routes are not necessarily equivalent. An employee signing in to a free consumer service with a work email address has not automatically created a company-managed deployment. Conversely, a managed service is not automatically suitable for every task. The information, purpose and controls still need to fit together.
Meeting bots are AI too
A business may say, “We don't use AI,” while every Teams or Zoom meeting has transcription, automated notes, a summary, action extraction or a third-party meeting assistant. These features can be genuinely useful, particularly when people need an accessible record of a discussion.
They still deserve a place in your AI inventory. Ask:
- What is being recorded or transcribed?
- Do participants know, and is the meeting purpose clear?
- Where is the recording, transcript or summary stored?
- Who can access it, and how long is it retained?
- Could confidential or customer information be included?
- Who checks whether an important summary is accurate?
Where personal data is involved, signpost the relevant ICO guidance and take advice on the circumstances that apply to your organisation. This article is not legal advice.
ICO guidance on AI and data protection →
Start by asking people, not by policing them
You do not need to start with a software audit. Start by asking people, and ask in a way that is likely to produce an honest answer.
Bad question: “Is anyone using unauthorised AI?” If employees think they are about to be disciplined, they have a strong reason to tell you nothing.
A better opening question
“We're trying to understand how AI could help the business and make sure we're using it sensibly. Which AI tools have you used for work during the last month?”
This frames the exercise as discovery and support as well as risk management. You are more likely to learn what is actually happening, including the useful problems people have already found a way to solve.
The 10-minute AI Check
Ask everyone these three questions
- 1Which AI tools have you used for work in the last 30 days?
- 2What do you use them for?
- 3What information do you put into them?
Examples might include ChatGPT, Copilot, Gemini, Claude, Perplexity, meeting assistants, writing tools, image generators, AI browser extensions and AI features inside other software. This is an illustrative list, not an endorsement.
| Tool | Used for | Data entered | Company controlled? |
|---|---|---|---|
| Example: meeting assistant | Notes and actions | Meeting transcript | Yes / No / Unsure |
Congratulations. You have just started an AI discovery exercise. You do not need a consultant, a new platform or a 40-page policy to take this first step.
The completed table gives you something much more useful than an adoption percentage. It shows the tools, the work, the information and the gap between personal use and company control. If it reveals more than expected, treat that as useful knowledge rather than evidence that people have failed.
Now set three rules
Do not turn the result into a 40-page AI policy. For a small business starting from nothing, establish three basic questions in plain English:
- 1Which tools are approved? Staff should know which AI services and account types they can use for work.
- 2What information must not be entered? Define sensitive and confidential information for your organisation, with examples people recognise.
- 3What must a human check? AI-generated content should not automatically become business truth. Keep appropriate human review for customer advice, quotes, contracts, legal or financial information, HR decisions, security decisions and important factual claims.
The right controls depend on the business and the use case. A public marketing brainstorm and a customer decision do not need the same approval threshold.
AI can be confidently wrong
AI tools can produce incorrect facts, invented references, outdated information, misleading summaries and confidently worded mistakes. “AI wrote it” is not quality assurance.
- Ask the person using the output to check important claims against a reliable source.
- Keep a human decision-maker responsible for consequential work.
- Treat meeting summaries and extracted actions as drafts until someone confirms them.
- Give staff a route to ask for help when an answer looks plausible but cannot be verified.
What about Microsoft Copilot?
Many IT Club readers use Microsoft 365, so Copilot may already be part of the conversation. Microsoft says Microsoft Copilot operates within existing permissions and access controls, and its enterprise data protection commitments apply to organisational use under the relevant product terms. That is useful, but the exact product, licence and configuration matter.
Buying Copilot does not automatically create AI governance. The organisation still needs to consider permissions, data access, staff training, appropriate use, human checking and information governance. If Microsoft 365 content is overshared already, a tool that can help people find information does not fix the oversharing.
Copilot can be governed more centrally than a personal free account, but a business licence is not a substitute for deciding what staff may do with the information they can access.
Microsoft — Enterprise data protection in Microsoft 365 Copilot →
Do not block the good stuff
AI can genuinely help SMEs with drafting, summarising, research, brainstorming, administration, data analysis, meeting notes, customer communication and process automation. The objective is not to stop AI. It is to use AI deliberately.
Good AI governance should make safe use easier
Give staff an approved route that is quick enough to use, examples of information that must stay out, and a clear answer to “who do I ask?” If the safe way is always the slowest way, people will work around it.
Can everyone answer these five questions?
Five questions every member of staff should be able to answer
- Which AI tools can I use?
- What information can I put into them?
- What information must I not put into them?
- When must I check AI output?
- Who do I ask if I am unsure?
If people cannot answer these, you have found your first AI governance job.
Remember AI inside existing software
An AI inventory should not only ask which AI websites people visit. AI features may now be inside systems the business already uses:
- Microsoft 365 and Google Workspace
- CRM and helpdesk systems
- Accounting and finance platforms
- Cyber-security products
- Marketing and design tools
- Recruitment software
- Meeting, note-taking and transcription tools
Ask a second question: “Which of our existing systems now contain AI features?” Include those tools in the same simple inventory, even if nobody thinks of them as an AI purchase.
When the DIY check is enough
For a small organisation with simple AI use, this exercise may genuinely be enough to get started. You may simply need a short approved-tools list, basic data rules, human checking and an occasional review when tools or work change.
You do not automatically need to buy an AI consultancy project. The value of the first conversation is that it gives you a clearer basis for deciding what needs more attention.
When it gets more complicated
More formal help may make sense where customer or personal data is involved, many AI tools are already in use, AI is built into important processes, AI influences significant decisions, staff handle regulated or sensitive information, nobody knows where company data is going, or the organisation wants to deploy AI systematically.
If your 10-minute check uncovers more AI than you expected, Altitude AI can help you map what is already being used, identify practical opportunities and put sensible governance around it. That is an optional next step, not a reason to skip the useful DIY exercise.
Not sure whether an AI tool is safe to use with your business data? Use the existing Ask the IT Club Advisor route for a practical first question.
Read: AI Privacy Is Becoming a Competitive Advantage →
Read: The Free AI Account That Cost a Client Relationship →
Read: Microsoft Copilot: One App, Many AI Tools →
Back to Technology Intelligence →
Sources and further reading
These sources were checked on 30 August 2026. Guidance, product features, settings and terms change, so check the current source and your own circumstances before relying on a specific control. This article is general information for UK businesses, not legal advice.
ICO — Guidance on AI and data protection →
ICO — How should we assess security and data minimisation in AI? →
ICO — How do we ensure transparency in AI? →
NCSC — AI and cyber security: what you need to know →
NCSC — ChatGPT and large language models: what's the risk? →
UK Government — AI regulation: a pro-innovation approach →
Microsoft — Enterprise data protection in Microsoft 365 Copilot →
Plain-English Takeaway
The first AI governance question is not always what your business should buy. It is what your people are already using, what they use it for, what information they enter and who controls the account. Start with a no-blame 10-minute discovery exercise, set three plain-English rules — approved tools, information that must stay out and human checking — and make useful AI easier to use safely. This is general information for UK businesses, not legal advice.
Related Articles
Microsoft Is Combining Its Copilot Apps — What Changes for You?
Microsoft is moving Copilot towards one simpler app, but one front door does not mean one account, one data pool, one licence or one universal Copilot experience. Here is what UK users and businesses need to know.
Read articleDoes Your AI Keep Your Business Data in the UK?
A UK storage setting does not automatically mean UK-only AI processing. This practical guide maps where business AI data may be stored, processed, logged and passed to connected services across Microsoft 365 Copilot, ChatGPT, Claude and Gemini.
Read articleAI Privacy Is Becoming a Competitive Advantage
The business AI question is changing from 'Can it do this?' to 'What happens to the data it needs?' This independent UK guide explains training defaults, retention, residency, connectors, account types, shadow AI and the controls that make useful adoption possible.
Read article